mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2c3h-gr5x-3fh2",
|
||||
"modified": "2024-05-01T18:30:35Z",
|
||||
"modified": "2024-05-07T06:30:35Z",
|
||||
"published": "2024-02-21T09:31:00Z",
|
||||
"aliases": [
|
||||
"CVE-2023-42843"
|
||||
@@ -18,6 +18,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42843"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/HT213981"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-62qm-vc7f-rm93",
|
||||
"modified": "2024-05-01T18:30:36Z",
|
||||
"modified": "2024-05-07T06:30:35Z",
|
||||
"published": "2024-03-08T03:31:25Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23254"
|
||||
@@ -18,6 +18,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23254"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/HT214081"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6cvp-282g-6jp8",
|
||||
"modified": "2024-05-01T18:30:37Z",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-03-28T18:30:47Z",
|
||||
"aliases": [
|
||||
"CVE-2023-42950"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42950"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/HT214035"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jprr-pf4r-gvp5",
|
||||
"modified": "2024-05-01T18:30:37Z",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-03-28T18:30:47Z",
|
||||
"aliases": [
|
||||
"CVE-2023-42956"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42956"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/HT214035"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ppgm-9w39-cx97",
|
||||
"modified": "2024-05-01T18:30:36Z",
|
||||
"modified": "2024-05-07T06:30:35Z",
|
||||
"published": "2024-03-08T03:31:25Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23284"
|
||||
@@ -26,6 +26,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qc99-8rmf-q4mv",
|
||||
"modified": "2024-05-01T18:30:36Z",
|
||||
"modified": "2024-05-07T06:30:35Z",
|
||||
"published": "2024-03-08T03:31:25Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23280"
|
||||
@@ -26,6 +26,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xrrw-7rr2-829v",
|
||||
"modified": "2024-05-01T18:30:36Z",
|
||||
"modified": "2024-05-07T06:30:35Z",
|
||||
"published": "2024-03-08T03:31:25Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23263"
|
||||
@@ -26,6 +26,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-34vc-vhj3-rw45",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22472"
|
||||
],
|
||||
"details": "\nA buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution\n\nThis issue affects all versions of Silicon Labs 500 Series SDK prior to v6.85.2\n\nrunning on Silicon Labs 500 series Z-wave devices.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22472"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://community.silabs.com/068Vm000004rZwm"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T06:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-423h-mr5w-x796",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20859"
|
||||
],
|
||||
"details": "Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20859"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:49Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5cp5-vw87-7438",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20868"
|
||||
],
|
||||
"details": "Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20868"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7hfh-v896-8423",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20871"
|
||||
],
|
||||
"details": "Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20871"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8vh3-cqvx-p653",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20855"
|
||||
],
|
||||
"details": "Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20855"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:48Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-992p-cx4j-cc56",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20869"
|
||||
],
|
||||
"details": "Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20869"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9x5v-3vg8-q3c9",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20866"
|
||||
],
|
||||
"details": "Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20866"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ggv3-6xpg-23p3",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20867"
|
||||
],
|
||||
"details": "Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20867"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j33j-2cp2-2wjw",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20862"
|
||||
],
|
||||
"details": "Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20862"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j89p-fgqw-hjm3",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20864"
|
||||
],
|
||||
"details": "Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20864"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jcv7-6v4q-4m7x",
|
||||
"modified": "2024-05-07T03:30:35Z",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-06T21:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3661"
|
||||
@@ -29,6 +29,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://news.ycombinator.com/item?id=40279632"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://tunnelvisionbug.com"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m7gx-pf5v-mw6f",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20865"
|
||||
],
|
||||
"details": "Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20865"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T05:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mr2f-mm92-fppw",
|
||||
"modified": "2024-05-07T06:30:36Z",
|
||||
"published": "2024-05-07T06:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4186"
|
||||
],
|
||||
"details": "The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4186"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/browser/edwiser-bridge/tags/3.0.4/includes/class-eb-user-manager.php#L1571"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/changeset/3081961/edwiser-bridge#file1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6969d281-f280-4714-9859-38ac66e9cc60?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-07T06:15:09Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user