Publish Advisories

GHSA-3fm6-6429-pc94
GHSA-3jgh-cx2h-h5xp
GHSA-64v9-jgpj-cjqg
GHSA-77qj-2xp7-f745
GHSA-8vr8-mrh4-728w
GHSA-987w-wp8x-h99m
GHSA-9xww-4cjx-6w55
GHSA-cgf3-4cm8-wh3p
GHSA-q7fg-xj64-qmm7
GHSA-wg9r-cvfj-5cg2
This commit is contained in:
advisory-database[bot]
2024-12-16 06:32:11 +00:00
parent b3fec174de
commit abbaca9dee
10 changed files with 324 additions and 0 deletions
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3fm6-6429-pc94",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:43Z",
"aliases": [
"CVE-2024-53376"
],
"details": "CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53376"
},
{
"type": "WEB",
"url": "https://github.com/ThottySploity/CVE-2024-53376"
},
{
"type": "WEB",
"url": "https://github.com/ThottySploity/CVE-2024-53376/blob/aa306187323bd1127d56803cb34cac8820b61484/cyberpanel.py#L70"
},
{
"type": "WEB",
"url": "https://thottysploity.github.io/posts/cve-2024-53376"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T04:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jgh-cx2h-h5xp",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:43Z",
"aliases": [
"CVE-2024-56084"
],
"details": "An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56084"
},
{
"type": "WEB",
"url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137632418845-Remote-Code-Execution-while-creating-Universal-Normalizer"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:07Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64v9-jgpj-cjqg",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-5333"
],
"details": "The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5333"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:08Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77qj-2xp7-f745",
"modified": "2024-12-16T06:30:43Z",
"published": "2024-12-16T06:30:43Z",
"aliases": [
"CVE-2024-8116"
],
"details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8116"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2666216"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480509"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T05:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vr8-mrh4-728w",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-56087"
],
"details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56087"
},
{
"type": "WEB",
"url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137697881885-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard-Queries"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:07Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-987w-wp8x-h99m",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-56112"
],
"details": "CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56112"
},
{
"type": "WEB",
"url": "https://github.com/usmannasir/cyberpanel/commit/f0cf648c7851c96c36bb0c390d13e60931f45900"
},
{
"type": "WEB",
"url": "https://cyberpanel.net"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:07Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xww-4cjx-6w55",
"modified": "2024-12-16T06:30:43Z",
"published": "2024-12-16T06:30:43Z",
"aliases": [
"CVE-2024-8650"
],
"details": "An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8650"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2705909"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/486300"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T05:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgf3-4cm8-wh3p",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-56086"
],
"details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56086"
},
{
"type": "WEB",
"url": "https://servicedesk.logpoint.com/hc/en-us/articles/22136886421277-Remote-Code-Execution-while-creating-Report-Templates"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:07Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q7fg-xj64-qmm7",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-56085"
],
"details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56085"
},
{
"type": "WEB",
"url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137660393757-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:07Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wg9r-cvfj-5cg2",
"modified": "2024-12-16T06:30:44Z",
"published": "2024-12-16T06:30:44Z",
"aliases": [
"CVE-2024-11841"
],
"details": "The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11841"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/e344c722-c9b3-4527-a50d-50cdf07ebace"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T06:15:05Z"
}
}