From abbaca9dee470b6d15e2465a8f55bd981549cb39 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Dec 2024 06:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-3fm6-6429-pc94 GHSA-3jgh-cx2h-h5xp GHSA-64v9-jgpj-cjqg GHSA-77qj-2xp7-f745 GHSA-8vr8-mrh4-728w GHSA-987w-wp8x-h99m GHSA-9xww-4cjx-6w55 GHSA-cgf3-4cm8-wh3p GHSA-q7fg-xj64-qmm7 GHSA-wg9r-cvfj-5cg2 --- .../GHSA-3fm6-6429-pc94.json | 37 +++++++++++++++++ .../GHSA-3jgh-cx2h-h5xp.json | 29 ++++++++++++++ .../GHSA-64v9-jgpj-cjqg.json | 29 ++++++++++++++ .../GHSA-77qj-2xp7-f745.json | 40 +++++++++++++++++++ .../GHSA-8vr8-mrh4-728w.json | 29 ++++++++++++++ .../GHSA-987w-wp8x-h99m.json | 33 +++++++++++++++ .../GHSA-9xww-4cjx-6w55.json | 40 +++++++++++++++++++ .../GHSA-cgf3-4cm8-wh3p.json | 29 ++++++++++++++ .../GHSA-q7fg-xj64-qmm7.json | 29 ++++++++++++++ .../GHSA-wg9r-cvfj-5cg2.json | 29 ++++++++++++++ 10 files changed, 324 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-77qj-2xp7-f745/GHSA-77qj-2xp7-f745.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9xww-4cjx-6w55/GHSA-9xww-4cjx-6w55.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json diff --git a/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json b/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json new file mode 100644 index 00000000000..209c06c2751 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3fm6-6429-pc94/GHSA-3fm6-6429-pc94.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fm6-6429-pc94", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:43Z", + "aliases": [ + "CVE-2024-53376" + ], + "details": "CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53376" + }, + { + "type": "WEB", + "url": "https://github.com/ThottySploity/CVE-2024-53376" + }, + { + "type": "WEB", + "url": "https://github.com/ThottySploity/CVE-2024-53376/blob/aa306187323bd1127d56803cb34cac8820b61484/cyberpanel.py#L70" + }, + { + "type": "WEB", + "url": "https://thottysploity.github.io/posts/cve-2024-53376" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json b/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json new file mode 100644 index 00000000000..a8cedbb97cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jgh-cx2h-h5xp", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:43Z", + "aliases": [ + "CVE-2024-56084" + ], + "details": "An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56084" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137632418845-Remote-Code-Execution-while-creating-Universal-Normalizer" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json b/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json new file mode 100644 index 00000000000..e1456eccc95 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64v9-jgpj-cjqg", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-5333" + ], + "details": "The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5333" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77qj-2xp7-f745/GHSA-77qj-2xp7-f745.json b/advisories/unreviewed/2024/12/GHSA-77qj-2xp7-f745/GHSA-77qj-2xp7-f745.json new file mode 100644 index 00000000000..2f667237bd4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77qj-2xp7-f745/GHSA-77qj-2xp7-f745.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77qj-2xp7-f745", + "modified": "2024-12-16T06:30:43Z", + "published": "2024-12-16T06:30:43Z", + "aliases": [ + "CVE-2024-8116" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8116" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2666216" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480509" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json b/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json new file mode 100644 index 00000000000..149ef4af1f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vr8-mrh4-728w", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-56087" + ], + "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56087" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137697881885-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard-Queries" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json b/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json new file mode 100644 index 00000000000..ee0efba049f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-987w-wp8x-h99m", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-56112" + ], + "details": "CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56112" + }, + { + "type": "WEB", + "url": "https://github.com/usmannasir/cyberpanel/commit/f0cf648c7851c96c36bb0c390d13e60931f45900" + }, + { + "type": "WEB", + "url": "https://cyberpanel.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9xww-4cjx-6w55/GHSA-9xww-4cjx-6w55.json b/advisories/unreviewed/2024/12/GHSA-9xww-4cjx-6w55/GHSA-9xww-4cjx-6w55.json new file mode 100644 index 00000000000..923b9ae635a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xww-4cjx-6w55/GHSA-9xww-4cjx-6w55.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xww-4cjx-6w55", + "modified": "2024-12-16T06:30:43Z", + "published": "2024-12-16T06:30:43Z", + "aliases": [ + "CVE-2024-8650" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8650" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2705909" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/486300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json b/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json new file mode 100644 index 00000000000..c46f1216b38 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgf3-4cm8-wh3p", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-56086" + ], + "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56086" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/22136886421277-Remote-Code-Execution-while-creating-Report-Templates" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json b/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json new file mode 100644 index 00000000000..fad0062e1de --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7fg-xj64-qmm7", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-56085" + ], + "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56085" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/22137660393757-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json new file mode 100644 index 00000000000..39eb48d1ab7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg9r-cvfj-5cg2", + "modified": "2024-12-16T06:30:44Z", + "published": "2024-12-16T06:30:44Z", + "aliases": [ + "CVE-2024-11841" + ], + "details": "The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11841" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e344c722-c9b3-4527-a50d-50cdf07ebace" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T06:15:05Z" + } +} \ No newline at end of file