From af4d1f174bfd4a8d2e94b14694e7b735d9f94f4c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 3 Jan 2025 09:32:31 +0000 Subject: [PATCH] Publish Advisories GHSA-9q42-6557-vqcf GHSA-mqhc-c63f-9fc8 GHSA-p83h-g6jw-gh8f GHSA-wv93-f9g8-qg2r --- .../GHSA-9q42-6557-vqcf.json | 40 +++++++++++++++++++ .../GHSA-mqhc-c63f-9fc8.json | 40 +++++++++++++++++++ .../GHSA-p83h-g6jw-gh8f.json | 6 ++- .../GHSA-wv93-f9g8-qg2r.json | 40 +++++++++++++++++++ 4 files changed, 125 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-9q42-6557-vqcf/GHSA-9q42-6557-vqcf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mqhc-c63f-9fc8/GHSA-mqhc-c63f-9fc8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wv93-f9g8-qg2r/GHSA-wv93-f9g8-qg2r.json diff --git a/advisories/unreviewed/2025/01/GHSA-9q42-6557-vqcf/GHSA-9q42-6557-vqcf.json b/advisories/unreviewed/2025/01/GHSA-9q42-6557-vqcf/GHSA-9q42-6557-vqcf.json new file mode 100644 index 00000000000..3556592699f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9q42-6557-vqcf/GHSA-9q42-6557-vqcf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q42-6557-vqcf", + "modified": "2025-01-03T09:30:47Z", + "published": "2025-01-03T09:30:47Z", + "aliases": [ + "CVE-2024-12132" + ], + "details": "The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create jobs for companies that are unaffiliated with the attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12132" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3210251" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d19ac6fc-029f-4f19-913e-e082acecc594?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mqhc-c63f-9fc8/GHSA-mqhc-c63f-9fc8.json b/advisories/unreviewed/2025/01/GHSA-mqhc-c63f-9fc8/GHSA-mqhc-c63f-9fc8.json new file mode 100644 index 00000000000..e19c83af882 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqhc-c63f-9fc8/GHSA-mqhc-c63f-9fc8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqhc-c63f-9fc8", + "modified": "2025-01-03T09:30:47Z", + "published": "2025-01-03T09:30:47Z", + "aliases": [ + "CVE-2024-9140" + ], + "details": "Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9140" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p83h-g6jw-gh8f/GHSA-p83h-g6jw-gh8f.json b/advisories/unreviewed/2025/01/GHSA-p83h-g6jw-gh8f/GHSA-p83h-g6jw-gh8f.json index 421c99f04ff..14510df48f9 100644 --- a/advisories/unreviewed/2025/01/GHSA-p83h-g6jw-gh8f/GHSA-p83h-g6jw-gh8f.json +++ b/advisories/unreviewed/2025/01/GHSA-p83h-g6jw-gh8f/GHSA-p83h-g6jw-gh8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p83h-g6jw-gh8f", - "modified": "2025-01-03T06:32:10Z", + "modified": "2025-01-03T09:30:47Z", "published": "2025-01-03T06:32:10Z", "aliases": [ "CVE-2025-22275" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22275" }, + { + "type": "WEB", + "url": "https://gitlab.com/gnachman/iterm2/-/wikis/SSH-Integration-Information-Leak" + }, { "type": "WEB", "url": "https://iterm2.com/downloads/stable/iTerm2-3_5_11.changelog" diff --git a/advisories/unreviewed/2025/01/GHSA-wv93-f9g8-qg2r/GHSA-wv93-f9g8-qg2r.json b/advisories/unreviewed/2025/01/GHSA-wv93-f9g8-qg2r/GHSA-wv93-f9g8-qg2r.json new file mode 100644 index 00000000000..d7ba07eb95b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wv93-f9g8-qg2r/GHSA-wv93-f9g8-qg2r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv93-f9g8-qg2r", + "modified": "2025-01-03T09:30:47Z", + "published": "2025-01-03T09:30:47Z", + "aliases": [ + "CVE-2024-9138" + ], + "details": "Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9138" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-656" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T09:15:06Z" + } +} \ No newline at end of file