Publish Advisories

GHSA-j8gh-87rx-c7w9
GHSA-qqv8-ph7f-h3f7
GHSA-jcvj-vhj2-vgmw
GHSA-rfrh-3q7r-m8g9
GHSA-fmh4-p5x3-6hxh
GHSA-9387-xrfr-3wfr
GHSA-g8mr-6p9f-7c7x
GHSA-qj4x-mh6f-mw42
GHSA-v3gc-cff3-2vg3
GHSA-xj5f-4vpp-mxhf
This commit is contained in:
advisory-database[bot]
2024-09-19 03:32:01 +00:00
parent c10de02287
commit b1dec54d55
10 changed files with 46 additions and 15 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8gh-87rx-c7w9",
"modified": "2024-09-18T15:41:14Z",
"modified": "2024-09-19T03:30:31Z",
"published": "2024-09-17T00:31:06Z",
"aliases": [
"CVE-2024-45496"
@@ -48,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/openshift/openshift-controller-manager/commit/3af3628103f9ddc3b825e6e5243ec58e85311046"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6691"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45496"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qqv8-ph7f-h3f7",
"modified": "2024-09-18T15:42:03Z",
"modified": "2024-09-19T03:30:31Z",
"published": "2024-09-17T00:31:06Z",
"aliases": [
"CVE-2024-7387"
@@ -48,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/openshift/builder/commit/0b62633adfa2836465202bc851885e078ec888d1"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6691"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-7387"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcvj-vhj2-vgmw",
"modified": "2022-05-24T17:08:24Z",
"modified": "2024-09-19T03:30:30Z",
"published": "2022-05-24T17:08:24Z",
"aliases": [
"CVE-2020-0618"
],
"details": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfrh-3q7r-m8g9",
"modified": "2022-05-24T17:23:27Z",
"modified": "2024-09-19T03:30:30Z",
"published": "2022-05-24T17:23:27Z",
"aliases": [
"CVE-2020-14644"
],
"details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-294"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9387-xrfr-3wfr",
"modified": "2024-09-18T18:30:51Z",
"modified": "2024-09-19T03:30:31Z",
"published": "2024-09-18T18:30:51Z",
"aliases": [
"CVE-2023-41610"
],
"details": "Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-18T18:15:05Z"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8mr-6p9f-7c7x",
"modified": "2024-09-12T21:32:03Z",
"modified": "2024-09-19T03:30:30Z",
"published": "2024-09-12T21:32:03Z",
"aliases": [
"CVE-2024-7961"
],
"details": "A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qj4x-mh6f-mw42",
"modified": "2024-09-12T21:32:02Z",
"modified": "2024-09-19T03:30:30Z",
"published": "2024-09-12T21:32:02Z",
"aliases": [
"CVE-2024-8533"
],
"details": "A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -28,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89",
"CWE-94"
],
"severity": "CRITICAL",
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xj5f-4vpp-mxhf",
"modified": "2024-09-12T21:32:03Z",
"modified": "2024-09-19T03:30:30Z",
"published": "2024-09-12T21:32:02Z",
"aliases": [
"CVE-2024-7960"
],
"details": "The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"