diff --git a/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json b/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json index 3d80f58d2e5..e4e2f04aacf 100644 --- a/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json +++ b/advisories/github-reviewed/2024/09/GHSA-j8gh-87rx-c7w9/GHSA-j8gh-87rx-c7w9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8gh-87rx-c7w9", - "modified": "2024-09-18T15:41:14Z", + "modified": "2024-09-19T03:30:31Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-45496" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/openshift/openshift-controller-manager/commit/3af3628103f9ddc3b825e6e5243ec58e85311046" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6691" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45496" diff --git a/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json b/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json index 240f2a0c5e2..80a400f01ab 100644 --- a/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json +++ b/advisories/github-reviewed/2024/09/GHSA-qqv8-ph7f-h3f7/GHSA-qqv8-ph7f-h3f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqv8-ph7f-h3f7", - "modified": "2024-09-18T15:42:03Z", + "modified": "2024-09-19T03:30:31Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-7387" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/openshift/builder/commit/0b62633adfa2836465202bc851885e078ec888d1" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6691" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7387" diff --git a/advisories/unreviewed/2022/05/GHSA-jcvj-vhj2-vgmw/GHSA-jcvj-vhj2-vgmw.json b/advisories/unreviewed/2022/05/GHSA-jcvj-vhj2-vgmw/GHSA-jcvj-vhj2-vgmw.json index 6c766740542..b125e80e2d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcvj-vhj2-vgmw/GHSA-jcvj-vhj2-vgmw.json +++ b/advisories/unreviewed/2022/05/GHSA-jcvj-vhj2-vgmw/GHSA-jcvj-vhj2-vgmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcvj-vhj2-vgmw", - "modified": "2022-05-24T17:08:24Z", + "modified": "2024-09-19T03:30:30Z", "published": "2022-05-24T17:08:24Z", "aliases": [ "CVE-2020-0618" ], "details": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rfrh-3q7r-m8g9/GHSA-rfrh-3q7r-m8g9.json b/advisories/unreviewed/2022/05/GHSA-rfrh-3q7r-m8g9/GHSA-rfrh-3q7r-m8g9.json index 6548b9f7cb4..c83d5473697 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfrh-3q7r-m8g9/GHSA-rfrh-3q7r-m8g9.json +++ b/advisories/unreviewed/2022/05/GHSA-rfrh-3q7r-m8g9/GHSA-rfrh-3q7r-m8g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfrh-3q7r-m8g9", - "modified": "2022-05-24T17:23:27Z", + "modified": "2024-09-19T03:30:30Z", "published": "2022-05-24T17:23:27Z", "aliases": [ "CVE-2020-14644" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json index 411562ab705..2a1ff0f61cf 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json +++ b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-294" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json b/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json index 4129916ee06..6a10cf3d884 100644 --- a/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json +++ b/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9387-xrfr-3wfr", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-19T03:30:31Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2023-41610" ], "details": "Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-256" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json b/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json index 043421ee34a..a69c7234943 100644 --- a/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json +++ b/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8mr-6p9f-7c7x", - "modified": "2024-09-12T21:32:03Z", + "modified": "2024-09-19T03:30:30Z", "published": "2024-09-12T21:32:03Z", "aliases": [ "CVE-2024-7961" ], "details": "A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json b/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json index ff057a52209..e4f7092c3a9 100644 --- a/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json +++ b/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qj4x-mh6f-mw42", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-19T03:30:30Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-8533" ], "details": "A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json index 8ada3fbd9bc..9236303e9f0 100644 --- a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json +++ b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-89", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json b/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json index 08c26a8717c..f7bfb5a037b 100644 --- a/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json +++ b/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj5f-4vpp-mxhf", - "modified": "2024-09-12T21:32:03Z", + "modified": "2024-09-19T03:30:30Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-7960" ], "details": "The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"