Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-27 21:32:51 +00:00
parent 61a3aa6ac4
commit b31a057074
40 changed files with 402 additions and 55 deletions
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-449"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-80"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-176",
"CWE-74"
],
"severity": "CRITICAL",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h45c-25x4-6qq4",
"modified": "2024-04-04T06:42:54Z",
"modified": "2024-09-27T21:31:45Z",
"published": "2023-08-08T18:30:37Z",
"aliases": [
"CVE-2023-39217"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-80"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfj7-fpwh-q5vg",
"modified": "2023-12-14T18:30:18Z",
"modified": "2024-09-27T21:31:45Z",
"published": "2023-08-09T00:31:57Z",
"aliases": [
"CVE-2023-39214"
@@ -29,7 +29,8 @@
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-668"
"CWE-668",
"CWE-749"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-449",
"CWE-602"
],
"severity": "MODERATE",
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-347"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-449"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jmv-jvrv-qcv7",
"modified": "2023-11-15T00:31:07Z",
"modified": "2024-09-27T21:31:45Z",
"published": "2023-11-15T00:31:07Z",
"aliases": [
"CVE-2023-39203"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-789"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-280"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frh8-6qgg-hm8v",
"modified": "2023-12-14T00:30:26Z",
"modified": "2024-09-27T21:31:45Z",
"published": "2023-12-14T00:30:26Z",
"aliases": [
"CVE-2023-43585"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-449"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-449"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xvh-27wv-vhhr",
"modified": "2024-09-27T21:31:50Z",
"published": "2024-09-27T21:31:50Z",
"aliases": [
"CVE-2024-33368"
],
"details": "An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33368"
},
{
"type": "WEB",
"url": "https://gist.github.com/apple502j/54e0f80bfe082fd934e33970394adbb8"
},
{
"type": "WEB",
"url": "https://github.com/plasmoapp/RPShare"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-27T19:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c7c-8hj4-v9qh",
"modified": "2024-09-27T21:31:50Z",
"published": "2024-09-27T21:31:50Z",
"aliases": [
"CVE-2024-9160"
],
"details": "In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9160"
},
{
"type": "WEB",
"url": "https://portal.perforce.com/s/detail/a91PA000001SXN3YAO"
}
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-27T19:15:10Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hm7-x82q-99rh",
"modified": "2024-09-10T09:31:12Z",
"modified": "2024-09-27T21:31:49Z",
"published": "2024-09-10T09:31:12Z",
"aliases": [
"CVE-2024-8258"
],
"details": "Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mcf-rv8f-r9jf",
"modified": "2024-09-27T21:31:50Z",
"published": "2024-09-27T21:31:50Z",
"aliases": [
"CVE-2024-33369"
],
"details": "Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromConnection method in DownloadTask",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33369"
},
{
"type": "WEB",
"url": "https://gist.github.com/apple502j/54e0f80bfe082fd934e33970394adbb8"
},
{
"type": "WEB",
"url": "https://github.com/plasmoapp/RPShare"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-27T19:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p38-qv63-r35w",
"modified": "2024-09-27T00:31:04Z",
"modified": "2024-09-27T21:31:49Z",
"published": "2024-09-27T00:31:04Z",
"aliases": [
"CVE-2024-40507"
],
"details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-26T22:15:03Z"

Some files were not shown because too many files have changed in this diff Show More