mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-25c8-p796-jg6r GHSA-p57v-gv7q-4xfm GHSA-p8rx-fwgq-rh2f GHSA-h3hv-63q5-jgpr GHSA-5mfx-4wcx-rv27 GHSA-fr44-546p-7xcp GHSA-4vrx-8phj-x3mg GHSA-5jhg-px89-wqm9 GHSA-66xx-c9r9-f474 GHSA-rvgq-w6rq-jcjp
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-25c8-p796-jg6r",
|
||||
"modified": "2023-12-22T22:30:33Z",
|
||||
"modified": "2024-06-03T18:31:17Z",
|
||||
"published": "2023-07-11T22:45:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33170"
|
||||
|
||||
@@ -212,7 +212,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p8rx-fwgq-rh2f",
|
||||
"modified": "2023-08-09T13:15:38Z",
|
||||
"modified": "2024-06-03T18:31:18Z",
|
||||
"published": "2023-08-09T13:15:38Z",
|
||||
"aliases": [
|
||||
"CVE-2023-35390"
|
||||
@@ -70,7 +70,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-77"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h3hv-63q5-jgpr",
|
||||
"modified": "2023-09-12T19:57:06Z",
|
||||
"modified": "2024-06-03T18:31:18Z",
|
||||
"published": "2023-09-12T19:57:06Z",
|
||||
"aliases": [
|
||||
"CVE-2023-36799"
|
||||
@@ -300,7 +300,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5mfx-4wcx-rv27",
|
||||
"modified": "2023-10-18T20:55:13Z",
|
||||
"modified": "2024-06-03T18:31:33Z",
|
||||
"published": "2023-10-10T18:31:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-36414"
|
||||
@@ -55,7 +55,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-77"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fr44-546p-7xcp",
|
||||
"modified": "2023-10-10T22:23:28Z",
|
||||
"modified": "2024-06-03T18:31:15Z",
|
||||
"published": "2023-10-10T22:23:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-36435"
|
||||
@@ -78,6 +78,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-400",
|
||||
"CWE-401"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4vrx-8phj-x3mg",
|
||||
"modified": "2024-06-03T18:30:50Z",
|
||||
"published": "2024-06-03T18:30:50Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4540"
|
||||
],
|
||||
"details": "A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4540"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-4540"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279303"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-200"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-03T16:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5jhg-px89-wqm9",
|
||||
"modified": "2024-06-03T18:30:50Z",
|
||||
"published": "2024-06-03T18:30:50Z",
|
||||
"aliases": [
|
||||
"CVE-2024-36674"
|
||||
],
|
||||
"details": "LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36674"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/LyLme/lylme_spage/issues/91"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-03T16:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-66xx-c9r9-f474",
|
||||
"modified": "2024-06-03T18:30:50Z",
|
||||
"published": "2024-06-03T18:30:50Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4332"
|
||||
],
|
||||
"details": "An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional \"Auto-synchronize LDAP Users, Roles, and Groups\" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4332"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.fortra.com/security/advisory/fi-2024-006"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-303"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-03T18:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rvgq-w6rq-jcjp",
|
||||
"modified": "2024-06-03T18:30:50Z",
|
||||
"published": "2024-06-03T18:30:50Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37019"
|
||||
],
|
||||
"details": "Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37019"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mender.io/blog/cve-2024-37019-account-takeover-using-saml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://northern.tech"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-03T18:15:08Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user