Publish Advisories

GHSA-25c8-p796-jg6r
GHSA-p57v-gv7q-4xfm
GHSA-p8rx-fwgq-rh2f
GHSA-h3hv-63q5-jgpr
GHSA-5mfx-4wcx-rv27
GHSA-fr44-546p-7xcp
GHSA-4vrx-8phj-x3mg
GHSA-5jhg-px89-wqm9
GHSA-66xx-c9r9-f474
GHSA-rvgq-w6rq-jcjp
This commit is contained in:
advisory-database[bot]
2024-06-03 18:33:13 +00:00
parent 98f38fc356
commit b37e87840d
10 changed files with 161 additions and 9 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25c8-p796-jg6r",
"modified": "2023-12-22T22:30:33Z",
"modified": "2024-06-03T18:31:17Z",
"published": "2023-07-11T22:45:20Z",
"aliases": [
"CVE-2023-33170"
@@ -212,7 +212,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8rx-fwgq-rh2f",
"modified": "2023-08-09T13:15:38Z",
"modified": "2024-06-03T18:31:18Z",
"published": "2023-08-09T13:15:38Z",
"aliases": [
"CVE-2023-35390"
@@ -70,7 +70,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3hv-63q5-jgpr",
"modified": "2023-09-12T19:57:06Z",
"modified": "2024-06-03T18:31:18Z",
"published": "2023-09-12T19:57:06Z",
"aliases": [
"CVE-2023-36799"
@@ -300,7 +300,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mfx-4wcx-rv27",
"modified": "2023-10-18T20:55:13Z",
"modified": "2024-06-03T18:31:33Z",
"published": "2023-10-10T18:31:33Z",
"aliases": [
"CVE-2023-36414"
@@ -55,7 +55,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr44-546p-7xcp",
"modified": "2023-10-10T22:23:28Z",
"modified": "2024-06-03T18:31:15Z",
"published": "2023-10-10T22:23:28Z",
"aliases": [
"CVE-2023-36435"
@@ -78,6 +78,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-401"
],
"severity": "HIGH",
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vrx-8phj-x3mg",
"modified": "2024-06-03T18:30:50Z",
"published": "2024-06-03T18:30:50Z",
"aliases": [
"CVE-2024-4540"
],
"details": "A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4540"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4540"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279303"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T16:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jhg-px89-wqm9",
"modified": "2024-06-03T18:30:50Z",
"published": "2024-06-03T18:30:50Z",
"aliases": [
"CVE-2024-36674"
],
"details": "LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36674"
},
{
"type": "WEB",
"url": "https://github.com/LyLme/lylme_spage/issues/91"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T16:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66xx-c9r9-f474",
"modified": "2024-06-03T18:30:50Z",
"published": "2024-06-03T18:30:50Z",
"aliases": [
"CVE-2024-4332"
],
"details": "An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional \"Auto-synchronize LDAP Users, Roles, and Groups\" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4332"
},
{
"type": "WEB",
"url": "https://www.fortra.com/security/advisory/fi-2024-006"
}
],
"database_specific": {
"cwe_ids": [
"CWE-303"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T18:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvgq-w6rq-jcjp",
"modified": "2024-06-03T18:30:50Z",
"published": "2024-06-03T18:30:50Z",
"aliases": [
"CVE-2024-37019"
],
"details": "Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37019"
},
{
"type": "WEB",
"url": "https://mender.io/blog/cve-2024-37019-account-takeover-using-saml"
},
{
"type": "WEB",
"url": "https://northern.tech"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T18:15:08Z"
}
}