diff --git a/advisories/github-reviewed/2023/07/GHSA-25c8-p796-jg6r/GHSA-25c8-p796-jg6r.json b/advisories/github-reviewed/2023/07/GHSA-25c8-p796-jg6r/GHSA-25c8-p796-jg6r.json index 4b154a90571..ceff773e39f 100644 --- a/advisories/github-reviewed/2023/07/GHSA-25c8-p796-jg6r/GHSA-25c8-p796-jg6r.json +++ b/advisories/github-reviewed/2023/07/GHSA-25c8-p796-jg6r/GHSA-25c8-p796-jg6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25c8-p796-jg6r", - "modified": "2023-12-22T22:30:33Z", + "modified": "2024-06-03T18:31:17Z", "published": "2023-07-11T22:45:20Z", "aliases": [ "CVE-2023-33170" diff --git a/advisories/github-reviewed/2023/08/GHSA-p57v-gv7q-4xfm/GHSA-p57v-gv7q-4xfm.json b/advisories/github-reviewed/2023/08/GHSA-p57v-gv7q-4xfm/GHSA-p57v-gv7q-4xfm.json index d97dccc12b8..aa219125b73 100644 --- a/advisories/github-reviewed/2023/08/GHSA-p57v-gv7q-4xfm/GHSA-p57v-gv7q-4xfm.json +++ b/advisories/github-reviewed/2023/08/GHSA-p57v-gv7q-4xfm/GHSA-p57v-gv7q-4xfm.json @@ -212,7 +212,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/08/GHSA-p8rx-fwgq-rh2f/GHSA-p8rx-fwgq-rh2f.json b/advisories/github-reviewed/2023/08/GHSA-p8rx-fwgq-rh2f/GHSA-p8rx-fwgq-rh2f.json index 4abceed0d95..5905fe01bc3 100644 --- a/advisories/github-reviewed/2023/08/GHSA-p8rx-fwgq-rh2f/GHSA-p8rx-fwgq-rh2f.json +++ b/advisories/github-reviewed/2023/08/GHSA-p8rx-fwgq-rh2f/GHSA-p8rx-fwgq-rh2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8rx-fwgq-rh2f", - "modified": "2023-08-09T13:15:38Z", + "modified": "2024-06-03T18:31:18Z", "published": "2023-08-09T13:15:38Z", "aliases": [ "CVE-2023-35390" @@ -70,7 +70,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/09/GHSA-h3hv-63q5-jgpr/GHSA-h3hv-63q5-jgpr.json b/advisories/github-reviewed/2023/09/GHSA-h3hv-63q5-jgpr/GHSA-h3hv-63q5-jgpr.json index 7cd15f3922c..bc8d8bb2480 100644 --- a/advisories/github-reviewed/2023/09/GHSA-h3hv-63q5-jgpr/GHSA-h3hv-63q5-jgpr.json +++ b/advisories/github-reviewed/2023/09/GHSA-h3hv-63q5-jgpr/GHSA-h3hv-63q5-jgpr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3hv-63q5-jgpr", - "modified": "2023-09-12T19:57:06Z", + "modified": "2024-06-03T18:31:18Z", "published": "2023-09-12T19:57:06Z", "aliases": [ "CVE-2023-36799" @@ -300,7 +300,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/10/GHSA-5mfx-4wcx-rv27/GHSA-5mfx-4wcx-rv27.json b/advisories/github-reviewed/2023/10/GHSA-5mfx-4wcx-rv27/GHSA-5mfx-4wcx-rv27.json index d7568d6ac7b..3f7aec614f8 100644 --- a/advisories/github-reviewed/2023/10/GHSA-5mfx-4wcx-rv27/GHSA-5mfx-4wcx-rv27.json +++ b/advisories/github-reviewed/2023/10/GHSA-5mfx-4wcx-rv27/GHSA-5mfx-4wcx-rv27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mfx-4wcx-rv27", - "modified": "2023-10-18T20:55:13Z", + "modified": "2024-06-03T18:31:33Z", "published": "2023-10-10T18:31:33Z", "aliases": [ "CVE-2023-36414" @@ -55,7 +55,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/10/GHSA-fr44-546p-7xcp/GHSA-fr44-546p-7xcp.json b/advisories/github-reviewed/2023/10/GHSA-fr44-546p-7xcp/GHSA-fr44-546p-7xcp.json index 7bff42dd1fb..d97fba0f117 100644 --- a/advisories/github-reviewed/2023/10/GHSA-fr44-546p-7xcp/GHSA-fr44-546p-7xcp.json +++ b/advisories/github-reviewed/2023/10/GHSA-fr44-546p-7xcp/GHSA-fr44-546p-7xcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr44-546p-7xcp", - "modified": "2023-10-10T22:23:28Z", + "modified": "2024-06-03T18:31:15Z", "published": "2023-10-10T22:23:28Z", "aliases": [ "CVE-2023-36435" @@ -78,6 +78,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-401" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-4vrx-8phj-x3mg/GHSA-4vrx-8phj-x3mg.json b/advisories/unreviewed/2024/06/GHSA-4vrx-8phj-x3mg/GHSA-4vrx-8phj-x3mg.json new file mode 100644 index 00000000000..6811f717f19 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4vrx-8phj-x3mg/GHSA-4vrx-8phj-x3mg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrx-8phj-x3mg", + "modified": "2024-06-03T18:30:50Z", + "published": "2024-06-03T18:30:50Z", + "aliases": [ + "CVE-2024-4540" + ], + "details": "A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4540" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-4540" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-03T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5jhg-px89-wqm9/GHSA-5jhg-px89-wqm9.json b/advisories/unreviewed/2024/06/GHSA-5jhg-px89-wqm9/GHSA-5jhg-px89-wqm9.json new file mode 100644 index 00000000000..99c89528ef0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5jhg-px89-wqm9/GHSA-5jhg-px89-wqm9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jhg-px89-wqm9", + "modified": "2024-06-03T18:30:50Z", + "published": "2024-06-03T18:30:50Z", + "aliases": [ + "CVE-2024-36674" + ], + "details": "LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36674" + }, + { + "type": "WEB", + "url": "https://github.com/LyLme/lylme_spage/issues/91" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-03T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-66xx-c9r9-f474/GHSA-66xx-c9r9-f474.json b/advisories/unreviewed/2024/06/GHSA-66xx-c9r9-f474/GHSA-66xx-c9r9-f474.json new file mode 100644 index 00000000000..7089fb18b05 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-66xx-c9r9-f474/GHSA-66xx-c9r9-f474.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66xx-c9r9-f474", + "modified": "2024-06-03T18:30:50Z", + "published": "2024-06-03T18:30:50Z", + "aliases": [ + "CVE-2024-4332" + ], + "details": "An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional \"Auto-synchronize LDAP Users, Roles, and Groups\" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4332" + }, + { + "type": "WEB", + "url": "https://www.fortra.com/security/advisory/fi-2024-006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-03T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json b/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json new file mode 100644 index 00000000000..639aa18aae3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvgq-w6rq-jcjp", + "modified": "2024-06-03T18:30:50Z", + "published": "2024-06-03T18:30:50Z", + "aliases": [ + "CVE-2024-37019" + ], + "details": "Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37019" + }, + { + "type": "WEB", + "url": "https://mender.io/blog/cve-2024-37019-account-takeover-using-saml" + }, + { + "type": "WEB", + "url": "https://northern.tech" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-03T18:15:08Z" + } +} \ No newline at end of file