Publish Advisories

GHSA-jv9p-xg7j-p65c
GHSA-vqf3-8wjf-vm68
GHSA-jqrq-gqwg-r8r5
GHSA-q9rx-4p5p-q33x
GHSA-6jvg-hp25-42f6
GHSA-8w7r-5fhv-vwj9
GHSA-xf53-c458-r6pv
This commit is contained in:
advisory-database[bot]
2024-03-01 06:34:26 +00:00
parent 04d34503f1
commit b75c10df2d
7 changed files with 148 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv9p-xg7j-p65c",
"modified": "2023-10-25T03:30:36Z",
"modified": "2024-03-01T06:33:05Z",
"published": "2023-10-18T18:31:38Z",
"aliases": [
"CVE-2023-46009"
@@ -24,13 +24,21 @@
{
"type": "WEB",
"url": "https://github.com/kohler/gifsicle/issues/196"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3I6Z7VAHUYX3Q4DULJ76NFD2CIFZJYH5"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WLTXJS6AIKPGVOAJ7EYC4HL3NEG6CGF"
}
],
"database_specific": {
"cwe_ids": [
"CWE-697"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T16:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqf3-8wjf-vm68",
"modified": "2023-10-09T21:30:27Z",
"modified": "2024-03-01T06:33:05Z",
"published": "2023-10-09T21:30:27Z",
"aliases": [
"CVE-2023-44821"
],
"details": "Buffer Overflow vulnerability in gifsicle v.1.92 allows a remote attacker to cause a denial of service via the --crop parameter in the command line parameters.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -21,13 +24,25 @@
{
"type": "WEB",
"url": "https://github.com/kohler/gifsicle/issues/195"
},
{
"type": "WEB",
"url": "https://github.com/kohler/gifsicle/issues/65"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3I6Z7VAHUYX3Q4DULJ76NFD2CIFZJYH5"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WLTXJS6AIKPGVOAJ7EYC4HL3NEG6CGF"
}
],
"database_specific": {
"cwe_ids": [
"CWE-401"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-09T20:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqrq-gqwg-r8r5",
"modified": "2024-02-13T18:38:23Z",
"modified": "2024-03-01T06:33:06Z",
"published": "2024-02-13T18:38:23Z",
"aliases": [
"CVE-2024-21338"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21338"
},
{
"type": "WEB",
"url": "https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9rx-4p5p-q33x",
"modified": "2024-02-22T00:31:01Z",
"modified": "2024-03-01T06:33:06Z",
"published": "2024-02-22T00:31:01Z",
"aliases": [
"CVE-2024-0446"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jvg-hp25-42f6",
"modified": "2024-03-01T06:33:06Z",
"published": "2024-03-01T06:33:06Z",
"aliases": [
"CVE-2024-22891"
],
"details": "Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22891"
},
{
"type": "WEB",
"url": "https://github.com/EQSTLab/PoC/tree/main/2024/RCE/CVE-2024-22891"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T06:15:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w7r-5fhv-vwj9",
"modified": "2024-03-01T06:33:06Z",
"published": "2024-03-01T06:33:06Z",
"aliases": [
"CVE-2024-25293"
],
"details": "mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25293"
},
{
"type": "WEB",
"url": "https://github.com/EQSTLab/PoC/tree/main/2024/LCE/CVE-2024-25293"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T06:15:48Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf53-c458-r6pv",
"modified": "2024-03-01T06:33:06Z",
"published": "2024-03-01T06:33:06Z",
"aliases": [
"CVE-2024-25386"
],
"details": "Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25386"
},
{
"type": "WEB",
"url": "https://gist.github.com/Shulelk/15c9ba8d6b54dd4256a50a24ac7dd0a2"
},
{
"type": "WEB",
"url": "https://sec.1i6w31fen9.top/2024/02/02/dcf-operations-window-remote-command-execute"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T06:15:48Z"
}
}