Publish Advisories

GHSA-6r3p-fcvm-xh7c
GHSA-275x-9ffh-fhq2
GHSA-27fr-v43j-r34m
GHSA-2r3w-v93h-m6vw
GHSA-53g5-chm2-f34r
GHSA-6cqh-4xr5-c65x
GHSA-8ppr-www8-hfjx
GHSA-8r8f-v2fj-h7cp
GHSA-9ghw-mv5v-jx7g
GHSA-cjhg-7x4h-7j52
GHSA-h638-qfh6-65v5
GHSA-rmxq-q4j3-rg8f
GHSA-vvgj-qh7x-pf9r
GHSA-vxx9-qwhq-hgf4
GHSA-x7hp-f23m-66mj
This commit is contained in:
advisory-database[bot]
2024-03-25 15:31:09 +00:00
parent 2d8b304256
commit b822d8069a
15 changed files with 535 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r3p-fcvm-xh7c",
"modified": "2023-08-30T21:02:31Z",
"modified": "2024-03-25T15:29:46Z",
"published": "2020-12-17T21:00:58Z",
"aliases": [
"CVE-2020-17513"
@@ -40,6 +40,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-17513"
},
{
"type": "WEB",
"url": "https://github.com/apache/airflow/commit/b606b871226d649913a37fd074eeae5d86ebc3a1"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rb3647269f07cc2775ca6568cbfd4994d862c842a58120d2aba9c658a%40%3Cusers.airflow.apache.org%3E"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-275x-9ffh-fhq2",
"modified": "2024-03-25T15:30:39Z",
"published": "2024-03-25T15:30:39Z",
"aliases": [
"CVE-2024-28393"
],
"details": "SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28393"
},
{
"type": "WEB",
"url": "https://addons.prestashop.com/fr/paiement-en-plusieurs-fois/87023-scalapay-payez-en-3-fois-sans-frais.html"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/03/19/scalapay.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27fr-v43j-r34m",
"modified": "2024-03-25T15:30:43Z",
"published": "2024-03-25T15:30:43Z",
"aliases": [
"CVE-2024-30204"
],
"details": "In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30204"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=6f9ea396f49cbe38c2173e0a72ba6af3e03b271c"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r3w-v93h-m6vw",
"modified": "2024-03-25T15:30:39Z",
"published": "2024-03-25T15:30:38Z",
"aliases": [
"CVE-2024-25002"
],
"details": "Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25002"
},
{
"type": "WEB",
"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-152190.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53g5-chm2-f34r",
"modified": "2024-03-25T15:30:39Z",
"published": "2024-03-25T15:30:39Z",
"aliases": [
"CVE-2024-28387"
],
"details": "An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28387"
},
{
"type": "WEB",
"url": "https://axonaut.com/integration/detail/prestashop"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/03/19/axonaut.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cqh-4xr5-c65x",
"modified": "2024-03-25T15:30:40Z",
"published": "2024-03-25T15:30:40Z",
"aliases": [
"CVE-2024-28435"
],
"details": "The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28435"
},
{
"type": "WEB",
"url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-28435"
},
{
"type": "WEB",
"url": "https://github.com/twentyhq/twenty"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8ppr-www8-hfjx",
"modified": "2024-03-25T15:30:41Z",
"published": "2024-03-25T15:30:41Z",
"aliases": [
"CVE-2024-29650"
],
"details": "An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29650"
},
{
"type": "WEB",
"url": "https://gist.github.com/tariqhawis/1bc340ca5ea6ae115c9ab9665cfd5921"
},
{
"type": "WEB",
"url": "https://learn.snyk.io/lesson/prototype-pollution/#a0a863a5-fd3a-539f-e1ed-a0769f6c6e3b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r8f-v2fj-h7cp",
"modified": "2024-03-25T15:30:41Z",
"published": "2024-03-25T15:30:41Z",
"aliases": [
"CVE-2024-30202"
],
"details": "In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30202"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=befa9fcaae29a6c9a283ba371c3c5234c7f644eb"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=003ddacf1c8d869b1858181c29ea21b731a8d8d9"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ghw-mv5v-jx7g",
"modified": "2024-03-25T15:30:40Z",
"published": "2024-03-25T15:30:40Z",
"aliases": [
"CVE-2024-25175"
],
"details": "An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25175"
},
{
"type": "WEB",
"url": "https://github.com/jet-pentest/CVE-2024-25175"
},
{
"type": "WEB",
"url": "https://www.kickidler.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjhg-7x4h-7j52",
"modified": "2024-03-25T15:30:39Z",
"published": "2024-03-25T15:30:39Z",
"aliases": [
"CVE-2024-28386"
],
"details": "An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28386"
},
{
"type": "WEB",
"url": "https://reference1.example.com/modules/fastmagsync/crons/cron_mutualise_job_queue.php?hosting=.%20%26%20%20echo%20%27%3C%3Fphp%20echo%20%2242ovh%22%3B%27%20%3E%20a.php%3B%23&syncway=tofastmag"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/03/19/fastmagsync.html"
},
{
"type": "WEB",
"url": "https://www.home-made.io/module-fastmag-sync-prestashop"
},
{
"type": "WEB",
"url": "http://fastmagsync.com"
},
{
"type": "WEB",
"url": "http://home-madeio.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h638-qfh6-65v5",
"modified": "2024-03-25T15:30:40Z",
"published": "2024-03-25T15:30:40Z",
"aliases": [
"CVE-2024-2865"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality Management System: through 25032024.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2865"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-0229"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmxq-q4j3-rg8f",
"modified": "2024-03-25T15:30:42Z",
"published": "2024-03-25T15:30:42Z",
"aliases": [
"CVE-2024-30203"
],
"details": "In Emacs before 29.3, Gnus treats inline MIME contents as trusted.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30203"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=937b9042ad7426acdcca33e3d931d8f495bdd804"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvgj-qh7x-pf9r",
"modified": "2024-03-24T09:31:04Z",
"modified": "2024-03-25T15:30:38Z",
"published": "2024-03-24T09:31:04Z",
"aliases": [
"CVE-2024-2856"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.257780"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.299741"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxx9-qwhq-hgf4",
"modified": "2024-03-25T15:30:43Z",
"published": "2024-03-25T15:30:43Z",
"aliases": [
"CVE-2024-30205"
],
"details": "In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30205"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=2bc865ace050ff118db43f01457f95f95112b877"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29"
},
{
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=4255d5dcc0657915f90e4fba7e0a5514cced514d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T15:15:52Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7hp-f23m-66mj",
"modified": "2024-03-25T15:30:39Z",
"published": "2024-03-25T15:30:39Z",
"aliases": [
"CVE-2024-28434"
],
"details": "The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28434"
},
{
"type": "WEB",
"url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-28434"
},
{
"type": "WEB",
"url": "https://github.com/twentyhq/twenty"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T14:15:09Z"
}
}