From b84d606cfd0e785bfbab7b320b3e45131ab0615a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Dec 2024 03:33:08 +0000 Subject: [PATCH] Publish Advisories GHSA-972x-whc8-5v95 GHSA-9928-7c25-jv7c GHSA-ffg3-vmf8-h87g GHSA-qgcp-q9v9-wfx5 GHSA-r4xg-5xjw-6vvv --- .../GHSA-972x-whc8-5v95.json | 36 +++++++++++++++++ .../GHSA-9928-7c25-jv7c.json | 36 +++++++++++++++++ .../GHSA-ffg3-vmf8-h87g.json | 36 +++++++++++++++++ .../GHSA-qgcp-q9v9-wfx5.json | 36 +++++++++++++++++ .../GHSA-r4xg-5xjw-6vvv.json | 40 +++++++++++++++++++ 5 files changed, 184 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-972x-whc8-5v95/GHSA-972x-whc8-5v95.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9928-7c25-jv7c/GHSA-9928-7c25-jv7c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-ffg3-vmf8-h87g/GHSA-ffg3-vmf8-h87g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qgcp-q9v9-wfx5/GHSA-qgcp-q9v9-wfx5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r4xg-5xjw-6vvv/GHSA-r4xg-5xjw-6vvv.json diff --git a/advisories/unreviewed/2024/12/GHSA-972x-whc8-5v95/GHSA-972x-whc8-5v95.json b/advisories/unreviewed/2024/12/GHSA-972x-whc8-5v95/GHSA-972x-whc8-5v95.json new file mode 100644 index 00000000000..63f28f0b57c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-972x-whc8-5v95/GHSA-972x-whc8-5v95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-972x-whc8-5v95", + "modified": "2024-12-17T03:31:42Z", + "published": "2024-12-17T03:31:42Z", + "aliases": [ + "CVE-2020-12484" + ], + "details": "When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12484" + }, + { + "type": "WEB", + "url": "https://www.vivo.com/en/support/security-advisory-detail?id=3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9928-7c25-jv7c/GHSA-9928-7c25-jv7c.json b/advisories/unreviewed/2024/12/GHSA-9928-7c25-jv7c/GHSA-9928-7c25-jv7c.json new file mode 100644 index 00000000000..2918a0ce273 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9928-7c25-jv7c/GHSA-9928-7c25-jv7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9928-7c25-jv7c", + "modified": "2024-12-17T03:31:42Z", + "published": "2024-12-17T03:31:42Z", + "aliases": [ + "CVE-2021-26278" + ], + "details": "The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26278" + }, + { + "type": "WEB", + "url": "https://www.vivo.com/en/support/security-advisory-detail?id=7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ffg3-vmf8-h87g/GHSA-ffg3-vmf8-h87g.json b/advisories/unreviewed/2024/12/GHSA-ffg3-vmf8-h87g/GHSA-ffg3-vmf8-h87g.json new file mode 100644 index 00000000000..713e4f1b248 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ffg3-vmf8-h87g/GHSA-ffg3-vmf8-h87g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffg3-vmf8-h87g", + "modified": "2024-12-17T03:31:42Z", + "published": "2024-12-17T03:31:42Z", + "aliases": [ + "CVE-2024-10205" + ], + "details": "Authentication Bypass\nvulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics \n\ncomponent\n\n).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10205" + }, + { + "type": "WEB", + "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2024-151/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T02:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qgcp-q9v9-wfx5/GHSA-qgcp-q9v9-wfx5.json b/advisories/unreviewed/2024/12/GHSA-qgcp-q9v9-wfx5/GHSA-qgcp-q9v9-wfx5.json new file mode 100644 index 00000000000..2c6939fabf8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qgcp-q9v9-wfx5/GHSA-qgcp-q9v9-wfx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgcp-q9v9-wfx5", + "modified": "2024-12-17T03:31:42Z", + "published": "2024-12-17T03:31:42Z", + "aliases": [ + "CVE-2020-12487" + ], + "details": "Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12487" + }, + { + "type": "WEB", + "url": "https://www.vivo.com/en/support/security-advisory-detail?id=4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r4xg-5xjw-6vvv/GHSA-r4xg-5xjw-6vvv.json b/advisories/unreviewed/2024/12/GHSA-r4xg-5xjw-6vvv/GHSA-r4xg-5xjw-6vvv.json new file mode 100644 index 00000000000..632ff590df2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r4xg-5xjw-6vvv/GHSA-r4xg-5xjw-6vvv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4xg-5xjw-6vvv", + "modified": "2024-12-17T03:31:42Z", + "published": "2024-12-17T03:31:42Z", + "aliases": [ + "CVE-2024-12239" + ], + "details": "The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12239" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/powerpack-addon-for-beaver-builder/trunk/includes/admin-settings-templates.php#L62" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5138ed4c-3e9c-45da-917e-e8d8396a62f1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T03:15:06Z" + } +} \ No newline at end of file