Publish Advisories

GHSA-wx8f-p63x-543f
GHSA-6572-8r92-7fjf
GHSA-8vm5-mx6j-hvfc
GHSA-92vm-7577-pphj
GHSA-99rv-gqrg-p5fc
GHSA-cc4r-8r99-3qmp
GHSA-g5wh-4vxr-qmjg
GHSA-phh7-8q4v-gv55
GHSA-q2fj-w5rc-hrq8
GHSA-w9qp-xc8f-8xcq
GHSA-2848-mrx7-c934
GHSA-c69h-4c8j-wh43
GHSA-cx25-3m56-wvfv
GHSA-mh5w-3vmr-jrf6
GHSA-mh6c-x63v-xvfr
GHSA-qmg8-6x2f-h3h3
GHSA-rrc8-qmq6-vv7c
GHSA-vjwj-m2x7-8w7q
GHSA-wxcq-86jx-7hv5
GHSA-xpcc-5cmh-qxxp
This commit is contained in:
advisory-database[bot]
2024-08-01 09:32:41 +00:00
parent 233497629f
commit b9111b91d4
20 changed files with 454 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx8f-p63x-543f",
"modified": "2024-07-02T21:32:00Z",
"modified": "2024-08-01T09:30:48Z",
"published": "2022-02-12T00:00:38Z",
"aliases": [
"CVE-2022-24975"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g"
},
{
"type": "WEB",
"url": "https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6572-8r92-7fjf",
"modified": "2024-07-26T15:31:51Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T15:31:51Z",
"aliases": [
"CVE-2024-41692"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vm5-mx6j-hvfc",
"modified": "2024-07-26T12:35:48Z",
"modified": "2024-08-01T09:30:48Z",
"published": "2024-07-26T12:35:48Z",
"aliases": [
"CVE-2024-41684"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92vm-7577-pphj",
"modified": "2024-07-26T12:35:49Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:49Z",
"aliases": [
"CVE-2024-41689"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99rv-gqrg-p5fc",
"modified": "2024-07-26T12:35:49Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:49Z",
"aliases": [
"CVE-2024-41688"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc4r-8r99-3qmp",
"modified": "2024-07-26T12:35:50Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:50Z",
"aliases": [
"CVE-2024-41691"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5wh-4vxr-qmjg",
"modified": "2024-07-26T12:35:50Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:50Z",
"aliases": [
"CVE-2024-41690"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phh7-8q4v-gv55",
"modified": "2024-07-26T12:35:49Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:49Z",
"aliases": [
"CVE-2024-41686"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2fj-w5rc-hrq8",
"modified": "2024-07-26T12:35:49Z",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-07-26T12:35:49Z",
"aliases": [
"CVE-2024-41687"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9qp-xc8f-8xcq",
"modified": "2024-07-26T12:35:49Z",
"modified": "2024-08-01T09:30:48Z",
"published": "2024-07-26T12:35:49Z",
"aliases": [
"CVE-2024-41685"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2848-mrx7-c934",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-5330"
],
"details": "The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5330"
},
{
"type": "WEB",
"url": "https://breakdance.com/breakdance-2-0-now-available"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbd26f5-b75e-41a3-aefb-d6c8cc2cec7b?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T07:15:02Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c69h-4c8j-wh43",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-5331"
],
"details": "The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5331"
},
{
"type": "WEB",
"url": "https://breakdance.com/breakdance-2-0-now-available"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dbe8d453-21f0-43e2-84d3-3c520ab9c308?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T07:15:02Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx25-3m56-wvfv",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-38489"
],
"details": "Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38489"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T08:15:02Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh5w-3vmr-jrf6",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-28972"
],
"details": "Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28972"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000226567/dsa-2024-211-security-update-for-a-dell-insightiq-broken-or-risky-cryptographic-algorithm-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T08:15:02Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh6c-x63v-xvfr",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-38481"
],
"details": "Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38481"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T08:15:02Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmg8-6x2f-h3h3",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-7302"
],
"details": "The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7302"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/blog2social/tags/7.5.4/includes/Ajax/Post.php#L78"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3128861"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3128861/#file434"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/blog2social/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94afe3e2-a1f1-470b-afaf-c7926beaec9a?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T07:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrc8-qmq6-vv7c",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-5678"
],
"details": "Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5678"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2024-5678.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T07:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjwj-m2x7-8w7q",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-25948"
],
"details": "Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25948"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T08:15:02Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxcq-86jx-7hv5",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-38490"
],
"details": "Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38490"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T08:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xpcc-5cmh-qxxp",
"modified": "2024-08-01T09:30:49Z",
"published": "2024-08-01T09:30:49Z",
"aliases": [
"CVE-2024-25947"
],
"details": "Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25947"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-01T07:15:02Z"
}
}