From b9b9c8d70ad75d5fa63e5b3a2fa2a784c626fc42 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 23 Dec 2024 00:32:19 +0000 Subject: [PATCH] Publish Advisories GHSA-325m-pvh6-hvj7 GHSA-3q7m-2c53-555m GHSA-533g-7w58-g89m GHSA-58gj-55xv-pwhg GHSA-cpq8-gjrv-h7mr GHSA-crw4-8858-pw4f GHSA-h369-f67q-2q4c --- .../GHSA-325m-pvh6-hvj7.json | 52 +++++++++++++++++++ .../GHSA-3q7m-2c53-555m.json | 33 ++++++++++++ .../GHSA-533g-7w58-g89m.json | 29 +++++++++++ .../GHSA-58gj-55xv-pwhg.json | 33 ++++++++++++ .../GHSA-cpq8-gjrv-h7mr.json | 52 +++++++++++++++++++ .../GHSA-crw4-8858-pw4f.json | 33 ++++++++++++ .../GHSA-h369-f67q-2q4c.json | 37 +++++++++++++ 7 files changed, 269 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-325m-pvh6-hvj7/GHSA-325m-pvh6-hvj7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3q7m-2c53-555m/GHSA-3q7m-2c53-555m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-533g-7w58-g89m/GHSA-533g-7w58-g89m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-58gj-55xv-pwhg/GHSA-58gj-55xv-pwhg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cpq8-gjrv-h7mr/GHSA-cpq8-gjrv-h7mr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-crw4-8858-pw4f/GHSA-crw4-8858-pw4f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h369-f67q-2q4c/GHSA-h369-f67q-2q4c.json diff --git a/advisories/unreviewed/2024/12/GHSA-325m-pvh6-hvj7/GHSA-325m-pvh6-hvj7.json b/advisories/unreviewed/2024/12/GHSA-325m-pvh6-hvj7/GHSA-325m-pvh6-hvj7.json new file mode 100644 index 00000000000..aed5c8088d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-325m-pvh6-hvj7/GHSA-325m-pvh6-hvj7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-325m-pvh6-hvj7", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-12896" + ], + "details": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that \"the information disclosed in the URL is not sensitive or poses any risk to the user\".", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12896" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/IntelBras-IP-Camera-Information-Disclosure-15e6b683e67c80a89f89daf59daa9ea8?pvs=73" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.464258" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3q7m-2c53-555m/GHSA-3q7m-2c53-555m.json b/advisories/unreviewed/2024/12/GHSA-3q7m-2c53-555m/GHSA-3q7m-2c53-555m.json new file mode 100644 index 00000000000..c75daeee34c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3q7m-2c53-555m/GHSA-3q7m-2c53-555m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q7m-2c53-555m", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-56314" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 15.0.0 allows authenticated users to inject malicious scripts into the name field of a Project. When a user clicks on the project name to access it, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56314" + }, + { + "type": "WEB", + "url": "https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-22T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-533g-7w58-g89m/GHSA-533g-7w58-g89m.json b/advisories/unreviewed/2024/12/GHSA-533g-7w58-g89m/GHSA-533g-7w58-g89m.json new file mode 100644 index 00000000000..d4fbcadd656 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-533g-7w58-g89m/GHSA-533g-7w58-g89m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-533g-7w58-g89m", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-56375" + ], + "details": "An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array during a shuffle attempt, before the validation that would normally reject it when empty. This out-of-bounds access is caused by an integer underflow that causes the surrounding loop to iterate infinitely. Because the product is permanently stuck attempting to overshuffle an array that doesn't actually exist, a crash is nearly guaranteed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56375" + }, + { + "type": "WEB", + "url": "https://nicmx.github.io/FORT-validator/CVE.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-22T23:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-58gj-55xv-pwhg/GHSA-58gj-55xv-pwhg.json b/advisories/unreviewed/2024/12/GHSA-58gj-55xv-pwhg/GHSA-58gj-55xv-pwhg.json new file mode 100644 index 00000000000..8e9fcec38b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-58gj-55xv-pwhg/GHSA-58gj-55xv-pwhg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58gj-55xv-pwhg", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-56313" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 15.0.0 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56313" + }, + { + "type": "WEB", + "url": "https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-22T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cpq8-gjrv-h7mr/GHSA-cpq8-gjrv-h7mr.json b/advisories/unreviewed/2024/12/GHSA-cpq8-gjrv-h7mr/GHSA-cpq8-gjrv-h7mr.json new file mode 100644 index 00000000000..3d2fcba80c2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cpq8-gjrv-h7mr/GHSA-cpq8-gjrv-h7mr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpq8-gjrv-h7mr", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-12897" + ], + "details": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12897" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Path-Traversal-Vulnerability-in-IntelBras-IP-Cameras-mtd-Config-Sha1Account1-and-mtd-Confi-15e6b683e67c80809442ee3425f753b7?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.464260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-23T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-crw4-8858-pw4f/GHSA-crw4-8858-pw4f.json b/advisories/unreviewed/2024/12/GHSA-crw4-8858-pw4f/GHSA-crw4-8858-pw4f.json new file mode 100644 index 00000000000..aca44ea7e4e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-crw4-8858-pw4f/GHSA-crw4-8858-pw4f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crw4-8858-pw4f", + "modified": "2024-12-23T00:30:53Z", + "published": "2024-12-23T00:30:53Z", + "aliases": [ + "CVE-2024-56312" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 15.0.0 allows authenticated users to inject malicious scripts into the name field of a Project Dashboard. When a user clicks on the project Dashboard name, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56312" + }, + { + "type": "WEB", + "url": "https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-22T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h369-f67q-2q4c/GHSA-h369-f67q-2q4c.json b/advisories/unreviewed/2024/12/GHSA-h369-f67q-2q4c/GHSA-h369-f67q-2q4c.json new file mode 100644 index 00000000000..f6a140c26a7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h369-f67q-2q4c/GHSA-h369-f67q-2q4c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h369-f67q-2q4c", + "modified": "2024-12-23T00:30:54Z", + "published": "2024-12-23T00:30:54Z", + "aliases": [ + "CVE-2024-56378" + ], + "details": "libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56378" + }, + { + "type": "WEB", + "url": "https://gitlab.freedesktop.org/poppler/poppler/-/blob/30eada0d2bceb42c2d2a87361339063e0b9bea50/CMakeLists.txt#L621" + }, + { + "type": "WEB", + "url": "https://gitlab.freedesktop.org/poppler/poppler/-/commit/ade9b5ebed44b0c15522c27669ef6cdf93eff84e" + }, + { + "type": "WEB", + "url": "https://gitlab.freedesktop.org/poppler/poppler/-/issues/1553" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-23T00:15:05Z" + } +} \ No newline at end of file