From bb52b5781eb766d9fbb25d80f55ce08e8f9d111d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 Aug 2024 00:32:21 +0000 Subject: [PATCH] Publish Advisories GHSA-84cf-cm69-mj8w GHSA-8rfc-c9wp-w4x6 GHSA-373g-hg3v-qf78 GHSA-3v8g-fm64-g4mc GHSA-563c-g7mm-g4xp GHSA-69x6-6jqx-q847 GHSA-7369-x5q2-rh2m GHSA-7j5g-jfh2-w58c GHSA-7jrj-xq8x-h553 GHSA-9wvx-3hw8-4ghf GHSA-9x8m-8qxp-gj73 GHSA-cr94-c6j4-q6g5 GHSA-gqq7-89cw-236x GHSA-gvhm-xpqg-38jw GHSA-gx25-vx95-m52w GHSA-hf5v-h65q-2g27 GHSA-jgv7-f85p-m95j GHSA-mcjx-2c4v-mvg9 GHSA-vhmm-vh3j-5vww --- .../GHSA-84cf-cm69-mj8w.json | 11 ++++-- .../GHSA-8rfc-c9wp-w4x6.json | 11 ++++-- .../GHSA-373g-hg3v-qf78.json | 9 +++-- .../GHSA-3v8g-fm64-g4mc.json | 9 +++-- .../GHSA-563c-g7mm-g4xp.json | 10 ++++- .../GHSA-69x6-6jqx-q847.json | 10 ++++- .../GHSA-7369-x5q2-rh2m.json | 19 ++++++++-- .../GHSA-7j5g-jfh2-w58c.json | 6 ++- .../GHSA-7jrj-xq8x-h553.json | 10 ++++- .../GHSA-9wvx-3hw8-4ghf.json | 10 ++++- .../GHSA-9x8m-8qxp-gj73.json | 38 +++++++++++++++++++ .../GHSA-cr94-c6j4-q6g5.json | 10 ++++- .../GHSA-gqq7-89cw-236x.json | 9 +++-- .../GHSA-gvhm-xpqg-38jw.json | 11 ++++-- .../GHSA-gx25-vx95-m52w.json | 6 ++- .../GHSA-hf5v-h65q-2g27.json | 10 ++++- .../GHSA-jgv7-f85p-m95j.json | 38 +++++++++++++++++++ .../GHSA-mcjx-2c4v-mvg9.json | 6 ++- .../GHSA-vhmm-vh3j-5vww.json | 11 ++++-- 19 files changed, 206 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-9x8m-8qxp-gj73/GHSA-9x8m-8qxp-gj73.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jgv7-f85p-m95j/GHSA-jgv7-f85p-m95j.json diff --git a/advisories/unreviewed/2024/04/GHSA-84cf-cm69-mj8w/GHSA-84cf-cm69-mj8w.json b/advisories/unreviewed/2024/04/GHSA-84cf-cm69-mj8w/GHSA-84cf-cm69-mj8w.json index f3dc0d38f8e..3db12160965 100644 --- a/advisories/unreviewed/2024/04/GHSA-84cf-cm69-mj8w/GHSA-84cf-cm69-mj8w.json +++ b/advisories/unreviewed/2024/04/GHSA-84cf-cm69-mj8w/GHSA-84cf-cm69-mj8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84cf-cm69-mj8w", - "modified": "2024-04-29T18:30:46Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-04-29T18:30:46Z", "aliases": [ "CVE-2023-51254" ], "details": "Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T18:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8rfc-c9wp-w4x6/GHSA-8rfc-c9wp-w4x6.json b/advisories/unreviewed/2024/04/GHSA-8rfc-c9wp-w4x6/GHSA-8rfc-c9wp-w4x6.json index db3f427310c..de69dc5552f 100644 --- a/advisories/unreviewed/2024/04/GHSA-8rfc-c9wp-w4x6/GHSA-8rfc-c9wp-w4x6.json +++ b/advisories/unreviewed/2024/04/GHSA-8rfc-c9wp-w4x6/GHSA-8rfc-c9wp-w4x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rfc-c9wp-w4x6", - "modified": "2024-04-26T15:30:34Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-04-26T15:30:34Z", "aliases": [ "CVE-2024-33258" ], "details": "Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T15:15:49Z" diff --git a/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json index f11442d10af..74374d530e5 100644 --- a/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json +++ b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-373g-hg3v-qf78", - "modified": "2024-08-06T21:30:48Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T21:30:48Z", "aliases": [ "CVE-2024-7534" ], "details": "Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T21:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json b/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json index 298e37a8a48..0dcca811495 100644 --- a/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json +++ b/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3v8g-fm64-g4mc", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-6991" ], "details": "Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json b/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json index afb66dad009..f054af0dafb 100644 --- a/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json +++ b/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-563c-g7mm-g4xp", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7521" @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json index 808415f84f0..fa0399ac209 100644 --- a/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json +++ b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69x6-6jqx-q847", - "modified": "2024-08-06T18:30:56Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7527" @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json b/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json index ccda3402b44..c68019c3861 100644 --- a/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json +++ b/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7369-x5q2-rh2m", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7525" ], "details": "It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,13 +36,21 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json index 074f2112333..4a5e993da11 100644 --- a/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json +++ b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7j5g-jfh2-w58c", - "modified": "2024-08-06T18:30:56Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7520" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json index 74957ea2aa3..79b14bb2365 100644 --- a/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json +++ b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jrj-xq8x-h553", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7522" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json b/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json index 03dd58d365d..efa6d5c35d9 100644 --- a/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json +++ b/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9wvx-3hw8-4ghf", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7519" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-9x8m-8qxp-gj73/GHSA-9x8m-8qxp-gj73.json b/advisories/unreviewed/2024/08/GHSA-9x8m-8qxp-gj73/GHSA-9x8m-8qxp-gj73.json new file mode 100644 index 00000000000..f38bbedbf5d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9x8m-8qxp-gj73/GHSA-9x8m-8qxp-gj73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x8m-8qxp-gj73", + "modified": "2024-08-07T00:30:47Z", + "published": "2024-08-07T00:30:47Z", + "aliases": [ + "CVE-2024-38166" + ], + "details": "An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38166" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38166" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T22:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json b/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json index c7ad1a6fc82..630abcbb73e 100644 --- a/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json +++ b/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr94-c6j4-q6g5", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-7529" @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json b/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json index 068be1d06bd..c03ea49f7d3 100644 --- a/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json +++ b/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqq7-89cw-236x", - "modified": "2024-08-06T21:30:48Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T21:30:48Z", "aliases": [ "CVE-2024-7536" ], "details": "Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T21:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json b/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json index 8b7d304e0a7..33697af8f7b 100644 --- a/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json +++ b/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvhm-xpqg-38jw", - "modified": "2024-08-06T21:30:47Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T21:30:47Z", "aliases": [ "CVE-2024-28739" ], "details": "An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T19:15:56Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json index b3ddf068e60..bcf1fdf36fe 100644 --- a/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json +++ b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx25-vx95-m52w", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-7528" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json b/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json index 95a65684c4a..89326f22187 100644 --- a/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json +++ b/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hf5v-h65q-2g27", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7526" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-jgv7-f85p-m95j/GHSA-jgv7-f85p-m95j.json b/advisories/unreviewed/2024/08/GHSA-jgv7-f85p-m95j/GHSA-jgv7-f85p-m95j.json new file mode 100644 index 00000000000..aa375668eda --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jgv7-f85p-m95j/GHSA-jgv7-f85p-m95j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgv7-f85p-m95j", + "modified": "2024-08-07T00:30:47Z", + "published": "2024-08-07T00:30:47Z", + "aliases": [ + "CVE-2024-38206" + ], + "details": "An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38206" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38206" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T22:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json index 14d3a00f03c..9b32ac7b64d 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json +++ b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcjx-2c4v-mvg9", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7518" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json b/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json index 819e475e668..b14681a86ac 100644 --- a/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json +++ b/advisories/unreviewed/2024/08/GHSA-vhmm-vh3j-5vww/GHSA-vhmm-vh3j-5vww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhmm-vh3j-5vww", - "modified": "2024-08-02T18:31:12Z", + "modified": "2024-08-07T00:30:47Z", "published": "2024-08-02T18:31:12Z", "aliases": [ "CVE-2024-38886" ], "details": "An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-940" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T18:16:19Z"