Publish Advisories

GHSA-mq7v-2xj4-rhjj
GHSA-vrjf-gppf-qvj4
GHSA-vwmq-g758-4rpf
This commit is contained in:
advisory-database[bot]
2024-01-30 12:31:42 +00:00
parent 16d818ea14
commit bb654b5549
3 changed files with 119 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq7v-2xj4-rhjj",
"modified": "2024-01-30T12:30:18Z",
"published": "2024-01-30T12:30:18Z",
"aliases": [
"CVE-2024-22894"
],
"details": "An issue in AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 and Novelan Heatpumps wp2reg-V.3.88.0-9015, allows remote attackers to execute arbitrary code via the password component in the shadow file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22894"
},
{
"type": "WEB",
"url": "https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/"
},
{
"type": "WEB",
"url": "https://github.com/Jaarden/CVE-2024-22894"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T10:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrjf-gppf-qvj4",
"modified": "2024-01-30T12:30:18Z",
"published": "2024-01-30T12:30:18Z",
"aliases": [
"CVE-2024-1063"
],
"details": "Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1063"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/research/tra-2024-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T10:15:09Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vwmq-g758-4rpf",
"modified": "2024-01-30T12:30:18Z",
"published": "2024-01-30T12:30:18Z",
"aliases": [
"CVE-2024-1030"
],
"details": "A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part of the file /front/admin/tenancyDetail.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-252303.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1030"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252303"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252303"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T10:15:08Z"
}
}