mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-3h9f-mm2x-4j58 GHSA-5xx6-pf4v-cpf2 GHSA-c625-6f4r-x698 GHSA-cp2c-x2pc-fph7 GHSA-fc8m-x59c-5f6r GHSA-grg4-p2px-v4hg GHSA-p8wp-3m3g-qg4j GHSA-r8h6-cwxj-rv5j GHSA-xg5j-69w2-9h88
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3h9f-mm2x-4j58",
|
||||
"modified": "2024-07-30T15:31:28Z",
|
||||
"published": "2024-07-30T15:31:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-38909"
|
||||
],
|
||||
"details": "Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38909"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://elfinder.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-30T14:15:02Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5xx6-pf4v-cpf2",
|
||||
"modified": "2024-07-30T00:34:24Z",
|
||||
"modified": "2024-07-30T15:31:22Z",
|
||||
"published": "2024-07-10T18:32:17Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5217"
|
||||
@@ -40,7 +40,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-184"
|
||||
"CWE-184",
|
||||
"CWE-697"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c625-6f4r-x698",
|
||||
"modified": "2024-07-30T15:31:29Z",
|
||||
"published": "2024-07-30T15:31:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4188"
|
||||
],
|
||||
"details": "Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:C/RE:H/U:Red"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4188"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0815868"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-523"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-30T15:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cp2c-x2pc-fph7",
|
||||
"modified": "2024-07-30T09:32:05Z",
|
||||
"modified": "2024-07-30T15:31:27Z",
|
||||
"published": "2024-07-30T09:32:05Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48396"
|
||||
@@ -21,6 +21,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread/1tdxfjksx0vb9gtyt77wlr6rdcy1qwmw"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/07/30/1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fc8m-x59c-5f6r",
|
||||
"modified": "2024-07-30T03:30:52Z",
|
||||
"modified": "2024-07-30T15:31:24Z",
|
||||
"published": "2024-07-30T00:34:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40800"
|
||||
@@ -30,6 +30,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/HT214120"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2010"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://seclists.org/fulldisclosure/2024/Jul/18"
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-grg4-p2px-v4hg",
|
||||
"modified": "2024-07-30T15:31:28Z",
|
||||
"published": "2024-07-30T15:31:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23091"
|
||||
],
|
||||
"details": "Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23091"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://medium.com/%40cnetsec/security-advisory-cve-2024-23091-weak-password-hashing-using-md5-f18a6fe3a473"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.hoteldruid.com/en/download.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-30T14:15:02Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p8wp-3m3g-qg4j",
|
||||
"modified": "2024-07-30T15:31:28Z",
|
||||
"published": "2024-07-30T15:31:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6699"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0 before v3.1.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6699"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.usom.gov.tr/bildirim/tr-24-1105"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-30T13:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r8h6-cwxj-rv5j",
|
||||
"modified": "2024-07-30T03:30:51Z",
|
||||
"modified": "2024-07-30T15:31:23Z",
|
||||
"published": "2024-07-30T00:34:24Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3219"
|
||||
@@ -26,6 +26,26 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/pull/122134"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/06fa244666ec6335a3b9bf2367e31b42b9a89b20"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/0b65c8bf5367625673eafb92f85046a1b31259f2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/5f90abaa786f994db3907fc31e2ee00ea2cf0929"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python/cpython/commit/b252317956b7fc035bb3774ef6a177e227f9fc54"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYKDQWIERRE2ICIYMSVRZJO33GSCWU2B"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xg5j-69w2-9h88",
|
||||
"modified": "2024-07-30T06:30:37Z",
|
||||
"modified": "2024-07-30T15:31:25Z",
|
||||
"published": "2024-07-30T06:30:37Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6230"
|
||||
|
||||
Reference in New Issue
Block a user