Publish Advisories

GHSA-3h9f-mm2x-4j58
GHSA-5xx6-pf4v-cpf2
GHSA-c625-6f4r-x698
GHSA-cp2c-x2pc-fph7
GHSA-fc8m-x59c-5f6r
GHSA-grg4-p2px-v4hg
GHSA-p8wp-3m3g-qg4j
GHSA-r8h6-cwxj-rv5j
GHSA-xg5j-69w2-9h88
This commit is contained in:
advisory-database[bot]
2024-07-30 15:32:51 +00:00
parent bb758a09e9
commit bba5a2ffa5
9 changed files with 189 additions and 6 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h9f-mm2x-4j58",
"modified": "2024-07-30T15:31:28Z",
"published": "2024-07-30T15:31:28Z",
"aliases": [
"CVE-2024-38909"
],
"details": "Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38909"
},
{
"type": "WEB",
"url": "https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909"
},
{
"type": "WEB",
"url": "http://elfinder.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T14:15:02Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xx6-pf4v-cpf2",
"modified": "2024-07-30T00:34:24Z",
"modified": "2024-07-30T15:31:22Z",
"published": "2024-07-10T18:32:17Z",
"aliases": [
"CVE-2024-5217"
@@ -40,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-184"
"CWE-184",
"CWE-697"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c625-6f4r-x698",
"modified": "2024-07-30T15:31:29Z",
"published": "2024-07-30T15:31:29Z",
"aliases": [
"CVE-2024-4188"
],
"details": "Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:C/RE:H/U:Red"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4188"
},
{
"type": "WEB",
"url": "https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0815868"
}
],
"database_specific": {
"cwe_ids": [
"CWE-523"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T15:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp2c-x2pc-fph7",
"modified": "2024-07-30T09:32:05Z",
"modified": "2024-07-30T15:31:27Z",
"published": "2024-07-30T09:32:05Z",
"aliases": [
"CVE-2023-48396"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/1tdxfjksx0vb9gtyt77wlr6rdcy1qwmw"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/30/1"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc8m-x59c-5f6r",
"modified": "2024-07-30T03:30:52Z",
"modified": "2024-07-30T15:31:24Z",
"published": "2024-07-30T00:34:27Z",
"aliases": [
"CVE-2024-40800"
@@ -30,6 +30,10 @@
"type": "WEB",
"url": "https://support.apple.com/en-us/HT214120"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2010"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Jul/18"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grg4-p2px-v4hg",
"modified": "2024-07-30T15:31:28Z",
"published": "2024-07-30T15:31:28Z",
"aliases": [
"CVE-2024-23091"
],
"details": "Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23091"
},
{
"type": "WEB",
"url": "https://medium.com/%40cnetsec/security-advisory-cve-2024-23091-weak-password-hashing-using-md5-f18a6fe3a473"
},
{
"type": "WEB",
"url": "https://www.hoteldruid.com/en/download.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T14:15:02Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8wp-3m3g-qg4j",
"modified": "2024-07-30T15:31:28Z",
"published": "2024-07-30T15:31:28Z",
"aliases": [
"CVE-2024-6699"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0 before v3.1.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6699"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1105"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T13:15:10Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8h6-cwxj-rv5j",
"modified": "2024-07-30T03:30:51Z",
"modified": "2024-07-30T15:31:23Z",
"published": "2024-07-30T00:34:24Z",
"aliases": [
"CVE-2024-3219"
@@ -26,6 +26,26 @@
"type": "WEB",
"url": "https://github.com/python/cpython/pull/122134"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/06fa244666ec6335a3b9bf2367e31b42b9a89b20"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/0b65c8bf5367625673eafb92f85046a1b31259f2"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/5f90abaa786f994db3907fc31e2ee00ea2cf0929"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/b252317956b7fc035bb3774ef6a177e227f9fc54"
},
{
"type": "WEB",
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYKDQWIERRE2ICIYMSVRZJO33GSCWU2B"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xg5j-69w2-9h88",
"modified": "2024-07-30T06:30:37Z",
"modified": "2024-07-30T15:31:25Z",
"published": "2024-07-30T06:30:37Z",
"aliases": [
"CVE-2024-6230"