diff --git a/advisories/unreviewed/2024/07/GHSA-3h9f-mm2x-4j58/GHSA-3h9f-mm2x-4j58.json b/advisories/unreviewed/2024/07/GHSA-3h9f-mm2x-4j58/GHSA-3h9f-mm2x-4j58.json new file mode 100644 index 00000000000..0c643d2f108 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3h9f-mm2x-4j58/GHSA-3h9f-mm2x-4j58.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h9f-mm2x-4j58", + "modified": "2024-07-30T15:31:28Z", + "published": "2024-07-30T15:31:28Z", + "aliases": [ + "CVE-2024-38909" + ], + "details": "Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38909" + }, + { + "type": "WEB", + "url": "https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909" + }, + { + "type": "WEB", + "url": "http://elfinder.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json b/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json index 4ab4a098a80..eb2189ed5ac 100644 --- a/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json +++ b/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xx6-pf4v-cpf2", - "modified": "2024-07-30T00:34:24Z", + "modified": "2024-07-30T15:31:22Z", "published": "2024-07-10T18:32:17Z", "aliases": [ "CVE-2024-5217" @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-184" + "CWE-184", + "CWE-697" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-c625-6f4r-x698/GHSA-c625-6f4r-x698.json b/advisories/unreviewed/2024/07/GHSA-c625-6f4r-x698/GHSA-c625-6f4r-x698.json new file mode 100644 index 00000000000..c03f6bd4e3b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c625-6f4r-x698/GHSA-c625-6f4r-x698.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c625-6f4r-x698", + "modified": "2024-07-30T15:31:29Z", + "published": "2024-07-30T15:31:29Z", + "aliases": [ + "CVE-2024-4188" + ], + "details": "Unprotected Transport of Credentials vulnerability in OpenTextâ„¢ Documentumâ„¢ Server could allow Credential Stuffing.This issue affects Documentumâ„¢ Server: from 16.7 through 23.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:C/RE:H/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4188" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0815868" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-523" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cp2c-x2pc-fph7/GHSA-cp2c-x2pc-fph7.json b/advisories/unreviewed/2024/07/GHSA-cp2c-x2pc-fph7/GHSA-cp2c-x2pc-fph7.json index 3ea6af506d3..faa972a8a97 100644 --- a/advisories/unreviewed/2024/07/GHSA-cp2c-x2pc-fph7/GHSA-cp2c-x2pc-fph7.json +++ b/advisories/unreviewed/2024/07/GHSA-cp2c-x2pc-fph7/GHSA-cp2c-x2pc-fph7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cp2c-x2pc-fph7", - "modified": "2024-07-30T09:32:05Z", + "modified": "2024-07-30T15:31:27Z", "published": "2024-07-30T09:32:05Z", "aliases": [ "CVE-2023-48396" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/1tdxfjksx0vb9gtyt77wlr6rdcy1qwmw" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/30/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-fc8m-x59c-5f6r/GHSA-fc8m-x59c-5f6r.json b/advisories/unreviewed/2024/07/GHSA-fc8m-x59c-5f6r/GHSA-fc8m-x59c-5f6r.json index 1b7f69be725..fa65b7c73e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-fc8m-x59c-5f6r/GHSA-fc8m-x59c-5f6r.json +++ b/advisories/unreviewed/2024/07/GHSA-fc8m-x59c-5f6r/GHSA-fc8m-x59c-5f6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc8m-x59c-5f6r", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-07-30T15:31:24Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40800" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214120" }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2010" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jul/18" diff --git a/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json b/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json new file mode 100644 index 00000000000..65336a019a3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-grg4-p2px-v4hg/GHSA-grg4-p2px-v4hg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grg4-p2px-v4hg", + "modified": "2024-07-30T15:31:28Z", + "published": "2024-07-30T15:31:28Z", + "aliases": [ + "CVE-2024-23091" + ], + "details": "Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23091" + }, + { + "type": "WEB", + "url": "https://medium.com/%40cnetsec/security-advisory-cve-2024-23091-weak-password-hashing-using-md5-f18a6fe3a473" + }, + { + "type": "WEB", + "url": "https://www.hoteldruid.com/en/download.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json b/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json new file mode 100644 index 00000000000..73d5f84eead --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p8wp-3m3g-qg4j/GHSA-p8wp-3m3g-qg4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8wp-3m3g-qg4j", + "modified": "2024-07-30T15:31:28Z", + "published": "2024-07-30T15:31:28Z", + "aliases": [ + "CVE-2024-6699" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0 before v3.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6699" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json b/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json index 745b4f96693..ab122b3b1ff 100644 --- a/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json +++ b/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8h6-cwxj-rv5j", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-07-30T15:31:23Z", "published": "2024-07-30T00:34:24Z", "aliases": [ "CVE-2024-3219" @@ -26,6 +26,26 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/122134" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/06fa244666ec6335a3b9bf2367e31b42b9a89b20" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/0b65c8bf5367625673eafb92f85046a1b31259f2" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/5f90abaa786f994db3907fc31e2ee00ea2cf0929" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/b252317956b7fc035bb3774ef6a177e227f9fc54" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYKDQWIERRE2ICIYMSVRZJO33GSCWU2B" diff --git a/advisories/unreviewed/2024/07/GHSA-xg5j-69w2-9h88/GHSA-xg5j-69w2-9h88.json b/advisories/unreviewed/2024/07/GHSA-xg5j-69w2-9h88/GHSA-xg5j-69w2-9h88.json index 735c4102c7a..3d8b933143a 100644 --- a/advisories/unreviewed/2024/07/GHSA-xg5j-69w2-9h88/GHSA-xg5j-69w2-9h88.json +++ b/advisories/unreviewed/2024/07/GHSA-xg5j-69w2-9h88/GHSA-xg5j-69w2-9h88.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xg5j-69w2-9h88", - "modified": "2024-07-30T06:30:37Z", + "modified": "2024-07-30T15:31:25Z", "published": "2024-07-30T06:30:37Z", "aliases": [ "CVE-2024-6230"