Publish Advisories

GHSA-78hx-gp6g-7mj6
GHSA-pv5w-g537-v27f
GHSA-2874-f7gx-365p
GHSA-3wqm-ppwr-mjfv
GHSA-4m76-9mrc-2hg5
GHSA-5m7g-hw7h-q4qh
GHSA-7rp9-cgvf-834p
GHSA-9pf7-cj2r-vr62
GHSA-fmh4-p5x3-6hxh
GHSA-p4g5-chr9-3gf5
GHSA-qxx4-523c-98q7
This commit is contained in:
advisory-database[bot]
2024-05-23 00:32:05 +00:00
parent bc1422c6e7
commit bf21fa964d
11 changed files with 391 additions and 63 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78hx-gp6g-7mj6",
"modified": "2024-05-22T18:30:40Z",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-03-20T18:10:36Z",
"aliases": [
"CVE-2024-1394"
@@ -136,35 +136,7 @@
},
{
"type": "WEB",
"url": "https://vuln.go.dev/ID/GO-2024-2660.json"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2024-2660"
},
{
"type": "WEB",
"url": "https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9"
},
{
"type": "WEB",
"url": "https://github.com/golang-fips/openssl/releases/tag/v2.0.1"
},
{
"type": "PACKAGE",
"url": "https://github.com/golang-fips/openssl"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262921"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1394"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3265"
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
@@ -172,63 +144,47 @@
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2568"
"url": "https://access.redhat.com/errata/RHSA-2024:2729"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2562"
"url": "https://access.redhat.com/errata/RHSA-2024:2730"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1897"
"url": "https://access.redhat.com/errata/RHSA-2024:2767"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1763"
"url": "https://access.redhat.com/errata/RHSA-2024:3265"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1646"
"url": "https://access.redhat.com/security/cve/CVE-2024-1394"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1644"
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262921"
},
{
"type": "PACKAGE",
"url": "https://github.com/golang-fips/openssl"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1640"
"url": "https://github.com/golang-fips/openssl/releases/tag/v2.0.1"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1574"
"url": "https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1567"
"url": "https://pkg.go.dev/vuln/GO-2024-2660"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1566"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1563"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1561"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1501"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1472"
"url": "https://vuln.go.dev/ID/GO-2024-2660.json"
},
{
"type": "WEB",
@@ -236,7 +192,63 @@
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
"url": "https://access.redhat.com/errata/RHSA-2024:1472"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1501"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1561"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1563"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1566"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1567"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1574"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1640"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1644"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1646"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1763"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1897"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2562"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2568"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv5w-g537-v27f",
"modified": "2024-03-15T15:30:43Z",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-03-15T15:30:42Z",
"aliases": [
"CVE-2023-6725"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6725"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2736"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2770"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6725"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2874-f7gx-365p",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2024-29850"
],
"details": "Veeam Backup Enterprise Manager allows account takeover via NTLM relay.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29850"
},
{
"type": "WEB",
"url": "https://veeam.com/kb4581"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wqm-ppwr-mjfv",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2023-46807"
],
"details": "An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46807"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m76-9mrc-2hg5",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2024-22026"
],
"details": "A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22026"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5m7g-hw7h-q4qh",
"modified": "2024-05-08T09:30:50Z",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-08T09:30:50Z",
"aliases": [
"CVE-2024-4438"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4438"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2729"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4438"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7rp9-cgvf-834p",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2023-46806"
],
"details": "An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. ",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46806"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pf7-cj2r-vr62",
"modified": "2024-05-23T00:30:38Z",
"published": "2024-05-23T00:30:38Z",
"aliases": [
"CVE-2024-29853"
],
"details": "An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29853"
},
{
"type": "WEB",
"url": "https://veeam.com/kb4582"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmh4-p5x3-6hxh",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2024-29851"
],
"details": "Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29851"
},
{
"type": "WEB",
"url": "https://veeam.com/kb4581"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4g5-chr9-3gf5",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2024-29849"
],
"details": "Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29849"
},
{
"type": "WEB",
"url": "https://veeam.com/kb4581"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxx4-523c-98q7",
"modified": "2024-05-23T00:30:37Z",
"published": "2024-05-23T00:30:37Z",
"aliases": [
"CVE-2024-29852"
],
"details": "Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29852"
},
{
"type": "WEB",
"url": "https://veeam.com/kb4581"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T23:15:09Z"
}
}