From bf21fa964d3af968054dc37bbaa80699c7036913 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 23 May 2024 00:32:05 +0000 Subject: [PATCH] Publish Advisories GHSA-78hx-gp6g-7mj6 GHSA-pv5w-g537-v27f GHSA-2874-f7gx-365p GHSA-3wqm-ppwr-mjfv GHSA-4m76-9mrc-2hg5 GHSA-5m7g-hw7h-q4qh GHSA-7rp9-cgvf-834p GHSA-9pf7-cj2r-vr62 GHSA-fmh4-p5x3-6hxh GHSA-p4g5-chr9-3gf5 GHSA-qxx4-523c-98q7 --- .../GHSA-78hx-gp6g-7mj6.json | 134 ++++++++++-------- .../GHSA-pv5w-g537-v27f.json | 10 +- .../GHSA-2874-f7gx-365p.json | 38 +++++ .../GHSA-3wqm-ppwr-mjfv.json | 38 +++++ .../GHSA-4m76-9mrc-2hg5.json | 38 +++++ .../GHSA-5m7g-hw7h-q4qh.json | 6 +- .../GHSA-7rp9-cgvf-834p.json | 38 +++++ .../GHSA-9pf7-cj2r-vr62.json | 38 +++++ .../GHSA-fmh4-p5x3-6hxh.json | 38 +++++ .../GHSA-p4g5-chr9-3gf5.json | 38 +++++ .../GHSA-qxx4-523c-98q7.json | 38 +++++ 11 files changed, 391 insertions(+), 63 deletions(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4m76-9mrc-2hg5/GHSA-4m76-9mrc-2hg5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json create mode 100644 advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index 7be1957fa52..671e8b5480c 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-05-23T00:30:37Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -136,35 +136,7 @@ }, { "type": "WEB", - "url": "https://vuln.go.dev/ID/GO-2024-2660.json" - }, - { - "type": "WEB", - "url": "https://pkg.go.dev/vuln/GO-2024-2660" - }, - { - "type": "WEB", - "url": "https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9" - }, - { - "type": "WEB", - "url": "https://github.com/golang-fips/openssl/releases/tag/v2.0.1" - }, - { - "type": "PACKAGE", - "url": "https://github.com/golang-fips/openssl" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262921" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/CVE-2024-1394" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:3265" + "url": "https://access.redhat.com/errata/RHSA-2024:1462" }, { "type": "WEB", @@ -172,63 +144,47 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:2568" + "url": "https://access.redhat.com/errata/RHSA-2024:2729" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:2562" + "url": "https://access.redhat.com/errata/RHSA-2024:2730" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1897" + "url": "https://access.redhat.com/errata/RHSA-2024:2767" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1763" + "url": "https://access.redhat.com/errata/RHSA-2024:3265" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1646" + "url": "https://access.redhat.com/security/cve/CVE-2024-1394" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1644" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262921" + }, + { + "type": "PACKAGE", + "url": "https://github.com/golang-fips/openssl" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1640" + "url": "https://github.com/golang-fips/openssl/releases/tag/v2.0.1" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1574" + "url": "https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1567" + "url": "https://pkg.go.dev/vuln/GO-2024-2660" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1566" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1563" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1561" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1501" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1472" + "url": "https://vuln.go.dev/ID/GO-2024-2660.json" }, { "type": "WEB", @@ -236,7 +192,63 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1462" + "url": "https://access.redhat.com/errata/RHSA-2024:1472" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1501" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1561" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1563" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1566" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1567" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1574" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1640" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1644" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1646" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1763" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1897" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2562" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2568" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-pv5w-g537-v27f/GHSA-pv5w-g537-v27f.json b/advisories/unreviewed/2024/03/GHSA-pv5w-g537-v27f/GHSA-pv5w-g537-v27f.json index 51b7b05eb6d..e4389ae6e30 100644 --- a/advisories/unreviewed/2024/03/GHSA-pv5w-g537-v27f/GHSA-pv5w-g537-v27f.json +++ b/advisories/unreviewed/2024/03/GHSA-pv5w-g537-v27f/GHSA-pv5w-g537-v27f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv5w-g537-v27f", - "modified": "2024-03-15T15:30:43Z", + "modified": "2024-05-23T00:30:37Z", "published": "2024-03-15T15:30:42Z", "aliases": [ "CVE-2023-6725" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2736" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2770" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6725" diff --git a/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json b/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json new file mode 100644 index 00000000000..5f5a17c4998 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2874-f7gx-365p", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2024-29850" + ], + "details": "Veeam Backup Enterprise Manager allows account takeover via NTLM relay.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29850" + }, + { + "type": "WEB", + "url": "https://veeam.com/kb4581" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json b/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json new file mode 100644 index 00000000000..0d2d4fc38a1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wqm-ppwr-mjfv", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2023-46807" + ], + "details": "An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46807" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4m76-9mrc-2hg5/GHSA-4m76-9mrc-2hg5.json b/advisories/unreviewed/2024/05/GHSA-4m76-9mrc-2hg5/GHSA-4m76-9mrc-2hg5.json new file mode 100644 index 00000000000..a883138b02b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4m76-9mrc-2hg5/GHSA-4m76-9mrc-2hg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m76-9mrc-2hg5", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2024-22026" + ], + "details": "A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22026" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5m7g-hw7h-q4qh/GHSA-5m7g-hw7h-q4qh.json b/advisories/unreviewed/2024/05/GHSA-5m7g-hw7h-q4qh/GHSA-5m7g-hw7h-q4qh.json index c8712eda25d..ccd804f905a 100644 --- a/advisories/unreviewed/2024/05/GHSA-5m7g-hw7h-q4qh/GHSA-5m7g-hw7h-q4qh.json +++ b/advisories/unreviewed/2024/05/GHSA-5m7g-hw7h-q4qh/GHSA-5m7g-hw7h-q4qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5m7g-hw7h-q4qh", - "modified": "2024-05-08T09:30:50Z", + "modified": "2024-05-23T00:30:37Z", "published": "2024-05-08T09:30:50Z", "aliases": [ "CVE-2024-4438" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4438" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2729" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4438" diff --git a/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json b/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json new file mode 100644 index 00000000000..8fe8a4256d8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rp9-cgvf-834p", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2023-46806" + ], + "details": "An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46806" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPMM-May-2024?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json b/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json new file mode 100644 index 00000000000..db2d52a831a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pf7-cj2r-vr62", + "modified": "2024-05-23T00:30:38Z", + "published": "2024-05-23T00:30:38Z", + "aliases": [ + "CVE-2024-29853" + ], + "details": "An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29853" + }, + { + "type": "WEB", + "url": "https://veeam.com/kb4582" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json new file mode 100644 index 00000000000..411562ab705 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmh4-p5x3-6hxh", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2024-29851" + ], + "details": "Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29851" + }, + { + "type": "WEB", + "url": "https://veeam.com/kb4581" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json b/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json new file mode 100644 index 00000000000..eaf0076d5a9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4g5-chr9-3gf5", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2024-29849" + ], + "details": "Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29849" + }, + { + "type": "WEB", + "url": "https://veeam.com/kb4581" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json b/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json new file mode 100644 index 00000000000..dfddb1d42b2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxx4-523c-98q7", + "modified": "2024-05-23T00:30:37Z", + "published": "2024-05-23T00:30:37Z", + "aliases": [ + "CVE-2024-29852" + ], + "details": "Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29852" + }, + { + "type": "WEB", + "url": "https://veeam.com/kb4581" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T23:15:09Z" + } +} \ No newline at end of file