Publish Advisories

GHSA-rqhw-p5r2-7vq4
GHSA-4f92-w438-f484
GHSA-7wxj-7h8h-wm4h
GHSA-8g74-32fg-5ghc
GHSA-8x64-q7xh-c63j
GHSA-j32c-w9r8-wvjv
GHSA-j847-crmf-8mpc
GHSA-vcvq-fwj6-w7gm
This commit is contained in:
advisory-database[bot]
2024-05-02 12:31:51 +00:00
parent 1793baa678
commit bfcebb1fd8
8 changed files with 277 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqhw-p5r2-7vq4",
"modified": "2024-04-05T15:30:31Z",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-04-03T12:31:06Z",
"aliases": [
"CVE-2024-31390"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://snicco.io/vulnerability-disclosure/breakdance/client-mode-remote-code-execution-breakdance-1-7-0?_s_id=cve"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=9glx54-LfRE"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f92-w438-f484",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-3955"
],
"details": "URL GET parameter \"logtime\" utilized within the \"downloadlog\" function from \"cbpi/http_endpoints/http_system.py\" is subsequently passed to the \"os.system\" function in \"cbpi/controller/system_controller.py\" without prior validation allowing to execute arbitrary code.This issue affects CraftBeerPi 4: from 4.0.0.58 (commit 563fae9) before 4.4.1.a1 (commit 57572c7).\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3955"
},
{
"type": "WEB",
"url": "https://github.com/PiBrewing/craftbeerpi4/issues/132"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2024/05/CVE-2024-3955"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2024/05/CVE-2024-3955"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T10:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wxj-7h8h-wm4h",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-33922"
],
"details": "Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Media Cleaner: from n/a through 6.7.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33922"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/media-cleaner/wordpress-wp-media-cleaner-plugin-6-7-2-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T11:15:46Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g74-32fg-5ghc",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-32638"
],
"details": "Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.\n\nUsers are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32638"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/ngvgxllw4zn4hgngkqw2o225kf9wotov"
}
],
"database_specific": {
"cwe_ids": [
"CWE-444"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T10:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x64-q7xh-c63j",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-33930"
],
"details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share This Image: from n/a through 1.97.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33930"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/share-this-image/wordpress-share-this-image-plugin-1-97-open-redirection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T11:15:46Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j32c-w9r8-wvjv",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-33913"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a through 1.6.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33913"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/xserver-migrator/wordpress-xserver-migrator-plugin-1-6-1-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T11:15:45Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j847-crmf-8mpc",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-33911"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33911"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/school-management-pro/wordpress-the-school-management-pro-plugin-10-3-4-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T11:15:45Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcvq-fwj6-w7gm",
"modified": "2024-05-02T12:30:40Z",
"published": "2024-05-02T12:30:40Z",
"aliases": [
"CVE-2024-3005"
],
"details": "The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3005"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3079793/lastudio-element-kit"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/544db0d5-1760-4229-8429-d2391e328304?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T11:15:46Z"
}
}