From c10de022876193501ceacac481d6996fbfd3bb43 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 19 Sep 2024 00:33:03 +0000 Subject: [PATCH] Publish Advisories GHSA-g5c7-69g3-565r GHSA-pp8w-q3c5-5qcp GHSA-p68r-f2j8-7389 GHSA-rgqw-g866-w59h GHSA-5hc5-fxr9-5frc GHSA-p47r-4xrv-2qwg --- .../GHSA-g5c7-69g3-565r.json | 3 +- .../GHSA-pp8w-q3c5-5qcp.json | 3 +- .../GHSA-p68r-f2j8-7389.json | 3 +- .../GHSA-rgqw-g866-w59h.json | 3 +- .../GHSA-5hc5-fxr9-5frc.json | 38 +++++++++++++++++++ .../GHSA-p47r-4xrv-2qwg.json | 35 +++++++++++++++++ 6 files changed, 81 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-5hc5-fxr9-5frc/GHSA-5hc5-fxr9-5frc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p47r-4xrv-2qwg/GHSA-p47r-4xrv-2qwg.json diff --git a/advisories/unreviewed/2023/08/GHSA-g5c7-69g3-565r/GHSA-g5c7-69g3-565r.json b/advisories/unreviewed/2023/08/GHSA-g5c7-69g3-565r/GHSA-g5c7-69g3-565r.json index e15503c5522..329b91d7fd8 100644 --- a/advisories/unreviewed/2023/08/GHSA-g5c7-69g3-565r/GHSA-g5c7-69g3-565r.json +++ b/advisories/unreviewed/2023/08/GHSA-g5c7-69g3-565r/GHSA-g5c7-69g3-565r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5c7-69g3-565r", - "modified": "2023-11-24T09:30:27Z", + "modified": "2024-09-19T00:31:32Z", "published": "2023-08-31T03:30:36Z", "aliases": [ "CVE-2023-4162" @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-125", + "CWE-252", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/08/GHSA-pp8w-q3c5-5qcp/GHSA-pp8w-q3c5-5qcp.json b/advisories/unreviewed/2023/08/GHSA-pp8w-q3c5-5qcp/GHSA-pp8w-q3c5-5qcp.json index 80679a1a766..4a236fd3328 100644 --- a/advisories/unreviewed/2023/08/GHSA-pp8w-q3c5-5qcp/GHSA-pp8w-q3c5-5qcp.json +++ b/advisories/unreviewed/2023/08/GHSA-pp8w-q3c5-5qcp/GHSA-pp8w-q3c5-5qcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp8w-q3c5-5qcp", - "modified": "2023-11-02T03:30:25Z", + "modified": "2024-09-19T00:31:32Z", "published": "2023-08-01T21:30:43Z", "aliases": [ "CVE-2023-31429" @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-200", + "CWE-209", "CWE-77" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json b/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json index 5dcec9d12fa..e601df8498f 100644 --- a/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json +++ b/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json b/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json index b664d4ae423..a25b3427b57 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json +++ b/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-922" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5hc5-fxr9-5frc/GHSA-5hc5-fxr9-5frc.json b/advisories/unreviewed/2024/09/GHSA-5hc5-fxr9-5frc/GHSA-5hc5-fxr9-5frc.json new file mode 100644 index 00000000000..9447c78b9fb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5hc5-fxr9-5frc/GHSA-5hc5-fxr9-5frc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hc5-fxr9-5frc", + "modified": "2024-09-19T00:31:32Z", + "published": "2024-09-19T00:31:32Z", + "aliases": [ + "CVE-2022-25770" + ], + "details": "Mautic allows you to update the application via an upgrade script.\n\nThe upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.\n\nThis vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrc" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25770" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p47r-4xrv-2qwg/GHSA-p47r-4xrv-2qwg.json b/advisories/unreviewed/2024/09/GHSA-p47r-4xrv-2qwg/GHSA-p47r-4xrv-2qwg.json new file mode 100644 index 00000000000..19151da0643 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p47r-4xrv-2qwg/GHSA-p47r-4xrv-2qwg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p47r-4xrv-2qwg", + "modified": "2024-09-19T00:31:32Z", + "published": "2024-09-19T00:31:32Z", + "aliases": [ + "CVE-2024-37406" + ], + "details": "In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37406" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2501378" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T22:15:04Z" + } +} \ No newline at end of file