Publish Advisories

GHSA-fc22-jfw7-2qhg
GHSA-wrh5-96rf-7qq2
GHSA-j3w3-rrqq-mpx3
GHSA-9hq5-xh26-hcx9
GHSA-9p47-x6rm-qgxw
GHSA-mjh6-hm62-6x3r
GHSA-2r34-6f9h-2rxg
GHSA-5777-q3q8-vhh3
GHSA-5rq6-q8gw-qqpr
GHSA-99w6-3xph-cx78
GHSA-jmg6-w85r-58w8
GHSA-m3m4-wgh9-w3h5
GHSA-rrg5-rjgq-p223
GHSA-v24h-h5qr-mqm8
GHSA-wq8w-m2g8-mv57
This commit is contained in:
advisory-database[bot]
2024-11-12 00:31:44 +00:00
parent af83453708
commit c11d3469dc
15 changed files with 368 additions and 7 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc22-jfw7-2qhg",
"modified": "2022-07-13T00:01:27Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2021-12-08T00:00:49Z",
"aliases": [
"CVE-2021-34543"
@@ -36,6 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-306",
"CWE-862"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrh5-96rf-7qq2",
"modified": "2021-12-10T00:01:15Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2021-12-08T00:00:49Z",
"aliases": [
"CVE-2021-34544"
],
"details": "An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3w3-rrqq-mpx3",
"modified": "2023-02-06T18:30:30Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2023-01-26T21:30:20Z",
"aliases": [
"CVE-2022-47767"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hq5-xh26-hcx9",
"modified": "2024-02-09T21:30:57Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2024-02-02T03:30:32Z",
"aliases": [
"CVE-2023-46344"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/vinnie1717/CVE-2023-46344/blob/main/Solar-Log%20XSS"
},
{
"type": "WEB",
"url": "https://www.solar-log.com/en/support/firmware-database-1"
},
{
"type": "WEB",
"url": "http://solar-log.com"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9p47-x6rm-qgxw",
"modified": "2024-08-01T15:32:13Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2024-07-26T21:31:16Z",
"aliases": [
"CVE-2024-40117"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Incorrect%20Access%20Control"
},
{
"type": "WEB",
"url": "https://www.solar-log.com/en/support/firmware-database-1"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjh6-hm62-6x3r",
"modified": "2024-07-26T21:31:16Z",
"modified": "2024-11-12T00:30:35Z",
"published": "2024-07-26T21:31:16Z",
"aliases": [
"CVE-2024-40116"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unprotected%20Storage%20of%20Credentials"
},
{
"type": "WEB",
"url": "https://www.solar-log.com/en/support/firmware-database-1"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r34-6f9h-2rxg",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-51213"
],
"details": "Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51213"
},
{
"type": "WEB",
"url": "https://github.com/Prabhatsk7/CVE/blob/main/CVE-2024-51213"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5777-q3q8-vhh3",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-50601"
],
"details": "Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50601"
},
{
"type": "WEB",
"url": "https://www.axigen.com/knowledgebase/Axigen-WebMail-Persistent-and-Reflected-XSS-Vulnerabilities-CVE-2024-50601-_403.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rq6-q8gw-qqpr",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-52533"
],
"details": "gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\\0' character.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52533"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3461"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99w6-3xph-cx78",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-11079"
],
"details": "A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11079"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-11079"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325171"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-12T00:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmg6-w85r-58w8",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-25254"
],
"details": "SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25254"
},
{
"type": "WEB",
"url": "https://exploitart.ist/exploit/2023/09/18/superscan-os-command-injection.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3m4-wgh9-w3h5",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-25255"
],
"details": "Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25255"
},
{
"type": "WEB",
"url": "https://exploitart.ist/exploit/2023/09/17/sublime-text-os-command-injection.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrg5-rjgq-p223",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-23983"
],
"details": "Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:M/U:Amber"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23983"
},
{
"type": "WEB",
"url": "https://docs.pingidentity.com/pingaccess/latest/release_notes/pa_811_rn.html"
},
{
"type": "WEB",
"url": "https://www.pingidentity.com/en/resources/downloads/pingaccess.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-177"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v24h-h5qr-mqm8",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-25253"
],
"details": "Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25253"
},
{
"type": "WEB",
"url": "https://exploitart.ist/exploit/2023/09/10/driver-booster-buffer-overflow.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq8w-m2g8-mv57",
"modified": "2024-11-12T00:30:36Z",
"published": "2024-11-12T00:30:36Z",
"aliases": [
"CVE-2024-50636"
],
"details": "PyMOL 2.5.0 contains a vulnerability in its \"Run Script\" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote Command Execution (RCE). This vulnerability arises because PyMOL treats .PYM files as Python scripts without properly validating or restricting the commands within the script, enabling attackers to run unauthorized commands in the context of the user running the application.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50636"
},
{
"type": "WEB",
"url": "https://github.com/schrodinger/pymol-open-source/issues/405"
},
{
"type": "WEB",
"url": "https://github.com/yamerooo123/CVE/blob/main/CVE-2024-50636/Description.md"
},
{
"type": "WEB",
"url": "https://youtu.be/SWnN_a1tUNc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T23:15:05Z"
}
}