mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-fc22-jfw7-2qhg GHSA-wrh5-96rf-7qq2 GHSA-j3w3-rrqq-mpx3 GHSA-9hq5-xh26-hcx9 GHSA-9p47-x6rm-qgxw GHSA-mjh6-hm62-6x3r GHSA-2r34-6f9h-2rxg GHSA-5777-q3q8-vhh3 GHSA-5rq6-q8gw-qqpr GHSA-99w6-3xph-cx78 GHSA-jmg6-w85r-58w8 GHSA-m3m4-wgh9-w3h5 GHSA-rrg5-rjgq-p223 GHSA-v24h-h5qr-mqm8 GHSA-wq8w-m2g8-mv57
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fc22-jfw7-2qhg",
|
||||
"modified": "2022-07-13T00:01:27Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2021-12-08T00:00:49Z",
|
||||
"aliases": [
|
||||
"CVE-2021-34543"
|
||||
@@ -36,6 +36,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-306",
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wrh5-96rf-7qq2",
|
||||
"modified": "2021-12-10T00:01:15Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2021-12-08T00:00:49Z",
|
||||
"aliases": [
|
||||
"CVE-2021-34544"
|
||||
],
|
||||
"details": "An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j3w3-rrqq-mpx3",
|
||||
"modified": "2023-02-06T18:30:30Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2023-01-26T21:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2022-47767"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9hq5-xh26-hcx9",
|
||||
"modified": "2024-02-09T21:30:57Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2024-02-02T03:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46344"
|
||||
@@ -25,6 +25,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/vinnie1717/CVE-2023-46344/blob/main/Solar-Log%20XSS"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.solar-log.com/en/support/firmware-database-1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://solar-log.com"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9p47-x6rm-qgxw",
|
||||
"modified": "2024-08-01T15:32:13Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2024-07-26T21:31:16Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40117"
|
||||
@@ -28,6 +28,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Incorrect%20Access%20Control"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.solar-log.com/en/support/firmware-database-1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mjh6-hm62-6x3r",
|
||||
"modified": "2024-07-26T21:31:16Z",
|
||||
"modified": "2024-11-12T00:30:35Z",
|
||||
"published": "2024-07-26T21:31:16Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40116"
|
||||
@@ -21,6 +21,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unprotected%20Storage%20of%20Credentials"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.solar-log.com/en/support/firmware-database-1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2r34-6f9h-2rxg",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51213"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51213"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/Prabhatsk7/CVE/blob/main/CVE-2024-51213"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5777-q3q8-vhh3",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-50601"
|
||||
],
|
||||
"details": "Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50601"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.axigen.com/knowledgebase/Axigen-WebMail-Persistent-and-Reflected-XSS-Vulnerabilities-CVE-2024-50601-_403.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5rq6-q8gw-qqpr",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-52533"
|
||||
],
|
||||
"details": "gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\\0' character.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52533"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3461"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-99w6-3xph-cx78",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-11079"
|
||||
],
|
||||
"details": "A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11079"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-11079"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325171"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-12T00:15:15Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jmg6-w85r-58w8",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25254"
|
||||
],
|
||||
"details": "SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25254"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://exploitart.ist/exploit/2023/09/18/superscan-os-command-injection.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m3m4-wgh9-w3h5",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25255"
|
||||
],
|
||||
"details": "Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25255"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://exploitart.ist/exploit/2023/09/17/sublime-text-os-command-injection.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rrg5-rjgq-p223",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-23983"
|
||||
],
|
||||
"details": "Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:M/U:Amber"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23983"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.pingidentity.com/pingaccess/latest/release_notes/pa_811_rn.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.pingidentity.com/en/resources/downloads/pingaccess.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-177"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v24h-h5qr-mqm8",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25253"
|
||||
],
|
||||
"details": "Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25253"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://exploitart.ist/exploit/2023/09/10/driver-booster-buffer-overflow.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wq8w-m2g8-mv57",
|
||||
"modified": "2024-11-12T00:30:36Z",
|
||||
"published": "2024-11-12T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-50636"
|
||||
],
|
||||
"details": "PyMOL 2.5.0 contains a vulnerability in its \"Run Script\" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote Command Execution (RCE). This vulnerability arises because PyMOL treats .PYM files as Python scripts without properly validating or restricting the commands within the script, enabling attackers to run unauthorized commands in the context of the user running the application.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50636"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/schrodinger/pymol-open-source/issues/405"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/yamerooo123/CVE/blob/main/CVE-2024-50636/Description.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://youtu.be/SWnN_a1tUNc"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-11-11T23:15:05Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user