From c3b6f566739a76c234378626502ddd853efdeea8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 2 Apr 2024 03:32:04 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jw98-jrc9-mrx5.json | 3 +- .../GHSA-p3jh-mv97-74gv.json | 2 +- .../GHSA-pjqv-pvfh-2w6m.json | 6 ++- .../GHSA-ppgm-9w39-cx97.json | 6 ++- .../GHSA-qc99-8rmf-q4mv.json | 6 ++- .../GHSA-xrrw-7rr2-829v.json | 6 ++- .../GHSA-2xvf-jhh8-xv4f.json | 50 +++++++++++++++++++ .../GHSA-392q-fqh8-rw5h.json | 50 +++++++++++++++++++ .../GHSA-57q5-h622-3cpx.json | 38 ++++++++++++++ .../GHSA-6wpm-mvc7-c878.json | 38 ++++++++++++++ .../GHSA-8mh7-5jr7-g9jm.json | 50 +++++++++++++++++++ .../GHSA-frvq-2rgm-73qv.json | 38 ++++++++++++++ .../GHSA-gg92-wfhm-m46w.json | 38 ++++++++++++++ .../GHSA-gqgg-x55f-28q4.json | 38 ++++++++++++++ .../GHSA-h933-77ww-w86w.json | 38 ++++++++++++++ .../GHSA-hj29-7gh7-97xr.json | 38 ++++++++++++++ .../GHSA-hxmf-m9x7-frw3.json | 38 ++++++++++++++ .../GHSA-j4j9-wc5g-p586.json | 38 ++++++++++++++ .../GHSA-m66c-qm7g-w5qx.json | 38 ++++++++++++++ .../GHSA-mcgw-94j6-6g4q.json | 50 +++++++++++++++++++ .../GHSA-r692-wrf3-rhfw.json | 38 ++++++++++++++ .../GHSA-v244-3pmj-9qfc.json | 50 +++++++++++++++++++ .../GHSA-v5rg-5x87-5xv9.json | 38 ++++++++++++++ .../GHSA-v79g-8rxh-2q7g.json | 38 ++++++++++++++ .../GHSA-vgjg-mpj8-9q8q.json | 38 ++++++++++++++ .../GHSA-wgj9-rrf6-3qqq.json | 50 +++++++++++++++++++ .../GHSA-wrv6-52mc-xwcq.json | 50 +++++++++++++++++++ .../GHSA-xmqc-9cfr-hg4r.json | 50 +++++++++++++++++++ 28 files changed, 955 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2xvf-jhh8-xv4f/GHSA-2xvf-jhh8-xv4f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-392q-fqh8-rw5h/GHSA-392q-fqh8-rw5h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-57q5-h622-3cpx/GHSA-57q5-h622-3cpx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6wpm-mvc7-c878/GHSA-6wpm-mvc7-c878.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8mh7-5jr7-g9jm/GHSA-8mh7-5jr7-g9jm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-frvq-2rgm-73qv/GHSA-frvq-2rgm-73qv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gg92-wfhm-m46w/GHSA-gg92-wfhm-m46w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gqgg-x55f-28q4/GHSA-gqgg-x55f-28q4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h933-77ww-w86w/GHSA-h933-77ww-w86w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hj29-7gh7-97xr/GHSA-hj29-7gh7-97xr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hxmf-m9x7-frw3/GHSA-hxmf-m9x7-frw3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m66c-qm7g-w5qx/GHSA-m66c-qm7g-w5qx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r692-wrf3-rhfw/GHSA-r692-wrf3-rhfw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v244-3pmj-9qfc/GHSA-v244-3pmj-9qfc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v5rg-5x87-5xv9/GHSA-v5rg-5x87-5xv9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v79g-8rxh-2q7g/GHSA-v79g-8rxh-2q7g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vgjg-mpj8-9q8q/GHSA-vgjg-mpj8-9q8q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wgj9-rrf6-3qqq/GHSA-wgj9-rrf6-3qqq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wrv6-52mc-xwcq/GHSA-wrv6-52mc-xwcq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xmqc-9cfr-hg4r/GHSA-xmqc-9cfr-hg4r.json diff --git a/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json b/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json index 6ca53ac010b..e04314b7d27 100644 --- a/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json +++ b/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-131" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json b/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json index cf9686c75fe..6cb1045b170 100644 --- a/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json +++ b/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json index e4d4acc4528..c35fda29622 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json +++ b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjqv-pvfh-2w6m", - "modified": "2024-03-27T15:30:37Z", + "modified": "2024-04-02T03:30:43Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-26651" @@ -53,6 +53,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/f546cc19f9b82975238d0ba413adc27714750774" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SI2D7K2T6QCWALKLYEWZ22P4UXMEBCGB" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json index 414de446f9e..346782ec848 100644 --- a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json +++ b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppgm-9w39-cx97", - "modified": "2024-03-26T03:31:33Z", + "modified": "2024-04-02T03:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23284" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214081" diff --git a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json index fe8a1563fd6..95c5a166018 100644 --- a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json +++ b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc99-8rmf-q4mv", - "modified": "2024-03-26T03:31:33Z", + "modified": "2024-04-02T03:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23280" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214081" diff --git a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json index 85d8a1d2ce8..d6af51f64de 100644 --- a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json +++ b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrrw-7rr2-829v", - "modified": "2024-03-26T03:31:33Z", + "modified": "2024-04-02T03:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23263" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214081" diff --git a/advisories/unreviewed/2024/04/GHSA-2xvf-jhh8-xv4f/GHSA-2xvf-jhh8-xv4f.json b/advisories/unreviewed/2024/04/GHSA-2xvf-jhh8-xv4f/GHSA-2xvf-jhh8-xv4f.json new file mode 100644 index 00000000000..a8286c94036 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2xvf-jhh8-xv4f/GHSA-2xvf-jhh8-xv4f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xvf-jhh8-xv4f", + "modified": "2024-04-02T03:30:44Z", + "published": "2024-04-02T03:30:44Z", + "aliases": [ + "CVE-2024-3160" + ], + "details": "** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008 and HDCVI 1016 up to 20240401. This affects an unknown part of the file /cap.js of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier VDB-258933 was assigned to this vulnerability. NOTE: The vendor explains that they do not classify the information shown as sensitive and therefore there is no vulnerability which is about to harm the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3160" + }, + { + "type": "WEB", + "url": "https://github.com/netsecfish/intelbras_cap_js" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.305410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-392q-fqh8-rw5h/GHSA-392q-fqh8-rw5h.json b/advisories/unreviewed/2024/04/GHSA-392q-fqh8-rw5h/GHSA-392q-fqh8-rw5h.json new file mode 100644 index 00000000000..b6928546d2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-392q-fqh8-rw5h/GHSA-392q-fqh8-rw5h.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-392q-fqh8-rw5h", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3147" + ], + "details": "A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/makehtml_map.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258922 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3147" + }, + { + "type": "WEB", + "url": "https://github.com/Hckwzh/cms/blob/main/15.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-57q5-h622-3cpx/GHSA-57q5-h622-3cpx.json b/advisories/unreviewed/2024/04/GHSA-57q5-h622-3cpx/GHSA-57q5-h622-3cpx.json new file mode 100644 index 00000000000..ec17f61b04f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-57q5-h622-3cpx/GHSA-57q5-h622-3cpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57q5-h622-3cpx", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3137" + ], + "details": "Improper Privilege Management in uvdesk/community-skeleton", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3137" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/faf74783-644c-40cd-aa98-2239e5fafcd1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T01:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6wpm-mvc7-c878/GHSA-6wpm-mvc7-c878.json b/advisories/unreviewed/2024/04/GHSA-6wpm-mvc7-c878/GHSA-6wpm-mvc7-c878.json new file mode 100644 index 00000000000..9c4011f58ba --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6wpm-mvc7-c878/GHSA-6wpm-mvc7-c878.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wpm-mvc7-c878", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20849" + ], + "details": "Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20849" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8mh7-5jr7-g9jm/GHSA-8mh7-5jr7-g9jm.json b/advisories/unreviewed/2024/04/GHSA-8mh7-5jr7-g9jm/GHSA-8mh7-5jr7-g9jm.json new file mode 100644 index 00000000000..0dc2e8a66b0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8mh7-5jr7-g9jm/GHSA-8mh7-5jr7-g9jm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mh7-5jr7-g9jm", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3145" + ], + "details": "A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/makehtml_js_action.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258920. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3145" + }, + { + "type": "WEB", + "url": "https://github.com/Hckwzh/cms/blob/main/13.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-frvq-2rgm-73qv/GHSA-frvq-2rgm-73qv.json b/advisories/unreviewed/2024/04/GHSA-frvq-2rgm-73qv/GHSA-frvq-2rgm-73qv.json new file mode 100644 index 00000000000..247a9ad6546 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-frvq-2rgm-73qv/GHSA-frvq-2rgm-73qv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frvq-2rgm-73qv", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20844" + ], + "details": "Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20844" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gg92-wfhm-m46w/GHSA-gg92-wfhm-m46w.json b/advisories/unreviewed/2024/04/GHSA-gg92-wfhm-m46w/GHSA-gg92-wfhm-m46w.json new file mode 100644 index 00000000000..d2334f4b339 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gg92-wfhm-m46w/GHSA-gg92-wfhm-m46w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg92-wfhm-m46w", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20846" + ], + "details": "Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20846" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gqgg-x55f-28q4/GHSA-gqgg-x55f-28q4.json b/advisories/unreviewed/2024/04/GHSA-gqgg-x55f-28q4/GHSA-gqgg-x55f-28q4.json new file mode 100644 index 00000000000..dbd3354c2e7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gqgg-x55f-28q4/GHSA-gqgg-x55f-28q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqgg-x55f-28q4", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20843" + ], + "details": "Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20843" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h933-77ww-w86w/GHSA-h933-77ww-w86w.json b/advisories/unreviewed/2024/04/GHSA-h933-77ww-w86w/GHSA-h933-77ww-w86w.json new file mode 100644 index 00000000000..d56b52b09d3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h933-77ww-w86w/GHSA-h933-77ww-w86w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h933-77ww-w86w", + "modified": "2024-04-02T03:30:44Z", + "published": "2024-04-02T03:30:44Z", + "aliases": [ + "CVE-2024-20854" + ], + "details": "Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20854" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hj29-7gh7-97xr/GHSA-hj29-7gh7-97xr.json b/advisories/unreviewed/2024/04/GHSA-hj29-7gh7-97xr/GHSA-hj29-7gh7-97xr.json new file mode 100644 index 00000000000..f5dcd517d51 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hj29-7gh7-97xr/GHSA-hj29-7gh7-97xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj29-7gh7-97xr", + "modified": "2024-04-02T03:30:44Z", + "published": "2024-04-02T03:30:44Z", + "aliases": [ + "CVE-2024-20851" + ], + "details": "Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity with Samsung Data Store privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20851" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hxmf-m9x7-frw3/GHSA-hxmf-m9x7-frw3.json b/advisories/unreviewed/2024/04/GHSA-hxmf-m9x7-frw3/GHSA-hxmf-m9x7-frw3.json new file mode 100644 index 00000000000..fd59c89a2d4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hxmf-m9x7-frw3/GHSA-hxmf-m9x7-frw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxmf-m9x7-frw3", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20848" + ], + "details": "Out-of-bound Write vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20848" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json b/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json new file mode 100644 index 00000000000..a2c728db9ab --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4j9-wc5g-p586", + "modified": "2024-04-02T03:30:44Z", + "published": "2024-04-02T03:30:44Z", + "aliases": [ + "CVE-2024-20853" + ], + "details": "Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20853" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m66c-qm7g-w5qx/GHSA-m66c-qm7g-w5qx.json b/advisories/unreviewed/2024/04/GHSA-m66c-qm7g-w5qx/GHSA-m66c-qm7g-w5qx.json new file mode 100644 index 00000000000..ed0f74fb844 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m66c-qm7g-w5qx/GHSA-m66c-qm7g-w5qx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m66c-qm7g-w5qx", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20845" + ], + "details": "Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20845" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json new file mode 100644 index 00000000000..a39fe0a96a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcgw-94j6-6g4q", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3142" + ], + "details": "A vulnerability was found in Clavister E10 and E80 up to 20240323 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258917 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3142" + }, + { + "type": "WEB", + "url": "https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303530" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T01:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r692-wrf3-rhfw/GHSA-r692-wrf3-rhfw.json b/advisories/unreviewed/2024/04/GHSA-r692-wrf3-rhfw/GHSA-r692-wrf3-rhfw.json new file mode 100644 index 00000000000..0609d86041b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r692-wrf3-rhfw/GHSA-r692-wrf3-rhfw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r692-wrf3-rhfw", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20850" + ], + "details": "Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20850" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v244-3pmj-9qfc/GHSA-v244-3pmj-9qfc.json b/advisories/unreviewed/2024/04/GHSA-v244-3pmj-9qfc/GHSA-v244-3pmj-9qfc.json new file mode 100644 index 00000000000..2b3fab6de42 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v244-3pmj-9qfc/GHSA-v244-3pmj-9qfc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v244-3pmj-9qfc", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3146" + ], + "details": "A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/makehtml_rss_action.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258921 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3146" + }, + { + "type": "WEB", + "url": "https://github.com/Hckwzh/cms/blob/main/14.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303956" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v5rg-5x87-5xv9/GHSA-v5rg-5x87-5xv9.json b/advisories/unreviewed/2024/04/GHSA-v5rg-5x87-5xv9/GHSA-v5rg-5x87-5xv9.json new file mode 100644 index 00000000000..8213c8c3283 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v5rg-5x87-5xv9/GHSA-v5rg-5x87-5xv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5rg-5x87-5xv9", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20847" + ], + "details": "Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20847" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v79g-8rxh-2q7g/GHSA-v79g-8rxh-2q7g.json b/advisories/unreviewed/2024/04/GHSA-v79g-8rxh-2q7g/GHSA-v79g-8rxh-2q7g.json new file mode 100644 index 00000000000..bf52e6cff60 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v79g-8rxh-2q7g/GHSA-v79g-8rxh-2q7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v79g-8rxh-2q7g", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-20842" + ], + "details": "Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20842" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vgjg-mpj8-9q8q/GHSA-vgjg-mpj8-9q8q.json b/advisories/unreviewed/2024/04/GHSA-vgjg-mpj8-9q8q/GHSA-vgjg-mpj8-9q8q.json new file mode 100644 index 00000000000..76a04bc14c0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vgjg-mpj8-9q8q/GHSA-vgjg-mpj8-9q8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgjg-mpj8-9q8q", + "modified": "2024-04-02T03:30:44Z", + "published": "2024-04-02T03:30:44Z", + "aliases": [ + "CVE-2024-20852" + ], + "details": "Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20852" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wgj9-rrf6-3qqq/GHSA-wgj9-rrf6-3qqq.json b/advisories/unreviewed/2024/04/GHSA-wgj9-rrf6-3qqq/GHSA-wgj9-rrf6-3qqq.json new file mode 100644 index 00000000000..6dc1de3ecdb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wgj9-rrf6-3qqq/GHSA-wgj9-rrf6-3qqq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgj9-rrf6-3qqq", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3143" + ], + "details": "A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/member_rank.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258918 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3143" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/demo/blob/main/39.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T01:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wrv6-52mc-xwcq/GHSA-wrv6-52mc-xwcq.json b/advisories/unreviewed/2024/04/GHSA-wrv6-52mc-xwcq/GHSA-wrv6-52mc-xwcq.json new file mode 100644 index 00000000000..94ff173a31e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wrv6-52mc-xwcq/GHSA-wrv6-52mc-xwcq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrv6-52mc-xwcq", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3148" + ], + "details": "A vulnerability, which was classified as critical, has been found in DedeCMS 5.7.112. This issue affects some unknown processing of the file dede/makehtml_archives_action.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258923. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3148" + }, + { + "type": "WEB", + "url": "https://github.com/gatsby2003/DedeCms/blob/main/DedeCms%20sql%20time-based%20blind%20injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303889" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xmqc-9cfr-hg4r/GHSA-xmqc-9cfr-hg4r.json b/advisories/unreviewed/2024/04/GHSA-xmqc-9cfr-hg4r/GHSA-xmqc-9cfr-hg4r.json new file mode 100644 index 00000000000..9689b1964e3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xmqc-9cfr-hg4r/GHSA-xmqc-9cfr-hg4r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmqc-9cfr-hg4r", + "modified": "2024-04-02T03:30:43Z", + "published": "2024-04-02T03:30:43Z", + "aliases": [ + "CVE-2024-3144" + ], + "details": "A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3144" + }, + { + "type": "WEB", + "url": "https://github.com/Hckwzh/cms/blob/main/12.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303954" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T02:15:07Z" + } +} \ No newline at end of file