diff --git a/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json b/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json index e7b53797371..48813129669 100644 --- a/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json +++ b/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4x75-37xv-wgwv/GHSA-4x75-37xv-wgwv.json b/advisories/unreviewed/2022/05/GHSA-4x75-37xv-wgwv/GHSA-4x75-37xv-wgwv.json index c661e276441..09dc2455139 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x75-37xv-wgwv/GHSA-4x75-37xv-wgwv.json +++ b/advisories/unreviewed/2022/05/GHSA-4x75-37xv-wgwv/GHSA-4x75-37xv-wgwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x75-37xv-wgwv", - "modified": "2022-05-24T17:07:54Z", + "modified": "2024-10-29T15:31:58Z", "published": "2022-05-24T17:07:54Z", "aliases": [ "CVE-2020-8549" diff --git a/advisories/unreviewed/2022/05/GHSA-v4m3-hw9h-pqgx/GHSA-v4m3-hw9h-pqgx.json b/advisories/unreviewed/2022/05/GHSA-v4m3-hw9h-pqgx/GHSA-v4m3-hw9h-pqgx.json index 35e12587ef0..c64c50eb0a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4m3-hw9h-pqgx/GHSA-v4m3-hw9h-pqgx.json +++ b/advisories/unreviewed/2022/05/GHSA-v4m3-hw9h-pqgx/GHSA-v4m3-hw9h-pqgx.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-wm64-883p-84j3/GHSA-wm64-883p-84j3.json b/advisories/unreviewed/2022/05/GHSA-wm64-883p-84j3/GHSA-wm64-883p-84j3.json index 5ff8ef416c3..625c57bc5f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm64-883p-84j3/GHSA-wm64-883p-84j3.json +++ b/advisories/unreviewed/2022/05/GHSA-wm64-883p-84j3/GHSA-wm64-883p-84j3.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-277", "CWE-59" ], diff --git a/advisories/unreviewed/2023/08/GHSA-f4mg-7m9f-26xv/GHSA-f4mg-7m9f-26xv.json b/advisories/unreviewed/2023/08/GHSA-f4mg-7m9f-26xv/GHSA-f4mg-7m9f-26xv.json index 7c965ec3606..704a43fdadd 100644 --- a/advisories/unreviewed/2023/08/GHSA-f4mg-7m9f-26xv/GHSA-f4mg-7m9f-26xv.json +++ b/advisories/unreviewed/2023/08/GHSA-f4mg-7m9f-26xv/GHSA-f4mg-7m9f-26xv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3cp5-cfv6-4x6r/GHSA-3cp5-cfv6-4x6r.json b/advisories/unreviewed/2024/06/GHSA-3cp5-cfv6-4x6r/GHSA-3cp5-cfv6-4x6r.json index db8411911eb..3f9d7141fce 100644 --- a/advisories/unreviewed/2024/06/GHSA-3cp5-cfv6-4x6r/GHSA-3cp5-cfv6-4x6r.json +++ b/advisories/unreviewed/2024/06/GHSA-3cp5-cfv6-4x6r/GHSA-3cp5-cfv6-4x6r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json b/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json index cf0d8fd64f9..eb57962eb67 100644 --- a/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json +++ b/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94mv-6g8w-jxvx", - "modified": "2024-08-16T00:32:04Z", + "modified": "2024-10-29T15:31:58Z", "published": "2024-06-11T21:32:17Z", "aliases": [ "CVE-2024-28020" diff --git a/advisories/unreviewed/2024/10/GHSA-2443-9w48-793g/GHSA-2443-9w48-793g.json b/advisories/unreviewed/2024/10/GHSA-2443-9w48-793g/GHSA-2443-9w48-793g.json new file mode 100644 index 00000000000..4a53bdd674a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2443-9w48-793g/GHSA-2443-9w48-793g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2443-9w48-793g", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7472" + ], + "details": "lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \\xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7472" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/a39837d7c49936a0c435d241f37ca2ea7904d2cd" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/dc1feec6-1efb-4538-9b56-ab25deb80948" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-75" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-286r-8vxx-54v4/GHSA-286r-8vxx-54v4.json b/advisories/unreviewed/2024/10/GHSA-286r-8vxx-54v4/GHSA-286r-8vxx-54v4.json new file mode 100644 index 00000000000..239740b0e9e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-286r-8vxx-54v4/GHSA-286r-8vxx-54v4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-286r-8vxx-54v4", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7475" + ], + "details": "An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7475" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/78c824f7-3b6d-443d-bb76-0f8031c6c126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2h96-7jv3-737m/GHSA-2h96-7jv3-737m.json b/advisories/unreviewed/2024/10/GHSA-2h96-7jv3-737m/GHSA-2h96-7jv3-737m.json new file mode 100644 index 00000000000..6f061c8b026 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2h96-7jv3-737m/GHSA-2h96-7jv3-737m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h96-7jv3-737m", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-8143" + ], + "details": "In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8143" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/ccc7479ace5c9e1a1d9f4daf2e794ffd3865fc2b" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/71c5ea4b-524a-4173-8fd4-2fbabd69502e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1057" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2w8h-hch2-v23h/GHSA-2w8h-hch2-v23h.json b/advisories/unreviewed/2024/10/GHSA-2w8h-hch2-v23h/GHSA-2w8h-hch2-v23h.json new file mode 100644 index 00000000000..18b8f832224 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2w8h-hch2-v23h/GHSA-2w8h-hch2-v23h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w8h-hch2-v23h", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-6868" + ], + "details": "mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be exploited to perform a 'tarslip' attack, allowing files to be written to arbitrary locations on the server, bypassing checks that normally restrict files to the models directory. This vulnerability can lead to remote code execution (RCE) by overwriting backend assets used by the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6868" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/a181dd0ebc5d3092fc50f61674d552604fe8ef9c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/752d2376-2d9a-4e17-b462-3c267f9dd229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2wmg-wcpx-h559/GHSA-2wmg-wcpx-h559.json b/advisories/unreviewed/2024/10/GHSA-2wmg-wcpx-h559/GHSA-2wmg-wcpx-h559.json new file mode 100644 index 00000000000..f60e031f3cc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2wmg-wcpx-h559/GHSA-2wmg-wcpx-h559.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wmg-wcpx-h559", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49645" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smdp-affiliate-platform/wordpress-affiliate-platform-plugin-1-4-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3422-7r3j-w49g/GHSA-3422-7r3j-w49g.json b/advisories/unreviewed/2024/10/GHSA-3422-7r3j-w49g/GHSA-3422-7r3j-w49g.json new file mode 100644 index 00000000000..7fbb52feb46 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3422-7r3j-w49g/GHSA-3422-7r3j-w49g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3422-7r3j-w49g", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-51181" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via \" searchifsccode\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51181" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/IFSC%20Code%20Finder/IFSC%20Code%20Finder%20Admin.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3qxp-588w-rmqg/GHSA-3qxp-588w-rmqg.json b/advisories/unreviewed/2024/10/GHSA-3qxp-588w-rmqg/GHSA-3qxp-588w-rmqg.json new file mode 100644 index 00000000000..992537277d2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3qxp-588w-rmqg/GHSA-3qxp-588w-rmqg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qxp-588w-rmqg", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-6674" + ], + "details": "A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6674" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/c1bb1ad19752aa7541675b398495eaf98fd589f1" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e688f71b-a3a4-4f6d-b48a-837073fa6908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3rpw-c8rg-p3f5/GHSA-3rpw-c8rg-p3f5.json b/advisories/unreviewed/2024/10/GHSA-3rpw-c8rg-p3f5/GHSA-3rpw-c8rg-p3f5.json new file mode 100644 index 00000000000..c446b22d4a9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3rpw-c8rg-p3f5/GHSA-3rpw-c8rg-p3f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rpw-c8rg-p3f5", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-41153" + ], + "details": "Command injection vulnerability in the Edge Computing UI for the\nTRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the\nweb UI can execute commands on the device with root privileges,\nfar more extensive than what the write privilege intends.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41153" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000147&LanguageCode=en&DocumentPartId=&Action=launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json b/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json new file mode 100644 index 00000000000..29d9731c891 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43hm-c86x-ppxj", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7474" + ], + "details": "In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on the 'id' parameter, allowing unauthorized access to external user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7474" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/95d8b993-3347-4ef5-a2b3-1f57219b7871" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-45pg-36p6-83v9/GHSA-45pg-36p6-83v9.json b/advisories/unreviewed/2024/10/GHSA-45pg-36p6-83v9/GHSA-45pg-36p6-83v9.json new file mode 100644 index 00000000000..8c4ccb0ea71 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-45pg-36p6-83v9/GHSA-45pg-36p6-83v9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45pg-36p6-83v9", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-8309" + ], + "details": "A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8309" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json b/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json new file mode 100644 index 00000000000..9e99552409e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jv6-884h-v282", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10463" + ], + "details": "Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10463" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1920800" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-57" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json new file mode 100644 index 00000000000..b6d6cf17b2b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wjh-chq6-qh88", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10466" + ], + "details": "By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10466" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1924154" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-54qh-mqj6-f2v8/GHSA-54qh-mqj6-f2v8.json b/advisories/unreviewed/2024/10/GHSA-54qh-mqj6-f2v8/GHSA-54qh-mqj6-f2v8.json new file mode 100644 index 00000000000..9f4b39ce2c6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-54qh-mqj6-f2v8/GHSA-54qh-mqj6-f2v8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qh-mqj6-f2v8", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-51076" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the \"searchdata\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51076" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Online%20DJ%20Booking/Reflected%20Cross%20Site%20Scripting%20b.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json b/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json new file mode 100644 index 00000000000..e09ce363ec9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6723-8fqj-mw26", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-9505" + ], + "details": "The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9505" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3177345" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/beaver-builder-lite-version/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7cfab048-efc6-4c7c-a1bd-0a9daf8779bc?source=cve" + }, + { + "type": "WEB", + "url": "https://www.wpbeaverbuilder.com/change-logs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-679j-4q32-w85w/GHSA-679j-4q32-w85w.json b/advisories/unreviewed/2024/10/GHSA-679j-4q32-w85w/GHSA-679j-4q32-w85w.json new file mode 100644 index 00000000000..9639b3357ab --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-679j-4q32-w85w/GHSA-679j-4q32-w85w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-679j-4q32-w85w", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10461" + ], + "details": "In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10461" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1914521" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6m59-8fmv-m5f9/GHSA-6m59-8fmv-m5f9.json b/advisories/unreviewed/2024/10/GHSA-6m59-8fmv-m5f9/GHSA-6m59-8fmv-m5f9.json new file mode 100644 index 00000000000..d6b929a44b0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6m59-8fmv-m5f9/GHSA-6m59-8fmv-m5f9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m59-8fmv-m5f9", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7042" + ], + "details": "A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7042" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchainjs/commit/615b9d9ab30a2d23a2f95fb8d7acfdf4b41ad7a6" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b612defb-1104-4fff-9fef-001ab07c7b2d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json b/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json new file mode 100644 index 00000000000..c6967e34b62 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rc3-wcpj-59ch", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10462" + ], + "details": "Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10462" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1920423" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json b/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json new file mode 100644 index 00000000000..c2cdb2cb59a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77hv-rqc3-4gm6", + "modified": "2024-10-29T15:32:02Z", + "published": "2024-10-29T15:32:02Z", + "aliases": [ + "CVE-2024-10459" + ], + "details": "An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10459" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1919087" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-57" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-78x6-2j48-rwjh/GHSA-78x6-2j48-rwjh.json b/advisories/unreviewed/2024/10/GHSA-78x6-2j48-rwjh/GHSA-78x6-2j48-rwjh.json new file mode 100644 index 00000000000..92f125e6425 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-78x6-2j48-rwjh/GHSA-78x6-2j48-rwjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78x6-2j48-rwjh", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49634" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bp-member-type-manager/wordpress-bp-member-type-manager-plugin-1-01-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7fc7-2hpf-4v5m/GHSA-7fc7-2hpf-4v5m.json b/advisories/unreviewed/2024/10/GHSA-7fc7-2hpf-4v5m/GHSA-7fc7-2hpf-4v5m.json new file mode 100644 index 00000000000..1de630abec6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7fc7-2hpf-4v5m/GHSA-7fc7-2hpf-4v5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fc7-2hpf-4v5m", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49643" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Abdullah Irfan Whitelist allows Reflected XSS.This issue affects Whitelist: from n/a through 3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fifthsegment-whitelist/wordpress-whitelist-plugin-3-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-86h6-4672-7vx7/GHSA-86h6-4672-7vx7.json b/advisories/unreviewed/2024/10/GHSA-86h6-4672-7vx7/GHSA-86h6-4672-7vx7.json new file mode 100644 index 00000000000..20dc3f4f081 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-86h6-4672-7vx7/GHSA-86h6-4672-7vx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86h6-4672-7vx7", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49638" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali Azlan Risk Warning Bar allows Reflected XSS.This issue affects Risk Warning Bar: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/risk-warning-bar/wordpress-risk-warning-bar-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-86j7-ghr3-wmhx/GHSA-86j7-ghr3-wmhx.json b/advisories/unreviewed/2024/10/GHSA-86j7-ghr3-wmhx/GHSA-86j7-ghr3-wmhx.json new file mode 100644 index 00000000000..f0b90aca981 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-86j7-ghr3-wmhx/GHSA-86j7-ghr3-wmhx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86j7-ghr3-wmhx", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-6673" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6673" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/c1bb1ad19752aa7541675b398495eaf98fd589f1" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a38f9a7d-b357-427d-adac-f9654d8c0e3c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json b/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json new file mode 100644 index 00000000000..42523f66f3c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87x3-r6f2-m885", + "modified": "2024-10-29T15:32:02Z", + "published": "2024-10-29T15:32:02Z", + "aliases": [ + "CVE-2024-10458" + ], + "details": "A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10458" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1921733" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-57" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9hcm-hr65-2825/GHSA-9hcm-hr65-2825.json b/advisories/unreviewed/2024/10/GHSA-9hcm-hr65-2825/GHSA-9hcm-hr65-2825.json new file mode 100644 index 00000000000..f3a3bfee892 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9hcm-hr65-2825/GHSA-9hcm-hr65-2825.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hcm-hr65-2825", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7010" + ], + "details": "mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7010" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/db1159b6511e8fa09e594f9db0fec6ab4e142468" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e286ed00-6383-47de-b5bc-9b9fad67c362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json new file mode 100644 index 00000000000..a3c8329fdcc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v98-vwhg-6x24", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10467" + ], + "details": "Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10467" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1829029%2C1888538%2C1900394%2C1904059%2C1917742%2C1919809%2C1923706" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9xqp-xm5r-jj9c/GHSA-9xqp-xm5r-jj9c.json b/advisories/unreviewed/2024/10/GHSA-9xqp-xm5r-jj9c/GHSA-9xqp-xm5r-jj9c.json new file mode 100644 index 00000000000..f130b3a3442 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9xqp-xm5r-jj9c/GHSA-9xqp-xm5r-jj9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xqp-xm5r-jj9c", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-41156" + ], + "details": "Profile files from TRO600 series radios are extracted in plain-text\nand encrypted file formats. Profile files provide potential attackers\nvaluable configuration information about the Tropos network. Profiles\ncan only be exported by authenticated users with write access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41156" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000147&LanguageCode=en&DocumentPartId=&Action=launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-212" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cm59-8rmv-f2cj/GHSA-cm59-8rmv-f2cj.json b/advisories/unreviewed/2024/10/GHSA-cm59-8rmv-f2cj/GHSA-cm59-8rmv-f2cj.json new file mode 100644 index 00000000000..249342de7f7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cm59-8rmv-f2cj/GHSA-cm59-8rmv-f2cj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm59-8rmv-f2cj", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-6581" + ], + "details": "A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code execution. The sanitize_svg function only removes script elements and 'on*' event attributes, but does not account for other potential vectors for XSS within SVG files. This vulnerability can be exploited when authorized users access a malicious URL containing the crafted SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6581" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms/commit/328b960a0de2097e13654ac752253e9541521ddd" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ad68ecd6-44e2-449b-8e7e-f2b71b1b43c7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json index b334a7e7991..3a7f419222e 100644 --- a/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json +++ b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cr9c-949p-jxvr", - "modified": "2024-10-04T15:31:19Z", + "modified": "2024-10-29T15:31:59Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2023-37822" ], "details": "Eufy HomeBase 2 model T8010X v3.2.8.3h was discovered to use the deprecated wireless protocol WPA2-PSK.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-331" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T18:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cvp2-5m4q-66qv/GHSA-cvp2-5m4q-66qv.json b/advisories/unreviewed/2024/10/GHSA-cvp2-5m4q-66qv/GHSA-cvp2-5m4q-66qv.json new file mode 100644 index 00000000000..878e3942d93 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cvp2-5m4q-66qv/GHSA-cvp2-5m4q-66qv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvp2-5m4q-66qv", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10474" + ], + "details": "Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10474" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1863832" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-60" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cwxv-7jhg-q486/GHSA-cwxv-7jhg-q486.json b/advisories/unreviewed/2024/10/GHSA-cwxv-7jhg-q486/GHSA-cwxv-7jhg-q486.json new file mode 100644 index 00000000000..55629447c38 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cwxv-7jhg-q486/GHSA-cwxv-7jhg-q486.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwxv-7jhg-q486", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49640" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AmaderCode Lab ACL Floating Cart for WooCommerce allows Reflected XSS.This issue affects ACL Floating Cart for WooCommerce: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/acl-floating-cart-for-woocommerce/wordpress-acl-floating-cart-for-woocommerce-plugin-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json b/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json new file mode 100644 index 00000000000..21ba26707fc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3xm-22x6-vg3g", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-5823" + ], + "details": "A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5823" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/720c23d755a4a955dcb0a54e8c200a2247a27f8b" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ca361701-7d68-4df6-8da0-caad4b85b9ae" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fwm9-jrh2-v628/GHSA-fwm9-jrh2-v628.json b/advisories/unreviewed/2024/10/GHSA-fwm9-jrh2-v628/GHSA-fwm9-jrh2-v628.json new file mode 100644 index 00000000000..a2f1eb6434c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fwm9-jrh2-v628/GHSA-fwm9-jrh2-v628.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwm9-jrh2-v628", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49637" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bet-wc-2018-russia/wordpress-bet-wc-2018-russia-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h9qp-pr9g-xfr8/GHSA-h9qp-pr9g-xfr8.json b/advisories/unreviewed/2024/10/GHSA-h9qp-pr9g-xfr8/GHSA-h9qp-pr9g-xfr8.json new file mode 100644 index 00000000000..dd5149a8463 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h9qp-pr9g-xfr8/GHSA-h9qp-pr9g-xfr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9qp-pr9g-xfr8", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49641" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tidaweb Tida URL Screenshot allows Reflected XSS.This issue affects Tida URL Screenshot: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tida-url-screenshot/wordpress-tida-url-screenshot-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hc5w-c9f8-9cc4/GHSA-hc5w-c9f8-9cc4.json b/advisories/unreviewed/2024/10/GHSA-hc5w-c9f8-9cc4/GHSA-hc5w-c9f8-9cc4.json new file mode 100644 index 00000000000..1eb4feb0392 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hc5w-c9f8-9cc4/GHSA-hc5w-c9f8-9cc4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc5w-c9f8-9cc4", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7774" + ], + "details": "A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is exploited through the `setFileContent`, `getParsedFile`, and `mdelete` methods, which do not properly sanitize user input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7774" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchainjs/commit/a0fad77d6b569e5872bd4a9d33be0c0785e538a9" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8fe40685-b714-4191-af7a-3de5e5628cee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json b/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json new file mode 100644 index 00000000000..a62e8efcb19 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv24-5j5x-m8w6", + "modified": "2024-10-29T15:32:03Z", + "published": "2024-10-29T15:32:03Z", + "aliases": [ + "CVE-2024-10460" + ], + "details": "The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10460" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1912537" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json b/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json new file mode 100644 index 00000000000..51e56a336f5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx2m-9x57-vwr5", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10465" + ], + "details": "A clipboard \"paste\" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10465" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1918853" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json b/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json new file mode 100644 index 00000000000..11e65b08c40 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrpf-hrph-4gm4", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7473" + ], + "details": "An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7473" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/88b55b01fcbab0fbbc5b8032a38d0345af98ecfa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/afecd927-b5f6-44ba-9147-5c45091beda5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mvvf-4rgv-2jc9/GHSA-mvvf-4rgv-2jc9.json b/advisories/unreviewed/2024/10/GHSA-mvvf-4rgv-2jc9/GHSA-mvvf-4rgv-2jc9.json new file mode 100644 index 00000000000..f960e4cedda --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mvvf-4rgv-2jc9/GHSA-mvvf-4rgv-2jc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvvf-4rgv-2jc9", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-47640" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/erp/wordpress-wp-erp-plugin-1-13-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mw8q-c9cq-qfgc/GHSA-mw8q-c9cq-qfgc.json b/advisories/unreviewed/2024/10/GHSA-mw8q-c9cq-qfgc/GHSA-mw8q-c9cq-qfgc.json new file mode 100644 index 00000000000..243abf5a2e5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mw8q-c9cq-qfgc/GHSA-mw8q-c9cq-qfgc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw8q-c9cq-qfgc", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49639" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Edward Stoever Monitor.Chat allows Reflected XSS.This issue affects Monitor.Chat: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/monitor-chat/wordpress-monitor-chat-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p5rg-5qm3-r4j3/GHSA-p5rg-5qm3-r4j3.json b/advisories/unreviewed/2024/10/GHSA-p5rg-5qm3-r4j3/GHSA-p5rg-5qm3-r4j3.json new file mode 100644 index 00000000000..6c58b7de091 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p5rg-5qm3-r4j3/GHSA-p5rg-5qm3-r4j3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5rg-5qm3-r4j3", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-49632" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cwd-3d-image-gallery/wordpress-cwd-3d-image-gallery-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p6jm-98c6-m9x8/GHSA-p6jm-98c6-m9x8.json b/advisories/unreviewed/2024/10/GHSA-p6jm-98c6-m9x8/GHSA-p6jm-98c6-m9x8.json new file mode 100644 index 00000000000..3414cda7fc4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p6jm-98c6-m9x8/GHSA-p6jm-98c6-m9x8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6jm-98c6-m9x8", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-5982" + ], + "details": "A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Specifically, the load_chat_history function in modules/models/base_model.py allows arbitrary file uploads, potentially leading to remote code execution (RCE). The get_history_names function in utils.py permits arbitrary directory creation. Additionally, the load_template function in utils.py can be exploited to leak the first column of CSV files. These issues stem from improper sanitization of user inputs concatenated with directory paths using os.path.join.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5982" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/952fc8c3cbacead858311747cddd4bedcb4721d7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5d5c5356-e893-44d1-b5ca-642aa05d96bb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ppv9-6fx3-phfw/GHSA-ppv9-6fx3-phfw.json b/advisories/unreviewed/2024/10/GHSA-ppv9-6fx3-phfw/GHSA-ppv9-6fx3-phfw.json new file mode 100644 index 00000000000..439144d3876 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ppv9-6fx3-phfw/GHSA-ppv9-6fx3-phfw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppv9-6fx3-phfw", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-10226" + ], + "details": "The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10226" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3176718" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/arconix-shortcodes/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94bae97d-2959-4ace-992d-1f4b1ccc8c3b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pq68-xwgm-w862/GHSA-pq68-xwgm-w862.json b/advisories/unreviewed/2024/10/GHSA-pq68-xwgm-w862/GHSA-pq68-xwgm-w862.json new file mode 100644 index 00000000000..091750da0f8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pq68-xwgm-w862/GHSA-pq68-xwgm-w862.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq68-xwgm-w862", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-51075" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51075" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Online%20DJ%20Booking/DJ%20online%20Cross%20Site%20Scripting%20%20u.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q2x2-wjjv-pmmp/GHSA-q2x2-wjjv-pmmp.json b/advisories/unreviewed/2024/10/GHSA-q2x2-wjjv-pmmp/GHSA-q2x2-wjjv-pmmp.json new file mode 100644 index 00000000000..054528facfb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q2x2-wjjv-pmmp/GHSA-q2x2-wjjv-pmmp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2x2-wjjv-pmmp", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-51180" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via the \"searchifsccode\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51180" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/IFSC%20Code%20Finder/IFSC%20Code%20Finder%20do.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q5j5-g96w-h2x7/GHSA-q5j5-g96w-h2x7.json b/advisories/unreviewed/2024/10/GHSA-q5j5-g96w-h2x7/GHSA-q5j5-g96w-h2x7.json index 3dbfe01af86..fd8d8c512ab 100644 --- a/advisories/unreviewed/2024/10/GHSA-q5j5-g96w-h2x7/GHSA-q5j5-g96w-h2x7.json +++ b/advisories/unreviewed/2024/10/GHSA-q5j5-g96w-h2x7/GHSA-q5j5-g96w-h2x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q5j5-g96w-h2x7", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-29T15:31:59Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-44205" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. A sandboxed app may be able to access sensitive user data in system logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json b/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json new file mode 100644 index 00000000000..9695f4972e9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q97q-7j3c-mx9j", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7962" + ], + "details": "An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json extension and, except for the first line, every other line must contain commas. This vulnerability allows reading parts of format-compliant files, including code and log files, which may contain highly sensitive information such as account credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7962" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/2836fd1db3efcd5ede63c0e7fbbdf677730dbb51" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/83f0a8e1-490c-49e7-b334-02125ee0f1b1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json b/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json new file mode 100644 index 00000000000..1a71817f3b1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2v5-q2jv-5cff", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10464" + ], + "details": "Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10464" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1913000" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-56" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-58" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r8mm-hp23-g238/GHSA-r8mm-hp23-g238.json b/advisories/unreviewed/2024/10/GHSA-r8mm-hp23-g238/GHSA-r8mm-hp23-g238.json index 10b4d1ebdb4..f39c1c6ce8b 100644 --- a/advisories/unreviewed/2024/10/GHSA-r8mm-hp23-g238/GHSA-r8mm-hp23-g238.json +++ b/advisories/unreviewed/2024/10/GHSA-r8mm-hp23-g238/GHSA-r8mm-hp23-g238.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8mm-hp23-g238", - "modified": "2024-10-24T18:30:42Z", + "modified": "2024-10-29T15:31:59Z", "published": "2024-10-24T18:30:42Z", "aliases": [ "CVE-2024-40810" ], "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause a coprocessor crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r94w-jwpm-jpc6/GHSA-r94w-jwpm-jpc6.json b/advisories/unreviewed/2024/10/GHSA-r94w-jwpm-jpc6/GHSA-r94w-jwpm-jpc6.json new file mode 100644 index 00000000000..aa244e153ce --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r94w-jwpm-jpc6/GHSA-r94w-jwpm-jpc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r94w-jwpm-jpc6", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-49636" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Prashant Mavinkurve Agile Video Player Lite allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/agile-video-player/wordpress-agile-video-player-lite-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rxmp-x6cw-79xv/GHSA-rxmp-x6cw-79xv.json b/advisories/unreviewed/2024/10/GHSA-rxmp-x6cw-79xv/GHSA-rxmp-x6cw-79xv.json new file mode 100644 index 00000000000..e9f2751238c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rxmp-x6cw-79xv/GHSA-rxmp-x6cw-79xv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxmp-x6cw-79xv", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7783" + ], + "details": "mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7783" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/4430ddb05988470bc8f0479e7d07db1f7d4646ba" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/20e9950f-ad41-4d6b-8bd0-c7f7051695b3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w2x8-m6jw-mwwv/GHSA-w2x8-m6jw-mwwv.json b/advisories/unreviewed/2024/10/GHSA-w2x8-m6jw-mwwv/GHSA-w2x8-m6jw-mwwv.json new file mode 100644 index 00000000000..4077a7165bd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w2x8-m6jw-mwwv/GHSA-w2x8-m6jw-mwwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2x8-m6jw-mwwv", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-49635" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manzurul Haque Banner Slider allows Reflected XSS.This issue affects Banner Slider: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/banner-slider/wordpress-banner-slider-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8g6-73fg-2x53/GHSA-w8g6-73fg-2x53.json b/advisories/unreviewed/2024/10/GHSA-w8g6-73fg-2x53/GHSA-w8g6-73fg-2x53.json new file mode 100644 index 00000000000..d0065aadc95 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8g6-73fg-2x53/GHSA-w8g6-73fg-2x53.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8g6-73fg-2x53", + "modified": "2024-10-29T15:32:05Z", + "published": "2024-10-29T15:32:05Z", + "aliases": [ + "CVE-2024-7807" + ], + "details": "A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering ChuanhuChatGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7807" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/919222d285d73b9dcd71fb34de379eef8c90d175" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/db67276d-36ee-4487-9165-b621c67ef8a3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400", + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json new file mode 100644 index 00000000000..31175872841 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhw3-h8gq-2w23", + "modified": "2024-10-29T15:32:04Z", + "published": "2024-10-29T15:32:04Z", + "aliases": [ + "CVE-2024-10468" + ], + "details": "Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10468" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1914982" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-55" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-59" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xjj4-3gwf-mwqh/GHSA-xjj4-3gwf-mwqh.json b/advisories/unreviewed/2024/10/GHSA-xjj4-3gwf-mwqh/GHSA-xjj4-3gwf-mwqh.json index ab4114e8d99..382ae84a6a9 100644 --- a/advisories/unreviewed/2024/10/GHSA-xjj4-3gwf-mwqh/GHSA-xjj4-3gwf-mwqh.json +++ b/advisories/unreviewed/2024/10/GHSA-xjj4-3gwf-mwqh/GHSA-xjj4-3gwf-mwqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xjj4-3gwf-mwqh", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-29T15:31:59Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-44185" ], "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z"