Publish Advisories

GHSA-27xq-w3jc-436c
GHSA-3jx4-3grj-xm5w
GHSA-47gj-j96m-3hhg
GHSA-4ghr-47h5-v2hf
GHSA-6726-2rx3-cgwh
GHSA-87m3-6qj3-p3xh
GHSA-9c5v-wp94-33vx
GHSA-9vgq-w5pv-v77q
GHSA-chj3-8q43-rcc8
GHSA-crr8-wrxj-8vg6
GHSA-f7cf-fr2r-2cwx
GHSA-gfhx-2xqr-982p
GHSA-hvff-fx7p-9p3g
GHSA-jqqj-j2ch-3qv8
GHSA-pvv5-7gwv-cvmf
GHSA-rvgx-76xx-c287
GHSA-v96m-4x27-3m5j
This commit is contained in:
advisory-database[bot]
2024-02-07 15:32:04 +00:00
parent 540ba4c2ea
commit c692c11206
17 changed files with 412 additions and 9 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27xq-w3jc-436c",
"modified": "2024-02-05T15:30:23Z",
"modified": "2024-02-07T15:30:47Z",
"published": "2024-02-05T15:30:23Z",
"aliases": [
"CVE-2024-23109"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jx4-3grj-xm5w",
"modified": "2024-02-07T03:30:32Z",
"modified": "2024-02-07T15:30:47Z",
"published": "2024-02-07T03:30:32Z",
"aliases": [
"CVE-2024-22021"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
"CWE-1391",
"CWE-287"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4ghr-47h5-v2hf",
"modified": "2024-02-02T00:31:25Z",
"modified": "2024-02-07T15:30:47Z",
"published": "2024-02-02T00:31:25Z",
"aliases": [
"CVE-2023-47257"
],
"details": "ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T22:15:55Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6726-2rx3-cgwh",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2023-39196"
],
"details": "Improper Authentication vulnerability in Apache Ozone.\n\nThe vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication.\nThe attacker is not allowed to do any modification within the Ozone Storage Container Manager service using this vulnerability.\nThe accessible metadata does not contain sensitive information that can be used to exploit the system later on, and the accessible data does not make it possible to gain access to actual user data within Ozone.\nThis issue affects Apache Ozone: 1.2.0 and subsequent releases up until 1.3.0.\n\nUsers are recommended to upgrade to version 1.4.0, which fixes the issue.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39196"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/o96ct5t7kj5cgrmmfc6756m931t08nky"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/02/07/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T13:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87m3-6qj3-p3xh",
"modified": "2024-02-07T15:30:50Z",
"published": "2024-02-07T15:30:50Z",
"aliases": [
"CVE-2024-25143"
],
"details": "The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25143"
},
{
"type": "WEB",
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T15:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c5v-wp94-33vx",
"modified": "2024-02-07T15:30:49Z",
"published": "2024-02-07T15:30:49Z",
"aliases": [
"CVE-2024-25200"
],
"details": "Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25200"
},
{
"type": "WEB",
"url": "https://github.com/espruino/Espruino/issues/2457"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:53Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vgq-w5pv-v77q",
"modified": "2024-02-07T15:30:50Z",
"published": "2024-02-07T15:30:50Z",
"aliases": [
"CVE-2024-25145"
],
"details": "Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25145"
},
{
"type": "WEB",
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25145"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T15:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chj3-8q43-rcc8",
"modified": "2024-02-05T15:30:23Z",
"modified": "2024-02-07T15:30:47Z",
"published": "2024-02-05T15:30:23Z",
"aliases": [
"CVE-2024-23108"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crr8-wrxj-8vg6",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2024-24188"
],
"details": "Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24188"
},
{
"type": "WEB",
"url": "https://github.com/pcmacdon/jsish/issues/100"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7cf-fr2r-2cwx",
"modified": "2024-02-07T15:30:49Z",
"published": "2024-02-07T15:30:49Z",
"aliases": [
"CVE-2024-25201"
],
"details": "Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25201"
},
{
"type": "WEB",
"url": "https://github.com/espruino/Espruino/issues/2456"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:53Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfhx-2xqr-982p",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2024-24131"
],
"details": "SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24131"
},
{
"type": "WEB",
"url": "https://github.com/Hebing123/cve/issues/14"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvff-fx7p-9p3g",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2024-24186"
],
"details": "Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24186"
},
{
"type": "WEB",
"url": "https://github.com/pcmacdon/jsish/issues/98"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqqj-j2ch-3qv8",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2024-24133"
],
"details": "Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24133"
},
{
"type": "WEB",
"url": "https://github.com/Hebing123/cve/issues/16"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-258"
"CWE-258",
"CWE-521"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvgx-76xx-c287",
"modified": "2024-02-07T15:30:48Z",
"published": "2024-02-07T15:30:48Z",
"aliases": [
"CVE-2024-24130"
],
"details": "Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24130"
},
{
"type": "WEB",
"url": "https://github.com/Hebing123/cve/issues/13"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v96m-4x27-3m5j",
"modified": "2024-02-07T15:30:49Z",
"published": "2024-02-07T15:30:49Z",
"aliases": [
"CVE-2024-24189"
],
"details": "Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24189"
},
{
"type": "WEB",
"url": "https://github.com/pcmacdon/jsish/issues/101"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T14:15:52Z"
}
}