From c692c112068c0e8bb854b24e984303cce8f1ebe4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 Feb 2024 15:32:04 +0000 Subject: [PATCH] Publish Advisories GHSA-27xq-w3jc-436c GHSA-3jx4-3grj-xm5w GHSA-47gj-j96m-3hhg GHSA-4ghr-47h5-v2hf GHSA-6726-2rx3-cgwh GHSA-87m3-6qj3-p3xh GHSA-9c5v-wp94-33vx GHSA-9vgq-w5pv-v77q GHSA-chj3-8q43-rcc8 GHSA-crr8-wrxj-8vg6 GHSA-f7cf-fr2r-2cwx GHSA-gfhx-2xqr-982p GHSA-hvff-fx7p-9p3g GHSA-jqqj-j2ch-3qv8 GHSA-pvv5-7gwv-cvmf GHSA-rvgx-76xx-c287 GHSA-v96m-4x27-3m5j --- .../GHSA-27xq-w3jc-436c.json | 2 +- .../GHSA-3jx4-3grj-xm5w.json | 2 +- .../GHSA-47gj-j96m-3hhg.json | 3 +- .../GHSA-4ghr-47h5-v2hf.json | 11 +++-- .../GHSA-6726-2rx3-cgwh.json | 42 +++++++++++++++++++ .../GHSA-87m3-6qj3-p3xh.json | 38 +++++++++++++++++ .../GHSA-9c5v-wp94-33vx.json | 35 ++++++++++++++++ .../GHSA-9vgq-w5pv-v77q.json | 38 +++++++++++++++++ .../GHSA-chj3-8q43-rcc8.json | 2 +- .../GHSA-crr8-wrxj-8vg6.json | 35 ++++++++++++++++ .../GHSA-f7cf-fr2r-2cwx.json | 35 ++++++++++++++++ .../GHSA-gfhx-2xqr-982p.json | 35 ++++++++++++++++ .../GHSA-hvff-fx7p-9p3g.json | 35 ++++++++++++++++ .../GHSA-jqqj-j2ch-3qv8.json | 35 ++++++++++++++++ .../GHSA-pvv5-7gwv-cvmf.json | 3 +- .../GHSA-rvgx-76xx-c287.json | 35 ++++++++++++++++ .../GHSA-v96m-4x27-3m5j.json | 35 ++++++++++++++++ 17 files changed, 412 insertions(+), 9 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-6726-2rx3-cgwh/GHSA-6726-2rx3-cgwh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-87m3-6qj3-p3xh/GHSA-87m3-6qj3-p3xh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9c5v-wp94-33vx/GHSA-9c5v-wp94-33vx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9vgq-w5pv-v77q/GHSA-9vgq-w5pv-v77q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-crr8-wrxj-8vg6/GHSA-crr8-wrxj-8vg6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-f7cf-fr2r-2cwx/GHSA-f7cf-fr2r-2cwx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gfhx-2xqr-982p/GHSA-gfhx-2xqr-982p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hvff-fx7p-9p3g/GHSA-hvff-fx7p-9p3g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jqqj-j2ch-3qv8/GHSA-jqqj-j2ch-3qv8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rvgx-76xx-c287/GHSA-rvgx-76xx-c287.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v96m-4x27-3m5j/GHSA-v96m-4x27-3m5j.json diff --git a/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json b/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json index 8665aa66dd6..5aaa1f6022c 100644 --- a/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json +++ b/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27xq-w3jc-436c", - "modified": "2024-02-05T15:30:23Z", + "modified": "2024-02-07T15:30:47Z", "published": "2024-02-05T15:30:23Z", "aliases": [ "CVE-2024-23109" diff --git a/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json b/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json index 8eb7c50f7a4..acb8821c3b3 100644 --- a/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json +++ b/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jx4-3grj-xm5w", - "modified": "2024-02-07T03:30:32Z", + "modified": "2024-02-07T15:30:47Z", "published": "2024-02-07T03:30:32Z", "aliases": [ "CVE-2024-22021" diff --git a/advisories/unreviewed/2024/02/GHSA-47gj-j96m-3hhg/GHSA-47gj-j96m-3hhg.json b/advisories/unreviewed/2024/02/GHSA-47gj-j96m-3hhg/GHSA-47gj-j96m-3hhg.json index 04626eca91e..e89d8b32462 100644 --- a/advisories/unreviewed/2024/02/GHSA-47gj-j96m-3hhg/GHSA-47gj-j96m-3hhg.json +++ b/advisories/unreviewed/2024/02/GHSA-47gj-j96m-3hhg/GHSA-47gj-j96m-3hhg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1391" + "CWE-1391", + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json b/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json index aa33a971225..e9afe0e66f8 100644 --- a/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json +++ b/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4ghr-47h5-v2hf", - "modified": "2024-02-02T00:31:25Z", + "modified": "2024-02-07T15:30:47Z", "published": "2024-02-02T00:31:25Z", "aliases": [ "CVE-2023-47257" ], "details": "ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-01T22:15:55Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6726-2rx3-cgwh/GHSA-6726-2rx3-cgwh.json b/advisories/unreviewed/2024/02/GHSA-6726-2rx3-cgwh/GHSA-6726-2rx3-cgwh.json new file mode 100644 index 00000000000..088e3915b03 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6726-2rx3-cgwh/GHSA-6726-2rx3-cgwh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6726-2rx3-cgwh", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2023-39196" + ], + "details": "Improper Authentication vulnerability in Apache Ozone.\n\nThe vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication.\nThe attacker is not allowed to do any modification within the Ozone Storage Container Manager service using this vulnerability.\nThe accessible metadata does not contain sensitive information that can be used to exploit the system later on, and the accessible data does not make it possible to gain access to actual user data within Ozone.\nThis issue affects Apache Ozone: 1.2.0 and subsequent releases up until 1.3.0.\n\nUsers are recommended to upgrade to version 1.4.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39196" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/o96ct5t7kj5cgrmmfc6756m931t08nky" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/07/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-87m3-6qj3-p3xh/GHSA-87m3-6qj3-p3xh.json b/advisories/unreviewed/2024/02/GHSA-87m3-6qj3-p3xh/GHSA-87m3-6qj3-p3xh.json new file mode 100644 index 00000000000..7b2eeff3b5e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-87m3-6qj3-p3xh/GHSA-87m3-6qj3-p3xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87m3-6qj3-p3xh", + "modified": "2024-02-07T15:30:50Z", + "published": "2024-02-07T15:30:50Z", + "aliases": [ + "CVE-2024-25143" + ], + "details": "The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25143" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9c5v-wp94-33vx/GHSA-9c5v-wp94-33vx.json b/advisories/unreviewed/2024/02/GHSA-9c5v-wp94-33vx/GHSA-9c5v-wp94-33vx.json new file mode 100644 index 00000000000..a7800733a6b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9c5v-wp94-33vx/GHSA-9c5v-wp94-33vx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c5v-wp94-33vx", + "modified": "2024-02-07T15:30:49Z", + "published": "2024-02-07T15:30:49Z", + "aliases": [ + "CVE-2024-25200" + ], + "details": "Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25200" + }, + { + "type": "WEB", + "url": "https://github.com/espruino/Espruino/issues/2457" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9vgq-w5pv-v77q/GHSA-9vgq-w5pv-v77q.json b/advisories/unreviewed/2024/02/GHSA-9vgq-w5pv-v77q/GHSA-9vgq-w5pv-v77q.json new file mode 100644 index 00000000000..441e0ca4c1f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9vgq-w5pv-v77q/GHSA-9vgq-w5pv-v77q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vgq-w5pv-v77q", + "modified": "2024-02-07T15:30:50Z", + "published": "2024-02-07T15:30:50Z", + "aliases": [ + "CVE-2024-25145" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25145" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json b/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json index d4f84b3b420..3efc2c90b21 100644 --- a/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json +++ b/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chj3-8q43-rcc8", - "modified": "2024-02-05T15:30:23Z", + "modified": "2024-02-07T15:30:47Z", "published": "2024-02-05T15:30:23Z", "aliases": [ "CVE-2024-23108" diff --git a/advisories/unreviewed/2024/02/GHSA-crr8-wrxj-8vg6/GHSA-crr8-wrxj-8vg6.json b/advisories/unreviewed/2024/02/GHSA-crr8-wrxj-8vg6/GHSA-crr8-wrxj-8vg6.json new file mode 100644 index 00000000000..d234e9a044d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-crr8-wrxj-8vg6/GHSA-crr8-wrxj-8vg6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crr8-wrxj-8vg6", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2024-24188" + ], + "details": "Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24188" + }, + { + "type": "WEB", + "url": "https://github.com/pcmacdon/jsish/issues/100" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f7cf-fr2r-2cwx/GHSA-f7cf-fr2r-2cwx.json b/advisories/unreviewed/2024/02/GHSA-f7cf-fr2r-2cwx/GHSA-f7cf-fr2r-2cwx.json new file mode 100644 index 00000000000..a44f7434d53 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f7cf-fr2r-2cwx/GHSA-f7cf-fr2r-2cwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7cf-fr2r-2cwx", + "modified": "2024-02-07T15:30:49Z", + "published": "2024-02-07T15:30:49Z", + "aliases": [ + "CVE-2024-25201" + ], + "details": "Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25201" + }, + { + "type": "WEB", + "url": "https://github.com/espruino/Espruino/issues/2456" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gfhx-2xqr-982p/GHSA-gfhx-2xqr-982p.json b/advisories/unreviewed/2024/02/GHSA-gfhx-2xqr-982p/GHSA-gfhx-2xqr-982p.json new file mode 100644 index 00000000000..f09b3c1535c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gfhx-2xqr-982p/GHSA-gfhx-2xqr-982p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfhx-2xqr-982p", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2024-24131" + ], + "details": "SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24131" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/14" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hvff-fx7p-9p3g/GHSA-hvff-fx7p-9p3g.json b/advisories/unreviewed/2024/02/GHSA-hvff-fx7p-9p3g/GHSA-hvff-fx7p-9p3g.json new file mode 100644 index 00000000000..8f006381fc0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hvff-fx7p-9p3g/GHSA-hvff-fx7p-9p3g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvff-fx7p-9p3g", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2024-24186" + ], + "details": "Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24186" + }, + { + "type": "WEB", + "url": "https://github.com/pcmacdon/jsish/issues/98" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jqqj-j2ch-3qv8/GHSA-jqqj-j2ch-3qv8.json b/advisories/unreviewed/2024/02/GHSA-jqqj-j2ch-3qv8/GHSA-jqqj-j2ch-3qv8.json new file mode 100644 index 00000000000..478c0a87c1f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jqqj-j2ch-3qv8/GHSA-jqqj-j2ch-3qv8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqqj-j2ch-3qv8", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2024-24133" + ], + "details": "Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24133" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pvv5-7gwv-cvmf/GHSA-pvv5-7gwv-cvmf.json b/advisories/unreviewed/2024/02/GHSA-pvv5-7gwv-cvmf/GHSA-pvv5-7gwv-cvmf.json index 1f7f626d67c..869d473ffcf 100644 --- a/advisories/unreviewed/2024/02/GHSA-pvv5-7gwv-cvmf/GHSA-pvv5-7gwv-cvmf.json +++ b/advisories/unreviewed/2024/02/GHSA-pvv5-7gwv-cvmf/GHSA-pvv5-7gwv-cvmf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-258" + "CWE-258", + "CWE-521" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rvgx-76xx-c287/GHSA-rvgx-76xx-c287.json b/advisories/unreviewed/2024/02/GHSA-rvgx-76xx-c287/GHSA-rvgx-76xx-c287.json new file mode 100644 index 00000000000..99666ee1afd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rvgx-76xx-c287/GHSA-rvgx-76xx-c287.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvgx-76xx-c287", + "modified": "2024-02-07T15:30:48Z", + "published": "2024-02-07T15:30:48Z", + "aliases": [ + "CVE-2024-24130" + ], + "details": "Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24130" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v96m-4x27-3m5j/GHSA-v96m-4x27-3m5j.json b/advisories/unreviewed/2024/02/GHSA-v96m-4x27-3m5j/GHSA-v96m-4x27-3m5j.json new file mode 100644 index 00000000000..2b673aad931 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v96m-4x27-3m5j/GHSA-v96m-4x27-3m5j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v96m-4x27-3m5j", + "modified": "2024-02-07T15:30:49Z", + "published": "2024-02-07T15:30:49Z", + "aliases": [ + "CVE-2024-24189" + ], + "details": "Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24189" + }, + { + "type": "WEB", + "url": "https://github.com/pcmacdon/jsish/issues/101" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T14:15:52Z" + } +} \ No newline at end of file