From c7189d416b43568991c2e91c084c71ef53f6f688 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 15 May 2024 18:32:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-wq43-8r5p-w3mc.json | 85 +++++++++++++++++ .../GHSA-wxxw-5gq6-j2g5.json | 92 +++++++++++++++++++ .../GHSA-26f5-24g6-27vm.json | 38 ++++++++ .../GHSA-2h39-83vm-vq42.json | 38 ++++++++ .../GHSA-34wr-w2h3-hr5x.json | 38 ++++++++ .../GHSA-389q-94h9-f6qm.json | 38 ++++++++ .../GHSA-57h3-6mh3-cjrr.json | 35 +++++++ .../GHSA-585p-p962-9hrc.json | 38 ++++++++ .../GHSA-6xj9-2c6f-3mhx.json | 38 ++++++++ .../GHSA-76v2-48w6-crxr.json | 35 +++++++ .../GHSA-77g7-q65f-rmxf.json | 50 ++++++++++ .../GHSA-8483-3cvj-46c5.json | 38 ++++++++ .../GHSA-856w-rm82-4hp7.json | 38 ++++++++ .../GHSA-8jrr-vwjm-wj7q.json | 38 ++++++++ .../GHSA-8mcf-fh2m-245p.json | 38 ++++++++ .../GHSA-946r-mx2c-f2pf.json | 50 ++++++++++ .../GHSA-c24r-pxmj-hx9h.json | 38 ++++++++ .../GHSA-c5q5-64hr-5mwm.json | 38 ++++++++ .../GHSA-cj69-9qw7-84pj.json | 38 ++++++++ .../GHSA-cmcg-f6r6-g4hh.json | 38 ++++++++ .../GHSA-f2q8-66wc-mcgp.json | 38 ++++++++ .../GHSA-f37v-v67w-4jmp.json | 38 ++++++++ .../GHSA-fc6q-xmrf-7jx4.json | 38 ++++++++ .../GHSA-fpvx-gw57-2p3v.json | 38 ++++++++ .../GHSA-g96r-v5qq-9qch.json | 38 ++++++++ .../GHSA-gmvc-mphj-2pr4.json | 38 ++++++++ .../GHSA-hxv9-64g4-jhvj.json | 38 ++++++++ .../GHSA-j5rg-hrw2-2gf7.json | 38 ++++++++ .../GHSA-jg34-vvwh-5qv9.json | 38 ++++++++ .../GHSA-jwfg-733h-8pc5.json | 38 ++++++++ .../GHSA-m4rj-rphf-266h.json | 38 ++++++++ .../GHSA-m82c-2r7m-qgcj.json | 35 +++++++ .../GHSA-p7hw-w67j-562v.json | 38 ++++++++ .../GHSA-pr8j-5v55-885c.json | 38 ++++++++ .../GHSA-q3jf-xfc9-6rc2.json | 38 ++++++++ .../GHSA-r73q-j7fc-5g2p.json | 38 ++++++++ .../GHSA-rc98-whmj-qg8f.json | 38 ++++++++ .../GHSA-rgcv-xpj5-8x8f.json | 38 ++++++++ .../GHSA-vpv3-mggc-9fwh.json | 38 ++++++++ .../GHSA-w3pf-5jqj-rj4q.json | 35 +++++++ .../GHSA-xppr-6c99-hp78.json | 38 ++++++++ 41 files changed, 1671 insertions(+) create mode 100644 advisories/github-reviewed/2024/05/GHSA-wq43-8r5p-w3mc/GHSA-wq43-8r5p-w3mc.json create mode 100644 advisories/github-reviewed/2024/05/GHSA-wxxw-5gq6-j2g5/GHSA-wxxw-5gq6-j2g5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-26f5-24g6-27vm/GHSA-26f5-24g6-27vm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-2h39-83vm-vq42/GHSA-2h39-83vm-vq42.json create mode 100644 advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-389q-94h9-f6qm/GHSA-389q-94h9-f6qm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-585p-p962-9hrc/GHSA-585p-p962-9hrc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6xj9-2c6f-3mhx/GHSA-6xj9-2c6f-3mhx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-856w-rm82-4hp7/GHSA-856w-rm82-4hp7.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8mcf-fh2m-245p/GHSA-8mcf-fh2m-245p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-946r-mx2c-f2pf/GHSA-946r-mx2c-f2pf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c24r-pxmj-hx9h/GHSA-c24r-pxmj-hx9h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f2q8-66wc-mcgp/GHSA-f2q8-66wc-mcgp.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f37v-v67w-4jmp/GHSA-f37v-v67w-4jmp.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fpvx-gw57-2p3v/GHSA-fpvx-gw57-2p3v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-g96r-v5qq-9qch/GHSA-g96r-v5qq-9qch.json create mode 100644 advisories/unreviewed/2024/05/GHSA-gmvc-mphj-2pr4/GHSA-gmvc-mphj-2pr4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-j5rg-hrw2-2gf7/GHSA-j5rg-hrw2-2gf7.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jwfg-733h-8pc5/GHSA-jwfg-733h-8pc5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-m4rj-rphf-266h/GHSA-m4rj-rphf-266h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-pr8j-5v55-885c/GHSA-pr8j-5v55-885c.json create mode 100644 advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r73q-j7fc-5g2p/GHSA-r73q-j7fc-5g2p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rc98-whmj-qg8f/GHSA-rc98-whmj-qg8f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rgcv-xpj5-8x8f/GHSA-rgcv-xpj5-8x8f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vpv3-mggc-9fwh/GHSA-vpv3-mggc-9fwh.json create mode 100644 advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json diff --git a/advisories/github-reviewed/2024/05/GHSA-wq43-8r5p-w3mc/GHSA-wq43-8r5p-w3mc.json b/advisories/github-reviewed/2024/05/GHSA-wq43-8r5p-w3mc/GHSA-wq43-8r5p-w3mc.json new file mode 100644 index 00000000000..03518f5779f --- /dev/null +++ b/advisories/github-reviewed/2024/05/GHSA-wq43-8r5p-w3mc/GHSA-wq43-8r5p-w3mc.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq43-8r5p-w3mc", + "modified": "2024-05-15T18:31:04Z", + "published": "2024-05-15T18:31:04Z", + "aliases": [ + + ], + "summary": "contao/core PHP object injection vulnerability allows for arbitrary code execution", + "details": "PHP object injection vulnerability was identified in contao/core due to untrusted data being passed to `deserialize()` function.\n", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.11.14" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.2.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/core/issues/6695" + }, + { + "type": "WEB", + "url": "https://github.com/contao/core/commit/d67c46c1f1283134e3050244cfdda0ef26fa5cd4" + }, + { + "type": "WEB", + "url": "https://github.com/contao/core/commit/f939b5be8a0048ef779def3289e2072febef1b37" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/major-security-hole-found-in-contao.html" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/2014-02-13.yaml" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-05-15T18:31:04Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/05/GHSA-wxxw-5gq6-j2g5/GHSA-wxxw-5gq6-j2g5.json b/advisories/github-reviewed/2024/05/GHSA-wxxw-5gq6-j2g5/GHSA-wxxw-5gq6-j2g5.json new file mode 100644 index 00000000000..7034fcf9a86 --- /dev/null +++ b/advisories/github-reviewed/2024/05/GHSA-wxxw-5gq6-j2g5/GHSA-wxxw-5gq6-j2g5.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxxw-5gq6-j2g5", + "modified": "2024-05-15T18:31:02Z", + "published": "2024-05-15T18:31:02Z", + "aliases": [ + + ], + "summary": "contao/core Insufficient input validation allows for code injection and remote execution", + "details": "contao/core versions 2.x prior to 2.11.17 and 3.x prior to 3.2.9 are vulnerable to arbitrary code execution on the server due to insufficient input validation. In fact, attackers can remove or change pathconfig.php by entering a URL, meaning that the entire Contao installation will no longer be accessible or malicious code can be executed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.11.17" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.2.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/core/issues/6855" + }, + { + "type": "WEB", + "url": "https://github.com/contao/core/commit/d45503568751a868193929ef349a49ae5e6686f0" + }, + { + "type": "WEB", + "url": "https://github.com/contao/core/commit/d4a14f167e0cbb2e77c7829299e5b36f55c1ebce" + }, + { + "type": "WEB", + "url": "https://c-c-a.org/aktuelles/news/details/eine-neue-kritische-sicherheitsluecke-in-contao-entdeckt" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/2014-04-07.yaml" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20240214121817/https://contao.org/en/news/new-security-hole-found-in-contao" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-05-15T18:31:02Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-26f5-24g6-27vm/GHSA-26f5-24g6-27vm.json b/advisories/unreviewed/2024/05/GHSA-26f5-24g6-27vm/GHSA-26f5-24g6-27vm.json new file mode 100644 index 00000000000..33b22d8b12c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-26f5-24g6-27vm/GHSA-26f5-24g6-27vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26f5-24g6-27vm", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20256" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20256" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-2h39-83vm-vq42/GHSA-2h39-83vm-vq42.json b/advisories/unreviewed/2024/05/GHSA-2h39-83vm-vq42/GHSA-2h39-83vm-vq42.json new file mode 100644 index 00000000000..15203f0c2f1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2h39-83vm-vq42/GHSA-2h39-83vm-vq42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h39-83vm-vq42", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2023-7258" + ], + "details": "A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7258" + }, + { + "type": "WEB", + "url": "https://github.com/google/gvisor/commit/6a112c60a257dadac59962e0bc9e9b5aee70b5b6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json b/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json new file mode 100644 index 00000000000..40f85ddc970 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34wr-w2h3-hr5x", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3488" + ], + "details": "File Upload vulnerability in unauthenticated\nsession found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a\nfile without authentication.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3488" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-389q-94h9-f6qm/GHSA-389q-94h9-f6qm.json b/advisories/unreviewed/2024/05/GHSA-389q-94h9-f6qm/GHSA-389q-94h9-f6qm.json new file mode 100644 index 00000000000..db6588e74c0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-389q-94h9-f6qm/GHSA-389q-94h9-f6qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-389q-94h9-f6qm", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-28042" + ], + "details": "SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28042" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1357" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json b/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json new file mode 100644 index 00000000000..74037d934ca --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57h3-6mh3-cjrr", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-27593" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27593" + }, + { + "type": "WEB", + "url": "https://blog.smarttecs.com/posts/2024-002-cve-2024-27593" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-585p-p962-9hrc/GHSA-585p-p962-9hrc.json b/advisories/unreviewed/2024/05/GHSA-585p-p962-9hrc/GHSA-585p-p962-9hrc.json new file mode 100644 index 00000000000..fe3bb666fae --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-585p-p962-9hrc/GHSA-585p-p962-9hrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-585p-p962-9hrc", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2023-5938" + ], + "details": "Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks.\n\n\n\nAn administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim’s machine).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5938" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2023:16-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6xj9-2c6f-3mhx/GHSA-6xj9-2c6f-3mhx.json b/advisories/unreviewed/2024/05/GHSA-6xj9-2c6f-3mhx/GHSA-6xj9-2c6f-3mhx.json new file mode 100644 index 00000000000..5c4e5fc00e2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6xj9-2c6f-3mhx/GHSA-6xj9-2c6f-3mhx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xj9-2c6f-3mhx", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20258" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.\n\n This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20258" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json b/advisories/unreviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json new file mode 100644 index 00000000000..0b4ba6f0531 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76v2-48w6-crxr", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-28087" + ], + "details": "In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28087" + }, + { + "type": "WEB", + "url": "https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_2024_1_2024_04_11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json b/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json new file mode 100644 index 00000000000..edff518da17 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77g7-q65f-rmxf", + "modified": "2024-05-15T18:30:36Z", + "published": "2024-05-15T18:30:36Z", + "aliases": [ + "CVE-2024-4905" + ], + "details": "A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4905" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.264438" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.264438" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.332543" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json b/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json new file mode 100644 index 00000000000..c5b0f2a778a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8483-3cvj-46c5", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3967" + ], + "details": "Remote Code\nExecution has been discovered in\nOpenText™ iManager 3.2.6.0200. The vulnerability can\ntrigger remote code execution unisng unsafe java object deserialization.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3967" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-856w-rm82-4hp7/GHSA-856w-rm82-4hp7.json b/advisories/unreviewed/2024/05/GHSA-856w-rm82-4hp7/GHSA-856w-rm82-4hp7.json new file mode 100644 index 00000000000..f4e4108b93d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-856w-rm82-4hp7/GHSA-856w-rm82-4hp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-856w-rm82-4hp7", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-4837" + ], + "details": "In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4837" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/report-server/knowledge-base/information-exposure-cve-2024-4837" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json b/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json new file mode 100644 index 00000000000..017ba5c2316 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jrr-vwjm-wj7q", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3484" + ], + "details": "Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation\nor file disclosure.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3484" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8mcf-fh2m-245p/GHSA-8mcf-fh2m-245p.json b/advisories/unreviewed/2024/05/GHSA-8mcf-fh2m-245p/GHSA-8mcf-fh2m-245p.json new file mode 100644 index 00000000000..5b239244060 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8mcf-fh2m-245p/GHSA-8mcf-fh2m-245p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mcf-fh2m-245p", + "modified": "2024-05-15T18:30:36Z", + "published": "2024-05-15T18:30:36Z", + "aliases": [ + "CVE-2024-20394" + ], + "details": "A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to the inability to handle unexpected input. An attacker who has local device access could exploit this vulnerability by sending an HTTP request to the targeted service. A successful exploit could allow the attacker to cause a DoS condition by stopping the Network Agent Service on the local device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20394" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appd-netvisdos-9zNbsJtK" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-946r-mx2c-f2pf/GHSA-946r-mx2c-f2pf.json b/advisories/unreviewed/2024/05/GHSA-946r-mx2c-f2pf/GHSA-946r-mx2c-f2pf.json new file mode 100644 index 00000000000..d7c5655cbdf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-946r-mx2c-f2pf/GHSA-946r-mx2c-f2pf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-946r-mx2c-f2pf", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-4903" + ], + "details": "A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation of the argument M_ID_STR leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264436. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4903" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.264436" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.264436" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c24r-pxmj-hx9h/GHSA-c24r-pxmj-hx9h.json b/advisories/unreviewed/2024/05/GHSA-c24r-pxmj-hx9h/GHSA-c24r-pxmj-hx9h.json new file mode 100644 index 00000000000..3d92e26b601 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c24r-pxmj-hx9h/GHSA-c24r-pxmj-hx9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c24r-pxmj-hx9h", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-3319" + ], + "details": "An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3319" + }, + { + "type": "WEB", + "url": "https://www.sailpoint.com/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json b/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json new file mode 100644 index 00000000000..61ba8a19a1c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5q5-64hr-5mwm", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3968" + ], + "details": "Remote Code\nExecution has been discovered in\nOpenText™ iManager 3.2.6.0200. The vulnerability can\ntrigger remote code execution using custom file upload task.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3968" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json b/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json new file mode 100644 index 00000000000..d61a6208a24 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj69-9qw7-84pj", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3487" + ], + "details": "Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This\nvulnerability allows an attacker to manipulate certain parameters to bypass\nauthentication.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3487" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json b/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json new file mode 100644 index 00000000000..c9032fee131 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmcg-f6r6-g4hh", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3486" + ], + "details": "XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3486" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f2q8-66wc-mcgp/GHSA-f2q8-66wc-mcgp.json b/advisories/unreviewed/2024/05/GHSA-f2q8-66wc-mcgp/GHSA-f2q8-66wc-mcgp.json new file mode 100644 index 00000000000..4833021cce3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f2q8-66wc-mcgp/GHSA-f2q8-66wc-mcgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2q8-66wc-mcgp", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20392" + ], + "details": "A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. \n\n This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20392" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-http-split-GLrnnOwS" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-113" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f37v-v67w-4jmp/GHSA-f37v-v67w-4jmp.json b/advisories/unreviewed/2024/05/GHSA-f37v-v67w-4jmp/GHSA-f37v-v67w-4jmp.json new file mode 100644 index 00000000000..c82bbcc3ea0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f37v-v67w-4jmp/GHSA-f37v-v67w-4jmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f37v-v67w-4jmp", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20257" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r\n\n This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20257" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json b/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json new file mode 100644 index 00000000000..d8ff11ade36 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc6q-xmrf-7jx4", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-4202" + ], + "details": "In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4202" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/reporting/knowledge-base/instantiation-vulnerability-cve-2024-4202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fpvx-gw57-2p3v/GHSA-fpvx-gw57-2p3v.json b/advisories/unreviewed/2024/05/GHSA-fpvx-gw57-2p3v/GHSA-fpvx-gw57-2p3v.json new file mode 100644 index 00000000000..36b6fc22c93 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fpvx-gw57-2p3v/GHSA-fpvx-gw57-2p3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpvx-gw57-2p3v", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20366" + ], + "details": "A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device.\n\n This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker could exploit this vulnerability by configuring the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. To exploit this vulnerability, the attacker would need valid credentials on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20366" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-hcc-priv-esc-OWBWCs5D" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-g96r-v5qq-9qch/GHSA-g96r-v5qq-9qch.json b/advisories/unreviewed/2024/05/GHSA-g96r-v5qq-9qch/GHSA-g96r-v5qq-9qch.json new file mode 100644 index 00000000000..413c544a295 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-g96r-v5qq-9qch/GHSA-g96r-v5qq-9qch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g96r-v5qq-9qch", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20369" + ], + "details": "A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.\n\n\n This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20369" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-ordir-MNM8YqzO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gmvc-mphj-2pr4/GHSA-gmvc-mphj-2pr4.json b/advisories/unreviewed/2024/05/GHSA-gmvc-mphj-2pr4/GHSA-gmvc-mphj-2pr4.json new file mode 100644 index 00000000000..07cfd86ae70 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gmvc-mphj-2pr4/GHSA-gmvc-mphj-2pr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmvc-mphj-2pr4", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20391" + ], + "details": "A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM.\n\n This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20391" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-nam-priv-esc-szu2vYpZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json b/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json new file mode 100644 index 00000000000..5f38d932bd2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxv9-64g4-jhvj", + "modified": "2024-05-15T18:30:36Z", + "published": "2024-05-15T18:30:36Z", + "aliases": [ + "CVE-2024-3182" + ], + "details": "Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3182" + }, + { + "type": "WEB", + "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j5rg-hrw2-2gf7/GHSA-j5rg-hrw2-2gf7.json b/advisories/unreviewed/2024/05/GHSA-j5rg-hrw2-2gf7/GHSA-j5rg-hrw2-2gf7.json new file mode 100644 index 00000000000..b218ef2ae4d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j5rg-hrw2-2gf7/GHSA-j5rg-hrw2-2gf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5rg-hrw2-2gf7", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-3318" + ], + "details": "A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3318" + }, + { + "type": "WEB", + "url": "https://www.sailpoint.com/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json b/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json new file mode 100644 index 00000000000..8b84ace8dd9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg34-vvwh-5qv9", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3485" + ], + "details": "Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This\ncould lead to senstive information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3485" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jwfg-733h-8pc5/GHSA-jwfg-733h-8pc5.json b/advisories/unreviewed/2024/05/GHSA-jwfg-733h-8pc5/GHSA-jwfg-733h-8pc5.json new file mode 100644 index 00000000000..d38bf6f1e36 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jwfg-733h-8pc5/GHSA-jwfg-733h-8pc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwfg-733h-8pc5", + "modified": "2024-05-15T18:30:33Z", + "published": "2024-05-15T18:30:33Z", + "aliases": [ + "CVE-2023-5937" + ], + "details": "On Windows systems, the Arc configuration files resulted to be world-readable.\n\n\n\nThis can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5937" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2023:15-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m4rj-rphf-266h/GHSA-m4rj-rphf-266h.json b/advisories/unreviewed/2024/05/GHSA-m4rj-rphf-266h/GHSA-m4rj-rphf-266h.json new file mode 100644 index 00000000000..62c0eb35254 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-m4rj-rphf-266h/GHSA-m4rj-rphf-266h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4rj-rphf-266h", + "modified": "2024-05-15T18:30:34Z", + "published": "2024-05-15T18:30:34Z", + "aliases": [ + "CVE-2024-3317" + ], + "details": "An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3317" + }, + { + "type": "WEB", + "url": "https://www.sailpoint.com/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json b/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json new file mode 100644 index 00000000000..936dc8ecc38 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m82c-2r7m-qgcj", + "modified": "2024-05-15T18:30:36Z", + "published": "2024-05-15T18:30:36Z", + "aliases": [ + "CVE-2024-25743" + ], + "details": "In the Linux kernel through 6.7.2, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25743" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json b/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json new file mode 100644 index 00000000000..946d9990b70 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hw-w67j-562v", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-4200" + ], + "details": "In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4200" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-4200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pr8j-5v55-885c/GHSA-pr8j-5v55-885c.json b/advisories/unreviewed/2024/05/GHSA-pr8j-5v55-885c/GHSA-pr8j-5v55-885c.json new file mode 100644 index 00000000000..849dd932164 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pr8j-5v55-885c/GHSA-pr8j-5v55-885c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr8j-5v55-885c", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-20383" + ], + "details": "A vulnerability in the Cisco Crosswork NSO CLI and the ConfD CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system.\n\n This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20383" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json b/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json new file mode 100644 index 00000000000..06ec3f77636 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3jf-xfc9-6rc2", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3483" + ], + "details": "Remote Code\nExecution has been discovered in\nOpenText™ iManager 3.2.6.0200. The vulnerability can\ntrigger command injection and insecure deserialization issues.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3483" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r73q-j7fc-5g2p/GHSA-r73q-j7fc-5g2p.json b/advisories/unreviewed/2024/05/GHSA-r73q-j7fc-5g2p/GHSA-r73q-j7fc-5g2p.json new file mode 100644 index 00000000000..f2402c35df1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r73q-j7fc-5g2p/GHSA-r73q-j7fc-5g2p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r73q-j7fc-5g2p", + "modified": "2024-05-15T18:30:33Z", + "published": "2024-05-15T18:30:33Z", + "aliases": [ + "CVE-2023-5936" + ], + "details": "On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges.\n\n\n\nBy tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5936" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2023:14-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rc98-whmj-qg8f/GHSA-rc98-whmj-qg8f.json b/advisories/unreviewed/2024/05/GHSA-rc98-whmj-qg8f/GHSA-rc98-whmj-qg8f.json new file mode 100644 index 00000000000..27b635fe9be --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rc98-whmj-qg8f/GHSA-rc98-whmj-qg8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc98-whmj-qg8f", + "modified": "2024-05-15T18:30:33Z", + "published": "2024-05-15T18:30:33Z", + "aliases": [ + "CVE-2023-5935" + ], + "details": "When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.\n\n\n\nA malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5935" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2023:13-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rgcv-xpj5-8x8f/GHSA-rgcv-xpj5-8x8f.json b/advisories/unreviewed/2024/05/GHSA-rgcv-xpj5-8x8f/GHSA-rgcv-xpj5-8x8f.json new file mode 100644 index 00000000000..ceaadcb7cc2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rgcv-xpj5-8x8f/GHSA-rgcv-xpj5-8x8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgcv-xpj5-8x8f", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-4357" + ], + "details": "An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4357" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024-4357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vpv3-mggc-9fwh/GHSA-vpv3-mggc-9fwh.json b/advisories/unreviewed/2024/05/GHSA-vpv3-mggc-9fwh/GHSA-vpv3-mggc-9fwh.json new file mode 100644 index 00000000000..9c6568fc52a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vpv3-mggc-9fwh/GHSA-vpv3-mggc-9fwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpv3-mggc-9fwh", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3892" + ], + "details": "A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3892" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/winforms/knowledge-base/local-code-execution-vulnerability-cve-2024-3892" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json b/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json new file mode 100644 index 00000000000..a77ce31ff2d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3pf-5jqj-rj4q", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-4622" + ], + "details": "If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface \nprotected by authentication. If the default credentials are not changed,\n an attacker can use public knowledge to access the device as an \nadministrator.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4622" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-130-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json b/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json new file mode 100644 index 00000000000..d0a6304d8b5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xppr-6c99-hp78", + "modified": "2024-05-15T18:30:35Z", + "published": "2024-05-15T18:30:35Z", + "aliases": [ + "CVE-2024-3970" + ], + "details": "Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This\ncould lead to senstive information disclosure by directory traversal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3970" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T17:15:15Z" + } +} \ No newline at end of file