mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f8h5-v2vg-46rr",
|
||||
"modified": "2024-05-31T03:30:32Z",
|
||||
"modified": "2024-06-20T18:34:07Z",
|
||||
"published": "2024-04-04T15:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-2700"
|
||||
@@ -108,6 +108,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:3527"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:4028"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-2700"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2hmr-w3hv-h898",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:06Z",
|
||||
"published": "2023-11-17T06:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38320"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38320"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.2vJg3d85.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3w3w-vm78-84r8",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:06Z",
|
||||
"published": "2023-11-17T06:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38315"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38315"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-53v5-7h5p-m6g9",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:07Z",
|
||||
"published": "2023-11-17T06:31:22Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38324"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38324"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cwe.mitre.org/data/definitions/1390.html"
|
||||
@@ -37,6 +41,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://openwrt.org/docs/guide-user/services/captive-portal/opennds"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.forescout.com/resources/sierra21-vulnerabilities"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-596w-g2cr-x93q",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:07Z",
|
||||
"published": "2023-11-17T06:31:22Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38322"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38322"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-75j8-mr4c-4x59",
|
||||
"modified": "2023-11-25T03:30:32Z",
|
||||
"modified": "2024-06-20T18:34:07Z",
|
||||
"published": "2023-11-17T06:31:22Z",
|
||||
"aliases": [
|
||||
"CVE-2023-41101"
|
||||
@@ -25,9 +25,17 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/commit/c294cf30e0a2512062c66e6becb674557b4aed8d"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/88c98c910acccab694b3afb6d36d70ca429118a6"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.3"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-857f-w8mj-5g2g",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:06Z",
|
||||
"published": "2023-11-17T06:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38316"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38316"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9752-mq4c-65h9",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:06Z",
|
||||
"published": "2023-11-17T06:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38314"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38314"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-98jh-839r-xp86",
|
||||
"modified": "2023-11-25T03:30:32Z",
|
||||
"modified": "2024-06-20T18:34:07Z",
|
||||
"published": "2023-11-17T06:31:22Z",
|
||||
"aliases": [
|
||||
"CVE-2023-41102"
|
||||
@@ -25,9 +25,17 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.3"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pg75-xxxv-pv8j",
|
||||
"modified": "2023-11-23T06:30:28Z",
|
||||
"modified": "2024-06-20T18:34:06Z",
|
||||
"published": "2023-11-17T06:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-38313"
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38313"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2mr3-36qv-4rmf",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37347"
|
||||
],
|
||||
"details": "There is a cross-site scripting vulnerability in the pool\nconfiguration component of the management UI of Absolute Secure Access prior to\n13.06. Attackers with system administrator permissions can pass a limited\nlength script to be run by another administrator. The scope is unchanged, there\nis no loss of confidentiality. Impact to system integrity is high, impact to\nsystem availability is none.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37347"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37347"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T17:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-68f4-m7ww-959w",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37626"
|
||||
],
|
||||
"details": "A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37626"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/lakemoon602/vuln/blob/main/totolink/TOTOlink%20A6000R%20vif_enable.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.totolink.net"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://a6000r.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T17:15:52Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7ghr-qrgp-2cq4",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37346"
|
||||
],
|
||||
"details": "There is an insufficient input validation vulnerability in\nthe Warehouse component of Absolute Secure Access prior to 13.06. Attackers\nwith system administrator permissions can impair the availability of certain\nelements of the Secure Access administrative UI by writing invalid data to the\nwarehouse over the network. There is no loss of warehouse integrity or\nconfidentiality, the security scope is unchanged. Loss of availability is high.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37346"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37346"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T17:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8fqh-4hjv-48fq",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37345"
|
||||
],
|
||||
"details": "There is a cross-site scripting vulnerability in the Secure\nAccess administrative UI of Absolute Secure Access prior to version 13.06.\nAttackers can pass a limited-length script to the administrative UI which is\nthen stored where an administrator can access it. The scope is unchanged, there\nis no loss of confidentiality. Impact to system availability is none, impact to\nsystem integrity is high",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37345"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37345"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T17:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -28,6 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-119",
|
||||
"CWE-822"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9pmm-wf44-xjqc",
|
||||
"modified": "2024-06-14T06:34:45Z",
|
||||
"modified": "2024-06-20T18:34:08Z",
|
||||
"published": "2024-06-11T21:32:18Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5831"
|
||||
],
|
||||
"details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -37,9 +40,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-11T21:15:54Z"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9pwr-528x-xv6m",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37352"
|
||||
],
|
||||
"details": "There is a cross-site scripting vulnerability in the\nmanagement UI of Absolute Secure Access prior to version 13.06 that allows\nattackers with system administrator permissions to interfere with other system\nadministrators’ use of the management UI when the second administrator accesses\nthe vulnerable page. The scope is unchanged, there is no loss of\nconfidentiality. Impact to system integrity is high, impact to system\navailability is none.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37352"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37352"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T18:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c2w9-h5r4-gc47",
|
||||
"modified": "2024-06-20T18:34:08Z",
|
||||
"published": "2024-06-20T18:34:08Z",
|
||||
"aliases": [
|
||||
"CVE-2022-41324"
|
||||
],
|
||||
"details": "Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41324"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mender.io/blog/cve-2022-45929-cve-2022-41324-improper-access-control-for-low-privileged-users"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://northern.tech"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T17:15:50Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c8q9-3mqw-64x8",
|
||||
"modified": "2024-06-20T18:34:09Z",
|
||||
"published": "2024-06-20T18:34:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37349"
|
||||
],
|
||||
"details": "There is a cross-site scripting vulnerability in the\nmanagement UI of Absolute Secure Access prior to version 13.06. Attackers with\nsystem administrator permissions can interfere with other system\nadministrator’s use of the management UI when the victim administrator edits\nthe same management object. This vulnerability is distinct from CVE-2024-37348 and\nCVE-2024-37351. The scope is unchanged, there is no loss of confidentiality. Impact\nto system integrity is high, impact to system availability is none.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37349"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37349"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T18:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -28,7 +28,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-1390"
|
||||
"CWE-1390",
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user