diff --git a/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json index e4f7722ffd7..b03b33e36b1 100644 --- a/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json +++ b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8h5-v2vg-46rr", - "modified": "2024-05-31T03:30:32Z", + "modified": "2024-06-20T18:34:07Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-2700" @@ -108,6 +108,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3527" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4028" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-2700" diff --git a/advisories/unreviewed/2023/11/GHSA-2hmr-w3hv-h898/GHSA-2hmr-w3hv-h898.json b/advisories/unreviewed/2023/11/GHSA-2hmr-w3hv-h898/GHSA-2hmr-w3hv-h898.json index 10ca83ce35d..1276c4fb292 100644 --- a/advisories/unreviewed/2023/11/GHSA-2hmr-w3hv-h898/GHSA-2hmr-w3hv-h898.json +++ b/advisories/unreviewed/2023/11/GHSA-2hmr-w3hv-h898/GHSA-2hmr-w3hv-h898.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hmr-w3hv-h898", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:06Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-38320" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38320" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.2vJg3d85.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-3w3w-vm78-84r8/GHSA-3w3w-vm78-84r8.json b/advisories/unreviewed/2023/11/GHSA-3w3w-vm78-84r8/GHSA-3w3w-vm78-84r8.json index c940fb6a3c3..ea8c8f59704 100644 --- a/advisories/unreviewed/2023/11/GHSA-3w3w-vm78-84r8/GHSA-3w3w-vm78-84r8.json +++ b/advisories/unreviewed/2023/11/GHSA-3w3w-vm78-84r8/GHSA-3w3w-vm78-84r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w3w-vm78-84r8", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:06Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-38315" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38315" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-53v5-7h5p-m6g9/GHSA-53v5-7h5p-m6g9.json b/advisories/unreviewed/2023/11/GHSA-53v5-7h5p-m6g9/GHSA-53v5-7h5p-m6g9.json index 9a42092e92e..d85d7eb0712 100644 --- a/advisories/unreviewed/2023/11/GHSA-53v5-7h5p-m6g9/GHSA-53v5-7h5p-m6g9.json +++ b/advisories/unreviewed/2023/11/GHSA-53v5-7h5p-m6g9/GHSA-53v5-7h5p-m6g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53v5-7h5p-m6g9", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:07Z", "published": "2023-11-17T06:31:22Z", "aliases": [ "CVE-2023-38324" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38324" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/1390.html" @@ -37,6 +41,10 @@ "type": "WEB", "url": "https://openwrt.org/docs/guide-user/services/captive-portal/opennds" }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" + }, { "type": "WEB", "url": "https://www.forescout.com/resources/sierra21-vulnerabilities" diff --git a/advisories/unreviewed/2023/11/GHSA-596w-g2cr-x93q/GHSA-596w-g2cr-x93q.json b/advisories/unreviewed/2023/11/GHSA-596w-g2cr-x93q/GHSA-596w-g2cr-x93q.json index 7ab9cf84f34..ee65d24086f 100644 --- a/advisories/unreviewed/2023/11/GHSA-596w-g2cr-x93q/GHSA-596w-g2cr-x93q.json +++ b/advisories/unreviewed/2023/11/GHSA-596w-g2cr-x93q/GHSA-596w-g2cr-x93q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-596w-g2cr-x93q", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:07Z", "published": "2023-11-17T06:31:22Z", "aliases": [ "CVE-2023-38322" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38322" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-75j8-mr4c-4x59/GHSA-75j8-mr4c-4x59.json b/advisories/unreviewed/2023/11/GHSA-75j8-mr4c-4x59/GHSA-75j8-mr4c-4x59.json index 100eea8fac5..8dab6e184d4 100644 --- a/advisories/unreviewed/2023/11/GHSA-75j8-mr4c-4x59/GHSA-75j8-mr4c-4x59.json +++ b/advisories/unreviewed/2023/11/GHSA-75j8-mr4c-4x59/GHSA-75j8-mr4c-4x59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75j8-mr4c-4x59", - "modified": "2023-11-25T03:30:32Z", + "modified": "2024-06-20T18:34:07Z", "published": "2023-11-17T06:31:22Z", "aliases": [ "CVE-2023-41101" @@ -25,9 +25,17 @@ "type": "WEB", "url": "https://github.com/openNDS/openNDS/commit/c294cf30e0a2512062c66e6becb674557b4aed8d" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/88c98c910acccab694b3afb6d36d70ca429118a6" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.3" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-857f-w8mj-5g2g/GHSA-857f-w8mj-5g2g.json b/advisories/unreviewed/2023/11/GHSA-857f-w8mj-5g2g/GHSA-857f-w8mj-5g2g.json index 7577b8fb956..8e94257ba41 100644 --- a/advisories/unreviewed/2023/11/GHSA-857f-w8mj-5g2g/GHSA-857f-w8mj-5g2g.json +++ b/advisories/unreviewed/2023/11/GHSA-857f-w8mj-5g2g/GHSA-857f-w8mj-5g2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-857f-w8mj-5g2g", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:06Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-38316" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38316" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-9752-mq4c-65h9/GHSA-9752-mq4c-65h9.json b/advisories/unreviewed/2023/11/GHSA-9752-mq4c-65h9/GHSA-9752-mq4c-65h9.json index 330b6f6a0e7..7bcbd1ff209 100644 --- a/advisories/unreviewed/2023/11/GHSA-9752-mq4c-65h9/GHSA-9752-mq4c-65h9.json +++ b/advisories/unreviewed/2023/11/GHSA-9752-mq4c-65h9/GHSA-9752-mq4c-65h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9752-mq4c-65h9", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:06Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-38314" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38314" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json b/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json index 6cba5db2073..c2becf7fa97 100644 --- a/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json +++ b/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98jh-839r-xp86", - "modified": "2023-11-25T03:30:32Z", + "modified": "2024-06-20T18:34:07Z", "published": "2023-11-17T06:31:22Z", "aliases": [ "CVE-2023-41102" @@ -25,9 +25,17 @@ "type": "WEB", "url": "https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.3" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-pg75-xxxv-pv8j/GHSA-pg75-xxxv-pv8j.json b/advisories/unreviewed/2023/11/GHSA-pg75-xxxv-pv8j/GHSA-pg75-xxxv-pv8j.json index 07bd02375c9..2be3f5761e1 100644 --- a/advisories/unreviewed/2023/11/GHSA-pg75-xxxv-pv8j/GHSA-pg75-xxxv-pv8j.json +++ b/advisories/unreviewed/2023/11/GHSA-pg75-xxxv-pv8j/GHSA-pg75-xxxv-pv8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg75-xxxv-pv8j", - "modified": "2023-11-23T06:30:28Z", + "modified": "2024-06-20T18:34:06Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-38313" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38313" }, + { + "type": "WEB", + "url": "https://github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80" + }, { "type": "WEB", "url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-2mr3-36qv-4rmf/GHSA-2mr3-36qv-4rmf.json b/advisories/unreviewed/2024/06/GHSA-2mr3-36qv-4rmf/GHSA-2mr3-36qv-4rmf.json new file mode 100644 index 00000000000..1d184cb98fc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2mr3-36qv-4rmf/GHSA-2mr3-36qv-4rmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mr3-36qv-4rmf", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37347" + ], + "details": "There is a cross-site scripting vulnerability in the pool\nconfiguration component of the management UI of Absolute Secure Access prior to\n13.06. Attackers with system administrator permissions can pass a limited\nlength script to be run by another administrator. The scope is unchanged, there\nis no loss of confidentiality. Impact to system integrity is high, impact to\nsystem availability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37347" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-68f4-m7ww-959w/GHSA-68f4-m7ww-959w.json b/advisories/unreviewed/2024/06/GHSA-68f4-m7ww-959w/GHSA-68f4-m7ww-959w.json new file mode 100644 index 00000000000..f81bacdc688 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-68f4-m7ww-959w/GHSA-68f4-m7ww-959w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68f4-m7ww-959w", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37626" + ], + "details": "A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37626" + }, + { + "type": "WEB", + "url": "https://github.com/lakemoon602/vuln/blob/main/totolink/TOTOlink%20A6000R%20vif_enable.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "http://a6000r.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json b/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json new file mode 100644 index 00000000000..03f697afe6a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghr-qrgp-2cq4", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37346" + ], + "details": "There is an insufficient input validation vulnerability in\nthe Warehouse component of Absolute Secure Access prior to 13.06. Attackers\nwith system administrator permissions can impair the availability of certain\nelements of the Secure Access administrative UI by writing invalid data to the\nwarehouse over the network. There is no loss of warehouse integrity or\nconfidentiality, the security scope is unchanged. Loss of availability is high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37346" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8fqh-4hjv-48fq/GHSA-8fqh-4hjv-48fq.json b/advisories/unreviewed/2024/06/GHSA-8fqh-4hjv-48fq/GHSA-8fqh-4hjv-48fq.json new file mode 100644 index 00000000000..db9d8612ad9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8fqh-4hjv-48fq/GHSA-8fqh-4hjv-48fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fqh-4hjv-48fq", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37345" + ], + "details": "There is a cross-site scripting vulnerability in the Secure\nAccess administrative UI of Absolute Secure Access prior to version 13.06.\nAttackers can pass a limited-length script to the administrative UI which is\nthen stored where an administrator can access it. The scope is unchanged, there\nis no loss of confidentiality. Impact to system availability is none, impact to\nsystem integrity is high", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37345" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37345" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json index 5de2c2fbabd..760beba708d 100644 --- a/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json +++ b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-9pmm-wf44-xjqc/GHSA-9pmm-wf44-xjqc.json b/advisories/unreviewed/2024/06/GHSA-9pmm-wf44-xjqc/GHSA-9pmm-wf44-xjqc.json index 531a069619e..a10c1047c76 100644 --- a/advisories/unreviewed/2024/06/GHSA-9pmm-wf44-xjqc/GHSA-9pmm-wf44-xjqc.json +++ b/advisories/unreviewed/2024/06/GHSA-9pmm-wf44-xjqc/GHSA-9pmm-wf44-xjqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9pmm-wf44-xjqc", - "modified": "2024-06-14T06:34:45Z", + "modified": "2024-06-20T18:34:08Z", "published": "2024-06-11T21:32:18Z", "aliases": [ "CVE-2024-5831" ], "details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T21:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json b/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json new file mode 100644 index 00000000000..c8eebd7db8b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pwr-528x-xv6m", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37352" + ], + "details": "There is a cross-site scripting vulnerability in the\nmanagement UI of Absolute Secure Access prior to version 13.06 that allows\nattackers with system administrator permissions to interfere with other system\nadministrators’ use of the management UI when the second administrator accesses\nthe vulnerable page. The scope is unchanged, there is no loss of\nconfidentiality. Impact to system integrity is high, impact to system\navailability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37352" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37352" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json b/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json new file mode 100644 index 00000000000..57f0be5eeaf --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2w9-h5r4-gc47", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2022-41324" + ], + "details": "Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41324" + }, + { + "type": "WEB", + "url": "https://mender.io/blog/cve-2022-45929-cve-2022-41324-improper-access-control-for-low-privileged-users" + }, + { + "type": "WEB", + "url": "https://northern.tech" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json b/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json new file mode 100644 index 00000000000..db45ffbeeab --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8q9-3mqw-64x8", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37349" + ], + "details": "There is a cross-site scripting vulnerability in the\nmanagement UI of Absolute Secure Access prior to version 13.06. Attackers with\nsystem administrator permissions can interfere with other system\nadministrator’s use of the management UI when the victim administrator edits\nthe same management object. This vulnerability is distinct from CVE-2024-37348 and\nCVE-2024-37351. The scope is unchanged, there is no loss of confidentiality. Impact\nto system integrity is high, impact to system availability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37349" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json b/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json index e709da5a587..86f7e6e53cc 100644 --- a/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json +++ b/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1390" + "CWE-1390", + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json b/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json index 863c61160b2..6af44b42cff 100644 --- a/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json +++ b/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fchp-8m28-g68f", - "modified": "2024-06-14T06:34:45Z", + "modified": "2024-06-20T18:34:08Z", "published": "2024-06-11T21:32:18Z", "aliases": [ "CVE-2024-5830" ], "details": "Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T21:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json b/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json new file mode 100644 index 00000000000..b5e827a8f7a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcqv-w7xc-5vmc", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37674" + ], + "details": "Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37674" + }, + { + "type": "WEB", + "url": "https://github.com/MohamedAzizMSALLEMI/Moodle_Security/blob/main/CVE-2024-37674.md" + }, + { + "type": "WEB", + "url": "http://moodle.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json b/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json new file mode 100644 index 00000000000..31f2ed8891e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjjq-g95w-h3w9", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37351" + ], + "details": "There is a cross-site scripting vulnerability in the\nmanagement UI of Absolute Secure Access prior to version 13.06. Attackers with\nsystem administrator permissions can interfere with other system\nadministrator’s use of the management UI when the second administrator later\nedits the same management object. This vulnerability is distinct from CVE-2024-37348 and\nCVE-2024-37349. The scope is unchanged, there is no loss of confidentiality. Impact\nto system integrity is high, impact to system availability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37351" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37351" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fpm4-ph9q-4wjx/GHSA-fpm4-ph9q-4wjx.json b/advisories/unreviewed/2024/06/GHSA-fpm4-ph9q-4wjx/GHSA-fpm4-ph9q-4wjx.json new file mode 100644 index 00000000000..91464bb72d3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fpm4-ph9q-4wjx/GHSA-fpm4-ph9q-4wjx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpm4-ph9q-4wjx", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37699" + ], + "details": "An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37699" + }, + { + "type": "WEB", + "url": "https://dle-news.ru/pressrelease/1909-datalife-engine-v172-press-release.html" + }, + { + "type": "WEB", + "url": "https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-17-0.19" + }, + { + "type": "WEB", + "url": "https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-sql-injection-sql-inekcija-17-1.19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json b/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json new file mode 100644 index 00000000000..c21ed7c6f63 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4fx-g364-89c4", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2022-45929" + ], + "details": "Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45929" + }, + { + "type": "WEB", + "url": "https://mender.io/blog/cve-2022-45929-cve-2022-41324-improper-access-control-for-low-privileged-users" + }, + { + "type": "WEB", + "url": "https://northern.tech" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h95x-26f3-88hr/GHSA-h95x-26f3-88hr.json b/advisories/unreviewed/2024/06/GHSA-h95x-26f3-88hr/GHSA-h95x-26f3-88hr.json new file mode 100644 index 00000000000..611981ad899 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h95x-26f3-88hr/GHSA-h95x-26f3-88hr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h95x-26f3-88hr", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-28397" + ], + "details": "An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28397" + }, + { + "type": "WEB", + "url": "https://github.com/Marven11" + }, + { + "type": "WEB", + "url": "https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hqh6-74v8-6c57/GHSA-hqh6-74v8-6c57.json b/advisories/unreviewed/2024/06/GHSA-hqh6-74v8-6c57/GHSA-hqh6-74v8-6c57.json new file mode 100644 index 00000000000..85f67042770 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hqh6-74v8-6c57/GHSA-hqh6-74v8-6c57.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqh6-74v8-6c57", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-6194" + ], + "details": "A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file editmeasurement.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269166 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6194" + }, + { + "type": "WEB", + "url": "https://github.com/HryspaHodor/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json b/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json index 56b0780fc0b..4c58e9626cd 100644 --- a/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json +++ b/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-j7q8-96xp-m3gc/GHSA-j7q8-96xp-m3gc.json b/advisories/unreviewed/2024/06/GHSA-j7q8-96xp-m3gc/GHSA-j7q8-96xp-m3gc.json new file mode 100644 index 00000000000..5731702be76 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j7q8-96xp-m3gc/GHSA-j7q8-96xp-m3gc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7q8-96xp-m3gc", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-37676" + ], + "details": "An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37676" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Cirno9-dev/0109cde3bdbe7eccc6770515106740b7" + }, + { + "type": "WEB", + "url": "https://github.com/htop-dev/htop" + }, + { + "type": "WEB", + "url": "http://htop.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json b/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json new file mode 100644 index 00000000000..bf735d4fb32 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6hp-rq22-2f6w", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37350" + ], + "details": "There is a cross-site scripting vulnerability in the policy\nmanagement UI of Absolute Secure Access prior to version 13.06. Attackers can\ninterfere with a system administrator’s use of the policy management UI when\nthe attacker convinces the victim administrator to follow a crafted link to the\nvulnerable component while the attacking administrator is authenticated to the\nconsole. The scope is unchanged, there is no loss of confidentiality. Impact to\nsystem integrity is high, impact to system availability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37350" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json b/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json index 540224b3325..b878e26e524 100644 --- a/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json +++ b/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qh49-g58p-8272/GHSA-qh49-g58p-8272.json b/advisories/unreviewed/2024/06/GHSA-qh49-g58p-8272/GHSA-qh49-g58p-8272.json new file mode 100644 index 00000000000..09fa4dbac37 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qh49-g58p-8272/GHSA-qh49-g58p-8272.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh49-g58p-8272", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37343" + ], + "details": "There is a cross-site scripting vulnerability in the Secure\nAccess administrative console of Absolute Secure Access prior to version 13.06.\nAttackers with valid tunnel credentials can pass a limited-length script to the\nadministrative console which is then temporarily stored where an administrator\nusing a non-default configuration could click on it while the attacker has a\nvalid tunnel session with the server. The scope is unchanged, there is no loss\nof confidentiality. Impact to system availability is none, impact to system\nintegrity is high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37343" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json b/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json new file mode 100644 index 00000000000..0316def10cc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcq4-qh6m-j28q", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-33335" + ], + "details": "SQL Injection vulnerability in H3C SeaSQL DWS v.2.0 allows a remote attacker to execute arbitrary code via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33335" + }, + { + "type": "WEB", + "url": "https://gist.github.com/vrhappy/08cb4c8721eed8a74fe786ecdff1ec1e" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wjj3-3mvj-p68r/GHSA-wjj3-3mvj-p68r.json b/advisories/unreviewed/2024/06/GHSA-wjj3-3mvj-p68r/GHSA-wjj3-3mvj-p68r.json new file mode 100644 index 00000000000..bce906e9736 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wjj3-3mvj-p68r/GHSA-wjj3-3mvj-p68r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjj3-3mvj-p68r", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-6196" + ], + "details": "A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269168.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6196" + }, + { + "type": "WEB", + "url": "https://github.com/2768210355/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269168" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269168" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wv2m-x4pc-hcv2/GHSA-wv2m-x4pc-hcv2.json b/advisories/unreviewed/2024/06/GHSA-wv2m-x4pc-hcv2/GHSA-wv2m-x4pc-hcv2.json new file mode 100644 index 00000000000..058aa744cdd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wv2m-x4pc-hcv2/GHSA-wv2m-x4pc-hcv2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv2m-x4pc-hcv2", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-6193" + ], + "details": "A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file driverprofile.php. The manipulation of the argument driverid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269165 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6193" + }, + { + "type": "WEB", + "url": "https://github.com/HryspaHodor/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json b/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json new file mode 100644 index 00000000000..1465f721244 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxxx-g5q4-gvrr", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37344" + ], + "details": "There is a cross-site scripting vulnerability in the Policy\nmanagement UI of Absolute Secure Access prior to version 13.06. Attackers with\nsystem administrator permissions can interfere with another system\nadministrator’s use of the policy management UI when the administrators are\nediting the same policy object. The scope is unchanged, there is no loss of\nconfidentiality. Impact to system availability is none, impact to system\nintegrity is high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37344" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37344" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x7mw-vv25-68cr/GHSA-x7mw-vv25-68cr.json b/advisories/unreviewed/2024/06/GHSA-x7mw-vv25-68cr/GHSA-x7mw-vv25-68cr.json new file mode 100644 index 00000000000..b80ede066e0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x7mw-vv25-68cr/GHSA-x7mw-vv25-68cr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7mw-vv25-68cr", + "modified": "2024-06-20T18:34:08Z", + "published": "2024-06-20T18:34:08Z", + "aliases": [ + "CVE-2024-6195" + ], + "details": "A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file orderadd.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269167.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6195" + }, + { + "type": "WEB", + "url": "https://github.com/2768210355/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json b/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json new file mode 100644 index 00000000000..ead6eb65db0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x9fg-8gx4-j4x2/GHSA-x9fg-8gx4-j4x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9fg-8gx4-j4x2", + "modified": "2024-06-20T18:34:09Z", + "published": "2024-06-20T18:34:09Z", + "aliases": [ + "CVE-2024-37348" + ], + "details": "There is a cross-site\nscripting vulnerability in the management UI of Absolute Secure Access prior to\nversion 13.06. Attackers with system administrator permissions can interfere\nwith another system administrator’s use of the management UI when the second\nadministrator later edits the same management object. This vulnerability is\ndistinct from CVE-2024-37349 and CVE-2024-37351. The scope is unchanged,\nthere is no loss of confidentiality. Impact to system integrity is high, impact\nto system availability is none.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37348" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T17:15:52Z" + } +} \ No newline at end of file