Publish Advisories

GHSA-hqmw-gvh2-3w2v
GHSA-248p-qmc2-qc97
GHSA-67p8-jrm8-g765
GHSA-9338-v6x4-3wv5
GHSA-9vq2-24jp-74ch
GHSA-9w72-8p6g-p73f
GHSA-c473-9ccp-22gc
GHSA-cqg5-mcpx-q78p
GHSA-f69p-5x38-xrmw
GHSA-fmp7-6783-4ggp
GHSA-j658-fjmg-478v
GHSA-qh69-9h65-cjx9
GHSA-r24r-m7ff-ghq2
GHSA-rj28-pp8g-vc2r
GHSA-rw28-wf4m-hxpv
GHSA-rxw3-jm8w-c989
This commit is contained in:
advisory-database[bot]
2024-06-26 15:32:33 +00:00
parent d5cb80de5b
commit c7f2b4d3a1
16 changed files with 181 additions and 37 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqmw-gvh2-3w2v",
"modified": "2022-05-17T00:01:19Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2022-05-07T00:00:37Z",
"aliases": [
"CVE-2022-29420"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-248p-qmc2-qc97",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-26T15:31:01Z",
"aliases": [
"CVE-2024-4604"
],
"details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4604"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-0800"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T15:15:20Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67p8-jrm8-g765",
"modified": "2024-06-25T21:31:16Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-25T21:31:16Z",
"aliases": [
"CVE-2024-5011"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.progress.com/network-monitoring"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1934"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9338-v6x4-3wv5",
"modified": "2024-06-24T15:31:45Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T15:31:45Z",
"aliases": [
"CVE-2024-39292"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\num: Add winch to winch_handlers before registering winch IRQ\n\nRegistering a winch IRQ is racy, an interrupt may occur before the winch is\nadded to the winch_handlers list.\n\nIf that happens, register_winch_irq() adds to that list a winch that is\nscheduled to be (or has already been) freed, causing a panic later in\nwinch_cleanup().\n\nAvoid the race by adding the winch to the winch_handlers list before\nregistering the IRQ, and rolling back if um_request_irq() fails.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-415"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T14:15:12Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vq2-24jp-74ch",
"modified": "2024-06-24T15:31:45Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T15:31:45Z",
"aliases": [
"CVE-2024-33687"
],
"details": "Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-345"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T15:15:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w72-8p6g-p73f",
"modified": "2024-06-24T18:31:37Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T18:31:37Z",
"aliases": [
"CVE-2024-33880"
],
"details": "An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T17:15:10Z"
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c473-9ccp-22gc",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-26T15:31:01Z",
"aliases": [
"CVE-2024-6349"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6349"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T15:15:20Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqg5-mcpx-q78p",
"modified": "2024-06-24T15:31:45Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T15:31:45Z",
"aliases": [
"CVE-2024-38667"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: prevent pt_regs corruption for secondary idle threads\n\nTop of the kernel thread stack should be reserved for pt_regs. However\nthis is not the case for the idle threads of the secondary boot harts.\nTheir stacks overlap with their pt_regs, so both may get corrupted.\n\nSimilar issue has been fixed for the primary hart, see c7cdd96eca28\n(\"riscv: prevent stack corruption by reserving task_pt_regs(p) early\").\nHowever that fix was not propagated to the secondary harts. The problem\nhas been noticed in some CPU hotplug tests with V enabled. The function\nsmp_callin stored several registers on stack, corrupting top of pt_regs\nstructure including status field. As a result, kernel attempted to save\nor restore inexistent V context.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T14:15:12Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f69p-5x38-xrmw",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-26T15:31:01Z",
"aliases": [
"CVE-2024-4228"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability in Magarsus Consultancy SSO (Single Sign On) allows SQL Injection.This issue affects SSO (Single Sign On): from 1.0 before 1.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4228"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-0800"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T15:15:19Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmp7-6783-4ggp",
"modified": "2024-06-24T15:31:45Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T15:31:45Z",
"aliases": [
"CVE-2024-4748"
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
"CWE-77",
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
File diff suppressed because one or more lines are too long
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qh69-9h65-cjx9",
"modified": "2024-06-24T18:31:36Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T18:31:36Z",
"aliases": [
"CVE-2024-33879"
],
"details": "An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T17:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r24r-m7ff-ghq2",
"modified": "2024-06-24T18:31:37Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-24T18:31:37Z",
"aliases": [
"CVE-2024-33881"
],
"details": "An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T17:15:10Z"
File diff suppressed because one or more lines are too long
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rw28-wf4m-hxpv",
"modified": "2024-06-25T21:31:16Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-25T21:31:16Z",
"aliases": [
"CVE-2024-5010"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.progress.com/network-monitoring"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1933"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rxw3-jm8w-c989",
"modified": "2024-06-25T21:31:18Z",
"modified": "2024-06-26T15:31:01Z",
"published": "2024-06-25T21:31:18Z",
"aliases": [
"CVE-2024-5017"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.progress.com/network-monitoring"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1932"
}
],
"database_specific": {