From c9d14d4ed394c5d6b56de9770294b7828ec6720f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 6 Nov 2024 15:31:47 +0000 Subject: [PATCH] Publish Advisories GHSA-5qvm-gfmw-9v64 GHSA-3m9q-xm72-wq62 GHSA-43xj-7j8x-m26r GHSA-4p4c-mrm8-gxcm GHSA-4r9c-ghcc-8xqw GHSA-6cgw-73x3-c2h9 GHSA-87qj-78xh-hx94 GHSA-953x-6wwg-wcxg GHSA-ch3r-qc65-hpfh GHSA-cvc7-ww7g-w56m GHSA-fj2w-q5f7-w82f GHSA-g66q-8cf5-g99m GHSA-hhh3-584m-qjr8 GHSA-hqxp-2xfg-g9qc GHSA-pfp9-w5f6-rg7c GHSA-q5h7-2qmh-rxhr GHSA-qp96-9hxv-3xx4 GHSA-rjw7-rc53-vqr5 GHSA-w47v-2qj7-9m4m GHSA-w5jc-xfq4-97p3 --- .../GHSA-5qvm-gfmw-9v64.json | 2 +- .../GHSA-3m9q-xm72-wq62.json | 38 ++++++++++++ .../GHSA-43xj-7j8x-m26r.json | 3 +- .../GHSA-4p4c-mrm8-gxcm.json | 2 +- .../GHSA-4r9c-ghcc-8xqw.json | 3 +- .../GHSA-6cgw-73x3-c2h9.json | 58 +++++++++++++++++++ .../GHSA-87qj-78xh-hx94.json | 3 +- .../GHSA-953x-6wwg-wcxg.json | 3 +- .../GHSA-ch3r-qc65-hpfh.json | 3 +- .../GHSA-cvc7-ww7g-w56m.json | 3 +- .../GHSA-fj2w-q5f7-w82f.json | 58 +++++++++++++++++++ .../GHSA-g66q-8cf5-g99m.json | 3 +- .../GHSA-hhh3-584m-qjr8.json | 3 +- .../GHSA-hqxp-2xfg-g9qc.json | 46 +++++++++++++++ .../GHSA-pfp9-w5f6-rg7c.json | 3 +- .../GHSA-q5h7-2qmh-rxhr.json | 54 +++++++++++++++++ .../GHSA-qp96-9hxv-3xx4.json | 58 +++++++++++++++++++ .../GHSA-rjw7-rc53-vqr5.json | 38 ++++++++++++ .../GHSA-w47v-2qj7-9m4m.json | 3 +- .../GHSA-w5jc-xfq4-97p3.json | 3 +- 20 files changed, 374 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3m9q-xm72-wq62/GHSA-3m9q-xm72-wq62.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6cgw-73x3-c2h9/GHSA-6cgw-73x3-c2h9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fj2w-q5f7-w82f/GHSA-fj2w-q5f7-w82f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hqxp-2xfg-g9qc/GHSA-hqxp-2xfg-g9qc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q5h7-2qmh-rxhr/GHSA-q5h7-2qmh-rxhr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rjw7-rc53-vqr5/GHSA-rjw7-rc53-vqr5.json diff --git a/advisories/unreviewed/2023/11/GHSA-5qvm-gfmw-9v64/GHSA-5qvm-gfmw-9v64.json b/advisories/unreviewed/2023/11/GHSA-5qvm-gfmw-9v64/GHSA-5qvm-gfmw-9v64.json index ca2c0be4f2e..9674343765c 100644 --- a/advisories/unreviewed/2023/11/GHSA-5qvm-gfmw-9v64/GHSA-5qvm-gfmw-9v64.json +++ b/advisories/unreviewed/2023/11/GHSA-5qvm-gfmw-9v64/GHSA-5qvm-gfmw-9v64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qvm-gfmw-9v64", - "modified": "2023-11-03T09:32:49Z", + "modified": "2024-11-06T15:30:38Z", "published": "2023-11-03T09:32:49Z", "aliases": [ "CVE-2023-42670" diff --git a/advisories/unreviewed/2024/11/GHSA-3m9q-xm72-wq62/GHSA-3m9q-xm72-wq62.json b/advisories/unreviewed/2024/11/GHSA-3m9q-xm72-wq62/GHSA-3m9q-xm72-wq62.json new file mode 100644 index 00000000000..0faabd5c24b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3m9q-xm72-wq62/GHSA-3m9q-xm72-wq62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m9q-xm72-wq62", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2020-11859" + ], + "details": "Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11859" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/imanager-32/imanager323_releasenotes/data/imanager323_releasenotes.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-43xj-7j8x-m26r/GHSA-43xj-7j8x-m26r.json b/advisories/unreviewed/2024/11/GHSA-43xj-7j8x-m26r/GHSA-43xj-7j8x-m26r.json index bba55c87d16..48c113d4838 100644 --- a/advisories/unreviewed/2024/11/GHSA-43xj-7j8x-m26r/GHSA-43xj-7j8x-m26r.json +++ b/advisories/unreviewed/2024/11/GHSA-43xj-7j8x-m26r/GHSA-43xj-7j8x-m26r.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4p4c-mrm8-gxcm/GHSA-4p4c-mrm8-gxcm.json b/advisories/unreviewed/2024/11/GHSA-4p4c-mrm8-gxcm/GHSA-4p4c-mrm8-gxcm.json index 3cb6c9d04de..d8732552eb4 100644 --- a/advisories/unreviewed/2024/11/GHSA-4p4c-mrm8-gxcm/GHSA-4p4c-mrm8-gxcm.json +++ b/advisories/unreviewed/2024/11/GHSA-4p4c-mrm8-gxcm/GHSA-4p4c-mrm8-gxcm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p4c-mrm8-gxcm", - "modified": "2024-11-05T06:30:34Z", + "modified": "2024-11-06T15:30:39Z", "published": "2024-11-05T06:30:34Z", "aliases": [ "CVE-2024-9459" diff --git a/advisories/unreviewed/2024/11/GHSA-4r9c-ghcc-8xqw/GHSA-4r9c-ghcc-8xqw.json b/advisories/unreviewed/2024/11/GHSA-4r9c-ghcc-8xqw/GHSA-4r9c-ghcc-8xqw.json index a3ac8c09759..1cb3b09b1db 100644 --- a/advisories/unreviewed/2024/11/GHSA-4r9c-ghcc-8xqw/GHSA-4r9c-ghcc-8xqw.json +++ b/advisories/unreviewed/2024/11/GHSA-4r9c-ghcc-8xqw/GHSA-4r9c-ghcc-8xqw.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-6cgw-73x3-c2h9/GHSA-6cgw-73x3-c2h9.json b/advisories/unreviewed/2024/11/GHSA-6cgw-73x3-c2h9/GHSA-6cgw-73x3-c2h9.json new file mode 100644 index 00000000000..6960e18dc2f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6cgw-73x3-c2h9/GHSA-6cgw-73x3-c2h9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cgw-73x3-c2h9", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-10915" + ], + "details": "A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10915" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Command-Injection-Vulnerability-in-group-parameter-for-D-Link-NAS-12d6b683e67c803fa1a0c0d236c9a4c5?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283310" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283310" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432848" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-707" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-87qj-78xh-hx94/GHSA-87qj-78xh-hx94.json b/advisories/unreviewed/2024/11/GHSA-87qj-78xh-hx94/GHSA-87qj-78xh-hx94.json index 7877b7fa762..a8691889497 100644 --- a/advisories/unreviewed/2024/11/GHSA-87qj-78xh-hx94/GHSA-87qj-78xh-hx94.json +++ b/advisories/unreviewed/2024/11/GHSA-87qj-78xh-hx94/GHSA-87qj-78xh-hx94.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-953x-6wwg-wcxg/GHSA-953x-6wwg-wcxg.json b/advisories/unreviewed/2024/11/GHSA-953x-6wwg-wcxg/GHSA-953x-6wwg-wcxg.json index 50132a2f1f6..11f8893aaaf 100644 --- a/advisories/unreviewed/2024/11/GHSA-953x-6wwg-wcxg/GHSA-953x-6wwg-wcxg.json +++ b/advisories/unreviewed/2024/11/GHSA-953x-6wwg-wcxg/GHSA-953x-6wwg-wcxg.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json b/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json index 76d31db475c..ac74c889ae5 100644 --- a/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json +++ b/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1394" + "CWE-1394", + "CWE-798" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cvc7-ww7g-w56m/GHSA-cvc7-ww7g-w56m.json b/advisories/unreviewed/2024/11/GHSA-cvc7-ww7g-w56m/GHSA-cvc7-ww7g-w56m.json index 50d303aecc7..0fe6181585d 100644 --- a/advisories/unreviewed/2024/11/GHSA-cvc7-ww7g-w56m/GHSA-cvc7-ww7g-w56m.json +++ b/advisories/unreviewed/2024/11/GHSA-cvc7-ww7g-w56m/GHSA-cvc7-ww7g-w56m.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-fj2w-q5f7-w82f/GHSA-fj2w-q5f7-w82f.json b/advisories/unreviewed/2024/11/GHSA-fj2w-q5f7-w82f/GHSA-fj2w-q5f7-w82f.json new file mode 100644 index 00000000000..0f913ab75b4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fj2w-q5f7-w82f/GHSA-fj2w-q5f7-w82f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2w-q5f7-w82f", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-10916" + ], + "details": "A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10916" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Information-Disclosure-Vulnerability-Report-in-xml-info-xml-for-D-Link-NAS-12d6b683e67c8019a311e699582f51b6?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283311" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283311" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432849" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g66q-8cf5-g99m/GHSA-g66q-8cf5-g99m.json b/advisories/unreviewed/2024/11/GHSA-g66q-8cf5-g99m/GHSA-g66q-8cf5-g99m.json index 67a462094b2..c0bdc79a944 100644 --- a/advisories/unreviewed/2024/11/GHSA-g66q-8cf5-g99m/GHSA-g66q-8cf5-g99m.json +++ b/advisories/unreviewed/2024/11/GHSA-g66q-8cf5-g99m/GHSA-g66q-8cf5-g99m.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hhh3-584m-qjr8/GHSA-hhh3-584m-qjr8.json b/advisories/unreviewed/2024/11/GHSA-hhh3-584m-qjr8/GHSA-hhh3-584m-qjr8.json index cb77349b46e..c0634185ba2 100644 --- a/advisories/unreviewed/2024/11/GHSA-hhh3-584m-qjr8/GHSA-hhh3-584m-qjr8.json +++ b/advisories/unreviewed/2024/11/GHSA-hhh3-584m-qjr8/GHSA-hhh3-584m-qjr8.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hqxp-2xfg-g9qc/GHSA-hqxp-2xfg-g9qc.json b/advisories/unreviewed/2024/11/GHSA-hqxp-2xfg-g9qc/GHSA-hqxp-2xfg-g9qc.json new file mode 100644 index 00000000000..4116614ec2c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hqxp-2xfg-g9qc/GHSA-hqxp-2xfg-g9qc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqxp-2xfg-g9qc", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-10186" + ], + "details": "The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10186" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3182549" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/event-post/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f3ae1c32-18a7-4109-a7ea-dfd18fa3a8e2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pfp9-w5f6-rg7c/GHSA-pfp9-w5f6-rg7c.json b/advisories/unreviewed/2024/11/GHSA-pfp9-w5f6-rg7c/GHSA-pfp9-w5f6-rg7c.json index 629d2cc610b..16bf3a801f7 100644 --- a/advisories/unreviewed/2024/11/GHSA-pfp9-w5f6-rg7c/GHSA-pfp9-w5f6-rg7c.json +++ b/advisories/unreviewed/2024/11/GHSA-pfp9-w5f6-rg7c/GHSA-pfp9-w5f6-rg7c.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-q5h7-2qmh-rxhr/GHSA-q5h7-2qmh-rxhr.json b/advisories/unreviewed/2024/11/GHSA-q5h7-2qmh-rxhr/GHSA-q5h7-2qmh-rxhr.json new file mode 100644 index 00000000000..36e60c6ee75 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q5h7-2qmh-rxhr/GHSA-q5h7-2qmh-rxhr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5h7-2qmh-rxhr", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-6861" + ], + "details": "A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2022:8506" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6861" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317450" + }, + { + "type": "WEB", + "url": "https://docs.theforeman.org/3.3/Release_Notes/index-katello.html#_foreman_2" + }, + { + "type": "WEB", + "url": "https://projects.theforeman.org/issues/34328" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json b/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json new file mode 100644 index 00000000000..dbb26c50a8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp96-9hxv-3xx4", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-10914" + ], + "details": "A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10914" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283309" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283309" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432847" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-707" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rjw7-rc53-vqr5/GHSA-rjw7-rc53-vqr5.json b/advisories/unreviewed/2024/11/GHSA-rjw7-rc53-vqr5/GHSA-rjw7-rc53-vqr5.json new file mode 100644 index 00000000000..1cacdbed9a6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rjw7-rc53-vqr5/GHSA-rjw7-rc53-vqr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjw7-rc53-vqr5", + "modified": "2024-11-06T15:30:40Z", + "published": "2024-11-06T15:30:40Z", + "aliases": [ + "CVE-2024-35146" + ], + "details": "IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35146" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174946" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w47v-2qj7-9m4m/GHSA-w47v-2qj7-9m4m.json b/advisories/unreviewed/2024/11/GHSA-w47v-2qj7-9m4m/GHSA-w47v-2qj7-9m4m.json index fc72efea1f4..890c29540aa 100644 --- a/advisories/unreviewed/2024/11/GHSA-w47v-2qj7-9m4m/GHSA-w47v-2qj7-9m4m.json +++ b/advisories/unreviewed/2024/11/GHSA-w47v-2qj7-9m4m/GHSA-w47v-2qj7-9m4m.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-w5jc-xfq4-97p3/GHSA-w5jc-xfq4-97p3.json b/advisories/unreviewed/2024/11/GHSA-w5jc-xfq4-97p3/GHSA-w5jc-xfq4-97p3.json index 90c90172136..06fa5f402a0 100644 --- a/advisories/unreviewed/2024/11/GHSA-w5jc-xfq4-97p3/GHSA-w5jc-xfq4-97p3.json +++ b/advisories/unreviewed/2024/11/GHSA-w5jc-xfq4-97p3/GHSA-w5jc-xfq4-97p3.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,