From ca62fbddeb714f13f0fc7a2110c79fea693f8eba Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 12:33:15 +0000 Subject: [PATCH] Publish Advisories GHSA-vmq6-5m68-f53m GHSA-9gp8-6cg8-7h34 GHSA-9442-gm4v-r222 GHSA-4gc7-5j7h-4qph GHSA-9mq2-v988-m7mr GHSA-fp86-2355-v99r GHSA-3q6h-q44p-xw88 GHSA-6v7c-pq5w-2jwg GHSA-w9cc-xrp8-ffx4 GHSA-45cm-4v3w-5jpw GHSA-x3h8-3mf2-v794 GHSA-2r3m-26p3-wr26 GHSA-3qm6-wcp5-fx9f GHSA-773m-x37x-96wr GHSA-88vw-p4cx-4677 GHSA-f63f-f9wj-5wjg GHSA-fr2x-xwp6-rg7p GHSA-g6j3-5m8r-7p3c GHSA-rwv8-hfhp-fj52 GHSA-whhw-2v2c-qg98 GHSA-xhf4-qqf8-2pw6 --- .../GHSA-vmq6-5m68-f53m.json | 6 ++- .../GHSA-9gp8-6cg8-7h34.json | 6 ++- .../GHSA-9442-gm4v-r222.json | 6 ++- .../GHSA-4gc7-5j7h-4qph.json | 6 ++- .../GHSA-9mq2-v988-m7mr.json | 22 ++++++++-- .../GHSA-fp86-2355-v99r.json | 6 ++- .../GHSA-3q6h-q44p-xw88.json | 10 +++-- .../GHSA-6v7c-pq5w-2jwg.json | 10 +++-- .../GHSA-w9cc-xrp8-ffx4.json | 10 +++-- .../GHSA-45cm-4v3w-5jpw.json | 22 +++++----- .../GHSA-x3h8-3mf2-v794.json | 14 +++---- .../GHSA-2r3m-26p3-wr26.json | 40 +++++++++++++++++++ .../GHSA-3qm6-wcp5-fx9f.json | 36 +++++++++++++++++ .../GHSA-773m-x37x-96wr.json | 36 +++++++++++++++++ .../GHSA-88vw-p4cx-4677.json | 40 +++++++++++++++++++ .../GHSA-f63f-f9wj-5wjg.json | 36 +++++++++++++++++ .../GHSA-fr2x-xwp6-rg7p.json | 36 +++++++++++++++++ .../GHSA-g6j3-5m8r-7p3c.json | 40 +++++++++++++++++++ .../GHSA-rwv8-hfhp-fj52.json | 40 +++++++++++++++++++ .../GHSA-whhw-2v2c-qg98.json | 36 +++++++++++++++++ .../GHSA-xhf4-qqf8-2pw6.json | 36 +++++++++++++++++ 21 files changed, 456 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2r3m-26p3-wr26/GHSA-2r3m-26p3-wr26.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3qm6-wcp5-fx9f/GHSA-3qm6-wcp5-fx9f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-773m-x37x-96wr/GHSA-773m-x37x-96wr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-88vw-p4cx-4677/GHSA-88vw-p4cx-4677.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fr2x-xwp6-rg7p/GHSA-fr2x-xwp6-rg7p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g6j3-5m8r-7p3c/GHSA-g6j3-5m8r-7p3c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rwv8-hfhp-fj52/GHSA-rwv8-hfhp-fj52.json create mode 100644 advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xhf4-qqf8-2pw6/GHSA-xhf4-qqf8-2pw6.json diff --git a/advisories/github-reviewed/2023/11/GHSA-vmq6-5m68-f53m/GHSA-vmq6-5m68-f53m.json b/advisories/github-reviewed/2023/11/GHSA-vmq6-5m68-f53m/GHSA-vmq6-5m68-f53m.json index aeeca8f595b..bd8e14c10d7 100644 --- a/advisories/github-reviewed/2023/11/GHSA-vmq6-5m68-f53m/GHSA-vmq6-5m68-f53m.json +++ b/advisories/github-reviewed/2023/11/GHSA-vmq6-5m68-f53m/GHSA-vmq6-5m68-f53m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vmq6-5m68-f53m", - "modified": "2023-12-05T21:31:10Z", + "modified": "2024-11-29T12:31:48Z", "published": "2023-11-29T12:30:16Z", "aliases": [ "CVE-2023-6378" @@ -166,6 +166,10 @@ { "type": "WEB", "url": "https://logback.qos.ch/news.html#1.3.12" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0012" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-9gp8-6cg8-7h34/GHSA-9gp8-6cg8-7h34.json b/advisories/github-reviewed/2024/02/GHSA-9gp8-6cg8-7h34/GHSA-9gp8-6cg8-7h34.json index aaf8244cf30..4e9740da743 100644 --- a/advisories/github-reviewed/2024/02/GHSA-9gp8-6cg8-7h34/GHSA-9gp8-6cg8-7h34.json +++ b/advisories/github-reviewed/2024/02/GHSA-9gp8-6cg8-7h34/GHSA-9gp8-6cg8-7h34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gp8-6cg8-7h34", - "modified": "2024-02-12T21:34:32Z", + "modified": "2024-11-29T12:31:48Z", "published": "2024-02-06T00:30:25Z", "aliases": [ "CVE-2023-34042" @@ -117,6 +117,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0010" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2023-34042" diff --git a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json index 6c89d75d51e..334dcc907c8 100644 --- a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json +++ b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9442-gm4v-r222", - "modified": "2024-10-17T14:08:20Z", + "modified": "2024-11-29T12:31:48Z", "published": "2024-06-20T15:31:19Z", "aliases": [ "CVE-2024-6162" @@ -109,6 +109,10 @@ { "type": "WEB", "url": "https://issues.redhat.com/browse/UNDERTOW-2334" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0009" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-4gc7-5j7h-4qph/GHSA-4gc7-5j7h-4qph.json b/advisories/github-reviewed/2024/10/GHSA-4gc7-5j7h-4qph/GHSA-4gc7-5j7h-4qph.json index 91ca1a81238..77974471793 100644 --- a/advisories/github-reviewed/2024/10/GHSA-4gc7-5j7h-4qph/GHSA-4gc7-5j7h-4qph.json +++ b/advisories/github-reviewed/2024/10/GHSA-4gc7-5j7h-4qph/GHSA-4gc7-5j7h-4qph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gc7-5j7h-4qph", - "modified": "2024-11-05T22:01:57Z", + "modified": "2024-11-29T12:31:48Z", "published": "2024-10-18T06:30:32Z", "aliases": [ "CVE-2024-38820" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/spring-projects/spring-framework/commits/v6.2.0-RC2" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0003" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38820" diff --git a/advisories/unreviewed/2022/09/GHSA-9mq2-v988-m7mr/GHSA-9mq2-v988-m7mr.json b/advisories/unreviewed/2022/09/GHSA-9mq2-v988-m7mr/GHSA-9mq2-v988-m7mr.json index 6266dc60358..41825ce47a7 100644 --- a/advisories/unreviewed/2022/09/GHSA-9mq2-v988-m7mr/GHSA-9mq2-v988-m7mr.json +++ b/advisories/unreviewed/2022/09/GHSA-9mq2-v988-m7mr/GHSA-9mq2-v988-m7mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mq2-v988-m7mr", - "modified": "2022-09-25T00:00:26Z", + "modified": "2024-11-29T12:31:47Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-2795" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" @@ -45,6 +55,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202210-25" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0002" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5235" diff --git a/advisories/unreviewed/2023/04/GHSA-fp86-2355-v99r/GHSA-fp86-2355-v99r.json b/advisories/unreviewed/2023/04/GHSA-fp86-2355-v99r/GHSA-fp86-2355-v99r.json index 9cf18972ec1..edd61deca22 100644 --- a/advisories/unreviewed/2023/04/GHSA-fp86-2355-v99r/GHSA-fp86-2355-v99r.json +++ b/advisories/unreviewed/2023/04/GHSA-fp86-2355-v99r/GHSA-fp86-2355-v99r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp86-2355-v99r", - "modified": "2023-04-13T21:30:27Z", + "modified": "2024-11-29T12:31:47Z", "published": "2023-04-06T18:30:21Z", "aliases": [ "CVE-2023-24537" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json b/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json index a3fd7a9eab0..964c6c308f9 100644 --- a/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json +++ b/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q6h-q44p-xw88", - "modified": "2024-04-04T04:02:36Z", + "modified": "2024-11-29T12:31:47Z", "published": "2023-05-11T18:30:17Z", "aliases": [ "CVE-2023-24539" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,6 +34,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-1751" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-6v7c-pq5w-2jwg/GHSA-6v7c-pq5w-2jwg.json b/advisories/unreviewed/2023/05/GHSA-6v7c-pq5w-2jwg/GHSA-6v7c-pq5w-2jwg.json index 88f7a045a33..e9e002fa64d 100644 --- a/advisories/unreviewed/2023/05/GHSA-6v7c-pq5w-2jwg/GHSA-6v7c-pq5w-2jwg.json +++ b/advisories/unreviewed/2023/05/GHSA-6v7c-pq5w-2jwg/GHSA-6v7c-pq5w-2jwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v7c-pq5w-2jwg", - "modified": "2023-05-10T00:30:16Z", + "modified": "2024-11-29T12:31:47Z", "published": "2023-05-10T00:30:16Z", "aliases": [ "CVE-2023-2610" @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -41,6 +39,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0006" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT213844" diff --git a/advisories/unreviewed/2023/08/GHSA-w9cc-xrp8-ffx4/GHSA-w9cc-xrp8-ffx4.json b/advisories/unreviewed/2023/08/GHSA-w9cc-xrp8-ffx4/GHSA-w9cc-xrp8-ffx4.json index ff6b8e43863..2c86589d689 100644 --- a/advisories/unreviewed/2023/08/GHSA-w9cc-xrp8-ffx4/GHSA-w9cc-xrp8-ffx4.json +++ b/advisories/unreviewed/2023/08/GHSA-w9cc-xrp8-ffx4/GHSA-w9cc-xrp8-ffx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9cc-xrp8-ffx4", - "modified": "2024-04-04T07:08:10Z", + "modified": "2024-11-29T12:31:47Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2022-48174" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,6 +22,10 @@ { "type": "WEB", "url": "https://bugs.busybox.net/show_bug.cgi?id=15216" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-45cm-4v3w-5jpw/GHSA-45cm-4v3w-5jpw.json b/advisories/unreviewed/2024/05/GHSA-45cm-4v3w-5jpw/GHSA-45cm-4v3w-5jpw.json index 5ca03422ce9..55019fbd330 100644 --- a/advisories/unreviewed/2024/05/GHSA-45cm-4v3w-5jpw/GHSA-45cm-4v3w-5jpw.json +++ b/advisories/unreviewed/2024/05/GHSA-45cm-4v3w-5jpw/GHSA-45cm-4v3w-5jpw.json @@ -1,18 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-45cm-4v3w-5jpw", - "modified": "2024-06-27T15:30:38Z", + "modified": "2024-11-29T12:31:48Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27398" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix use-after-free bugs caused by sco_sock_timeout\n\nWhen the sco connection is established and then, the sco socket\nis releasing, timeout_work will be scheduled to judge whether\nthe sco disconnection is timeout. The sock will be deallocated\nlater, but it is dereferenced again in sco_sock_timeout. As a\nresult, the use-after-free bugs will happen. The root cause is\nshown below:\n\n Cleanup Thread | Worker Thread\nsco_sock_release |\n sco_sock_close |\n __sco_sock_close |\n sco_sock_set_timer |\n schedule_delayed_work |\n sco_sock_kill | (wait a time)\n sock_put(sk) //FREE | sco_sock_timeout\n | sock_hold(sk) //USE\n\nThe KASAN report triggered by POC is shown below:\n\n[ 95.890016] ==================================================================\n[ 95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0\n[ 95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7\n...\n[ 95.890755] Workqueue: events sco_sock_timeout\n[ 95.890755] Call Trace:\n[ 95.890755] \n[ 95.890755] dump_stack_lvl+0x45/0x110\n[ 95.890755] print_address_description+0x78/0x390\n[ 95.890755] print_report+0x11b/0x250\n[ 95.890755] ? __virt_addr_valid+0xbe/0xf0\n[ 95.890755] ? sco_sock_timeout+0x5e/0x1c0\n[ 95.890755] kasan_report+0x139/0x170\n[ 95.890755] ? update_load_avg+0xe5/0x9f0\n[ 95.890755] ? sco_sock_timeout+0x5e/0x1c0\n[ 95.890755] kasan_check_range+0x2c3/0x2e0\n[ 95.890755] sco_sock_timeout+0x5e/0x1c0\n[ 95.890755] process_one_work+0x561/0xc50\n[ 95.890755] worker_thread+0xab2/0x13c0\n[ 95.890755] ? pr_cont_work+0x490/0x490\n[ 95.890755] kthread+0x279/0x300\n[ 95.890755] ? pr_cont_work+0x490/0x490\n[ 95.890755] ? kthread_blkcg+0xa0/0xa0\n[ 95.890755] ret_from_fork+0x34/0x60\n[ 95.890755] ? kthread_blkcg+0xa0/0xa0\n[ 95.890755] ret_from_fork_asm+0x11/0x20\n[ 95.890755] \n[ 95.890755]\n[ 95.890755] Allocated by task 506:\n[ 95.890755] kasan_save_track+0x3f/0x70\n[ 95.890755] __kasan_kmalloc+0x86/0x90\n[ 95.890755] __kmalloc+0x17f/0x360\n[ 95.890755] sk_prot_alloc+0xe1/0x1a0\n[ 95.890755] sk_alloc+0x31/0x4e0\n[ 95.890755] bt_sock_alloc+0x2b/0x2a0\n[ 95.890755] sco_sock_create+0xad/0x320\n[ 95.890755] bt_sock_create+0x145/0x320\n[ 95.890755] __sock_create+0x2e1/0x650\n[ 95.890755] __sys_socket+0xd0/0x280\n[ 95.890755] __x64_sys_socket+0x75/0x80\n[ 95.890755] do_syscall_64+0xc4/0x1b0\n[ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f\n[ 95.890755]\n[ 95.890755] Freed by task 506:\n[ 95.890755] kasan_save_track+0x3f/0x70\n[ 95.890755] kasan_save_free_info+0x40/0x50\n[ 95.890755] poison_slab_object+0x118/0x180\n[ 95.890755] __kasan_slab_free+0x12/0x30\n[ 95.890755] kfree+0xb2/0x240\n[ 95.890755] __sk_destruct+0x317/0x410\n[ 95.890755] sco_sock_release+0x232/0x280\n[ 95.890755] sock_close+0xb2/0x210\n[ 95.890755] __fput+0x37f/0x770\n[ 95.890755] task_work_run+0x1ae/0x210\n[ 95.890755] get_signal+0xe17/0xf70\n[ 95.890755] arch_do_signal_or_restart+0x3f/0x520\n[ 95.890755] syscall_exit_to_user_mode+0x55/0x120\n[ 95.890755] do_syscall_64+0xd1/0x1b0\n[ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f\n[ 95.890755]\n[ 95.890755] The buggy address belongs to the object at ffff88800c388000\n[ 95.890755] which belongs to the cache kmalloc-1k of size 1024\n[ 95.890755] The buggy address is located 128 bytes inside of\n[ 95.890755] freed 1024-byte region [ffff88800c388000, ffff88800c388400)\n[ 95.890755]\n[ 95.890755] The buggy address belongs to the physical page:\n[ 95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388\n[ 95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n[ 95.890755] ano\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -65,12 +61,18 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OTB4HWU2PTVW5NEYHHLOCXDKG3PYA534" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240912-0012" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/29/1" } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-x3h8-3mf2-v794/GHSA-x3h8-3mf2-v794.json b/advisories/unreviewed/2024/07/GHSA-x3h8-3mf2-v794/GHSA-x3h8-3mf2-v794.json index 9eab5523895..283a27c7747 100644 --- a/advisories/unreviewed/2024/07/GHSA-x3h8-3mf2-v794/GHSA-x3h8-3mf2-v794.json +++ b/advisories/unreviewed/2024/07/GHSA-x3h8-3mf2-v794/GHSA-x3h8-3mf2-v794.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3h8-3mf2-v794", - "modified": "2024-08-01T15:32:07Z", + "modified": "2024-11-29T12:31:48Z", "published": "2024-07-24T09:30:40Z", "aliases": [ "CVE-2024-6197" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -33,6 +31,10 @@ "type": "WEB", "url": "https://curl.se/docs/CVE-2024-6197.json" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241129-0008" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/24/1" @@ -43,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-2r3m-26p3-wr26/GHSA-2r3m-26p3-wr26.json b/advisories/unreviewed/2024/11/GHSA-2r3m-26p3-wr26/GHSA-2r3m-26p3-wr26.json new file mode 100644 index 00000000000..982118abb36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2r3m-26p3-wr26/GHSA-2r3m-26p3-wr26.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r3m-26p3-wr26", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11981" + ], + "details": "Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11981" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8276-1defb-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8275-50f42-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3qm6-wcp5-fx9f/GHSA-3qm6-wcp5-fx9f.json b/advisories/unreviewed/2024/11/GHSA-3qm6-wcp5-fx9f/GHSA-3qm6-wcp5-fx9f.json new file mode 100644 index 00000000000..debd49ebb3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3qm6-wcp5-fx9f/GHSA-3qm6-wcp5-fx9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qm6-wcp5-fx9f", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11013" + ], + "details": "Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11013" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-009_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-773m-x37x-96wr/GHSA-773m-x37x-96wr.json b/advisories/unreviewed/2024/11/GHSA-773m-x37x-96wr/GHSA-773m-x37x-96wr.json new file mode 100644 index 00000000000..72c63605ae2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-773m-x37x-96wr/GHSA-773m-x37x-96wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-773m-x37x-96wr", + "modified": "2024-11-29T12:31:49Z", + "published": "2024-11-29T12:31:49Z", + "aliases": [ + "CVE-2024-9044" + ], + "details": "A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9044" + }, + { + "type": "WEB", + "url": "https://www.ag.ch/de/verwaltung/dfr/steuern/natuerliche-personen/steuererklaerung-easytax" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-88vw-p4cx-4677/GHSA-88vw-p4cx-4677.json b/advisories/unreviewed/2024/11/GHSA-88vw-p4cx-4677/GHSA-88vw-p4cx-4677.json new file mode 100644 index 00000000000..ab70c37addd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-88vw-p4cx-4677/GHSA-88vw-p4cx-4677.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88vw-p4cx-4677", + "modified": "2024-11-29T12:31:49Z", + "published": "2024-11-29T12:31:49Z", + "aliases": [ + "CVE-2024-11983" + ], + "details": "Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11983" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8280-ae6e1-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8279-bf67e-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json b/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json new file mode 100644 index 00000000000..70c7210af19 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f63f-f9wj-5wjg", + "modified": "2024-11-29T12:31:49Z", + "published": "2024-11-29T12:31:49Z", + "aliases": [ + "CVE-2024-47094" + ], + "details": "Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47094" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fr2x-xwp6-rg7p/GHSA-fr2x-xwp6-rg7p.json b/advisories/unreviewed/2024/11/GHSA-fr2x-xwp6-rg7p/GHSA-fr2x-xwp6-rg7p.json new file mode 100644 index 00000000000..0c0b3a1f0b1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fr2x-xwp6-rg7p/GHSA-fr2x-xwp6-rg7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2x-xwp6-rg7p", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11481" + ], + "details": "A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11481" + }, + { + "type": "WEB", + "url": "https://thrive.trellix.com/s/article/000014058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g6j3-5m8r-7p3c/GHSA-g6j3-5m8r-7p3c.json b/advisories/unreviewed/2024/11/GHSA-g6j3-5m8r-7p3c/GHSA-g6j3-5m8r-7p3c.json new file mode 100644 index 00000000000..7afcd36e726 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g6j3-5m8r-7p3c/GHSA-g6j3-5m8r-7p3c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6j3-5m8r-7p3c", + "modified": "2024-11-29T12:31:49Z", + "published": "2024-11-29T12:31:49Z", + "aliases": [ + "CVE-2024-50357" + ], + "details": "FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50357" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU95001899" + }, + { + "type": "WEB", + "url": "https://www.centurysys.co.jp/backnumber/nxr_common/20241031-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-684" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rwv8-hfhp-fj52/GHSA-rwv8-hfhp-fj52.json b/advisories/unreviewed/2024/11/GHSA-rwv8-hfhp-fj52/GHSA-rwv8-hfhp-fj52.json new file mode 100644 index 00000000000..ecbc3e3ce88 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rwv8-hfhp-fj52/GHSA-rwv8-hfhp-fj52.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwv8-hfhp-fj52", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11982" + ], + "details": "Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11982" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8278-cb581-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8277-88b20-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json b/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json new file mode 100644 index 00000000000..dcf183e4bff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhw-2v2c-qg98", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11482" + ], + "details": "A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11482" + }, + { + "type": "WEB", + "url": "https://thrive.trellix.com/s/article/000014058#h2_0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xhf4-qqf8-2pw6/GHSA-xhf4-qqf8-2pw6.json b/advisories/unreviewed/2024/11/GHSA-xhf4-qqf8-2pw6/GHSA-xhf4-qqf8-2pw6.json new file mode 100644 index 00000000000..f1337520911 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xhf4-qqf8-2pw6/GHSA-xhf4-qqf8-2pw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhf4-qqf8-2pw6", + "modified": "2024-11-29T12:31:48Z", + "published": "2024-11-29T12:31:48Z", + "aliases": [ + "CVE-2024-11014" + ], + "details": "Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11014" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-009_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T08:15:04Z" + } +} \ No newline at end of file