From cad468ed35f8f2644c285d97eebe2e55185e3e52 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Sep 2024 21:33:01 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8xq6-frf7-63cg.json | 2 +- .../GHSA-9xm4-hw5v-jpjg.json | 2 +- .../GHSA-c67q-c83x-f549.json | 2 +- .../GHSA-86xc-mwv4-f994.json | 2 +- .../GHSA-jjpv-jrvp-jwr3.json | 3 +- .../GHSA-p7hh-r4jx-72fm.json | 6 ++- .../GHSA-2wwv-3g3g-h8w3.json | 11 ++-- .../GHSA-92g2-6qfc-5xw4.json | 11 ++-- .../GHSA-c5f9-wr82-c7qx.json | 11 ++-- .../GHSA-f58v-43c6-f6hf.json | 11 ++-- .../GHSA-qw3c-xh2p-rwmf.json | 11 ++-- .../GHSA-358h-hvvf-x4v2.json | 38 ++++++++++++++ .../GHSA-38rg-8rfh-j366.json | 11 ++-- .../GHSA-42p2-q66q-8hx8.json | 38 ++++++++++++++ .../GHSA-4gj3-5752-q8g8.json | 11 ++-- .../GHSA-4hj6-28gf-vw7g.json | 35 +++++++++++++ .../GHSA-5qf6-wqm9-p35x.json | 42 ++++++++++++++++ .../GHSA-8gx2-fcjg-wfjv.json | 50 +++++++++++++++++++ .../GHSA-8vw5-3vcf-59wh.json | 11 ++-- .../GHSA-98cg-f2r6-jq5c.json | 38 ++++++++++++++ .../GHSA-99m3-849w-rg54.json | 38 ++++++++++++++ .../GHSA-c45c-r247-q8hc.json | 38 ++++++++++++++ .../GHSA-c6f5-vg46-h8r2.json | 1 + .../GHSA-f3fq-wr7m-7vrp.json | 11 ++-- .../GHSA-g3j3-68hm-8gfm.json | 11 ++-- .../GHSA-g5cq-mqgj-wgjv.json | 38 ++++++++++++++ .../GHSA-h926-5fmr-p532.json | 38 ++++++++++++++ .../GHSA-hp6q-6g58-99wm.json | 2 +- .../GHSA-jv5c-8jgx-c489.json | 38 ++++++++++++++ .../GHSA-mm7m-mg28-rj6q.json | 11 ++-- .../GHSA-mqp5-vpv8-vhqm.json | 38 ++++++++++++++ .../GHSA-pmc5-pcm8-42pf.json | 11 ++-- .../GHSA-qjx2-rcx8-qr2r.json | 38 ++++++++++++++ .../GHSA-qr9q-g9r2-5x7c.json | 38 ++++++++++++++ .../GHSA-r47m-g4vh-pxf6.json | 39 +++++++++++++++ .../GHSA-r95v-7x7v-phw8.json | 11 ++-- .../GHSA-rj4v-5f39-crv6.json | 38 ++++++++++++++ .../GHSA-rqjx-229x-7jmc.json | 42 ++++++++++++++++ .../GHSA-wpwg-4rvh-5q27.json | 11 ++-- .../GHSA-x996-vwrq-5c5f.json | 11 ++-- 40 files changed, 782 insertions(+), 67 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-358h-hvvf-x4v2/GHSA-358h-hvvf-x4v2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-42p2-q66q-8hx8/GHSA-42p2-q66q-8hx8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5qf6-wqm9-p35x/GHSA-5qf6-wqm9-p35x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8gx2-fcjg-wfjv/GHSA-8gx2-fcjg-wfjv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-98cg-f2r6-jq5c/GHSA-98cg-f2r6-jq5c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-99m3-849w-rg54/GHSA-99m3-849w-rg54.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c45c-r247-q8hc/GHSA-c45c-r247-q8hc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g5cq-mqgj-wgjv/GHSA-g5cq-mqgj-wgjv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h926-5fmr-p532/GHSA-h926-5fmr-p532.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jv5c-8jgx-c489/GHSA-jv5c-8jgx-c489.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mqp5-vpv8-vhqm/GHSA-mqp5-vpv8-vhqm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qr9q-g9r2-5x7c/GHSA-qr9q-g9r2-5x7c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rj4v-5f39-crv6/GHSA-rj4v-5f39-crv6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rqjx-229x-7jmc/GHSA-rqjx-229x-7jmc.json diff --git a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json index 38680a96e54..03a981b7c9f 100644 --- a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json +++ b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json @@ -72,7 +72,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json b/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json index 82c0d79e3e1..2c5d6c77c20 100644 --- a/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json +++ b/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xm4-hw5v-jpjg", - "modified": "2024-01-30T00:30:29Z", + "modified": "2024-09-10T21:31:37Z", "published": "2024-01-23T15:30:57Z", "aliases": [ "CVE-2024-0744" diff --git a/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json b/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json index 73006150101..baf72d7431b 100644 --- a/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json +++ b/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c67q-c83x-f549", - "modified": "2024-01-31T00:30:17Z", + "modified": "2024-09-10T21:31:37Z", "published": "2024-01-24T03:31:25Z", "aliases": [ "CVE-2024-21796" diff --git a/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json index 39d8d5f5398..034292c11be 100644 --- a/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json +++ b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86xc-mwv4-f994", - "modified": "2024-07-17T15:30:50Z", + "modified": "2024-09-10T21:31:38Z", "published": "2024-07-17T15:30:50Z", "aliases": [ "CVE-2024-23465" diff --git a/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json b/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json index 92c81382ab3..1c0be75da8d 100644 --- a/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json +++ b/advisories/unreviewed/2024/07/GHSA-jjpv-jrvp-jwr3/GHSA-jjpv-jrvp-jwr3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json index ef3b2d94287..4bcd7918b4f 100644 --- a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json +++ b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7hh-r4jx-72fm", - "modified": "2024-07-23T03:30:33Z", + "modified": "2024-09-10T21:31:38Z", "published": "2024-07-22T21:30:40Z", "aliases": [ "CVE-2024-6911" ], "details": "Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json b/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json index 61b336b638a..3320a4194da 100644 --- a/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json +++ b/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wwv-3g3g-h8w3", - "modified": "2024-08-17T09:30:24Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42298" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked.\n\nFix this lack and check the returned value.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json b/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json index 3cf484c7362..de3a0f636a3 100644 --- a/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json +++ b/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92g2-6qfc-5xw4", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-10T21:31:38Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42277" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu: sprd: Avoid NULL deref in sprd_iommu_hw_en\n\nIn sprd_iommu_cleanup() before calling function sprd_iommu_hw_en()\ndom->sdev is equal to NULL, which leads to null dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json b/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json index ca663970eb0..6f7402ceb93 100644 --- a/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json +++ b/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5f9-wr82-c7qx", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-10T21:31:38Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42280" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: Fix a use after free in hfcmulti_tx()\n\nDon't dereference *sp after calling dev_kfree_skb(*sp).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json b/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json index e1b9c24df51..a52c736bb06 100644 --- a/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json +++ b/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f58v-43c6-f6hf", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42286" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: validate nvme_local_port correctly\n\nThe driver load failed with error message,\n\nqla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef\n\nand with a kernel crash,\n\n\tBUG: unable to handle kernel NULL pointer dereference at 0000000000000070\n\tWorkqueue: events_unbound qla_register_fcport_fn [qla2xxx]\n\tRIP: 0010:nvme_fc_register_remoteport+0x16/0x430 [nvme_fc]\n\tRSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282\n\tRAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000\n\tRDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000\n\tRBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030\n\tR10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4\n\tR13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8\n\tFS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000\n\tCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n\tCR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0\n\tCall Trace:\n\tqla_nvme_register_remote+0xeb/0x1f0 [qla2xxx]\n\t? qla2x00_dfs_create_rport+0x231/0x270 [qla2xxx]\n\tqla2x00_update_fcport+0x2a1/0x3c0 [qla2xxx]\n\tqla_register_fcport_fn+0x54/0xc0 [qla2xxx]\n\nExit the qla_nvme_register_remote() function when qla_nvme_register_hba()\nfails and correctly validate nvme_local_port.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json b/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json index 6df4e60f8fe..5eca452705e 100644 --- a/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json +++ b/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw3c-xh2p-rwmf", - "modified": "2024-08-19T06:30:53Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-08-17T09:30:24Z", "aliases": [ "CVE-2024-42287" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Complete command early within lock\n\nA crash was observed while performing NPIV and FW reset,\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 1 PREEMPT_RT SMP NOPTI\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffc90026f47b88 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000002\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8881041130d0\n RBP: ffff8881041130d0 R08: 0000000000000000 R09: 0000000000000034\n R10: ffffc90026f47c48 R11: 0000000000000031 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8881565e4a20 R15: 0000000000000000\n FS: 00007f4c69ed3d00(0000) GS:ffff889faac80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000000288a50002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x16f/0x4a0\n ? do_user_addr_fault+0x174/0x7f0\n ? exc_page_fault+0x69/0x1a0\n ? asm_exc_page_fault+0x22/0x30\n ? dma_direct_unmap_sg+0x51/0x1e0\n ? preempt_count_sub+0x96/0xe0\n qla2xxx_qpair_sp_free_dma+0x29f/0x3b0 [qla2xxx]\n qla2xxx_qpair_sp_compl+0x60/0x80 [qla2xxx]\n __qla2x00_abort_all_cmds+0xa2/0x450 [qla2xxx]\n\nThe command completion was done early while aborting the commands in driver\nunload path but outside lock to avoid the WARN_ON condition of performing\ndma_free_attr within the lock. However this caused race condition while\ncommand completion via multiple paths causing system crash.\n\nHence complete the command early in unload path but within the lock to\navoid race condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T09:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-358h-hvvf-x4v2/GHSA-358h-hvvf-x4v2.json b/advisories/unreviewed/2024/09/GHSA-358h-hvvf-x4v2/GHSA-358h-hvvf-x4v2.json new file mode 100644 index 00000000000..e773d1d4c77 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-358h-hvvf-x4v2/GHSA-358h-hvvf-x4v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-358h-hvvf-x4v2", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-44106" + ], + "details": "Insufficient server-side controls in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44106" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json b/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json index 43e26c0e377..b6c1cd5c9e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json +++ b/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38rg-8rfh-j366", - "modified": "2024-09-10T18:30:44Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:44Z", "aliases": [ "CVE-2024-44677" ], "details": "eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T16:15:20Z" diff --git a/advisories/unreviewed/2024/09/GHSA-42p2-q66q-8hx8/GHSA-42p2-q66q-8hx8.json b/advisories/unreviewed/2024/09/GHSA-42p2-q66q-8hx8/GHSA-42p2-q66q-8hx8.json new file mode 100644 index 00000000000..0d90c18b697 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-42p2-q66q-8hx8/GHSA-42p2-q66q-8hx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42p2-q66q-8hx8", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8321" + ], + "details": "Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8321" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json index 252bfa9a5a2..bdb6bad3828 100644 --- a/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json +++ b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gj3-5752-q8g8", - "modified": "2024-09-10T09:31:11Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T09:31:11Z", "aliases": [ "CVE-2024-44072" ], "details": "OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T07:15:01Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json b/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json new file mode 100644 index 00000000000..55943047ee1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4hj6-28gf-vw7g/GHSA-4hj6-28gf-vw7g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hj6-28gf-vw7g", + "modified": "2024-09-10T21:31:39Z", + "published": "2024-09-10T21:31:39Z", + "aliases": [ + "CVE-2024-43040" + ], + "details": "Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43040" + }, + { + "type": "WEB", + "url": "https://gist.github.com/X1lyS/75a8ea48c4997b683e8b41c94e79e5f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5qf6-wqm9-p35x/GHSA-5qf6-wqm9-p35x.json b/advisories/unreviewed/2024/09/GHSA-5qf6-wqm9-p35x/GHSA-5qf6-wqm9-p35x.json new file mode 100644 index 00000000000..e5731091d46 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5qf6-wqm9-p35x/GHSA-5qf6-wqm9-p35x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qf6-wqm9-p35x", + "modified": "2024-09-10T21:31:39Z", + "published": "2024-09-10T21:31:39Z", + "aliases": [ + "CVE-2024-8503" + ], + "details": "An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8503" + }, + { + "type": "WEB", + "url": "https://korelogic.com/Resources/Advisories/KL-001-2024-011.txt" + }, + { + "type": "WEB", + "url": "https://www.vicidial.org/vicidial.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8gx2-fcjg-wfjv/GHSA-8gx2-fcjg-wfjv.json b/advisories/unreviewed/2024/09/GHSA-8gx2-fcjg-wfjv/GHSA-8gx2-fcjg-wfjv.json new file mode 100644 index 00000000000..916ee616340 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8gx2-fcjg-wfjv/GHSA-8gx2-fcjg-wfjv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gx2-fcjg-wfjv", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8655" + ], + "details": "A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276963" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276963" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.401301" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json b/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json index 6851c2a9a19..24b01bab1cb 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json +++ b/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vw5-3vcf-59wh", - "modified": "2024-09-10T18:30:44Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:44Z", "aliases": [ "CVE-2024-44676" ], "details": "eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T16:15:20Z" diff --git a/advisories/unreviewed/2024/09/GHSA-98cg-f2r6-jq5c/GHSA-98cg-f2r6-jq5c.json b/advisories/unreviewed/2024/09/GHSA-98cg-f2r6-jq5c/GHSA-98cg-f2r6-jq5c.json new file mode 100644 index 00000000000..8fad96c2f79 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-98cg-f2r6-jq5c/GHSA-98cg-f2r6-jq5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98cg-f2r6-jq5c", + "modified": "2024-09-10T21:31:39Z", + "published": "2024-09-10T21:31:39Z", + "aliases": [ + "CVE-2024-44103" + ], + "details": "DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44103" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-99m3-849w-rg54/GHSA-99m3-849w-rg54.json b/advisories/unreviewed/2024/09/GHSA-99m3-849w-rg54/GHSA-99m3-849w-rg54.json new file mode 100644 index 00000000000..80b4c067338 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-99m3-849w-rg54/GHSA-99m3-849w-rg54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99m3-849w-rg54", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-44104" + ], + "details": "An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44104" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c45c-r247-q8hc/GHSA-c45c-r247-q8hc.json b/advisories/unreviewed/2024/09/GHSA-c45c-r247-q8hc/GHSA-c45c-r247-q8hc.json new file mode 100644 index 00000000000..106e2b3c4e3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c45c-r247-q8hc/GHSA-c45c-r247-q8hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c45c-r247-q8hc", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8320" + ], + "details": "Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8320" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json index 112ab7ff1ff..dd6cc6afab5 100644 --- a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json +++ b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json b/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json index 407e37ffc3e..0aa60a9b115 100644 --- a/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json +++ b/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3fq-wr7m-7vrp", - "modified": "2024-09-10T18:30:47Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:47Z", "aliases": [ "CVE-2024-44872" ], "details": "A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T17:15:37Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json b/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json index 600a6123882..4e6a2f8ee70 100644 --- a/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json +++ b/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3j3-68hm-8gfm", - "modified": "2024-09-10T18:30:47Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:47Z", "aliases": [ "CVE-2024-44871" ], "details": "An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T17:15:37Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g5cq-mqgj-wgjv/GHSA-g5cq-mqgj-wgjv.json b/advisories/unreviewed/2024/09/GHSA-g5cq-mqgj-wgjv/GHSA-g5cq-mqgj-wgjv.json new file mode 100644 index 00000000000..d0feb3d7af7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g5cq-mqgj-wgjv/GHSA-g5cq-mqgj-wgjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5cq-mqgj-wgjv", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-44107" + ], + "details": "DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44107" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h926-5fmr-p532/GHSA-h926-5fmr-p532.json b/advisories/unreviewed/2024/09/GHSA-h926-5fmr-p532/GHSA-h926-5fmr-p532.json new file mode 100644 index 00000000000..1aabe91e492 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h926-5fmr-p532/GHSA-h926-5fmr-p532.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h926-5fmr-p532", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8441" + ], + "details": "An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8441" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json b/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json index e66b0b48a11..9f9a998c93f 100644 --- a/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json +++ b/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-jv5c-8jgx-c489/GHSA-jv5c-8jgx-c489.json b/advisories/unreviewed/2024/09/GHSA-jv5c-8jgx-c489/GHSA-jv5c-8jgx-c489.json new file mode 100644 index 00000000000..31e27ea697f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jv5c-8jgx-c489/GHSA-jv5c-8jgx-c489.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv5c-8jgx-c489", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8322" + ], + "details": "Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8322" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json index 51ea94dd0f3..0ca901097ea 100644 --- a/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json +++ b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mm7m-mg28-rj6q", - "modified": "2024-09-10T18:30:44Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:44Z", "aliases": [ "CVE-2023-37232" ], "details": "Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T16:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mqp5-vpv8-vhqm/GHSA-mqp5-vpv8-vhqm.json b/advisories/unreviewed/2024/09/GHSA-mqp5-vpv8-vhqm/GHSA-mqp5-vpv8-vhqm.json new file mode 100644 index 00000000000..0b08235a9ea --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mqp5-vpv8-vhqm/GHSA-mqp5-vpv8-vhqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqp5-vpv8-vhqm", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8012" + ], + "details": "An authentication bypass weakness in the message broker service of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8012" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json b/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json index d36f017dacf..5f53590954a 100644 --- a/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json +++ b/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmc5-pcm8-42pf", - "modified": "2024-09-10T18:30:44Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:44Z", "aliases": [ "CVE-2023-36103" ], "details": "Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T16:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json b/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json new file mode 100644 index 00000000000..b0a1fba71d5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qjx2-rcx8-qr2r/GHSA-qjx2-rcx8-qr2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjx2-rcx8-qr2r", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8190" + ], + "details": "An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8190" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qr9q-g9r2-5x7c/GHSA-qr9q-g9r2-5x7c.json b/advisories/unreviewed/2024/09/GHSA-qr9q-g9r2-5x7c/GHSA-qr9q-g9r2-5x7c.json new file mode 100644 index 00000000000..52737704f8a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qr9q-g9r2-5x7c/GHSA-qr9q-g9r2-5x7c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr9q-g9r2-5x7c", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-44105" + ], + "details": "Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44105" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-IWC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json b/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json new file mode 100644 index 00000000000..b0a85809a57 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r47m-g4vh-pxf6/GHSA-r47m-g4vh-pxf6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r47m-g4vh-pxf6", + "modified": "2024-09-10T21:31:39Z", + "published": "2024-09-10T21:31:39Z", + "aliases": [ + "CVE-2024-8504" + ], + "details": "An attacker with authenticated access to VICIdial as an \"agent\" can execute arbitrary shell commands as the \"root\" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8504" + }, + { + "type": "WEB", + "url": "https://korelogic.com/Resources/Advisories/KL-001-2024-012.txt" + }, + { + "type": "WEB", + "url": "https://www.vicidial.org/vicidial.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json index 65e1ff8831d..b174334c458 100644 --- a/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json +++ b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r95v-7x7v-phw8", - "modified": "2024-09-10T18:30:47Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:47Z", "aliases": [ "CVE-2024-44667" ], "details": "Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T17:15:37Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rj4v-5f39-crv6/GHSA-rj4v-5f39-crv6.json b/advisories/unreviewed/2024/09/GHSA-rj4v-5f39-crv6/GHSA-rj4v-5f39-crv6.json new file mode 100644 index 00000000000..6a98b5b8254 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rj4v-5f39-crv6/GHSA-rj4v-5f39-crv6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj4v-5f39-crv6", + "modified": "2024-09-10T21:31:40Z", + "published": "2024-09-10T21:31:40Z", + "aliases": [ + "CVE-2024-8191" + ], + "details": "SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8191" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rqjx-229x-7jmc/GHSA-rqjx-229x-7jmc.json b/advisories/unreviewed/2024/09/GHSA-rqjx-229x-7jmc/GHSA-rqjx-229x-7jmc.json new file mode 100644 index 00000000000..b07a9ff67a3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rqjx-229x-7jmc/GHSA-rqjx-229x-7jmc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqjx-229x-7jmc", + "modified": "2024-09-10T21:31:39Z", + "published": "2024-09-10T21:31:39Z", + "aliases": [ + "CVE-2024-8232" + ], + "details": "SpiderControl SCADA Web Server has a vulnerability that could allow an \nattacker to upload specially crafted malicious files without \nauthentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8232" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-254-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json b/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json index 174dd0fab68..26896e37819 100644 --- a/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json +++ b/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpwg-4rvh-5q27", - "modified": "2024-09-10T18:30:47Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:47Z", "aliases": [ "CVE-2024-44893" ], "details": "An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T17:15:37Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json b/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json index 65a919df0bf..74a13de396f 100644 --- a/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json +++ b/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x996-vwrq-5c5f", - "modified": "2024-09-10T18:30:47Z", + "modified": "2024-09-10T21:31:39Z", "published": "2024-09-10T18:30:47Z", "aliases": [ "CVE-2024-34831" ], "details": "cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T18:15:03Z"