From cd272ebac89af53414b7471f86ccb8495eb2d8e3 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 5 Sep 2024 21:33:14 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-prcq-52f8-fp44.json | 6 ++-
.../GHSA-9cqc-m6m2-286c.json | 13 ++++--
.../GHSA-gvh8-jh2q-c22g.json | 2 +-
.../GHSA-jm56-5fwr-8p7q.json | 2 +-
.../GHSA-4mgj-2pcm-grp4.json | 2 +-
.../GHSA-qvcf-7rv4-rh36.json | 2 +-
.../GHSA-36xj-gcr2-cgrf.json | 2 +-
.../GHSA-gf9w-j28x-vmch.json | 2 +-
.../GHSA-27g4-crvm-h7gq.json | 11 +++--
.../GHSA-392h-pcr9-7j4w.json | 11 +++--
.../GHSA-44m4-gm9r-m853.json | 9 ++--
.../GHSA-7566-65rj-g85x.json | 9 ++--
.../GHSA-8v23-cgh2-vf2c.json | 11 +++--
.../GHSA-hxw3-49vc-4rrp.json | 9 ++--
.../GHSA-mxxf-4gg8-94vw.json | 11 +++--
.../GHSA-rcmr-c4gr-768m.json | 6 ++-
.../GHSA-vhvg-rmxw-qrqr.json | 11 +++--
.../GHSA-w88v-q2mr-5mff.json | 11 +++--
.../GHSA-5qmx-gqwp-wvwm.json | 11 +++--
.../GHSA-82fj-4p4v-8rc2.json | 11 +++--
.../GHSA-93pc-48xr-f962.json | 42 ++++++++++++++++++
.../GHSA-94j5-29m8-f8jq.json | 3 +-
.../GHSA-9qxr-9qr6-7x7w.json | 12 ++++--
.../GHSA-cq42-4xp3-5247.json | 11 +++--
.../GHSA-cr54-4mf7-rg5v.json | 43 +++++++++++++++++++
.../GHSA-cvp8-hm87-hr8x.json | 43 +++++++++++++++++++
.../GHSA-cx8j-vf9x-758j.json | 11 +++--
.../GHSA-f5qr-p3r9-wjr7.json | 11 +++--
.../GHSA-h7mq-2245-9qxr.json | 11 +++--
.../GHSA-hgfp-qxpq-6q7w.json | 1 +
.../GHSA-hw5v-7r63-g2h6.json | 43 +++++++++++++++++++
.../GHSA-p8gg-cp5h-w499.json | 9 ++--
.../GHSA-w8f6-p9wh-2f93.json | 11 +++--
33 files changed, 323 insertions(+), 80 deletions(-)
create mode 100644 advisories/unreviewed/2024/09/GHSA-93pc-48xr-f962/GHSA-93pc-48xr-f962.json
create mode 100644 advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json
create mode 100644 advisories/unreviewed/2024/09/GHSA-cvp8-hm87-hr8x/GHSA-cvp8-hm87-hr8x.json
create mode 100644 advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json
diff --git a/advisories/github-reviewed/2022/05/GHSA-prcq-52f8-fp44/GHSA-prcq-52f8-fp44.json b/advisories/github-reviewed/2022/05/GHSA-prcq-52f8-fp44/GHSA-prcq-52f8-fp44.json
index 41831dc3b6c..170a4ea2843 100644
--- a/advisories/github-reviewed/2022/05/GHSA-prcq-52f8-fp44/GHSA-prcq-52f8-fp44.json
+++ b/advisories/github-reviewed/2022/05/GHSA-prcq-52f8-fp44/GHSA-prcq-52f8-fp44.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-prcq-52f8-fp44",
- "modified": "2024-02-23T21:02:00Z",
+ "modified": "2024-09-05T21:32:21Z",
"published": "2022-05-17T05:19:14Z",
"aliases": [
"CVE-2012-3446"
@@ -48,6 +48,10 @@
"type": "PACKAGE",
"url": "https://github.com/apache/libcloud"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-libcloud/PYSEC-2012-12.yaml"
+ },
{
"type": "WEB",
"url": "https://svn.apache.org/repos/asf/libcloud/trunk/CHANGES"
diff --git a/advisories/unreviewed/2022/05/GHSA-9cqc-m6m2-286c/GHSA-9cqc-m6m2-286c.json b/advisories/unreviewed/2022/05/GHSA-9cqc-m6m2-286c/GHSA-9cqc-m6m2-286c.json
index 29d47af2971..576bfd70993 100644
--- a/advisories/unreviewed/2022/05/GHSA-9cqc-m6m2-286c/GHSA-9cqc-m6m2-286c.json
+++ b/advisories/unreviewed/2022/05/GHSA-9cqc-m6m2-286c/GHSA-9cqc-m6m2-286c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9cqc-m6m2-286c",
- "modified": "2022-05-24T17:27:40Z",
+ "modified": "2024-09-05T21:31:32Z",
"published": "2022-05-24T17:27:40Z",
"aliases": [
"CVE-2020-24198"
],
"details": "A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -22,6 +25,10 @@
"type": "WEB",
"url": "https://cxsecurity.com/issue/WLB-2020090024"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/Ambarella-Inc/amba-cve-info/tree/main/cve-2020-24918"
+ },
{
"type": "WEB",
"url": "https://www.sourcecodester.com/php/14366/stock-management-system-php.html"
@@ -29,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/10/GHSA-gvh8-jh2q-c22g/GHSA-gvh8-jh2q-c22g.json b/advisories/unreviewed/2023/10/GHSA-gvh8-jh2q-c22g/GHSA-gvh8-jh2q-c22g.json
index 0a3d42d053e..6ba79e80855 100644
--- a/advisories/unreviewed/2023/10/GHSA-gvh8-jh2q-c22g/GHSA-gvh8-jh2q-c22g.json
+++ b/advisories/unreviewed/2023/10/GHSA-gvh8-jh2q-c22g/GHSA-gvh8-jh2q-c22g.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/10/GHSA-jm56-5fwr-8p7q/GHSA-jm56-5fwr-8p7q.json b/advisories/unreviewed/2023/10/GHSA-jm56-5fwr-8p7q/GHSA-jm56-5fwr-8p7q.json
index f4f7ea8a325..ff0e035c60d 100644
--- a/advisories/unreviewed/2023/10/GHSA-jm56-5fwr-8p7q/GHSA-jm56-5fwr-8p7q.json
+++ b/advisories/unreviewed/2023/10/GHSA-jm56-5fwr-8p7q/GHSA-jm56-5fwr-8p7q.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json b/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json
index dde79e30667..1b3cc0b3e27 100644
--- a/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json
+++ b/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mgj-2pcm-grp4",
- "modified": "2023-11-09T03:30:19Z",
+ "modified": "2024-09-05T21:31:32Z",
"published": "2023-11-02T00:30:32Z",
"aliases": [
"CVE-2023-44954"
diff --git a/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json b/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json
index 73ce907d5cf..de637a4ee24 100644
--- a/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json
+++ b/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvcf-7rv4-rh36",
- "modified": "2023-11-14T21:30:50Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2023-11-06T06:30:27Z",
"aliases": [
"CVE-2023-47253"
diff --git a/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json
index 21654632625..666fee659d7 100644
--- a/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json
+++ b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36xj-gcr2-cgrf",
- "modified": "2024-02-05T15:30:23Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51888"
diff --git a/advisories/unreviewed/2024/01/GHSA-gf9w-j28x-vmch/GHSA-gf9w-j28x-vmch.json b/advisories/unreviewed/2024/01/GHSA-gf9w-j28x-vmch/GHSA-gf9w-j28x-vmch.json
index 58bc4866fb6..3f00b4e07f7 100644
--- a/advisories/unreviewed/2024/01/GHSA-gf9w-j28x-vmch/GHSA-gf9w-j28x-vmch.json
+++ b/advisories/unreviewed/2024/01/GHSA-gf9w-j28x-vmch/GHSA-gf9w-j28x-vmch.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gf9w-j28x-vmch",
- "modified": "2024-02-03T00:31:32Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-01-29T15:30:29Z",
"aliases": [
"CVE-2023-6503"
diff --git a/advisories/unreviewed/2024/07/GHSA-27g4-crvm-h7gq/GHSA-27g4-crvm-h7gq.json b/advisories/unreviewed/2024/07/GHSA-27g4-crvm-h7gq/GHSA-27g4-crvm-h7gq.json
index 489e90e47d8..eba28fde78a 100644
--- a/advisories/unreviewed/2024/07/GHSA-27g4-crvm-h7gq/GHSA-27g4-crvm-h7gq.json
+++ b/advisories/unreviewed/2024/07/GHSA-27g4-crvm-h7gq/GHSA-27g4-crvm-h7gq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27g4-crvm-h7gq",
- "modified": "2024-07-16T12:30:41Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-07-16T12:30:41Z",
"aliases": [
"CVE-2022-48826"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Fix deadlock on DSI device attach error\n\nDSI device attach to DSI host will be done with host device's lock\nheld.\n\nUn-registering host in \"device attach\" error path (ex: probe retry)\nwill result in deadlock with below call trace and non operational\nDSI display.\n\nStartup Call trace:\n[ 35.043036] rt_mutex_slowlock.constprop.21+0x184/0x1b8\n[ 35.043048] mutex_lock_nested+0x7c/0xc8\n[ 35.043060] device_del+0x4c/0x3e8\n[ 35.043075] device_unregister+0x20/0x40\n[ 35.043082] mipi_dsi_remove_device_fn+0x18/0x28\n[ 35.043093] device_for_each_child+0x68/0xb0\n[ 35.043105] mipi_dsi_host_unregister+0x40/0x90\n[ 35.043115] vc4_dsi_host_attach+0xf0/0x120 [vc4]\n[ 35.043199] mipi_dsi_attach+0x30/0x48\n[ 35.043209] tc358762_probe+0x128/0x164 [tc358762]\n[ 35.043225] mipi_dsi_drv_probe+0x28/0x38\n[ 35.043234] really_probe+0xc0/0x318\n[ 35.043244] __driver_probe_device+0x80/0xe8\n[ 35.043254] driver_probe_device+0xb8/0x118\n[ 35.043263] __device_attach_driver+0x98/0xe8\n[ 35.043273] bus_for_each_drv+0x84/0xd8\n[ 35.043281] __device_attach+0xf0/0x150\n[ 35.043290] device_initial_probe+0x1c/0x28\n[ 35.043300] bus_probe_device+0xa4/0xb0\n[ 35.043308] deferred_probe_work_func+0xa0/0xe0\n[ 35.043318] process_one_work+0x254/0x700\n[ 35.043330] worker_thread+0x4c/0x448\n[ 35.043339] kthread+0x19c/0x1a8\n[ 35.043348] ret_from_fork+0x10/0x20\n\nShutdown Call trace:\n[ 365.565417] Call trace:\n[ 365.565423] __switch_to+0x148/0x200\n[ 365.565452] __schedule+0x340/0x9c8\n[ 365.565467] schedule+0x48/0x110\n[ 365.565479] schedule_timeout+0x3b0/0x448\n[ 365.565496] wait_for_completion+0xac/0x138\n[ 365.565509] __flush_work+0x218/0x4e0\n[ 365.565523] flush_work+0x1c/0x28\n[ 365.565536] wait_for_device_probe+0x68/0x158\n[ 365.565550] device_shutdown+0x24/0x348\n[ 365.565561] kernel_restart_prepare+0x40/0x50\n[ 365.565578] kernel_restart+0x20/0x70\n[ 365.565591] __do_sys_reboot+0x10c/0x220\n[ 365.565605] __arm64_sys_reboot+0x2c/0x38\n[ 365.565619] invoke_syscall+0x4c/0x110\n[ 365.565634] el0_svc_common.constprop.3+0xfc/0x120\n[ 365.565648] do_el0_svc+0x2c/0x90\n[ 365.565661] el0_svc+0x4c/0xf0\n[ 365.565671] el0t_64_sync_handler+0x90/0xb8\n[ 365.565682] el0t_64_sync+0x180/0x184",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-667"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-16T12:15:06Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json b/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json
index a959fad20bc..a77e5f5d2f7 100644
--- a/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json
+++ b/advisories/unreviewed/2024/08/GHSA-392h-pcr9-7j4w/GHSA-392h-pcr9-7j4w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-392h-pcr9-7j4w",
- "modified": "2024-09-04T12:30:36Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43891"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have format file honor EVENT_FILE_FL_FREED\n\nWhen eventfs was introduced, special care had to be done to coordinate the\nfreeing of the file meta data with the files that are exposed to user\nspace. The file meta data would have a ref count that is set when the file\nis created and would be decremented and freed after the last user that\nopened the file closed it. When the file meta data was to be freed, it\nwould set a flag (EVENT_FILE_FL_FREED) to denote that the file is freed,\nand any new references made (like new opens or reads) would fail as it is\nmarked freed. This allowed other meta data to be freed after this flag was\nset (under the event_mutex).\n\nAll the files that were dynamically created in the events directory had a\npointer to the file meta data and would call event_release() when the last\nreference to the user space file was closed. This would be the time that it\nis safe to free the file meta data.\n\nA shortcut was made for the \"format\" file. It's i_private would point to\nthe \"call\" entry directly and not point to the file's meta data. This is\nbecause all format files are the same for the same \"call\", so it was\nthought there was no reason to differentiate them. The other files\nmaintain state (like the \"enable\", \"trigger\", etc). But this meant if the\nfile were to disappear, the \"format\" file would be unaware of it.\n\nThis caused a race that could be trigger via the user_events test (that\nwould create dynamic events and free them), and running a loop that would\nread the user_events format files:\n\nIn one console run:\n\n # cd tools/testing/selftests/user_events\n # while true; do ./ftrace_test; done\n\nAnd in another console run:\n\n # cd /sys/kernel/tracing/\n # while true; do cat events/user_events/__test_event/format; done 2>/dev/null\n\nWith KASAN memory checking, it would trigger a use-after-free bug report\n(which was a real bug). This was because the format file was not checking\nthe file's meta data flag \"EVENT_FILE_FL_FREED\", so it would access the\nevent that the file meta data pointed to after the event was freed.\n\nAfter inspection, there are other locations that were found to not check\nthe EVENT_FILE_FL_FREED flag when accessing the trace_event_file. Add a\nnew helper function: event_file_file() that will make sure that the\nevent_mutex is held, and will return NULL if the trace_event_file has the\nEVENT_FILE_FL_FREED flag set. Have the first reference of the struct file\npointer use event_file_file() and check for NULL. Later uses can still use\nthe event_file_data() helper function if the event_mutex is still held and\nwas not released since the event_file_file() call.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json b/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json
index aeaf8ce7336..e8088742a77 100644
--- a/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json
+++ b/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44m4-gm9r-m853",
- "modified": "2024-08-29T18:31:35Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43897"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: drop bad gso csum_start and offset in virtio_net_hdr\n\nTighten csum_start and csum_offset checks in virtio_net_hdr_to_skb\nfor GSO packets.\n\nThe function already checks that a checksum requested with\nVIRTIO_NET_HDR_F_NEEDS_CSUM is in skb linear. But for GSO packets\nthis might not hold for segs after segmentation.\n\nSyzkaller demonstrated to reach this warning in skb_checksum_help\n\n\toffset = skb_checksum_start_offset(skb);\n\tret = -EINVAL;\n\tif (WARN_ON_ONCE(offset >= skb_headlen(skb)))\n\nBy injecting a TSO packet:\n\nWARNING: CPU: 1 PID: 3539 at net/core/dev.c:3284 skb_checksum_help+0x3d0/0x5b0\n ip_do_fragment+0x209/0x1b20 net/ipv4/ip_output.c:774\n ip_finish_output_gso net/ipv4/ip_output.c:279 [inline]\n __ip_finish_output+0x2bd/0x4b0 net/ipv4/ip_output.c:301\n iptunnel_xmit+0x50c/0x930 net/ipv4/ip_tunnel_core.c:82\n ip_tunnel_xmit+0x2296/0x2c70 net/ipv4/ip_tunnel.c:813\n __gre_xmit net/ipv4/ip_gre.c:469 [inline]\n ipgre_xmit+0x759/0xa60 net/ipv4/ip_gre.c:661\n __netdev_start_xmit include/linux/netdevice.h:4850 [inline]\n netdev_start_xmit include/linux/netdevice.h:4864 [inline]\n xmit_one net/core/dev.c:3595 [inline]\n dev_hard_start_xmit+0x261/0x8c0 net/core/dev.c:3611\n __dev_queue_xmit+0x1b97/0x3c90 net/core/dev.c:4261\n packet_snd net/packet/af_packet.c:3073 [inline]\n\nThe geometry of the bad input packet at tcp_gso_segment:\n\n[ 52.003050][ T8403] skb len=12202 headroom=244 headlen=12093 tailroom=0\n[ 52.003050][ T8403] mac=(168,24) mac_len=24 net=(192,52) trans=244\n[ 52.003050][ T8403] shinfo(txflags=0 nr_frags=1 gso(size=1552 type=3 segs=0))\n[ 52.003050][ T8403] csum(0x60000c7 start=199 offset=1536\nip_summed=3 complete_sw=0 valid=0 level=0)\n\nMitigate with stricter input validation.\n\ncsum_offset: for GSO packets, deduce the correct value from gso_type.\nThis is already done for USO. Extend it to TSO. Let UFO be:\nudp[46]_ufo_fragment ignores these fields and always computes the\nchecksum in software.\n\ncsum_start: finding the real offset requires parsing to the transport\nheader. Do not add a parser, use existing segmentation parsing. Thanks\nto SKB_GSO_DODGY, that also catches bad packets that are hw offloaded.\nAgain test both TSO and USO. Do not test UFO for the above reason, and\ndo not test UDP tunnel offload.\n\nGSO packet are almost always CHECKSUM_PARTIAL. USO packets may be\nCHECKSUM_NONE since commit 10154dbded6d6 (\"udp: Allow GSO transmit\nfrom devices with no checksum offload\"), but then still these fields\nare initialized correctly in udp4_hwcsum/udp6_hwcsum_outgoing. So no\nneed to test for ip_summed == CHECKSUM_PARTIAL first.\n\nThis revises an existing fix mentioned in the Fixes tag, which broke\nsmall packets with GSO offload, as detected by kselftests.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-7566-65rj-g85x/GHSA-7566-65rj-g85x.json b/advisories/unreviewed/2024/08/GHSA-7566-65rj-g85x/GHSA-7566-65rj-g85x.json
index b2ecb7c5f57..7371873f6c8 100644
--- a/advisories/unreviewed/2024/08/GHSA-7566-65rj-g85x/GHSA-7566-65rj-g85x.json
+++ b/advisories/unreviewed/2024/08/GHSA-7566-65rj-g85x/GHSA-7566-65rj-g85x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7566-65rj-g85x",
- "modified": "2024-08-26T12:31:19Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43887"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp: Disable TCP-AO static key after RCU grace period\n\nThe lifetime of TCP-AO static_key is the same as the last\ntcp_ao_info. On the socket destruction tcp_ao_info ceases to be\nwith RCU grace period, while tcp-ao static branch is currently deferred\ndestructed. The static key definition is\n: DEFINE_STATIC_KEY_DEFERRED_FALSE(tcp_ao_needed, HZ);\n\nwhich means that if RCU grace period is delayed by more than a second\nand tcp_ao_needed is in the process of disablement, other CPUs may\nyet see tcp_ao_info which atent dead, but soon-to-be.\nAnd that breaks the assumption of static_key_fast_inc_not_disabled().\n\nSee the comment near the definition:\n> * The caller must make sure that the static key can't get disabled while\n> * in this function. It doesn't patch jump labels, only adds a user to\n> * an already enabled static key.\n\nOriginally it was introduced in commit eb8c507296f6 (\"jump_label:\nPrevent key->enabled int overflow\"), which is needed for the atomic\ncontexts, one of which would be the creation of a full socket from a\nrequest socket. In that atomic context, it's known by the presence\nof the key (md5/ao) that the static branch is already enabled.\nSo, the ref counter for that static branch is just incremented\ninstead of holding the proper mutex.\nstatic_key_fast_inc_not_disabled() is just a helper for such usage\ncase. But it must not be used if the static branch could get disabled\nin parallel as it's not protected by jump_label_mutex and as a result,\nraces with jump_label_update() implementation details.\n\nHappened on netdev test-bot[1], so not a theoretical issue:\n\n[] jump_label: Fatal kernel bug, unexpected op at tcp_inbound_hash+0x1a7/0x870 [ffffffffa8c4e9b7] (eb 50 0f 1f 44 != 66 90 0f 1f 00)) size:2 type:1\n[] ------------[ cut here ]------------\n[] kernel BUG at arch/x86/kernel/jump_label.c:73!\n[] Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[] CPU: 3 PID: 243 Comm: kworker/3:3 Not tainted 6.10.0-virtme #1\n[] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[] Workqueue: events jump_label_update_timeout\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n...\n[] Call Trace:\n[] \n[] arch_jump_label_transform_queue+0x6c/0x110\n[] __jump_label_update+0xef/0x350\n[] __static_key_slow_dec_cpuslocked.part.0+0x3c/0x60\n[] jump_label_update_timeout+0x2c/0x40\n[] process_one_work+0xe3b/0x1670\n[] worker_thread+0x587/0xce0\n[] kthread+0x28a/0x350\n[] ret_from_fork+0x31/0x70\n[] ret_from_fork_asm+0x1a/0x30\n[] \n[] Modules linked in: veth\n[] ---[ end trace 0000000000000000 ]---\n[] RIP: 0010:__jump_label_patch+0x2f6/0x350\n\n[1]: https://netdev-3.bots.linux.dev/vmksft-tcp-ao-dbg/results/696681/5-connect-deny-ipv6/stderr",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:03Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json b/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
index 09275d74314..6a45d551b6c 100644
--- a/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
+++ b/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v23-cgh2-vf2c",
- "modified": "2024-08-26T12:31:19Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43898"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: sanity check for NULL pointer after ext4_force_shutdown\n\nTest case: 2 threads write short inline data to a file.\nIn ext4_page_mkwrite the resulting inline data is converted.\nHandling ext4_grp_locked_error with description \"block bitmap\nand bg descriptor inconsistent: X vs Y free clusters\" calls\next4_force_shutdown. The conversion clears\nEXT4_STATE_MAY_INLINE_DATA but fails for\next4_destroy_inline_data_nolock and ext4_mark_iloc_dirty due\nto ext4_forced_shutdown. The restoration of inline data fails\nfor the same reason not setting EXT4_STATE_MAY_INLINE_DATA.\nWithout the flag set a regular process path in ext4_da_write_end\nfollows trying to dereference page folio private pointer that has\nnot been set. The fix calls early return with -EIO error shall the\npointer to private be NULL.\n\nSample crash report:\n\nUnable to handle kernel paging request at virtual address dfff800000000004\nKASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\nMem abort info:\n ESR = 0x0000000096000005\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x05: level 1 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000\n CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[dfff800000000004] address between user and kernel address ranges\nInternal error: Oops: 0000000096000005 [#1] PREEMPT SMP\nModules linked in:\nCPU: 1 PID: 20274 Comm: syz-executor185 Not tainted 6.9.0-rc7-syzkaller-gfda5695d692c #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : __block_commit_write+0x64/0x2b0 fs/buffer.c:2167\nlr : __block_commit_write+0x3c/0x2b0 fs/buffer.c:2160\nsp : ffff8000a1957600\nx29: ffff8000a1957610 x28: dfff800000000000 x27: ffff0000e30e34b0\nx26: 0000000000000000 x25: dfff800000000000 x24: dfff800000000000\nx23: fffffdffc397c9e0 x22: 0000000000000020 x21: 0000000000000020\nx20: 0000000000000040 x19: fffffdffc397c9c0 x18: 1fffe000367bd196\nx17: ffff80008eead000 x16: ffff80008ae89e3c x15: 00000000200000c0\nx14: 1fffe0001cbe4e04 x13: 0000000000000000 x12: 0000000000000000\nx11: 0000000000000001 x10: 0000000000ff0100 x9 : 0000000000000000\nx8 : 0000000000000004 x7 : 0000000000000000 x6 : 0000000000000000\nx5 : fffffdffc397c9c0 x4 : 0000000000000020 x3 : 0000000000000020\nx2 : 0000000000000040 x1 : 0000000000000020 x0 : fffffdffc397c9c0\nCall trace:\n __block_commit_write+0x64/0x2b0 fs/buffer.c:2167\n block_write_end+0xb4/0x104 fs/buffer.c:2253\n ext4_da_do_write_end fs/ext4/inode.c:2955 [inline]\n ext4_da_write_end+0x2c4/0xa40 fs/ext4/inode.c:3028\n generic_perform_write+0x394/0x588 mm/filemap.c:3985\n ext4_buffered_write_iter+0x2c0/0x4ec fs/ext4/file.c:299\n ext4_file_write_iter+0x188/0x1780\n call_write_iter include/linux/fs.h:2110 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0x968/0xc3c fs/read_write.c:590\n ksys_write+0x15c/0x26c fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:652\n __invoke_syscall arch/arm64/kernel/syscall.c:34 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:48\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:133\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:152\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:712\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\nCode: 97f85911 f94002da 91008356 d343fec8 (38796908)\n---[ end trace 0000000000000000 ]---\n----------------\nCode disassembly (best guess):\n 0:\t97f85911 \tbl\t0xffffffffffe16444\n 4:\tf94002da \tldr\tx26, [x22]\n 8:\t91008356 \tadd\tx22, x26, #0x20\n c:\td343fec8 \tlsr\tx8, x22, #3\n* 10:\t38796908 \tldrb\tw8, [x8, x25] <-- trapping instruction",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-hxw3-49vc-4rrp/GHSA-hxw3-49vc-4rrp.json b/advisories/unreviewed/2024/08/GHSA-hxw3-49vc-4rrp/GHSA-hxw3-49vc-4rrp.json
index 7880c85abcd..91861d8838d 100644
--- a/advisories/unreviewed/2024/08/GHSA-hxw3-49vc-4rrp/GHSA-hxw3-49vc-4rrp.json
+++ b/advisories/unreviewed/2024/08/GHSA-hxw3-49vc-4rrp/GHSA-hxw3-49vc-4rrp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxw3-49vc-4rrp",
- "modified": "2024-08-26T12:31:19Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43892"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: protect concurrent access to mem_cgroup_idr\n\nCommit 73f576c04b94 (\"mm: memcontrol: fix cgroup creation failure after\nmany small jobs\") decoupled the memcg IDs from the CSS ID space to fix the\ncgroup creation failures. It introduced IDR to maintain the memcg ID\nspace. The IDR depends on external synchronization mechanisms for\nmodifications. For the mem_cgroup_idr, the idr_alloc() and idr_replace()\nhappen within css callback and thus are protected through cgroup_mutex\nfrom concurrent modifications. However idr_remove() for mem_cgroup_idr\nwas not protected against concurrency and can be run concurrently for\ndifferent memcgs when they hit their refcnt to zero. Fix that.\n\nWe have been seeing list_lru based kernel crashes at a low frequency in\nour fleet for a long time. These crashes were in different part of\nlist_lru code including list_lru_add(), list_lru_del() and reparenting\ncode. Upon further inspection, it looked like for a given object (dentry\nand inode), the super_block's list_lru didn't have list_lru_one for the\nmemcg of that object. The initial suspicions were either the object is\nnot allocated through kmem_cache_alloc_lru() or somehow\nmemcg_list_lru_alloc() failed to allocate list_lru_one() for a memcg but\nreturned success. No evidence were found for these cases.\n\nLooking more deeply, we started seeing situations where valid memcg's id\nis not present in mem_cgroup_idr and in some cases multiple valid memcgs\nhave same id and mem_cgroup_idr is pointing to one of them. So, the most\nreasonable explanation is that these situations can happen due to race\nbetween multiple idr_remove() calls or race between\nidr_alloc()/idr_replace() and idr_remove(). These races are causing\nmultiple memcgs to acquire the same ID and then offlining of one of them\nwould cleanup list_lrus on the system for all of them. Later access from\nother memcgs to the list_lru cause crashes due to missing list_lru_one.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-mxxf-4gg8-94vw/GHSA-mxxf-4gg8-94vw.json b/advisories/unreviewed/2024/08/GHSA-mxxf-4gg8-94vw/GHSA-mxxf-4gg8-94vw.json
index ee29b6ca4b1..3365734e2b1 100644
--- a/advisories/unreviewed/2024/08/GHSA-mxxf-4gg8-94vw/GHSA-mxxf-4gg8-94vw.json
+++ b/advisories/unreviewed/2024/08/GHSA-mxxf-4gg8-94vw/GHSA-mxxf-4gg8-94vw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxxf-4gg8-94vw",
- "modified": "2024-08-26T12:31:19Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43890"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix overflow in get_free_elt()\n\n\"tracing_map->next_elt\" in get_free_elt() is at risk of overflowing.\n\nOnce it overflows, new elements can still be inserted into the tracing_map\neven though the maximum number of elements (`max_elts`) has been reached.\nContinuing to insert elements after the overflow could result in the\ntracing_map containing \"tracing_map->max_size\" elements, leaving no empty\nentries.\nIf any attempt is made to insert an element into a full tracing_map using\n`__tracing_map_insert()`, it will cause an infinite loop with preemption\ndisabled, leading to a CPU hang problem.\n\nFix this by preventing any further increments to \"tracing_map->next_elt\"\nonce it reaches \"tracing_map->max_elt\".",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-190"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json b/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json
index bb0ba75dd2d..b9391eb6d04 100644
--- a/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json
+++ b/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcmr-c4gr-768m",
- "modified": "2024-08-28T06:30:31Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T18:33:34Z",
"aliases": [
"CVE-2024-7401"
],
"details": "Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json b/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json
index a503ab9135c..97fcabbb6e2 100644
--- a/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json
+++ b/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhvg-rmxw-qrqr",
- "modified": "2024-08-28T21:31:28Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T18:33:34Z",
"aliases": [
"CVE-2024-42913"
],
"details": "RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T18:15:07Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-w88v-q2mr-5mff/GHSA-w88v-q2mr-5mff.json b/advisories/unreviewed/2024/08/GHSA-w88v-q2mr-5mff/GHSA-w88v-q2mr-5mff.json
index 07b5fc36f18..1b3bd8e62ea 100644
--- a/advisories/unreviewed/2024/08/GHSA-w88v-q2mr-5mff/GHSA-w88v-q2mr-5mff.json
+++ b/advisories/unreviewed/2024/08/GHSA-w88v-q2mr-5mff/GHSA-w88v-q2mr-5mff.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w88v-q2mr-5mff",
- "modified": "2024-08-26T12:31:19Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-08-26T12:31:19Z",
"aliases": [
"CVE-2024-43896"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: cs-amp-lib: Fix NULL pointer crash if efi.get_variable is NULL\n\nCall efi_rt_services_supported() to check that efi.get_variable exists\nbefore calling it.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-26T11:15:04Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json b/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json
index fe73bcba690..7b3f7f70f02 100644
--- a/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json
+++ b/advisories/unreviewed/2024/09/GHSA-5qmx-gqwp-wvwm/GHSA-5qmx-gqwp-wvwm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qmx-gqwp-wvwm",
- "modified": "2024-09-05T18:30:56Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:56Z",
"aliases": [
"CVE-2024-45171"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory \"/srv/www/backups\" on the C-MOR system, and can thus be accessed via the URL https:///backup/upload_. Due to broken access control, low-privileged authenticated users can also use this file upload functionality.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T16:15:08Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json b/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json
index dae24193b26..5fd83e2196d 100644
--- a/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json
+++ b/advisories/unreviewed/2024/09/GHSA-82fj-4p4v-8rc2/GHSA-82fj-4p4v-8rc2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82fj-4p4v-8rc2",
- "modified": "2024-09-05T18:30:57Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:57Z",
"aliases": [
"CVE-2024-45589"
],
"details": "RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-307"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T16:15:08Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-93pc-48xr-f962/GHSA-93pc-48xr-f962.json b/advisories/unreviewed/2024/09/GHSA-93pc-48xr-f962/GHSA-93pc-48xr-f962.json
new file mode 100644
index 00000000000..eb907bfd390
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-93pc-48xr-f962/GHSA-93pc-48xr-f962.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-93pc-48xr-f962",
+ "modified": "2024-09-05T21:31:34Z",
+ "published": "2024-09-05T21:31:34Z",
+ "aliases": [
+ "CVE-2024-8395"
+ ],
+ "details": "FlyCASS CASS and KCM systems did not correctly filter SQL queries, which\n made them vulnerable to attack by outside attackers with no \nauthentication.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8395"
+ },
+ {
+ "type": "WEB",
+ "url": "https://ian.sh/tsa"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-05T20:15:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json
index 3746f57a7bb..8937ef7834f 100644
--- a/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json
+++ b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-193"
+ "CWE-193",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json b/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json
index 7c3d2f463e6..3a5de093529 100644
--- a/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json
+++ b/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qxr-9qr6-7x7w",
- "modified": "2024-09-05T06:31:35Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T06:31:35Z",
"aliases": [
"CVE-2024-8178"
],
"details": "The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-908"
+ "CWE-908",
+ "CWE-909"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T05:15:13Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json b/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json
index 4d1e177f415..56b59f528e3 100644
--- a/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json
+++ b/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cq42-4xp3-5247",
- "modified": "2024-09-05T15:33:37Z",
+ "modified": "2024-09-05T21:31:33Z",
"published": "2024-09-05T15:33:37Z",
"aliases": [
"CVE-2024-45173"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T15:15:16Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json b/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json
new file mode 100644
index 00000000000..edfeadb0ae1
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-cr54-4mf7-rg5v/GHSA-cr54-4mf7-rg5v.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cr54-4mf7-rg5v",
+ "modified": "2024-09-05T21:31:34Z",
+ "published": "2024-09-05T21:31:34Z",
+ "aliases": [
+ "CVE-2024-45159"
+ ],
+ "details": "An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have the MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert).",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45159"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Mbed-TLS/mbedtls/releases"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-05T19:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-cvp8-hm87-hr8x/GHSA-cvp8-hm87-hr8x.json b/advisories/unreviewed/2024/09/GHSA-cvp8-hm87-hr8x/GHSA-cvp8-hm87-hr8x.json
new file mode 100644
index 00000000000..b8fceae2f25
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-cvp8-hm87-hr8x/GHSA-cvp8-hm87-hr8x.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cvp8-hm87-hr8x",
+ "modified": "2024-09-05T21:31:34Z",
+ "published": "2024-09-05T21:31:34Z",
+ "aliases": [
+ "CVE-2024-45157"
+ ],
+ "details": "An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45157"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Mbed-TLS/mbedtls/releases"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-05T19:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json b/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json
index 56b855019e9..51cee8cfa1a 100644
--- a/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json
+++ b/advisories/unreviewed/2024/09/GHSA-cx8j-vf9x-758j/GHSA-cx8j-vf9x-758j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx8j-vf9x-758j",
- "modified": "2024-09-05T18:30:56Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:56Z",
"aliases": [
"CVE-2024-45175"
],
"details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack, has access to the login data of all configured cameras, or the configured FTP server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T16:15:08Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json b/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json
index 6b4e1d72873..cf47dfc8cb0 100644
--- a/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json
+++ b/advisories/unreviewed/2024/09/GHSA-f5qr-p3r9-wjr7/GHSA-f5qr-p3r9-wjr7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5qr-p3r9-wjr7",
- "modified": "2024-09-05T18:30:56Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:56Z",
"aliases": [
"CVE-2024-42885"
],
"details": "SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T16:15:07Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json b/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json
index 96c2e62f77e..2a62e8c4466 100644
--- a/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json
+++ b/advisories/unreviewed/2024/09/GHSA-h7mq-2245-9qxr/GHSA-h7mq-2245-9qxr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7mq-2245-9qxr",
- "modified": "2024-09-05T18:30:57Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:57Z",
"aliases": [
"CVE-2024-44727"
],
"details": "Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T17:15:12Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json
index b55ec280d34..ca2fdbd33ec 100644
--- a/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json
+++ b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-1284",
"CWE-790"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json b/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json
new file mode 100644
index 00000000000..c9fbbd6570b
--- /dev/null
+++ b/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hw5v-7r63-g2h6",
+ "modified": "2024-09-05T21:31:34Z",
+ "published": "2024-09-05T21:31:34Z",
+ "aliases": [
+ "CVE-2024-45158"
+ ],
+ "details": "An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in internal library calls, but can affect applications that call these functions directly.)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45158"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Mbed-TLS/mbedtls/releases"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-09-05T19:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json b/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json
index 7f1ba9b5a87..84b3c5c3588 100644
--- a/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json
+++ b/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8gg-cp5h-w499",
- "modified": "2024-09-05T06:31:35Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T06:31:35Z",
"aliases": [
"CVE-2024-45063"
],
"details": "The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T05:15:13Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json b/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json
index 624c1387693..03ef17e97f9 100644
--- a/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json
+++ b/advisories/unreviewed/2024/09/GHSA-w8f6-p9wh-2f93/GHSA-w8f6-p9wh-2f93.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8f6-p9wh-2f93",
- "modified": "2024-09-05T18:30:57Z",
+ "modified": "2024-09-05T21:31:34Z",
"published": "2024-09-05T18:30:57Z",
"aliases": [
"CVE-2024-44728"
],
"details": "Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T17:15:12Z"