Publish Advisories

GHSA-6w7h-fpm5-3ww6
GHSA-r62p-gp92-7444
GHSA-29q2-fp4w-f7hm
GHSA-4mp7-6gp5-x248
GHSA-8mvv-2pq8-4996
GHSA-pwff-c3p7-fx7c
This commit is contained in:
advisory-database[bot]
2024-04-29 03:32:07 +00:00
parent 15c16fbbde
commit ce97a92222
6 changed files with 175 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w7h-fpm5-3ww6",
"modified": "2024-04-23T03:31:28Z",
"modified": "2024-04-29T03:30:46Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-4692"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUU42E7CPYLATXOYVYNW6YTXXULAOV6L"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRJ5UZRXX2KLR4IKBJEQUNGOCXMMDLY"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r62p-gp92-7444",
"modified": "2024-04-23T03:31:28Z",
"modified": "2024-04-29T03:30:46Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-4693"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUU42E7CPYLATXOYVYNW6YTXXULAOV6L"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRJ5UZRXX2KLR4IKBJEQUNGOCXMMDLY"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29q2-fp4w-f7hm",
"modified": "2024-04-29T03:30:46Z",
"published": "2024-04-29T03:30:46Z",
"aliases": [
"CVE-2024-4297"
],
"details": "The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4297"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-7767-ce3b4-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T03:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mp7-6gp5-x248",
"modified": "2024-04-29T03:30:46Z",
"published": "2024-04-29T03:30:46Z",
"aliases": [
"CVE-2024-4296"
],
"details": "The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4296"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-7765-49906-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T02:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mvv-2pq8-4996",
"modified": "2024-04-29T03:30:46Z",
"published": "2024-04-29T03:30:46Z",
"aliases": [
"CVE-2024-4298"
],
"details": "The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4298"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-7769-0773a-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T03:15:09Z"
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwff-c3p7-fx7c",
"modified": "2024-04-29T03:30:46Z",
"published": "2024-04-29T03:30:46Z",
"aliases": [
"CVE-2024-33903"
],
"details": "In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision sensor function is not exposed to the Blueprint library.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33903"
},
{
"type": "WEB",
"url": "https://github.com/carla-simulator/carla/issues/7025"
},
{
"type": "WEB",
"url": "https://github.com/carla-simulator/carla/issues/7394#issuecomment-2058130066"
},
{
"type": "WEB",
"url": "https://github.com/carla-simulator/carla/pull/7445"
},
{
"type": "WEB",
"url": "https://github.com/carla-simulator/carla/blob/60bd026b4822b4edb8a68cc17b9119866f303853/Docs/core_concepts.md"
},
{
"type": "WEB",
"url": "https://github.com/carla-simulator/carla/tags"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T01:15:09Z"
}
}