diff --git a/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json b/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json new file mode 100644 index 00000000000..7aa38818c84 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33vc-jm33-3f35", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55578" + ], + "details": "Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55578" + }, + { + "type": "WEB", + "url": "https://zammad.com/en/advisories/zaa-2024-05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json b/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json new file mode 100644 index 00000000000..25bb1ed12db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-38h9-g2p9-689w/GHSA-38h9-g2p9-689w.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38h9-g2p9-689w", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-12351" + ], + "details": "A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\\main\\java\\com\\cms\\entity\\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12351" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/JFinalCMS/sql-1/SQL_injection_vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287271" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287271" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-39hq-6rjp-w7f3/GHSA-39hq-6rjp-w7f3.json b/advisories/unreviewed/2024/12/GHSA-39hq-6rjp-w7f3/GHSA-39hq-6rjp-w7f3.json new file mode 100644 index 00000000000..aa199c67819 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-39hq-6rjp-w7f3/GHSA-39hq-6rjp-w7f3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39hq-6rjp-w7f3", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-12354" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12354" + }, + { + "type": "WEB", + "url": "https://github.com/jasontimwong/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457477" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3m63-4rwc-c6p8/GHSA-3m63-4rwc-c6p8.json b/advisories/unreviewed/2024/12/GHSA-3m63-4rwc-c6p8/GHSA-3m63-4rwc-c6p8.json new file mode 100644 index 00000000000..e64b46034fb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3m63-4rwc-c6p8/GHSA-3m63-4rwc-c6p8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m63-4rwc-c6p8", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-12352" + ], + "details": "A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12352" + }, + { + "type": "WEB", + "url": "https://github.com/zheng0064/cve/blob/main/StackOverFlow-CVE.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287272" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287272" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457392" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5985-x66x-p86v/GHSA-5985-x66x-p86v.json b/advisories/unreviewed/2024/12/GHSA-5985-x66x-p86v/GHSA-5985-x66x-p86v.json new file mode 100644 index 00000000000..ae4558760b1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5985-x66x-p86v/GHSA-5985-x66x-p86v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5985-x66x-p86v", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-12353" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name leads to improper input validation. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12353" + }, + { + "type": "WEB", + "url": "https://github.com/jasontimwong/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457438" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json b/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json new file mode 100644 index 00000000000..b1994d683e7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gjq-58c4-9ff5", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55564" + ], + "details": "The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55564" + }, + { + "type": "WEB", + "url": "https://metacpan.org/dist/POSIX-2008/changes" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-82x2-v3jv-gmrq/GHSA-82x2-v3jv-gmrq.json b/advisories/unreviewed/2024/12/GHSA-82x2-v3jv-gmrq/GHSA-82x2-v3jv-gmrq.json new file mode 100644 index 00000000000..a555ef26be0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-82x2-v3jv-gmrq/GHSA-82x2-v3jv-gmrq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82x2-v3jv-gmrq", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55563" + ], + "details": "Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents propagation of certain Lightning channel transactions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55563" + }, + { + "type": "WEB", + "url": "https://ariard.github.io" + }, + { + "type": "WEB", + "url": "https://bitcoincore.org" + }, + { + "type": "WEB", + "url": "https://delvingbitcoin.org/t/full-disclosure-transaction-relay-throughput-overflow-attacks-against-off-chain-protocols/1305" + }, + { + "type": "WEB", + "url": "https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures" + }, + { + "type": "WEB", + "url": "https://gnusha.org/pi/bitcoindev/CALZpt+EptER=p+P7VN3QAb9n=dODA9_LnR9xZwWpRsdAwedv=w@mail.gmail.com/T/#u" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json b/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json new file mode 100644 index 00000000000..078fa505bb6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8m4x-x8j4-mx4j/GHSA-8m4x-x8j4-mx4j.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m4x-x8j4-mx4j", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55582" + ], + "details": "Oxide before 6 has unencrypted Control Plane datastores.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55582" + }, + { + "type": "WEB", + "url": "https://docs.oxide.computer/security/advisories/20240118-1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c2xj-3mxc-4w9q/GHSA-c2xj-3mxc-4w9q.json b/advisories/unreviewed/2024/12/GHSA-c2xj-3mxc-4w9q/GHSA-c2xj-3mxc-4w9q.json new file mode 100644 index 00000000000..ccba7c7b51e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c2xj-3mxc-4w9q/GHSA-c2xj-3mxc-4w9q.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2xj-3mxc-4w9q", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55579" + ], + "details": "An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55579" + }, + { + "type": "WEB", + "url": "https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cc5m-pjxm-3867/GHSA-cc5m-pjxm-3867.json b/advisories/unreviewed/2024/12/GHSA-cc5m-pjxm-3867/GHSA-cc5m-pjxm-3867.json new file mode 100644 index 00000000000..c9993ee5871 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cc5m-pjxm-3867/GHSA-cc5m-pjxm-3867.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc5m-pjxm-3867", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55580" + ], + "details": "An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality risks. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55580" + }, + { + "type": "WEB", + "url": "https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cf5p-5qph-mhwp/GHSA-cf5p-5qph-mhwp.json b/advisories/unreviewed/2024/12/GHSA-cf5p-5qph-mhwp/GHSA-cf5p-5qph-mhwp.json new file mode 100644 index 00000000000..4e216accb2a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cf5p-5qph-mhwp/GHSA-cf5p-5qph-mhwp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf5p-5qph-mhwp", + "modified": "2024-12-09T03:30:58Z", + "published": "2024-12-09T03:30:58Z", + "aliases": [ + "CVE-2024-12348" + ], + "details": "A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12348" + }, + { + "type": "WEB", + "url": "https://github.com/dycccccccc/jpress/blob/main/JPRESS%20has%20XSS%20vulnerability.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287268" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287268" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.454825" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T01:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mwcw-c2x4-8c55/GHSA-mwcw-c2x4-8c55.json b/advisories/unreviewed/2024/12/GHSA-mwcw-c2x4-8c55/GHSA-mwcw-c2x4-8c55.json new file mode 100644 index 00000000000..2fd2a4a5d37 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mwcw-c2x4-8c55/GHSA-mwcw-c2x4-8c55.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwcw-c2x4-8c55", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55565" + ], + "details": "nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55565" + }, + { + "type": "WEB", + "url": "https://github.com/ai/nanoid/pull/510" + }, + { + "type": "WEB", + "url": "https://github.com/ai/nanoid/compare/3.3.7...3.3.8" + }, + { + "type": "WEB", + "url": "https://github.com/ai/nanoid/releases/tag/5.0.9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json b/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json new file mode 100644 index 00000000000..d93bf0bbde8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p4gh-942g-mc76/GHSA-p4gh-942g-mc76.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4gh-942g-mc76", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-55566" + ], + "details": "ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55566" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1225617" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/335.html" + }, + { + "type": "WEB", + "url": "https://github.com/CSCsw/ColPack/blob/9a7293a8dfd66a60434496b8df5ebb4274d70339/src/Utilities/extra.cpp#L184-L190" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json b/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json new file mode 100644 index 00000000000..df9493e29c6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rvc2-xvxc-m9fw/GHSA-rvc2-xvxc-m9fw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvc2-xvxc-m9fw", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:58Z", + "aliases": [ + "CVE-2024-12350" + ], + "details": "A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \\src\\main\\java\\com\\cms\\controller\\admin\\TemplateController.java of the component Template Handler. The manipulation of the argument content leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12350" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/JFinalCMS/Server_Side%20_Template_Injection/Server-Side-Template-Injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287270" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287270" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T01:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v8vc-6766-vww4/GHSA-v8vc-6766-vww4.json b/advisories/unreviewed/2024/12/GHSA-v8vc-6766-vww4/GHSA-v8vc-6766-vww4.json new file mode 100644 index 00000000000..68e7428d354 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v8vc-6766-vww4/GHSA-v8vc-6766-vww4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8vc-6766-vww4", + "modified": "2024-12-09T03:30:58Z", + "published": "2024-12-09T03:30:58Z", + "aliases": [ + "CVE-2024-12349" + ], + "details": "A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12349" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/JFinalCMS/Cross_Site_Request_Forgery/Cross-Site-Request-Forgery.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287269" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287269" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T01:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wx36-4mc3-6qf5/GHSA-wx36-4mc3-6qf5.json b/advisories/unreviewed/2024/12/GHSA-wx36-4mc3-6qf5/GHSA-wx36-4mc3-6qf5.json new file mode 100644 index 00000000000..baa45893606 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wx36-4mc3-6qf5/GHSA-wx36-4mc3-6qf5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx36-4mc3-6qf5", + "modified": "2024-12-09T03:30:59Z", + "published": "2024-12-09T03:30:59Z", + "aliases": [ + "CVE-2024-12355" + ], + "details": "A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input validation. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12355" + }, + { + "type": "WEB", + "url": "https://github.com/TinkAnet/cve/blob/main/BOF2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287275" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287275" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457864" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T02:15:19Z" + } +} \ No newline at end of file