Publish Advisories

GHSA-3p6c-w37j-m7g3
GHSA-g89w-hcgw-6g9p
GHSA-h4gg-fj5r-8573
GHSA-m295-r33q-79rg
GHSA-p5q6-j3pf-jwc7
GHSA-v7w7-wwgq-qmfw
GHSA-5gwf-rpm9-v6f8
GHSA-5p85-p472-x7wv
GHSA-75pc-2p8w-2hhf
GHSA-7p23-xhhw-3gg3
GHSA-jgmx-4v96-mgr5
GHSA-m5h5-93gh-rvhm
GHSA-pcwq-6cr8-wvr3
GHSA-r5r8-96pf-6r57
GHSA-v9vv-8xcq-rpqg
This commit is contained in:
advisory-database[bot]
2024-10-18 18:32:29 +00:00
parent 31f408c8ba
commit cfececf019
15 changed files with 281 additions and 14 deletions
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g89w-hcgw-6g9p",
"modified": "2024-01-30T00:30:29Z",
"modified": "2024-10-18T18:30:35Z",
"published": "2024-01-23T15:30:58Z",
"aliases": [
"CVE-2024-0755"
@@ -48,7 +48,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-276"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m295-r33q-79rg",
"modified": "2024-01-26T00:30:30Z",
"modified": "2024-10-18T18:30:36Z",
"published": "2024-01-26T00:30:30Z",
"aliases": [
"CVE-2024-23629"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gwf-rpm9-v6f8",
"modified": "2024-10-18T18:30:37Z",
"published": "2024-10-18T18:30:37Z",
"aliases": [
"CVE-2024-10120"
],
"details": "A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10120"
},
{
"type": "WEB",
"url": "https://github.com/weliveby/ForCVE/blob/main/radar%20Arbitrary%20file%20upload%20vulnerability.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.280912"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.280912"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.420959"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T17:15:12Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5p85-p472-x7wv",
"modified": "2024-10-08T00:31:40Z",
"modified": "2024-10-18T18:30:36Z",
"published": "2024-10-07T21:33:31Z",
"aliases": [
"CVE-2024-47967"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://https://www.solidigm.com/support-page/support-security.html"
},
{
"type": "WEB",
"url": "https://www.solidigm.com/support-page/support-security.html"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75pc-2p8w-2hhf",
"modified": "2024-10-18T18:30:37Z",
"published": "2024-10-18T18:30:36Z",
"aliases": [
"CVE-2023-6080"
],
"details": "Lakeside Softwares SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6080"
},
{
"type": "WEB",
"url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0009.md"
},
{
"type": "WEB",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-6080"
},
{
"type": "WEB",
"url": "https://www.lakesidesoftware.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-379"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T17:15:12Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7p23-xhhw-3gg3",
"modified": "2024-10-18T18:30:37Z",
"published": "2024-10-18T18:30:37Z",
"aliases": [
"CVE-2024-9593"
],
"details": "The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9593"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/time-clock/tags/1.2.2/includes/admin/ajax_functions_admin.php#L58"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3171046/time-clock#file40"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/247e599a-74e2-41d5-a1ba-978a807e6544?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T18:15:04Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgmx-4v96-mgr5",
"modified": "2024-10-07T21:33:31Z",
"modified": "2024-10-18T18:30:36Z",
"published": "2024-10-07T21:33:31Z",
"aliases": [
"CVE-2024-47974"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://https://www.solidigm.com/support-page/support-security.html"
},
{
"type": "WEB",
"url": "https://www.solidigm.com/support-page/support-security.html"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m5h5-93gh-rvhm",
"modified": "2024-10-18T18:30:36Z",
"published": "2024-10-18T18:30:36Z",
"aliases": [
"CVE-2024-42508"
],
"details": "This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42508"
},
{
"type": "WEB",
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04721en_us&docLocale=en_US"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T16:15:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcwq-6cr8-wvr3",
"modified": "2024-10-18T18:30:37Z",
"published": "2024-10-18T18:30:37Z",
"aliases": [
"CVE-2024-48016"
],
"details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use exposed credentials to access the system with privileges of the compromised account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48016"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T17:15:13Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5r8-96pf-6r57",
"modified": "2024-10-18T18:30:37Z",
"published": "2024-10-18T18:30:37Z",
"aliases": [
"CVE-2024-47241"
],
"details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47241"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T17:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9vv-8xcq-rpqg",
"modified": "2024-10-18T00:31:16Z",
"modified": "2024-10-18T18:30:36Z",
"published": "2024-10-18T00:31:16Z",
"aliases": [
"CVE-2024-27766"
],
"details": "An issue in MYSQL MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T22:15:02Z"