From cfececf0190cde230a0e4ba8ef2fb4f260760aa9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 18 Oct 2024 18:32:29 +0000 Subject: [PATCH] Publish Advisories GHSA-3p6c-w37j-m7g3 GHSA-g89w-hcgw-6g9p GHSA-h4gg-fj5r-8573 GHSA-m295-r33q-79rg GHSA-p5q6-j3pf-jwc7 GHSA-v7w7-wwgq-qmfw GHSA-5gwf-rpm9-v6f8 GHSA-5p85-p472-x7wv GHSA-75pc-2p8w-2hhf GHSA-7p23-xhhw-3gg3 GHSA-jgmx-4v96-mgr5 GHSA-m5h5-93gh-rvhm GHSA-pcwq-6cr8-wvr3 GHSA-r5r8-96pf-6r57 GHSA-v9vv-8xcq-rpqg --- .../GHSA-3p6c-w37j-m7g3.json | 2 +- .../GHSA-g89w-hcgw-6g9p.json | 4 +- .../GHSA-h4gg-fj5r-8573.json | 3 +- .../GHSA-m295-r33q-79rg.json | 5 +- .../GHSA-p5q6-j3pf-jwc7.json | 2 +- .../GHSA-v7w7-wwgq-qmfw.json | 2 +- .../GHSA-5gwf-rpm9-v6f8.json | 54 +++++++++++++++++++ .../GHSA-5p85-p472-x7wv.json | 6 ++- .../GHSA-75pc-2p8w-2hhf.json | 43 +++++++++++++++ .../GHSA-7p23-xhhw-3gg3.json | 46 ++++++++++++++++ .../GHSA-jgmx-4v96-mgr5.json | 6 ++- .../GHSA-m5h5-93gh-rvhm.json | 35 ++++++++++++ .../GHSA-pcwq-6cr8-wvr3.json | 38 +++++++++++++ .../GHSA-r5r8-96pf-6r57.json | 38 +++++++++++++ .../GHSA-v9vv-8xcq-rpqg.json | 11 ++-- 15 files changed, 281 insertions(+), 14 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json diff --git a/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json b/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json index 794e858ae4a..b89b1e6cd44 100644 --- a/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json +++ b/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json b/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json index c5b74c3b713..c2b19a244e7 100644 --- a/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json +++ b/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g89w-hcgw-6g9p", - "modified": "2024-01-30T00:30:29Z", + "modified": "2024-10-18T18:30:35Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0755" @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json b/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json index f13a280a489..2bd786a5958 100644 --- a/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json +++ b/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json b/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json index ac02557ba63..5b0b7ea87af 100644 --- a/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json +++ b/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m295-r33q-79rg", - "modified": "2024-01-26T00:30:30Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-01-26T00:30:30Z", "aliases": [ "CVE-2024-23629" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json b/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json index c3e19998341..77dab4ec70e 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json +++ b/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json b/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json index d19f7e079c2..e7592fa450b 100644 --- a/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json +++ b/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json b/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json new file mode 100644 index 00000000000..11895af050b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gwf-rpm9-v6f8", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-10120" + ], + "details": "A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10120" + }, + { + "type": "WEB", + "url": "https://github.com/weliveby/ForCVE/blob/main/radar%20Arbitrary%20file%20upload%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420959" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json index 72ba60fe686..af948854016 100644 --- a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json +++ b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p85-p472-x7wv", - "modified": "2024-10-08T00:31:40Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-07T21:33:31Z", "aliases": [ "CVE-2024-47967" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://https://www.solidigm.com/support-page/support-security.html" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json new file mode 100644 index 00000000000..90291c855bd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75pc-2p8w-2hhf", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:36Z", + "aliases": [ + "CVE-2023-6080" + ], + "details": "Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6080" + }, + { + "type": "WEB", + "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0009.md" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2023-6080" + }, + { + "type": "WEB", + "url": "https://www.lakesidesoftware.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-379" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json b/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json new file mode 100644 index 00000000000..28e72c9d009 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p23-xhhw-3gg3", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-9593" + ], + "details": "The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9593" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/time-clock/tags/1.2.2/includes/admin/ajax_functions_admin.php#L58" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3171046/time-clock#file40" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/247e599a-74e2-41d5-a1ba-978a807e6544?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json index 7ada2dd68e7..32620b758e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json +++ b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jgmx-4v96-mgr5", - "modified": "2024-10-07T21:33:31Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-07T21:33:31Z", "aliases": [ "CVE-2024-47974" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://https://www.solidigm.com/support-page/support-security.html" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json new file mode 100644 index 00000000000..75b35c67a77 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5h5-93gh-rvhm", + "modified": "2024-10-18T18:30:36Z", + "published": "2024-10-18T18:30:36Z", + "aliases": [ + "CVE-2024-42508" + ], + "details": "This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42508" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04721en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json b/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json new file mode 100644 index 00000000000..2583287c9b6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcwq-6cr8-wvr3", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-48016" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use exposed credentials to access the system with privileges of the compromised account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48016" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json b/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json new file mode 100644 index 00000000000..71bfd9e6681 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5r8-96pf-6r57", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-47241" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47241" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json b/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json index 3554ee6637f..718f07a801c 100644 --- a/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json +++ b/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9vv-8xcq-rpqg", - "modified": "2024-10-18T00:31:16Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-18T00:31:16Z", "aliases": [ "CVE-2024-27766" ], "details": "An issue in MYSQL MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-17T22:15:02Z"