Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-13 15:32:08 +00:00
parent a881675883
commit d008bffbff
244 changed files with 8392 additions and 19 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjp4-hw94-mvp5",
"modified": "2024-05-02T18:47:14Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2024-03-21T09:31:14Z",
"aliases": [
"CVE-2024-29131"
@@ -64,6 +64,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0001"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/03/20/4"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-735f-pc8j-v9w8",
"modified": "2024-09-23T20:07:08Z",
"modified": "2024-12-13T15:30:39Z",
"published": "2024-09-19T16:06:03Z",
"aliases": [
"CVE-2024-7254"
@@ -345,6 +345,10 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/google-protobuf/CVE-2024-7254.yml"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0010"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mxm-8w9r-4997",
"modified": "2022-05-13T01:27:49Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2022-05-13T01:27:49Z",
"aliases": [
"CVE-2018-12122"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202003-48"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0009"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/106043"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6m9-hpfw-xjw4",
"modified": "2022-05-13T01:27:48Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2022-05-13T01:27:48Z",
"aliases": [
"CVE-2018-12123"
@@ -30,10 +30,15 @@
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202003-48"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0008"
}
],
"database_specific": {
"cwe_ids": [
"CWE-115",
"CWE-20"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh5x-7c5f-4c44",
"modified": "2022-05-13T01:16:06Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2022-05-13T01:16:06Z",
"aliases": [
"CVE-2018-7738"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://bugs.debian.org/892179"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0002"
},
{
"type": "WEB",
"url": "https://usn.ubuntu.com/4512-1"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv82-vf69-rqqm",
"modified": "2022-05-13T01:04:11Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2022-05-13T01:04:11Z",
"aliases": [
"CVE-2017-9217"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://launchpad.net/bugs/1621396"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0003"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/98677"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9hr-fvm9-7c49",
"modified": "2024-04-04T04:02:38Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2023-05-11T18:30:17Z",
"aliases": [
"CVE-2023-29400"
@@ -34,6 +34,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-1753"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0005"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2cj-5636-4j38",
"modified": "2023-11-25T12:30:22Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2023-06-08T21:30:27Z",
"aliases": [
"CVE-2023-29402"
@@ -46,6 +46,10 @@
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202311-09"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0004"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53mx-8hhc-gmp3",
"modified": "2024-11-27T18:34:03Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2024-11-26T15:31:01Z",
"aliases": [
"CVE-2024-11691"
@@ -46,6 +46,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-68"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-70"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g337-g667-mjvw",
"modified": "2024-11-25T21:30:48Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2024-11-06T09:31:21Z",
"aliases": [
"CVE-2024-9681"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://curl.se/docs/CVE-2024-9681.json"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241213-0006"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/11/06/2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjcw-r3mg-3848",
"modified": "2024-11-27T18:34:03Z",
"modified": "2024-12-13T15:30:38Z",
"published": "2024-11-26T15:31:02Z",
"aliases": [
"CVE-2024-11694"
@@ -42,6 +42,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-68"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-70"
}
],
"database_specific": {
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23hv-h2r7-ggj5",
"modified": "2024-12-13T15:30:43Z",
"published": "2024-12-13T15:30:43Z",
"aliases": [
"CVE-2024-54266"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54266"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/imagerecycle-pdf-image-compression/vulnerability/wordpress-imagerecycle-pdf-image-compression-plugin-3-1-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:30Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26vh-hjq5-fv9v",
"modified": "2024-12-13T15:30:40Z",
"published": "2024-12-13T15:30:40Z",
"aliases": [
"CVE-2023-33324"
],
"details": "Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33324"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/easy-captcha/vulnerability/wordpress-easy-captcha-plugin-1-0-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:13Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-294c-hx25-mgvq",
"modified": "2024-12-13T15:30:39Z",
"published": "2024-12-13T15:30:39Z",
"aliases": [
"CVE-2024-48007"
],
"details": "Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48007"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T14:15:22Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fh3-rm73-hjxf",
"modified": "2024-12-13T15:30:44Z",
"published": "2024-12-13T15:30:44Z",
"aliases": [
"CVE-2024-54314"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54314"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/primary-addon-for-elementor/vulnerability/wordpress-primary-addon-for-elementor-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:37Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2hf9-h2hv-2f9c",
"modified": "2024-12-13T15:30:39Z",
"published": "2024-12-13T15:30:39Z",
"aliases": [
"CVE-2022-46795"
],
"details": "Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46795"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/woocommerce-delivery-notes/vulnerability/wordpress-print-invoice-delivery-notes-for-woocommerce-plugin-4-7-2-csrf-plugin-settings-reset-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jpx-8fpp-54rx",
"modified": "2024-12-13T15:30:42Z",
"published": "2024-12-13T15:30:42Z",
"aliases": [
"CVE-2023-41849"
],
"details": "Missing Authorization vulnerability in WP Happy Coders Posts Like Dislike allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Like Dislike: from n/a through 1.1.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41849"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/posts-like-dislike/vulnerability/wordpress-posts-like-dislike-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:24Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q85-m42h-7pqh",
"modified": "2024-12-13T15:30:43Z",
"published": "2024-12-13T15:30:43Z",
"aliases": [
"CVE-2024-54278"
],
"details": "Missing Authorization vulnerability in Plugin Devs News Ticker for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects News Ticker for Elementor: from n/a through 2.1.3.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54278"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/news-ticker-for-elementor/vulnerability/wordpress-news-ticker-for-elementor-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:32Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v26-7fm5-rmj8",
"modified": "2024-12-13T15:30:42Z",
"published": "2024-12-13T15:30:42Z",
"aliases": [
"CVE-2023-41848"
],
"details": "Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41848"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/carousel-slider/vulnerability/wordpress-carousel-slider-plugin-2-2-2-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:24Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33wx-gh7x-xv44",
"modified": "2024-12-13T15:30:42Z",
"published": "2024-12-13T15:30:42Z",
"aliases": [
"CVE-2023-41870"
],
"details": "Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41870"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/wp-crowdfunding/vulnerability/wordpress-wp-crowdfunding-plugin-2-1-5-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-13T15:15:25Z"
}
}

Some files were not shown because too many files have changed in this diff Show More