From d0370b16bd804abb32b0eea6539fe6f61d0b880d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 15:38:51 +0000 Subject: [PATCH] Publish Advisories GHSA-fxf5-c62c-5f69 GHSA-2hcr-79rm-r8rp GHSA-vq2c-8m6j-g4vh GHSA-w796-2gq9-7jm8 GHSA-pjw3-8x26-xpwm GHSA-52qx-x9h4-rv8r GHSA-6f7w-r4p9-954c GHSA-c75m-w45q-rj2j GHSA-g724-p2vc-8mfg GHSA-m36q-xm37-vj27 GHSA-m5xw-hwxw-fq3j GHSA-mcwr-8p82-73rf GHSA-mw3w-3jx9-mhff GHSA-w4vv-pf24-vw92 GHSA-x4x5-jx9j-mmv7 GHSA-x9jv-836g-q3x7 GHSA-xq44-wcjx-g3w9 --- .../GHSA-fxf5-c62c-5f69.json | 7 ++- .../GHSA-2hcr-79rm-r8rp.json | 10 +++-- .../GHSA-vq2c-8m6j-g4vh.json | 4 +- .../GHSA-w796-2gq9-7jm8.json | 7 ++- .../GHSA-pjw3-8x26-xpwm.json | 15 ++++--- .../GHSA-52qx-x9h4-rv8r.json | 13 +++--- .../GHSA-6f7w-r4p9-954c.json | 33 ++++++++++++++ .../GHSA-c75m-w45q-rj2j.json | 11 +++-- .../GHSA-g724-p2vc-8mfg.json | 45 +++++++++++++++++++ .../GHSA-m36q-xm37-vj27.json | 15 ++++--- .../GHSA-m5xw-hwxw-fq3j.json | 11 +++-- .../GHSA-mcwr-8p82-73rf.json | 36 +++++++++++++++ .../GHSA-mw3w-3jx9-mhff.json | 11 +++-- .../GHSA-w4vv-pf24-vw92.json | 11 +++-- .../GHSA-x4x5-jx9j-mmv7.json | 15 +++++-- .../GHSA-x9jv-836g-q3x7.json | 36 +++++++++++++++ .../GHSA-xq44-wcjx-g3w9.json | 4 +- 17 files changed, 230 insertions(+), 54 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mcwr-8p82-73rf/GHSA-mcwr-8p82-73rf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x9jv-836g-q3x7/GHSA-x9jv-836g-q3x7.json diff --git a/advisories/unreviewed/2023/08/GHSA-fxf5-c62c-5f69/GHSA-fxf5-c62c-5f69.json b/advisories/unreviewed/2023/08/GHSA-fxf5-c62c-5f69/GHSA-fxf5-c62c-5f69.json index c14a1c15363..21b38504411 100644 --- a/advisories/unreviewed/2023/08/GHSA-fxf5-c62c-5f69/GHSA-fxf5-c62c-5f69.json +++ b/advisories/unreviewed/2023/08/GHSA-fxf5-c62c-5f69/GHSA-fxf5-c62c-5f69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json index 8eb4d623a0b..6293f6b25c1 100644 --- a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json +++ b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hcr-79rm-r8rp", - "modified": "2024-04-26T09:30:33Z", + "modified": "2024-11-29T15:37:52Z", "published": "2023-09-21T21:31:00Z", "aliases": [ "CVE-2023-41993" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -73,6 +71,10 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT213930" }, + { + "type": "WEB", + "url": "https://webkitgtk.org/security/WSA-2023-0009.html" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5527" diff --git a/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json b/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json index cdde60d48c8..69168d393de 100644 --- a/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json +++ b/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-w796-2gq9-7jm8/GHSA-w796-2gq9-7jm8.json b/advisories/unreviewed/2023/09/GHSA-w796-2gq9-7jm8/GHSA-w796-2gq9-7jm8.json index 13d8fc02f66..b88bc556aac 100644 --- a/advisories/unreviewed/2023/09/GHSA-w796-2gq9-7jm8/GHSA-w796-2gq9-7jm8.json +++ b/advisories/unreviewed/2023/09/GHSA-w796-2gq9-7jm8/GHSA-w796-2gq9-7jm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-pjw3-8x26-xpwm/GHSA-pjw3-8x26-xpwm.json b/advisories/unreviewed/2024/03/GHSA-pjw3-8x26-xpwm/GHSA-pjw3-8x26-xpwm.json index f8f4eff7434..6d531e578cd 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjw3-8x26-xpwm/GHSA-pjw3-8x26-xpwm.json +++ b/advisories/unreviewed/2024/03/GHSA-pjw3-8x26-xpwm/GHSA-pjw3-8x26-xpwm.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-pjw3-8x26-xpwm", - "modified": "2024-03-27T06:30:32Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2023-46051" ], "details": "TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T06:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json b/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json index 0824154d3d7..b4e606a27d5 100644 --- a/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json +++ b/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-52qx-x9h4-rv8r", - "modified": "2024-04-08T12:30:32Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-04-08T12:30:32Z", "aliases": [ "CVE-2024-27896" ], "details": "Input verification vulnerability in the log module.\nImpact: Successful exploitation of this vulnerability can affect integrity.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,7 +32,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T10:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json b/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json new file mode 100644 index 00000000000..9ffbe636f23 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f7w-r4p9-954c", + "modified": "2024-11-29T15:37:53Z", + "published": "2024-11-29T15:37:53Z", + "aliases": [ + "CVE-2024-48406" + ], + "details": "Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48406" + }, + { + "type": "WEB", + "url": "https://github.com/SunBK201/umicat/issues/2" + }, + { + "type": "WEB", + "url": "https://github.com/SunBK201/umicat/pull/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json b/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json index d7cfaaab11d..d4685a684be 100644 --- a/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json +++ b/advisories/unreviewed/2024/11/GHSA-c75m-w45q-rj2j/GHSA-c75m-w45q-rj2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c75m-w45q-rj2j", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-10980" ], "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json b/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json new file mode 100644 index 00000000000..da7e85c1d02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g724-p2vc-8mfg", + "modified": "2024-11-29T15:37:53Z", + "published": "2024-11-29T15:37:53Z", + "aliases": [ + "CVE-2024-36671" + ], + "details": "nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36671" + }, + { + "type": "WEB", + "url": "https://github.com/nodemcu/nodemcu-firmware/issues/3626" + }, + { + "type": "WEB", + "url": "https://github.com/nodemcu/nodemcu-firmware/pull/3633" + }, + { + "type": "WEB", + "url": "https://github.com/nodemcu/nodemcu-firmware/pull/3634" + }, + { + "type": "WEB", + "url": "https://github.com/nodemcu/nodemcu-firmware/pull/3635" + }, + { + "type": "WEB", + "url": "https://github.com/nodemcu/nodemcu-firmware/commit/193fe3593eb1537667179089535cdb7457327887#diff-5c3fa597431eda03ac3339ae6bf7f05e1a50d6fc7333679ec38e21b337cb6721" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json b/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json index 26cf600865f..f870e73aa33 100644 --- a/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json +++ b/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-m36q-xm37-vj27", - "modified": "2024-11-27T15:31:45Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-27T15:31:45Z", "aliases": [ "CVE-2024-53604" ], "details": "A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -25,9 +26,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T14:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m5xw-hwxw-fq3j/GHSA-m5xw-hwxw-fq3j.json b/advisories/unreviewed/2024/11/GHSA-m5xw-hwxw-fq3j/GHSA-m5xw-hwxw-fq3j.json index 060d568c3b4..9670922b0a2 100644 --- a/advisories/unreviewed/2024/11/GHSA-m5xw-hwxw-fq3j/GHSA-m5xw-hwxw-fq3j.json +++ b/advisories/unreviewed/2024/11/GHSA-m5xw-hwxw-fq3j/GHSA-m5xw-hwxw-fq3j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m5xw-hwxw-fq3j", - "modified": "2024-11-28T21:31:40Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-28T18:38:38Z", "aliases": [ "CVE-2024-52338" ], "details": "Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it \nreads Arrow IPC, Feather or Parquet data from untrusted sources (for \nexample, user-supplied input files). This vulnerability only affects the arrow R package, not other Apache Arrow \nimplementations or bindings unless those bindings are specifically used via the R package (for example, an R application that embeds a Python interpreter and uses PyArrow to read files from untrusted sources is still vulnerable if the arrow R package is an affected version). It is recommended that users of the arrow R package upgrade to 17.0.0 or later. Similarly, it\n is recommended that downstream libraries upgrade their dependency \nrequirements to arrow 17.0.0 or later. If using an affected\nversion of the package, untrusted data can read into a Table and its internal to_data_frame() method can be used as a workaround (e.g., read_parquet(..., as_data_frame = FALSE)$to_data_frame()).\n\n\nThis issue affects the Apache Arrow R package: from 4.0.0 through 16.1.0.\n\n\nUsers are recommended to upgrade to version 17.0.0, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T17:15:48Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mcwr-8p82-73rf/GHSA-mcwr-8p82-73rf.json b/advisories/unreviewed/2024/11/GHSA-mcwr-8p82-73rf/GHSA-mcwr-8p82-73rf.json new file mode 100644 index 00000000000..f052c18fad5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mcwr-8p82-73rf/GHSA-mcwr-8p82-73rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcwr-8p82-73rf", + "modified": "2024-11-29T15:37:53Z", + "published": "2024-11-29T15:37:53Z", + "aliases": [ + "CVE-2024-11992" + ], + "details": "Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page. This vulnerability allows an attacker to delete files stored on the server due to a lack of proper verification of user-supplied input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11992" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/path-traversal-vulnerability-quickcms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json index 111bc5a0171..e7a6af466e5 100644 --- a/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json +++ b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mw3w-3jx9-mhff", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-48651" ], "details": "In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T05:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json b/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json index 45287e7c2be..017bd76c5a7 100644 --- a/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json +++ b/advisories/unreviewed/2024/11/GHSA-w4vv-pf24-vw92/GHSA-w4vv-pf24-vw92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w4vv-pf24-vw92", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-10704" ], "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json b/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json index 5562a436fe2..93fd8804434 100644 --- a/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json +++ b/advisories/unreviewed/2024/11/GHSA-x4x5-jx9j-mmv7/GHSA-x4x5-jx9j-mmv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x4x5-jx9j-mmv7", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T15:37:53Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-39162" ], "details": "pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x9jv-836g-q3x7/GHSA-x9jv-836g-q3x7.json b/advisories/unreviewed/2024/11/GHSA-x9jv-836g-q3x7/GHSA-x9jv-836g-q3x7.json new file mode 100644 index 00000000000..2e256fb7f82 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x9jv-836g-q3x7/GHSA-x9jv-836g-q3x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9jv-836g-q3x7", + "modified": "2024-11-29T15:37:53Z", + "published": "2024-11-29T15:37:53Z", + "aliases": [ + "CVE-2024-11990" + ], + "details": "A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11990" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-netwin-surgemail" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json index a7e9aaecf46..549561c389b 100644 --- a/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json +++ b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",