From d04ea08d16d427b9ede80de835f39a4440985587 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Jun 2024 09:32:01 +0000 Subject: [PATCH] Publish Advisories GHSA-2mhw-g2wf-7mpp GHSA-53r7-4q94-9fmr GHSA-fj7x-4jpw-qx69 GHSA-g5m9-q65c-x6m4 GHSA-gr87-q8xh-gq3c GHSA-jwjx-w4p3-gp4r GHSA-vwh8-pv47-v9mx --- .../GHSA-2mhw-g2wf-7mpp.json | 38 +++++++++++++++ .../GHSA-53r7-4q94-9fmr.json | 42 +++++++++++++++++ .../GHSA-fj7x-4jpw-qx69.json | 46 +++++++++++++++++++ .../GHSA-g5m9-q65c-x6m4.json | 38 +++++++++++++++ .../GHSA-gr87-q8xh-gq3c.json | 38 +++++++++++++++ .../GHSA-jwjx-w4p3-gp4r.json | 38 +++++++++++++++ .../GHSA-vwh8-pv47-v9mx.json | 31 +++++++++++++ 7 files changed, 271 insertions(+) create mode 100644 advisories/unreviewed/2024/06/GHSA-2mhw-g2wf-7mpp/GHSA-2mhw-g2wf-7mpp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json create mode 100644 advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gr87-q8xh-gq3c/GHSA-gr87-q8xh-gq3c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jwjx-w4p3-gp4r/GHSA-jwjx-w4p3-gp4r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vwh8-pv47-v9mx/GHSA-vwh8-pv47-v9mx.json diff --git a/advisories/unreviewed/2024/06/GHSA-2mhw-g2wf-7mpp/GHSA-2mhw-g2wf-7mpp.json b/advisories/unreviewed/2024/06/GHSA-2mhw-g2wf-7mpp/GHSA-2mhw-g2wf-7mpp.json new file mode 100644 index 00000000000..2074c7e92a4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2mhw-g2wf-7mpp/GHSA-2mhw-g2wf-7mpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mhw-g2wf-7mpp", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-36394" + ], + "details": "SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36394" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json b/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json new file mode 100644 index 00000000000..e0c8e28ab47 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53r7-4q94-9fmr", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-5221" + ], + "details": "The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5221" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3097241%40qi-blocks%2Ftrunk&old=3094374%40qi-blocks%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bdf00861-e31e-485c-a562-12dba56af1c7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json new file mode 100644 index 00000000000..6509aac25a3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj7x-4jpw-qx69", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-5665" + ], + "details": "The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary options on affected sites.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5665" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-login-woocommerce/trunk/includes/xoo-framework/admin/class-xoo-admin-settings.php?rev=3084943#L69" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3093994" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a304e9a-9518-4a6a-b36a-963cb329f5c3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T08:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json b/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json new file mode 100644 index 00000000000..a7ed618f740 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5m9-q65c-x6m4", + "modified": "2024-06-06T09:30:51Z", + "published": "2024-06-06T09:30:51Z", + "aliases": [ + "CVE-2024-4177" + ], + "details": "A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-2 that are running only on premise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4177" + }, + { + "type": "WEB", + "url": "https://bitdefender.com/consumer/support/support/security-advisories/host-whitelist-parser-issue-in-gravityzone-console-on-premise-va-11554" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T08:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gr87-q8xh-gq3c/GHSA-gr87-q8xh-gq3c.json b/advisories/unreviewed/2024/06/GHSA-gr87-q8xh-gq3c/GHSA-gr87-q8xh-gq3c.json new file mode 100644 index 00000000000..06067a185ce --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gr87-q8xh-gq3c/GHSA-gr87-q8xh-gq3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr87-q8xh-gq3c", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-28995" + ], + "details": "\n\n\n\n\n\n\n\n\n\n\n\nSolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. \n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28995" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28995" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jwjx-w4p3-gp4r/GHSA-jwjx-w4p3-gp4r.json b/advisories/unreviewed/2024/06/GHSA-jwjx-w4p3-gp4r/GHSA-jwjx-w4p3-gp4r.json new file mode 100644 index 00000000000..488c83520d1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jwjx-w4p3-gp4r/GHSA-jwjx-w4p3-gp4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwjx-w4p3-gp4r", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-36393" + ], + "details": "SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36393" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vwh8-pv47-v9mx/GHSA-vwh8-pv47-v9mx.json b/advisories/unreviewed/2024/06/GHSA-vwh8-pv47-v9mx/GHSA-vwh8-pv47-v9mx.json new file mode 100644 index 00000000000..10bc2de5686 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vwh8-pv47-v9mx/GHSA-vwh8-pv47-v9mx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwh8-pv47-v9mx", + "modified": "2024-06-06T09:30:52Z", + "published": "2024-06-06T09:30:52Z", + "aliases": [ + "CVE-2024-5089" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5089" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T09:15:14Z" + } +} \ No newline at end of file