diff --git a/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json b/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json index 2ebc754e94d..8e1a615b828 100644 --- a/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json +++ b/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcrr-rr6w-8c83", - "modified": "2023-12-22T19:51:38Z", + "modified": "2024-09-12T21:32:39Z", "published": "2023-12-22T12:31:52Z", "aliases": [ "CVE-2023-49391" @@ -55,7 +55,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/unreviewed/2023/02/GHSA-2xgw-64w9-83wm/GHSA-2xgw-64w9-83wm.json b/advisories/unreviewed/2023/02/GHSA-2xgw-64w9-83wm/GHSA-2xgw-64w9-83wm.json index ef1085a8d35..9adb82cebb1 100644 --- a/advisories/unreviewed/2023/02/GHSA-2xgw-64w9-83wm/GHSA-2xgw-64w9-83wm.json +++ b/advisories/unreviewed/2023/02/GHSA-2xgw-64w9-83wm/GHSA-2xgw-64w9-83wm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xgw-64w9-83wm", - "modified": "2023-02-09T21:30:28Z", + "modified": "2024-09-12T21:32:00Z", "published": "2023-02-02T18:30:48Z", "aliases": [ "CVE-2023-0651" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -36,6 +40,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.220038" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.82316" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json index 6b8046a18a1..3d622d500c1 100644 --- a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json +++ b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4qww-v3r6-7335/GHSA-4qww-v3r6-7335.json b/advisories/unreviewed/2023/10/GHSA-4qww-v3r6-7335/GHSA-4qww-v3r6-7335.json index 828b804dab2..c6b608c53c5 100644 --- a/advisories/unreviewed/2023/10/GHSA-4qww-v3r6-7335/GHSA-4qww-v3r6-7335.json +++ b/advisories/unreviewed/2023/10/GHSA-4qww-v3r6-7335/GHSA-4qww-v3r6-7335.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qww-v3r6-7335", - "modified": "2023-11-02T18:30:23Z", + "modified": "2024-09-12T21:32:00Z", "published": "2023-10-22T21:36:10Z", "aliases": [ "CVE-2023-46306" diff --git a/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json b/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json index 45bcbc03084..dea26f2f0fd 100644 --- a/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json +++ b/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json b/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json index e60e6422584..961e7848644 100644 --- a/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json +++ b/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json b/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json index 355e5c2afba..3871c1a810e 100644 --- a/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json +++ b/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json b/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json index 4c071c72a09..8ec006d35a9 100644 --- a/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json +++ b/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json b/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json index 4df6c156466..45f74edb075 100644 --- a/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json +++ b/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pp8-37pj-mhcc", - "modified": "2024-01-30T21:30:28Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52325" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-98" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json b/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json index 020aac7d7de..3816f15da17 100644 --- a/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json +++ b/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pmw-7j2g-cfp7", - "modified": "2024-07-29T09:36:16Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-07-29T09:36:16Z", "aliases": [ "CVE-2024-41143" ], "details": "Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T09:15:02Z" diff --git a/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json b/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json index 761a07ba104..7381cdde37b 100644 --- a/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json +++ b/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json b/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json index f24e471b436..39b601e259c 100644 --- a/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json +++ b/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27qw-rmpj-379q", - "modified": "2024-08-29T18:31:35Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44939" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix null ptr deref in dtInsertEntry\n\n[syzbot reported]\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nRIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713\n...\n[Analyze]\nIn dtInsertEntry(), when the pointer h has the same value as p, after writing\nname in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the\npreviously true judgment \"p->header.flag & BT-LEAF\" to change to no after writing\nthe name operation, this leads to entering an incorrect branch and accessing the\nuninitialized object ih when judging this condition for the second time.\n\n[Fix]\nAfter got the page, check freelist first, if freelist == 0 then exit dtInsert()\nand return -EINVAL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T12:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json index b42d76bd28d..3135cbe6494 100644 --- a/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json +++ b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27rm-pvpp-228f", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-37392" ], "details": "A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which gets executed when the SMS is viewed and specially interacted in web-GUI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T21:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2c74-9qcc-prpp/GHSA-2c74-9qcc-prpp.json b/advisories/unreviewed/2024/08/GHSA-2c74-9qcc-prpp/GHSA-2c74-9qcc-prpp.json index 3be0e570839..8d36016fc84 100644 --- a/advisories/unreviewed/2024/08/GHSA-2c74-9qcc-prpp/GHSA-2c74-9qcc-prpp.json +++ b/advisories/unreviewed/2024/08/GHSA-2c74-9qcc-prpp/GHSA-2c74-9qcc-prpp.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-277" + "CWE-277", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-3ffg-5vr4-3v59/GHSA-3ffg-5vr4-3v59.json b/advisories/unreviewed/2024/08/GHSA-3ffg-5vr4-3v59/GHSA-3ffg-5vr4-3v59.json index b901543b0c2..5df1d8b9ed9 100644 --- a/advisories/unreviewed/2024/08/GHSA-3ffg-5vr4-3v59/GHSA-3ffg-5vr4-3v59.json +++ b/advisories/unreviewed/2024/08/GHSA-3ffg-5vr4-3v59/GHSA-3ffg-5vr4-3v59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3ffg-5vr4-3v59", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44941" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to cover read extent cache access with lock\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\nRead of size 4 at addr ffff8880739ab220 by task syz-executor200/5097\n\nCPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\n do_read_inode fs/f2fs/inode.c:509 [inline]\n f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560\n f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237\n generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413\n exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444\n exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584\n do_handle_to_path fs/fhandle.c:155 [inline]\n handle_to_path fs/fhandle.c:210 [inline]\n do_handle_open+0x495/0x650 fs/fhandle.c:226\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWe missed to cover sanity_check_extent_cache() w/ extent cache lock,\nso, below race case may happen, result in use after free issue.\n\n- f2fs_iget\n - do_read_inode\n - f2fs_init_read_extent_tree\n : add largest extent entry in to cache\n\t\t\t\t\t- shrink\n\t\t\t\t\t - f2fs_shrink_read_extent_tree\n\t\t\t\t\t - __shrink_extent_tree\n\t\t\t\t\t - __detach_extent_node\n\t\t\t\t\t : drop largest extent entry\n - sanity_check_extent_cache\n : access et->largest w/o lock\n\nlet's refactor sanity_check_extent_cache() to avoid extent cache access\nand call it before f2fs_init_read_extent_tree() to fix this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T12:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7w35-8v2m-9grg/GHSA-7w35-8v2m-9grg.json b/advisories/unreviewed/2024/08/GHSA-7w35-8v2m-9grg/GHSA-7w35-8v2m-9grg.json index 8c340f5df99..53761d3c4b9 100644 --- a/advisories/unreviewed/2024/08/GHSA-7w35-8v2m-9grg/GHSA-7w35-8v2m-9grg.json +++ b/advisories/unreviewed/2024/08/GHSA-7w35-8v2m-9grg/GHSA-7w35-8v2m-9grg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-277" + "CWE-277", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json b/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json index ec903f5f619..c677a3373fe 100644 --- a/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json +++ b/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crf2-q686-qj4r", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-36446" ], "details": "The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T17:15:23Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pm23-3px3-qrh7/GHSA-pm23-3px3-qrh7.json b/advisories/unreviewed/2024/08/GHSA-pm23-3px3-qrh7/GHSA-pm23-3px3-qrh7.json index 625e6e7ae6f..c39abf99602 100644 --- a/advisories/unreviewed/2024/08/GHSA-pm23-3px3-qrh7/GHSA-pm23-3px3-qrh7.json +++ b/advisories/unreviewed/2024/08/GHSA-pm23-3px3-qrh7/GHSA-pm23-3px3-qrh7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pm23-3px3-qrh7", - "modified": "2024-08-26T00:30:54Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-26T00:30:54Z", "aliases": [ "CVE-2024-8158" ], "details": "A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any other valid filesystem user.\n\nThis is due to lib9p not properly verifying that the uname given in the Tauth and Tattach 9p messages matches the client UID returned from the factotum authentication handshake.\n\n\nThe only filesystem making use of these functions within the base 9front systems is the experimental hjfs disk filesystem, other disk filesystems (cwfs and gefs) are not affected by this bug.\n\nThis bug was inherited from Plan 9 and is present in all versions of 9front and is remedied fully in commit 9645ae07eb66a59015e3e118d0024790c37400da.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:C/RE:L/U:Red" diff --git a/advisories/unreviewed/2024/08/GHSA-vp43-mc38-mmg5/GHSA-vp43-mc38-mmg5.json b/advisories/unreviewed/2024/08/GHSA-vp43-mc38-mmg5/GHSA-vp43-mc38-mmg5.json index 434b25067bc..7541f84eae0 100644 --- a/advisories/unreviewed/2024/08/GHSA-vp43-mc38-mmg5/GHSA-vp43-mc38-mmg5.json +++ b/advisories/unreviewed/2024/08/GHSA-vp43-mc38-mmg5/GHSA-vp43-mc38-mmg5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vp43-mc38-mmg5", - "modified": "2024-08-26T03:30:44Z", + "modified": "2024-09-12T21:32:00Z", "published": "2024-08-26T03:30:44Z", "aliases": [ "CVE-2024-8073" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json b/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json new file mode 100644 index 00000000000..a6407f7db51 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qv6-5f5f-f89j", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-34336" + ], + "details": "User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34336" + }, + { + "type": "WEB", + "url": "https://mind-bytes.de/offenlegung-existierender-benutzerkonten-in-foss-online-cve-2024-34336" + }, + { + "type": "WEB", + "url": "http://foss-online.com" + }, + { + "type": "WEB", + "url": "http://ordat.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json b/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json index 6af9ccbdeee..0ed9bdc3c49 100644 --- a/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json +++ b/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h7r-mv43-gm2c", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-8399" ], "details": "Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T20:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-66wp-pmr8-89fq/GHSA-66wp-pmr8-89fq.json b/advisories/unreviewed/2024/09/GHSA-66wp-pmr8-89fq/GHSA-66wp-pmr8-89fq.json new file mode 100644 index 00000000000..f8d17723176 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-66wp-pmr8-89fq/GHSA-66wp-pmr8-89fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66wp-pmr8-89fq", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-45383" + ], + "details": "A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45383" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-664" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6c6w-688f-8mwx/GHSA-6c6w-688f-8mwx.json b/advisories/unreviewed/2024/09/GHSA-6c6w-688f-8mwx/GHSA-6c6w-688f-8mwx.json index 24c7c2b75fa..c73f9843e9f 100644 --- a/advisories/unreviewed/2024/09/GHSA-6c6w-688f-8mwx/GHSA-6c6w-688f-8mwx.json +++ b/advisories/unreviewed/2024/09/GHSA-6c6w-688f-8mwx/GHSA-6c6w-688f-8mwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6c6w-688f-8mwx", - "modified": "2024-09-12T18:31:42Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T18:31:42Z", "aliases": [ "CVE-2020-24061" ], "details": "Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies via a crafted script", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json b/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json index ac5d6094e8a..fbd64d05710 100644 --- a/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json +++ b/advisories/unreviewed/2024/09/GHSA-6pj4-296c-2375/GHSA-6pj4-296c-2375.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pj4-296c-2375", - "modified": "2024-09-12T06:30:22Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:22Z", "aliases": [ "CVE-2024-7766" ], "details": "The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json b/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json index 8acbf514867..a03579b95b7 100644 --- a/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json +++ b/advisories/unreviewed/2024/09/GHSA-6x3x-mhgp-4j2c/GHSA-6x3x-mhgp-4j2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6x3x-mhgp-4j2c", - "modified": "2024-09-12T06:30:21Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:21Z", "aliases": [ "CVE-2024-6019" ], "details": "The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json b/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json new file mode 100644 index 00000000000..bdf172d0ac9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ccr-ppgf-4r3x", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-44459" + ], + "details": "A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory consumption.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44459" + }, + { + "type": "WEB", + "url": "https://github.com/zzh-newlearner/MQTT_Crash/blob/main/Vernemq_crash.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8gv7-8h2v-9w6c/GHSA-8gv7-8h2v-9w6c.json b/advisories/unreviewed/2024/09/GHSA-8gv7-8h2v-9w6c/GHSA-8gv7-8h2v-9w6c.json index f8bdd5e809d..af7d9003c47 100644 --- a/advisories/unreviewed/2024/09/GHSA-8gv7-8h2v-9w6c/GHSA-8gv7-8h2v-9w6c.json +++ b/advisories/unreviewed/2024/09/GHSA-8gv7-8h2v-9w6c/GHSA-8gv7-8h2v-9w6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gv7-8h2v-9w6c", - "modified": "2024-09-03T18:31:32Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-03T18:31:32Z", "aliases": [ "CVE-2024-42903" ], "details": "A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T18:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-947f-qh3g-pcj5/GHSA-947f-qh3g-pcj5.json b/advisories/unreviewed/2024/09/GHSA-947f-qh3g-pcj5/GHSA-947f-qh3g-pcj5.json new file mode 100644 index 00000000000..dea88913f07 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-947f-qh3g-pcj5/GHSA-947f-qh3g-pcj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-947f-qh3g-pcj5", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-8311" + ], + "details": "An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8311" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/479315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-424" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json b/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json new file mode 100644 index 00000000000..4b8b98e1fe0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4q5-vjmp-xrgv", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-34335" + ], + "details": "ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34335" + }, + { + "type": "WEB", + "url": "https://mind-bytes.de/cross-site-scripting-in-foss-online-cve-2024-34335" + }, + { + "type": "WEB", + "url": "http://foss-online.com" + }, + { + "type": "WEB", + "url": "http://ordat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cf4q-v7mm-g53q/GHSA-cf4q-v7mm-g53q.json b/advisories/unreviewed/2024/09/GHSA-cf4q-v7mm-g53q/GHSA-cf4q-v7mm-g53q.json index a9bbdf29962..e380fcfefd9 100644 --- a/advisories/unreviewed/2024/09/GHSA-cf4q-v7mm-g53q/GHSA-cf4q-v7mm-g53q.json +++ b/advisories/unreviewed/2024/09/GHSA-cf4q-v7mm-g53q/GHSA-cf4q-v7mm-g53q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cf4q-v7mm-g53q", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-45678" ], "details": "Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T20:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json new file mode 100644 index 00000000000..f048d0659c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwr9-w5qw-fr62", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-44460" + ], + "details": "An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44460" + }, + { + "type": "WEB", + "url": "https://github.com/zzh-newlearner/MQTT_Crash/blob/main/Nanomq_invalid_read.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json b/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json new file mode 100644 index 00000000000..1c4820da2e3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jx-jjc7-hv9g", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-45181" + ], + "details": "An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45181" + }, + { + "type": "WEB", + "url": "https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-94453.pdf" + }, + { + "type": "WEB", + "url": "https://wibu.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g8hg-rjf5-vfrm/GHSA-g8hg-rjf5-vfrm.json b/advisories/unreviewed/2024/09/GHSA-g8hg-rjf5-vfrm/GHSA-g8hg-rjf5-vfrm.json new file mode 100644 index 00000000000..839d2f35287 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g8hg-rjf5-vfrm/GHSA-g8hg-rjf5-vfrm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8hg-rjf5-vfrm", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-4472" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4472" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2477062" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/460289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json b/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json new file mode 100644 index 00000000000..043421ee34a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g8mr-6p9f-7c7x/GHSA-g8mr-6p9f-7c7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8mr-6p9f-7c7x", + "modified": "2024-09-12T21:32:03Z", + "published": "2024-09-12T21:32:03Z", + "aliases": [ + "CVE-2024-7961" + ], + "details": "A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7961" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1695.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gvqc-g8mm-r66f/GHSA-gvqc-g8mm-r66f.json b/advisories/unreviewed/2024/09/GHSA-gvqc-g8mm-r66f/GHSA-gvqc-g8mm-r66f.json index afde8cf07d4..c8287895bd3 100644 --- a/advisories/unreviewed/2024/09/GHSA-gvqc-g8mm-r66f/GHSA-gvqc-g8mm-r66f.json +++ b/advisories/unreviewed/2024/09/GHSA-gvqc-g8mm-r66f/GHSA-gvqc-g8mm-r66f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvqc-g8mm-r66f", - "modified": "2024-09-10T06:30:49Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-10T06:30:49Z", "aliases": [ "CVE-2024-7891" ], "details": "The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json b/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json new file mode 100644 index 00000000000..13cb48a7fae --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcmh-526c-3ggp", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-45182" + ], + "details": "An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45182" + }, + { + "type": "WEB", + "url": "https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-94453.pdf" + }, + { + "type": "WEB", + "url": "https://wibu.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json b/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json index effb8aa60a3..d7baf3ca4cc 100644 --- a/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json +++ b/advisories/unreviewed/2024/09/GHSA-m2wr-9pq6-49jc/GHSA-m2wr-9pq6-49jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2wr-9pq6-49jc", - "modified": "2024-09-12T06:30:21Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:21Z", "aliases": [ "CVE-2024-6017" ], "details": "The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:23Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json b/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json new file mode 100644 index 00000000000..cbe9afd7c94 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m48w-79jh-f8w7/GHSA-m48w-79jh-f8w7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m48w-79jh-f8w7", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-25270" + ], + "details": "An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25270" + }, + { + "type": "WEB", + "url": "https://github.com/fbkcs/CVE-2024-25270" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json b/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json new file mode 100644 index 00000000000..0b00d9bb61f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrr5-8hm7-42xh", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-34334" + ], + "details": "ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34334" + }, + { + "type": "WEB", + "url": "https://mind-bytes.de/sql-injection-in-foss-online-cve-2024-34334" + }, + { + "type": "WEB", + "url": "http://foss-online.com" + }, + { + "type": "WEB", + "url": "http://ordat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ph8h-4mq7-vw5v/GHSA-ph8h-4mq7-vw5v.json b/advisories/unreviewed/2024/09/GHSA-ph8h-4mq7-vw5v/GHSA-ph8h-4mq7-vw5v.json new file mode 100644 index 00000000000..2d3b0748e9d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ph8h-4mq7-vw5v/GHSA-ph8h-4mq7-vw5v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph8h-4mq7-vw5v", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-6678" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6678" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2595495" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/471923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json b/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json new file mode 100644 index 00000000000..ff057a52209 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qj4x-mh6f-mw42/GHSA-qj4x-mh6f-mw42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj4x-mh6f-mw42", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-8533" + ], + "details": "A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8533" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1964.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json b/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json index 60dfd2ed4fc..784bb917312 100644 --- a/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json +++ b/advisories/unreviewed/2024/09/GHSA-qmm9-m4wr-gv24/GHSA-qmm9-m4wr-gv24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmm9-m4wr-gv24", - "modified": "2024-09-12T06:30:21Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:21Z", "aliases": [ "CVE-2024-6887" ], "details": "The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qxrx-gr5j-75cw/GHSA-qxrx-gr5j-75cw.json b/advisories/unreviewed/2024/09/GHSA-qxrx-gr5j-75cw/GHSA-qxrx-gr5j-75cw.json index 6e709d8a2a9..d5aa9c47b7a 100644 --- a/advisories/unreviewed/2024/09/GHSA-qxrx-gr5j-75cw/GHSA-qxrx-gr5j-75cw.json +++ b/advisories/unreviewed/2024/09/GHSA-qxrx-gr5j-75cw/GHSA-qxrx-gr5j-75cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxrx-gr5j-75cw", - "modified": "2024-09-03T18:31:32Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-03T18:31:32Z", "aliases": [ "CVE-2024-42904" ], "details": "A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T18:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json b/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json index 424718ae958..f83e15bac4d 100644 --- a/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json +++ b/advisories/unreviewed/2024/09/GHSA-rp3x-cq62-cvh4/GHSA-rp3x-cq62-cvh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rp3x-cq62-cvh4", - "modified": "2024-09-12T06:30:21Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:21Z", "aliases": [ "CVE-2024-6018" ], "details": "The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:23Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vpx9-6rc9-v679/GHSA-vpx9-6rc9-v679.json b/advisories/unreviewed/2024/09/GHSA-vpx9-6rc9-v679/GHSA-vpx9-6rc9-v679.json new file mode 100644 index 00000000000..a39c6f2c7ff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vpx9-6rc9-v679/GHSA-vpx9-6rc9-v679.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpx9-6rc9-v679", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-6077" + ], + "details": "A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6077" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpxq-m249-cq6r/GHSA-wpxq-m249-cq6r.json b/advisories/unreviewed/2024/09/GHSA-wpxq-m249-cq6r/GHSA-wpxq-m249-cq6r.json index 034159bdff5..4a2cb60b114 100644 --- a/advisories/unreviewed/2024/09/GHSA-wpxq-m249-cq6r/GHSA-wpxq-m249-cq6r.json +++ b/advisories/unreviewed/2024/09/GHSA-wpxq-m249-cq6r/GHSA-wpxq-m249-cq6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpxq-m249-cq6r", - "modified": "2024-09-12T06:30:21Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T06:30:21Z", "aliases": [ "CVE-2024-5799" ], "details": "The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T06:15:23Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x654-52cq-hxj3/GHSA-x654-52cq-hxj3.json b/advisories/unreviewed/2024/09/GHSA-x654-52cq-hxj3/GHSA-x654-52cq-hxj3.json new file mode 100644 index 00000000000..b6f5331a7c5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x654-52cq-hxj3/GHSA-x654-52cq-hxj3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x654-52cq-hxj3", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-8641" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8641" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2595495" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/471954" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-270" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json b/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json index ee7df4f0a51..4ce6bc5468e 100644 --- a/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json +++ b/advisories/unreviewed/2024/09/GHSA-x863-gchp-57m3/GHSA-x863-gchp-57m3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x863-gchp-57m3", - "modified": "2024-09-12T18:31:42Z", + "modified": "2024-09-12T21:32:01Z", "published": "2024-09-12T18:31:42Z", "aliases": [ "CVE-2024-41629" ], "details": "An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T18:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json b/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json new file mode 100644 index 00000000000..08c26a8717c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xj5f-4vpp-mxhf/GHSA-xj5f-4vpp-mxhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj5f-4vpp-mxhf", + "modified": "2024-09-12T21:32:03Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-7960" + ], + "details": "The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7960" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1695.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json b/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json new file mode 100644 index 00000000000..4b1bc86f052 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmrg-69jq-mfv5", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-36066" + ], + "details": "The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and only 6 octets long.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36066" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc4211#section-4.4" + }, + { + "type": "WEB", + "url": "https://support.keyfactor.com/hc/en-us/articles/26965687021595-EJBCA-Security-Advisory-EJBCA-standalone-CMP-CLI-client" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xwpv-8x3r-cvm2/GHSA-xwpv-8x3r-cvm2.json b/advisories/unreviewed/2024/09/GHSA-xwpv-8x3r-cvm2/GHSA-xwpv-8x3r-cvm2.json new file mode 100644 index 00000000000..6d803a9f4ee --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xwpv-8x3r-cvm2/GHSA-xwpv-8x3r-cvm2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwpv-8x3r-cvm2", + "modified": "2024-09-12T21:32:02Z", + "published": "2024-09-12T21:32:02Z", + "aliases": [ + "CVE-2024-20430" + ], + "details": "A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. \n\nThis vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged attacker could exploit this vulnerability by placing both malicious configuration files and malicious DLL files on an affected system, which would read and execute the files when Cisco Meraki SM launches on startup. A successful exploit could allow the attacker to execute arbitrary code on the affected system with SYSTEM privileges. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20430" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-agent-dll-hj-Ptn7PtKe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T20:15:04Z" + } +} \ No newline at end of file