Publish Advisories

GHSA-7w75-32cg-r6g2
GHSA-v682-8vv8-vpwr
GHSA-v727-f437-6cxx
GHSA-4jrv-6m77-vrhq
GHSA-fg9q-5cw2-p6r9
GHSA-39jw-2mcp-w35j
GHSA-5jm7-9q58-m675
GHSA-7jjc-f4w2-6g7w
GHSA-97xg-px2h-jvxp
GHSA-99jc-8q77-587x
GHSA-c38h-r4wc-m6rm
GHSA-c52r-8hmj-x4qg
GHSA-c9h7-qc47-j43v
GHSA-fh3p-6j2p-f5qv
GHSA-pf5m-h35j-7c4j
GHSA-wxj3-5cjf-39gh
GHSA-x6r6-h48x-gp8f
This commit is contained in:
advisory-database[bot]
2024-04-03 00:32:14 +00:00
parent 3ed0d048f0
commit d31d8a0f8d
17 changed files with 590 additions and 5 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w75-32cg-r6g2",
"modified": "2024-03-15T16:27:54Z",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-03-13T18:31:34Z",
"aliases": [
"CVE-2024-24549"
@@ -217,6 +217,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240402-0002"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v682-8vv8-vpwr",
"modified": "2024-03-14T14:04:04Z",
"modified": "2024-04-03T00:30:54Z",
"published": "2024-03-13T18:31:34Z",
"aliases": [
"CVE-2024-23672"
@@ -129,6 +129,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240402-0002"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v727-f437-6cxx",
"modified": "2024-04-02T21:30:27Z",
"modified": "2024-04-03T00:30:54Z",
"published": "2023-12-21T21:30:31Z",
"aliases": [
"CVE-2023-6546"
@@ -65,6 +65,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1612"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1614"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6546"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jrv-6m77-vrhq",
"modified": "2024-04-02T21:30:27Z",
"modified": "2024-04-03T00:30:54Z",
"published": "2024-01-15T21:30:24Z",
"aliases": [
"CVE-2024-0565"
@@ -41,6 +41,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1607"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1614"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0565"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fg9q-5cw2-p6r9",
"modified": "2024-03-07T21:30:21Z",
"modified": "2024-04-03T00:30:54Z",
"published": "2024-03-07T21:30:21Z",
"aliases": [
"CVE-2024-1725"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1725"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1559"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1725"
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39jw-2mcp-w35j",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:56Z",
"aliases": [
"CVE-2024-3221"
],
"details": "A vulnerability classified as critical was found in SourceCodester PHP Task Management System 1.0. This vulnerability affects unknown code of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259066 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3221"
},
{
"type": "WEB",
"url": "https://github.com/SLthendieck/cve-report/blob/main/1.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259066"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259066"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.308626"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T00:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jm7-9q58-m675",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3202"
],
"details": "A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-259049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3202"
},
{
"type": "WEB",
"url": "https://github.com/lcg-22266/cms/blob/main/2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259049"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259049"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.303941"
}
],
"database_specific": {
"cwe_ids": [
"CWE-307"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T22:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jjc-f4w2-6g7w",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:56Z",
"aliases": [
"CVE-2024-3248"
],
"details": "In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3248"
},
{
"type": "WEB",
"url": "https://forum.xpdfreader.com/viewtopic.php?t=43657"
}
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T23:15:55Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97xg-px2h-jvxp",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3209"
],
"details": "A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3209"
},
{
"type": "WEB",
"url": "https://drive.google.com/drive/folders/1qlUXvycOzGJygfkdQB9dGO6VwNRRZoih?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259055"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259055"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.304575"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T23:15:55Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99jc-8q77-587x",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:56Z",
"aliases": [
"CVE-2024-3222"
],
"details": "A vulnerability, which was classified as critical, has been found in SourceCodester PHP Task Management System 1.0. This issue affects some unknown processing of the file admin-password-change.php. The manipulation of the argument admin_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259067.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3222"
},
{
"type": "WEB",
"url": "https://github.com/SLthendieck/cve-report/blob/main/2.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259067"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259067"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.308627"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T00:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c38h-r4wc-m6rm",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:56Z",
"aliases": [
"CVE-2024-3247"
],
"details": "In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3247"
},
{
"type": "WEB",
"url": "https://forum.xpdfreader.com/viewtopic.php?t=43597"
}
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T23:15:55Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c52r-8hmj-x4qg",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3204"
],
"details": "A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259051. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3204"
},
{
"type": "WEB",
"url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259051"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259051"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.304557"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T22:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9h7-qc47-j43v",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3205"
],
"details": "A vulnerability was found in yaml libyaml up to 0.2.5 and classified as critical. Affected by this issue is the function yaml_emitter_emit_flow_sequence_item of the file /src/libyaml/src/emitter.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3205"
},
{
"type": "WEB",
"url": "https://drive.google.com/drive/folders/1lwNEs8wqwkUV52f3uQNYMPrxRuXPtGQs?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259052"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259052"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.304561"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T23:15:54Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fh3p-6j2p-f5qv",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-29434"
],
"details": "An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29434"
},
{
"type": "WEB",
"url": "https://gist.github.com/Raybye/6cf4aa273e12a220056e38bec764d42d"
},
{
"type": "WEB",
"url": "https://github.com/Raybye/alldata-bug/blob/main/alldata.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T22:15:09Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pf5m-h35j-7c4j",
"modified": "2024-04-03T00:30:55Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3203"
],
"details": "A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259050 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3203"
},
{
"type": "WEB",
"url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259050"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259050"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.304556"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T22:15:10Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxj3-5cjf-39gh",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:56Z",
"aliases": [
"CVE-2024-3218"
],
"details": "A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259065 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3218"
},
{
"type": "WEB",
"url": "https://github.com/garboa/cve_3/blob/main/file_put_content.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259065"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259065"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.308510"
}
],
"database_specific": {
"cwe_ids": [
"CWE-24"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T00:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x6r6-h48x-gp8f",
"modified": "2024-04-03T00:30:56Z",
"published": "2024-04-03T00:30:55Z",
"aliases": [
"CVE-2024-3207"
],
"details": "A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. VDB-259054 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3207"
},
{
"type": "WEB",
"url": "https://drive.google.com/drive/folders/1z0JBsZ-QR3RsuAf-uyit_ZGXCh0rEvFq?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.259054"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.259054"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.304572"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T23:15:54Z"
}
}