diff --git a/advisories/unreviewed/2023/09/GHSA-m8fg-c37h-w29q/GHSA-m8fg-c37h-w29q.json b/advisories/unreviewed/2023/09/GHSA-m8fg-c37h-w29q/GHSA-m8fg-c37h-w29q.json index 1194de27fb1..38a1681e6ba 100644 --- a/advisories/unreviewed/2023/09/GHSA-m8fg-c37h-w29q/GHSA-m8fg-c37h-w29q.json +++ b/advisories/unreviewed/2023/09/GHSA-m8fg-c37h-w29q/GHSA-m8fg-c37h-w29q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8fg-c37h-w29q", - "modified": "2023-11-01T00:30:48Z", + "modified": "2024-07-10T18:32:17Z", "published": "2023-09-10T00:30:12Z", "aliases": [ "CVE-2023-41915" @@ -64,6 +64,10 @@ { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5547" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json b/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json index 5744d4223e5..a57d5e2ced2 100644 --- a/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json +++ b/advisories/unreviewed/2024/02/GHSA-4828-5p9m-g4ff/GHSA-4828-5p9m-g4ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4828-5p9m-g4ff", - "modified": "2024-03-18T18:32:17Z", + "modified": "2024-07-10T18:32:17Z", "published": "2024-02-08T15:30:27Z", "aliases": [ "CVE-2024-0985" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00017.html" }, + { + "type": "WEB", + "url": "https://saites.dev/projects/personal/postgres-cve-2024-0985" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2024-0985" diff --git a/advisories/unreviewed/2024/07/GHSA-26vq-hm3j-jx75/GHSA-26vq-hm3j-jx75.json b/advisories/unreviewed/2024/07/GHSA-26vq-hm3j-jx75/GHSA-26vq-hm3j-jx75.json new file mode 100644 index 00000000000..d3681fc0a37 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-26vq-hm3j-jx75/GHSA-26vq-hm3j-jx75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26vq-hm3j-jx75", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-37498" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tablesome/wordpress-tablesome-plugin-1-0-33-sensitive-data-exposure-via-api-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index 0ff445e0b53..ccad2b3138f 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-10T03:30:35Z", + "modified": "2024-07-10T18:32:17Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -228,6 +228,18 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/09/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-32hx-c5c7-mvf8/GHSA-32hx-c5c7-mvf8.json b/advisories/unreviewed/2024/07/GHSA-32hx-c5c7-mvf8/GHSA-32hx-c5c7-mvf8.json new file mode 100644 index 00000000000..d7af3ed8401 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-32hx-c5c7-mvf8/GHSA-32hx-c5c7-mvf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32hx-c5c7-mvf8", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-20456" + ], + "details": "A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device.\n\n This vulnerability is due to an error in the software build process. An attacker could exploit this vulnerability by manipulating the system’s configuration options to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass of the requirement to run Cisco signed images or alter the security properties of the running system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20456" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr-secure-boot-quD5g8Ap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-355h-wpr8-m2qx/GHSA-355h-wpr8-m2qx.json b/advisories/unreviewed/2024/07/GHSA-355h-wpr8-m2qx/GHSA-355h-wpr8-m2qx.json new file mode 100644 index 00000000000..3a61699b6e9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-355h-wpr8-m2qx/GHSA-355h-wpr8-m2qx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-355h-wpr8-m2qx", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-4879" + ], + "details": "ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4879" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1644293" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1645154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json b/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json new file mode 100644 index 00000000000..c3c81067e44 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5xx6-pf4v-cpf2/GHSA-5xx6-pf4v-cpf2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xx6-pf4v-cpf2", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-5217" + ], + "details": "ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5217" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1644293" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-632x-gwj4-c7gf/GHSA-632x-gwj4-c7gf.json b/advisories/unreviewed/2024/07/GHSA-632x-gwj4-c7gf/GHSA-632x-gwj4-c7gf.json new file mode 100644 index 00000000000..8fa2a0b1d42 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-632x-gwj4-c7gf/GHSA-632x-gwj4-c7gf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-632x-gwj4-c7gf", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-6646" + ], + "details": "A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6646" + }, + { + "type": "WEB", + "url": "https://github.com/mikutool/vul/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.367382" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-73wr-h9hv-jwjj/GHSA-73wr-h9hv-jwjj.json b/advisories/unreviewed/2024/07/GHSA-73wr-h9hv-jwjj/GHSA-73wr-h9hv-jwjj.json new file mode 100644 index 00000000000..d068d5470e5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-73wr-h9hv-jwjj/GHSA-73wr-h9hv-jwjj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73wr-h9hv-jwjj", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-6647" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file admin/settings/settings/prefix/Theme of the component Setting Handler. The manipulation of the argument Content-Type leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271053 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6647" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271053" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271053" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.372009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index 9ab573a5412..95c23110b73 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-07-10T15:30:27Z", + "modified": "2024-07-10T18:32:17Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -68,6 +68,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/09/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/10/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-8qh8-5vx6-pv8r/GHSA-8qh8-5vx6-pv8r.json b/advisories/unreviewed/2024/07/GHSA-8qh8-5vx6-pv8r/GHSA-8qh8-5vx6-pv8r.json new file mode 100644 index 00000000000..29e5c9bedef --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8qh8-5vx6-pv8r/GHSA-8qh8-5vx6-pv8r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qh8-5vx6-pv8r", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2023-33859" + ], + "details": "IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33859" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/257697" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159770" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-99gf-frhc-hg67/GHSA-99gf-frhc-hg67.json b/advisories/unreviewed/2024/07/GHSA-99gf-frhc-hg67/GHSA-99gf-frhc-hg67.json new file mode 100644 index 00000000000..abee5c05bb1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-99gf-frhc-hg67/GHSA-99gf-frhc-hg67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99gf-frhc-hg67", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:18Z", + "aliases": [ + "CVE-2024-37270" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vendor/wordpress-trustedlogin-vendor-plugin-1-1-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c2q4-mfpf-x8wh/GHSA-c2q4-mfpf-x8wh.json b/advisories/unreviewed/2024/07/GHSA-c2q4-mfpf-x8wh/GHSA-c2q4-mfpf-x8wh.json new file mode 100644 index 00000000000..ef0e7c33d25 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c2q4-mfpf-x8wh/GHSA-c2q4-mfpf-x8wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2q4-mfpf-x8wh", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-3325" + ], + "details": "Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3325" + }, + { + "type": "WEB", + "url": "https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-july-9-2024-jasperreports-server-cve-2024-3325-r4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-crrp-jmhw-5cxr/GHSA-crrp-jmhw-5cxr.json b/advisories/unreviewed/2024/07/GHSA-crrp-jmhw-5cxr/GHSA-crrp-jmhw-5cxr.json new file mode 100644 index 00000000000..b1eeb0d076a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-crrp-jmhw-5cxr/GHSA-crrp-jmhw-5cxr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crrp-jmhw-5cxr", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-32759" + ], + "details": "Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32759" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-191-04" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1391" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cxrx-w35f-hjjq/GHSA-cxrx-w35f-hjjq.json b/advisories/unreviewed/2024/07/GHSA-cxrx-w35f-hjjq/GHSA-cxrx-w35f-hjjq.json new file mode 100644 index 00000000000..6c0a172622a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cxrx-w35f-hjjq/GHSA-cxrx-w35f-hjjq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxrx-w35f-hjjq", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-37770" + ], + "details": "14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37770" + }, + { + "type": "WEB", + "url": "https://github.com/b1ackc4t/14Finger/issues/13" + }, + { + "type": "WEB", + "url": "https://github.com/k3ppf0r/CVE-2024-37770" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json b/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json new file mode 100644 index 00000000000..ce2ef975bca --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8f7-g44v-jxm9", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2023-35006" + ], + "details": "IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 297165.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35006" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297165" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159770" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f9wm-g526-8xc9/GHSA-f9wm-g526-8xc9.json b/advisories/unreviewed/2024/07/GHSA-f9wm-g526-8xc9/GHSA-f9wm-g526-8xc9.json new file mode 100644 index 00000000000..95393e5fb9f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f9wm-g526-8xc9/GHSA-f9wm-g526-8xc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9wm-g526-8xc9", + "modified": "2024-07-10T18:32:18Z", + "published": "2024-07-10T18:32:18Z", + "aliases": [ + "CVE-2024-37205" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37205" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/affiliate-toolkit-starter/wordpress-affiliate-toolkit-plugin-3-4-4-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g4m4-xx42-vc78/GHSA-g4m4-xx42-vc78.json b/advisories/unreviewed/2024/07/GHSA-g4m4-xx42-vc78/GHSA-g4m4-xx42-vc78.json new file mode 100644 index 00000000000..3afb65009f4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g4m4-xx42-vc78/GHSA-g4m4-xx42-vc78.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4m4-xx42-vc78", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-6645" + ], + "details": "A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ExpressionUtil.java of the component AviatorScript Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-271051.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6645" + }, + { + "type": "WEB", + "url": "https://github.com/WuKongOpenSource/Wukong_nocode/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.367349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gf5q-62qg-2vxf/GHSA-gf5q-62qg-2vxf.json b/advisories/unreviewed/2024/07/GHSA-gf5q-62qg-2vxf/GHSA-gf5q-62qg-2vxf.json new file mode 100644 index 00000000000..6f6e6664f67 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gf5q-62qg-2vxf/GHSA-gf5q-62qg-2vxf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf5q-62qg-2vxf", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-6630" + ], + "details": "Rejected reason: **REJECT** This CVE ID was issued in error and is a duplicate. Please use CVE-2024-6500 instead.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6630" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jxxv-pfm8-7r47/GHSA-jxxv-pfm8-7r47.json b/advisories/unreviewed/2024/07/GHSA-jxxv-pfm8-7r47/GHSA-jxxv-pfm8-7r47.json new file mode 100644 index 00000000000..d31e01cae4f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jxxv-pfm8-7r47/GHSA-jxxv-pfm8-7r47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxxv-pfm8-7r47", + "modified": "2024-07-10T18:32:18Z", + "published": "2024-07-10T18:32:18Z", + "aliases": [ + "CVE-2024-37113" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37113" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wishlist-member-x/wordpress-wishlist-member-x-plugin-3-25-1-unauthenticated-database-backup-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m2hc-3jx3-75xg/GHSA-m2hc-3jx3-75xg.json b/advisories/unreviewed/2024/07/GHSA-m2hc-3jx3-75xg/GHSA-m2hc-3jx3-75xg.json new file mode 100644 index 00000000000..3d6937b954d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m2hc-3jx3-75xg/GHSA-m2hc-3jx3-75xg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2hc-3jx3-75xg", + "modified": "2024-07-10T18:32:19Z", + "published": "2024-07-10T18:32:19Z", + "aliases": [ + "CVE-2024-37504" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/filebird-document-library/wordpress-filebird-document-library-plugin-2-0-6-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m573-gr53-3hw7/GHSA-m573-gr53-3hw7.json b/advisories/unreviewed/2024/07/GHSA-m573-gr53-3hw7/GHSA-m573-gr53-3hw7.json new file mode 100644 index 00000000000..a417d16fd9b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m573-gr53-3hw7/GHSA-m573-gr53-3hw7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m573-gr53-3hw7", + "modified": "2024-07-10T18:32:18Z", + "published": "2024-07-10T18:32:18Z", + "aliases": [ + "CVE-2024-37110" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37110" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wishlist-member-x/wordpress-wishlist-member-x-plugin-3-25-1-unauthenticated-settings-users-data-dump-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p4c4-ff2v-qph3/GHSA-p4c4-ff2v-qph3.json b/advisories/unreviewed/2024/07/GHSA-p4c4-ff2v-qph3/GHSA-p4c4-ff2v-qph3.json new file mode 100644 index 00000000000..20d47a00eaa --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p4c4-ff2v-qph3/GHSA-p4c4-ff2v-qph3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4c4-ff2v-qph3", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2023-33860" + ], + "details": "IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257702.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33860" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/257702" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159770" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-614" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json b/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json new file mode 100644 index 00000000000..d4b40f038a5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxcv-w3gg-4fc7", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-40412" + ], + "details": "Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40412" + }, + { + "type": "WEB", + "url": "https://static.tenda.com.cn/tdcweb/download/uploadfile/AX12/V22.03.01.46.zip" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q597-gqv4-7v97/GHSA-q597-gqv4-7v97.json b/advisories/unreviewed/2024/07/GHSA-q597-gqv4-7v97/GHSA-q597-gqv4-7v97.json new file mode 100644 index 00000000000..38552a2c0f0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q597-gqv4-7v97/GHSA-q597-gqv4-7v97.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q597-gqv4-7v97", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-6644" + ], + "details": "A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java of the component AviatorScript Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-271050 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6644" + }, + { + "type": "WEB", + "url": "https://github.com/zmops/ArgusDBM/issues/64" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.271050" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.271050" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.367347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q728-xjr5-4gxf/GHSA-q728-xjr5-4gxf.json b/advisories/unreviewed/2024/07/GHSA-q728-xjr5-4gxf/GHSA-q728-xjr5-4gxf.json new file mode 100644 index 00000000000..759e5411c76 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q728-xjr5-4gxf/GHSA-q728-xjr5-4gxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q728-xjr5-4gxf", + "modified": "2024-07-10T18:32:18Z", + "published": "2024-07-10T18:32:18Z", + "aliases": [ + "CVE-2024-37115" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37115" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/newspack-blocks/wordpress-newspack-blocks-plugin-3-0-8-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qm6x-v3jw-cvp7/GHSA-qm6x-v3jw-cvp7.json b/advisories/unreviewed/2024/07/GHSA-qm6x-v3jw-cvp7/GHSA-qm6x-v3jw-cvp7.json new file mode 100644 index 00000000000..9b34e9bded5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qm6x-v3jw-cvp7/GHSA-qm6x-v3jw-cvp7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm6x-v3jw-cvp7", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-5178" + ], + "details": "ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5178" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1644293" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v2p8-7gm5-fh2m/GHSA-v2p8-7gm5-fh2m.json b/advisories/unreviewed/2024/07/GHSA-v2p8-7gm5-fh2m/GHSA-v2p8-7gm5-fh2m.json new file mode 100644 index 00000000000..b6ca4809c8f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v2p8-7gm5-fh2m/GHSA-v2p8-7gm5-fh2m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2p8-7gm5-fh2m", + "modified": "2024-07-10T18:32:17Z", + "published": "2024-07-10T18:32:17Z", + "aliases": [ + "CVE-2024-40417" + ], + "details": "A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40417" + }, + { + "type": "WEB", + "url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX_1806/1/SetIpMacBind.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-10T16:15:04Z" + } +} \ No newline at end of file