diff --git a/advisories/github-reviewed/2024/04/GHSA-4f53-xh3v-g8x4/GHSA-4f53-xh3v-g8x4.json b/advisories/github-reviewed/2024/04/GHSA-4f53-xh3v-g8x4/GHSA-4f53-xh3v-g8x4.json index 0565aab3fa0..03632c16025 100644 --- a/advisories/github-reviewed/2024/04/GHSA-4f53-xh3v-g8x4/GHSA-4f53-xh3v-g8x4.json +++ b/advisories/github-reviewed/2024/04/GHSA-4f53-xh3v-g8x4/GHSA-4f53-xh3v-g8x4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f53-xh3v-g8x4", - "modified": "2024-04-25T16:54:22Z", + "modified": "2024-08-07T12:31:28Z", "published": "2024-04-17T17:31:50Z", "aliases": [ "CVE-2023-3597" @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://github.com/keycloak/keycloak/commit/aa634aee882892960a526e49982806e103c8a432" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1866" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1867" diff --git a/advisories/unreviewed/2024/07/GHSA-36h2-g4c8-9xcm/GHSA-36h2-g4c8-9xcm.json b/advisories/unreviewed/2024/07/GHSA-36h2-g4c8-9xcm/GHSA-36h2-g4c8-9xcm.json index 3282d721ca9..65a703ace03 100644 --- a/advisories/unreviewed/2024/07/GHSA-36h2-g4c8-9xcm/GHSA-36h2-g4c8-9xcm.json +++ b/advisories/unreviewed/2024/07/GHSA-36h2-g4c8-9xcm/GHSA-36h2-g4c8-9xcm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-835" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5m47-pw5x-gvrc/GHSA-5m47-pw5x-gvrc.json b/advisories/unreviewed/2024/08/GHSA-5m47-pw5x-gvrc/GHSA-5m47-pw5x-gvrc.json new file mode 100644 index 00000000000..2d83c40cd82 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5m47-pw5x-gvrc/GHSA-5m47-pw5x-gvrc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m47-pw5x-gvrc", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-7553" + ], + "details": "Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1.\n\nRequired Configuration:\n\nOnly environments with Windows as the underlying operating system is affected by this issue", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7553" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/CDRIVER-5650" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/PHPC-2369" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-93211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json b/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json new file mode 100644 index 00000000000..b05b0c82e9c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5wvf-7fq8-m4w6/GHSA-5wvf-7fq8-m4w6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wvf-7fq8-m4w6", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-7266" + ], + "details": "Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:D/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7266" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/ezd-rp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7846-r2fj-c4x4/GHSA-7846-r2fj-c4x4.json b/advisories/unreviewed/2024/08/GHSA-7846-r2fj-c4x4/GHSA-7846-r2fj-c4x4.json new file mode 100644 index 00000000000..d26e97d3155 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7846-r2fj-c4x4/GHSA-7846-r2fj-c4x4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7846-r2fj-c4x4", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-6522" + ], + "details": "The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6522" + }, + { + "type": "WEB", + "url": "https://mec.webnus.net/change-log" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/modern-events-calendar-lite/trunk/app/features/fes.php#L54" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/modern-events-calendar-lite/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/00bf8f2f-6ab4-4430-800b-5b97abe7589e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9g2c-2x8r-pvcj/GHSA-9g2c-2x8r-pvcj.json b/advisories/unreviewed/2024/08/GHSA-9g2c-2x8r-pvcj/GHSA-9g2c-2x8r-pvcj.json new file mode 100644 index 00000000000..3404d3e41be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9g2c-2x8r-pvcj/GHSA-9g2c-2x8r-pvcj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g2c-2x8r-pvcj", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-7353" + ], + "details": "The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7353" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/stripe-payments/trunk/includes/shortcodes/class-asp-shortcode-ng.php#L715" + }, + { + "type": "WEB", + "url": "https://portswigger.net/research/xss-in-hidden-input-fields" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/stripe-payments/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f321e41a-3945-47db-a215-aeb001b7b80b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T12:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json b/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json new file mode 100644 index 00000000000..941ca2600e7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cq2c-35gp-j9qc/GHSA-cq2c-35gp-j9qc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq2c-35gp-j9qc", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-7267" + ], + "details": "Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:D/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7267" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/ezd-rp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-213" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json b/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json new file mode 100644 index 00000000000..3ae8181b051 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jvvm-gq28-8rgc/GHSA-jvvm-gq28-8rgc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvvm-gq28-8rgc", + "modified": "2024-08-07T12:31:28Z", + "published": "2024-08-07T12:31:28Z", + "aliases": [ + "CVE-2024-7265" + ], + "details": "Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:L/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7265" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/08/CVE-2023-7265" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/ezd-rp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T11:15:45Z" + } +} \ No newline at end of file