Publish Advisories

GHSA-32p4-gm2c-wmch
GHSA-7gm5-m2xc-vh2j
GHSA-38x5-mx6x-v39w
GHSA-f27h-g923-68hw
GHSA-h2r3-g3cv-6gh5
GHSA-m5x8-5g7c-7x6p
This commit is contained in:
advisory-database[bot]
2024-11-25 00:33:22 +00:00
parent 8ee6bd1588
commit d4adf35711
6 changed files with 187 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32p4-gm2c-wmch",
"modified": "2024-11-06T21:30:55Z",
"modified": "2024-11-25T00:31:54Z",
"published": "2024-11-06T12:31:32Z",
"aliases": [
"CVE-2024-9902"
@@ -144,6 +144,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8969"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9894"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9902"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gm5-m2xc-vh2j",
"modified": "2024-10-23T15:31:08Z",
"modified": "2024-11-25T00:31:54Z",
"published": "2024-10-23T15:31:08Z",
"aliases": [
"CVE-2024-10041"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10041"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9941"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-10041"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38x5-mx6x-v39w",
"modified": "2024-11-25T00:31:54Z",
"published": "2024-11-25T00:31:54Z",
"aliases": [
"CVE-2024-11666"
],
"details": "Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated users  suitably positioned on the network between an EV charger controller and eCharge infrastructure can execute arbitrary commands with elevated privileges on affected devices.\n\nThis issue affects cph2_echarge_firmware: through 2.0.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11666"
},
{
"type": "WEB",
"url": "https://www.onekey.com/resource/critical-vulnerabilities-in-ev-charging-stations-analysis-of-echarge-controllers"
}
],
"database_specific": {
"cwe_ids": [
"CWE-345"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-24T23:15:04Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f27h-g923-68hw",
"modified": "2024-11-25T00:31:55Z",
"published": "2024-11-25T00:31:55Z",
"aliases": [
"CVE-2024-53916"
],
"details": "In OpenStack Neutron through 25.0.0, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. NOTE: 935883 has the \"Work in Progress\" status as of 2024-11-24.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53916"
},
{
"type": "WEB",
"url": "https://github.com/openstack/neutron/blob/363ffa6e9e1ab5968f87d45bc2f1cb6394f48b9f/neutron/extensions/tagging.py#L138-L232"
},
{
"type": "WEB",
"url": "https://review.opendev.org/c/openstack/neutron/+/935883"
},
{
"type": "WEB",
"url": "https://review.opendev.org/q/project:openstack/neutron"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-25T00:15:04Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2r3-g3cv-6gh5",
"modified": "2024-11-25T00:31:55Z",
"published": "2024-11-25T00:31:55Z",
"aliases": [
"CVE-2024-11646"
],
"details": "A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-services.php. The manipulation of the argument sername leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11646"
},
{
"type": "WEB",
"url": "https://github.com/ppp-src/CVE/issues/33"
},
{
"type": "WEB",
"url": "https://1000projects.org"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.285967"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.285967"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.446575"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-25T00:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m5x8-5g7c-7x6p",
"modified": "2024-11-25T00:31:54Z",
"published": "2024-11-25T00:31:54Z",
"aliases": [
"CVE-2024-11665"
],
"details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11665"
},
{
"type": "WEB",
"url": "https://www.onekey.com/resource/critical-vulnerabilities-in-ev-charging-stations-analysis-of-echarge-controllers"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-24T23:15:03Z"
}
}