From d4adf35711c7cf1bc43854286b1ef51074cfeb93 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 25 Nov 2024 00:33:22 +0000 Subject: [PATCH] Publish Advisories GHSA-32p4-gm2c-wmch GHSA-7gm5-m2xc-vh2j GHSA-38x5-mx6x-v39w GHSA-f27h-g923-68hw GHSA-h2r3-g3cv-6gh5 GHSA-m5x8-5g7c-7x6p --- .../GHSA-32p4-gm2c-wmch.json | 6 +- .../GHSA-7gm5-m2xc-vh2j.json | 6 +- .../GHSA-38x5-mx6x-v39w.json | 38 ++++++++++++ .../GHSA-f27h-g923-68hw.json | 43 ++++++++++++++ .../GHSA-h2r3-g3cv-6gh5.json | 58 +++++++++++++++++++ .../GHSA-m5x8-5g7c-7x6p.json | 38 ++++++++++++ 6 files changed, 187 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f27h-g923-68hw/GHSA-f27h-g923-68hw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json diff --git a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json index 6de660b771b..af05661b361 100644 --- a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json +++ b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32p4-gm2c-wmch", - "modified": "2024-11-06T21:30:55Z", + "modified": "2024-11-25T00:31:54Z", "published": "2024-11-06T12:31:32Z", "aliases": [ "CVE-2024-9902" @@ -144,6 +144,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8969" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9894" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9902" diff --git a/advisories/unreviewed/2024/10/GHSA-7gm5-m2xc-vh2j/GHSA-7gm5-m2xc-vh2j.json b/advisories/unreviewed/2024/10/GHSA-7gm5-m2xc-vh2j/GHSA-7gm5-m2xc-vh2j.json index 1116a0f775f..53456d3795b 100644 --- a/advisories/unreviewed/2024/10/GHSA-7gm5-m2xc-vh2j/GHSA-7gm5-m2xc-vh2j.json +++ b/advisories/unreviewed/2024/10/GHSA-7gm5-m2xc-vh2j/GHSA-7gm5-m2xc-vh2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gm5-m2xc-vh2j", - "modified": "2024-10-23T15:31:08Z", + "modified": "2024-11-25T00:31:54Z", "published": "2024-10-23T15:31:08Z", "aliases": [ "CVE-2024-10041" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10041" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9941" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-10041" diff --git a/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json b/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json new file mode 100644 index 00000000000..f7da2a6a196 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38x5-mx6x-v39w", + "modified": "2024-11-25T00:31:54Z", + "published": "2024-11-25T00:31:54Z", + "aliases": [ + "CVE-2024-11666" + ], + "details": "Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated usersĀ  suitably positioned on the network between an EV charger controller and eCharge infrastructure can execute arbitrary commands with elevated privileges on affected devices.\n\nThis issue affects cph2_echarge_firmware: through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11666" + }, + { + "type": "WEB", + "url": "https://www.onekey.com/resource/critical-vulnerabilities-in-ev-charging-stations-analysis-of-echarge-controllers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-24T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f27h-g923-68hw/GHSA-f27h-g923-68hw.json b/advisories/unreviewed/2024/11/GHSA-f27h-g923-68hw/GHSA-f27h-g923-68hw.json new file mode 100644 index 00000000000..ad3b7d4b9cc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f27h-g923-68hw/GHSA-f27h-g923-68hw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f27h-g923-68hw", + "modified": "2024-11-25T00:31:55Z", + "published": "2024-11-25T00:31:55Z", + "aliases": [ + "CVE-2024-53916" + ], + "details": "In OpenStack Neutron through 25.0.0, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. NOTE: 935883 has the \"Work in Progress\" status as of 2024-11-24.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53916" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/neutron/blob/363ffa6e9e1ab5968f87d45bc2f1cb6394f48b9f/neutron/extensions/tagging.py#L138-L232" + }, + { + "type": "WEB", + "url": "https://review.opendev.org/c/openstack/neutron/+/935883" + }, + { + "type": "WEB", + "url": "https://review.opendev.org/q/project:openstack/neutron" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json b/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json new file mode 100644 index 00000000000..7da5e5b5fdc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2r3-g3cv-6gh5", + "modified": "2024-11-25T00:31:55Z", + "published": "2024-11-25T00:31:55Z", + "aliases": [ + "CVE-2024-11646" + ], + "details": "A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-services.php. The manipulation of the argument sername leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11646" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/CVE/issues/33" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.446575" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T00:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json b/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json new file mode 100644 index 00000000000..53229d336f9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5x8-5g7c-7x6p", + "modified": "2024-11-25T00:31:54Z", + "published": "2024-11-25T00:31:54Z", + "aliases": [ + "CVE-2024-11665" + ], + "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11665" + }, + { + "type": "WEB", + "url": "https://www.onekey.com/resource/critical-vulnerabilities-in-ev-charging-stations-analysis-of-echarge-controllers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-24T23:15:03Z" + } +} \ No newline at end of file