Publish Advisories

GHSA-frxj-5j27-f8rf
GHSA-4xfh-r54g-8ff7
GHSA-3xxg-9vrr-9g96
GHSA-475c-8mw8-7m88
GHSA-5jm2-m5ch-w9xp
GHSA-q98g-hxg3-268c
GHSA-r7x8-hv2q-v9r7
GHSA-232q-v7rp-6ff8
GHSA-6qcx-p3rr-pfwf
GHSA-h5fr-q576-q7rv
GHSA-h827-7423-x2vc
GHSA-ww4v-q9h8-2q3m
This commit is contained in:
advisory-database[bot]
2024-09-05 00:31:48 +00:00
parent cccc927bcb
commit d626daa2f1
12 changed files with 238 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frxj-5j27-f8rf",
"modified": "2021-08-31T21:09:59Z",
"modified": "2024-09-05T00:30:25Z",
"published": "2021-04-20T16:44:49Z",
"aliases": [
"CVE-2019-14905"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"
}
],
"affected": [
@@ -25,7 +29,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.7.0"
"introduced": "2.7.0a1"
},
{
"fixed": "2.7.16"
@@ -44,7 +48,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.8.0"
"introduced": "2.8.0a1"
},
{
"fixed": "2.8.8"
@@ -63,7 +67,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.9.0"
"introduced": "2.9.0a1"
},
{
"fixed": "2.9.3"
@@ -90,10 +94,18 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-frxj-5j27-f8rf"
},
{
"type": "PACKAGE",
"url": "https://github.com/ansible/ansible"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-206.yaml"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xfh-r54g-8ff7",
"modified": "2023-11-25T03:30:32Z",
"modified": "2024-09-05T00:31:21Z",
"published": "2023-11-17T12:30:19Z",
"aliases": [
"CVE-2020-11447"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q98g-hxg3-268c",
"modified": "2024-09-04T21:30:31Z",
"modified": "2024-09-05T00:31:23Z",
"published": "2024-08-22T21:31:29Z",
"aliases": [
"CVE-2024-8088"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/pull/122906"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/0aa1ee22ab6e204e9d3d0e9dd63ea648ed691ef1"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/2231286d78d328c2f575e0b05b16fe447d1656d6"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r7x8-hv2q-v9r7",
"modified": "2024-08-12T15:30:51Z",
"modified": "2024-09-05T00:31:22Z",
"published": "2024-08-12T15:30:51Z",
"aliases": [
"CVE-2024-7006"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7006"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6360"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-7006"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-232q-v7rp-6ff8",
"modified": "2024-09-05T00:31:23Z",
"published": "2024-09-05T00:31:23Z",
"aliases": [
"CVE-2024-2166"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2166"
},
{
"type": "WEB",
"url": "https://support.forcepoint.com/s/article/000042397"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T22:15:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qcx-p3rr-pfwf",
"modified": "2024-09-05T00:31:22Z",
"published": "2024-09-05T00:31:22Z",
"aliases": [
"CVE-2024-20505"
],
"details": "A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThe vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20505"
},
{
"type": "WEB",
"url": "https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T22:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5fr-q576-q7rv",
"modified": "2024-09-05T00:31:23Z",
"published": "2024-09-05T00:31:23Z",
"aliases": [
"CVE-2024-20506"
],
"details": "A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files.\n\nThe vulnerability is due to allowing the ClamD process to write to its log file while privileged without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by appending ClamD log messages after restart.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20506"
},
{
"type": "WEB",
"url": "https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T22:15:04Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h827-7423-x2vc",
"modified": "2024-09-05T00:31:23Z",
"published": "2024-09-05T00:31:23Z",
"aliases": [
"CVE-2024-45429"
],
"details": "Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45429"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN67963942"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/advanced-custom-fields"
},
{
"type": "WEB",
"url": "https://www.advancedcustomfields.com"
},
{
"type": "WEB",
"url": "https://www.advancedcustomfields.com/blog/acf-6-3-6"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T23:15:12Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ww4v-q9h8-2q3m",
"modified": "2024-09-05T00:31:23Z",
"published": "2024-09-05T00:31:23Z",
"aliases": [
"CVE-2024-45692"
],
"details": "Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45692"
},
{
"type": "WEB",
"url": "https://cispa.de/en/loop-dos"
},
{
"type": "WEB",
"url": "https://webmin.com"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/09/04/1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T23:15:12Z"
}
}