From d626daa2f1badbbe4cbecd3d63cbb4e514abb8d8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 5 Sep 2024 00:31:48 +0000 Subject: [PATCH] Publish Advisories GHSA-frxj-5j27-f8rf GHSA-4xfh-r54g-8ff7 GHSA-3xxg-9vrr-9g96 GHSA-475c-8mw8-7m88 GHSA-5jm2-m5ch-w9xp GHSA-q98g-hxg3-268c GHSA-r7x8-hv2q-v9r7 GHSA-232q-v7rp-6ff8 GHSA-6qcx-p3rr-pfwf GHSA-h5fr-q576-q7rv GHSA-h827-7423-x2vc GHSA-ww4v-q9h8-2q3m --- .../GHSA-frxj-5j27-f8rf.json | 20 ++++++-- .../GHSA-4xfh-r54g-8ff7.json | 4 +- .../GHSA-3xxg-9vrr-9g96.json | 3 +- .../GHSA-475c-8mw8-7m88.json | 3 +- .../GHSA-5jm2-m5ch-w9xp.json | 3 +- .../GHSA-q98g-hxg3-268c.json | 6 ++- .../GHSA-r7x8-hv2q-v9r7.json | 6 ++- .../GHSA-232q-v7rp-6ff8.json | 38 +++++++++++++++ .../GHSA-6qcx-p3rr-pfwf.json | 38 +++++++++++++++ .../GHSA-h5fr-q576-q7rv.json | 38 +++++++++++++++ .../GHSA-h827-7423-x2vc.json | 47 +++++++++++++++++++ .../GHSA-ww4v-q9h8-2q3m.json | 43 +++++++++++++++++ 12 files changed, 238 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-232q-v7rp-6ff8/GHSA-232q-v7rp-6ff8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6qcx-p3rr-pfwf/GHSA-6qcx-p3rr-pfwf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h5fr-q576-q7rv/GHSA-h5fr-q576-q7rv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json diff --git a/advisories/github-reviewed/2021/04/GHSA-frxj-5j27-f8rf/GHSA-frxj-5j27-f8rf.json b/advisories/github-reviewed/2021/04/GHSA-frxj-5j27-f8rf/GHSA-frxj-5j27-f8rf.json index 8b9ff2ec8ca..550840e8887 100644 --- a/advisories/github-reviewed/2021/04/GHSA-frxj-5j27-f8rf/GHSA-frxj-5j27-f8rf.json +++ b/advisories/github-reviewed/2021/04/GHSA-frxj-5j27-f8rf/GHSA-frxj-5j27-f8rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frxj-5j27-f8rf", - "modified": "2021-08-31T21:09:59Z", + "modified": "2024-09-05T00:30:25Z", "published": "2021-04-20T16:44:49Z", "aliases": [ "CVE-2019-14905" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ @@ -25,7 +29,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.7.0" + "introduced": "2.7.0a1" }, { "fixed": "2.7.16" @@ -44,7 +48,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.8.0" + "introduced": "2.8.0a1" }, { "fixed": "2.8.8" @@ -63,7 +67,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.9.0" + "introduced": "2.9.0a1" }, { "fixed": "2.9.3" @@ -90,10 +94,18 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-frxj-5j27-f8rf" + }, { "type": "PACKAGE", "url": "https://github.com/ansible/ansible" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-206.yaml" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR" diff --git a/advisories/unreviewed/2023/11/GHSA-4xfh-r54g-8ff7/GHSA-4xfh-r54g-8ff7.json b/advisories/unreviewed/2023/11/GHSA-4xfh-r54g-8ff7/GHSA-4xfh-r54g-8ff7.json index 39a888be574..4e6d98e4450 100644 --- a/advisories/unreviewed/2023/11/GHSA-4xfh-r54g-8ff7/GHSA-4xfh-r54g-8ff7.json +++ b/advisories/unreviewed/2023/11/GHSA-4xfh-r54g-8ff7/GHSA-4xfh-r54g-8ff7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xfh-r54g-8ff7", - "modified": "2023-11-25T03:30:32Z", + "modified": "2024-09-05T00:31:21Z", "published": "2023-11-17T12:30:19Z", "aliases": [ "CVE-2020-11447" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json b/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json index 5b7248ec7ce..4d9066c6f4f 100644 --- a/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json +++ b/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json b/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json index 470e1a1b18e..7a3d510db05 100644 --- a/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json +++ b/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json b/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json index 9c50ffa7134..efd4ce721c9 100644 --- a/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json +++ b/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json index dea285587a4..8a30dafdf51 100644 --- a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json +++ b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q98g-hxg3-268c", - "modified": "2024-09-04T21:30:31Z", + "modified": "2024-09-05T00:31:23Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-8088" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/122906" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/0aa1ee22ab6e204e9d3d0e9dd63ea648ed691ef1" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/2231286d78d328c2f575e0b05b16fe447d1656d6" diff --git a/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json b/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json index d891620c068..c21fb7f9ba8 100644 --- a/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json +++ b/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7x8-hv2q-v9r7", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-09-05T00:31:22Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-7006" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7006" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6360" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7006" diff --git a/advisories/unreviewed/2024/09/GHSA-232q-v7rp-6ff8/GHSA-232q-v7rp-6ff8.json b/advisories/unreviewed/2024/09/GHSA-232q-v7rp-6ff8/GHSA-232q-v7rp-6ff8.json new file mode 100644 index 00000000000..eaaba4d7bc2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-232q-v7rp-6ff8/GHSA-232q-v7rp-6ff8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-232q-v7rp-6ff8", + "modified": "2024-09-05T00:31:23Z", + "published": "2024-09-05T00:31:23Z", + "aliases": [ + "CVE-2024-2166" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2166" + }, + { + "type": "WEB", + "url": "https://support.forcepoint.com/s/article/000042397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6qcx-p3rr-pfwf/GHSA-6qcx-p3rr-pfwf.json b/advisories/unreviewed/2024/09/GHSA-6qcx-p3rr-pfwf/GHSA-6qcx-p3rr-pfwf.json new file mode 100644 index 00000000000..3a320a21eb6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6qcx-p3rr-pfwf/GHSA-6qcx-p3rr-pfwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qcx-p3rr-pfwf", + "modified": "2024-09-05T00:31:22Z", + "published": "2024-09-05T00:31:22Z", + "aliases": [ + "CVE-2024-20505" + ], + "details": "A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThe vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20505" + }, + { + "type": "WEB", + "url": "https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h5fr-q576-q7rv/GHSA-h5fr-q576-q7rv.json b/advisories/unreviewed/2024/09/GHSA-h5fr-q576-q7rv/GHSA-h5fr-q576-q7rv.json new file mode 100644 index 00000000000..521bd4880cf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h5fr-q576-q7rv/GHSA-h5fr-q576-q7rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5fr-q576-q7rv", + "modified": "2024-09-05T00:31:23Z", + "published": "2024-09-05T00:31:23Z", + "aliases": [ + "CVE-2024-20506" + ], + "details": "A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files.\n\nThe vulnerability is due to allowing the ClamD process to write to its log file while privileged without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by appending ClamD log messages after restart.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20506" + }, + { + "type": "WEB", + "url": "https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json b/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json new file mode 100644 index 00000000000..9911623d99e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h827-7423-x2vc/GHSA-h827-7423-x2vc.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h827-7423-x2vc", + "modified": "2024-09-05T00:31:23Z", + "published": "2024-09-05T00:31:23Z", + "aliases": [ + "CVE-2024-45429" + ], + "details": "Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45429" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN67963942" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/advanced-custom-fields" + }, + { + "type": "WEB", + "url": "https://www.advancedcustomfields.com" + }, + { + "type": "WEB", + "url": "https://www.advancedcustomfields.com/blog/acf-6-3-6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json b/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json new file mode 100644 index 00000000000..a4193a1b953 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww4v-q9h8-2q3m", + "modified": "2024-09-05T00:31:23Z", + "published": "2024-09-05T00:31:23Z", + "aliases": [ + "CVE-2024-45692" + ], + "details": "Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45692" + }, + { + "type": "WEB", + "url": "https://cispa.de/en/loop-dos" + }, + { + "type": "WEB", + "url": "https://webmin.com" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/09/04/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T23:15:12Z" + } +} \ No newline at end of file