From d773f86fbb3d3376e447ee3d1084f422a09ce328 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 14 Nov 2024 12:32:11 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2j54-3gcc-fxxg.json | 38 ++++++++++++++ .../GHSA-45gh-j7vr-755q.json | 35 +++++++++++++ .../GHSA-49rr-2fpg-hfw9.json | 38 ++++++++++++++ .../GHSA-4g4w-jrfj-2m5p.json | 38 ++++++++++++++ .../GHSA-4jjw-9p2j-2v46.json | 38 ++++++++++++++ .../GHSA-67mq-mrh8-wj53.json | 38 ++++++++++++++ .../GHSA-6j2p-q7p9-hmxw.json | 35 +++++++++++++ .../GHSA-6j5p-p5gv-2c73.json | 38 ++++++++++++++ .../GHSA-75r8-6x58-82p6.json | 38 ++++++++++++++ .../GHSA-77jf-qvrc-2mmc.json | 38 ++++++++++++++ .../GHSA-7h98-97f3-2x3x.json | 38 ++++++++++++++ .../GHSA-8j32-3852-6cwg.json | 38 ++++++++++++++ .../GHSA-c43q-432c-pfx8.json | 35 +++++++++++++ .../GHSA-c7vx-2f2q-xpfw.json | 42 ++++++++++++++++ .../GHSA-c7xg-c3jr-78wp.json | 38 ++++++++++++++ .../GHSA-gqjr-4mgj-g55g.json | 46 +++++++++++++++++ .../GHSA-hpvm-q8v2-j94r.json | 42 ++++++++++++++++ .../GHSA-m359-59cc-2426.json | 38 ++++++++++++++ .../GHSA-mg8m-g8m2-pgf8.json | 38 ++++++++++++++ .../GHSA-mq5w-grf9-5rp9.json | 50 +++++++++++++++++++ .../GHSA-p932-x66g-q6cc.json | 46 +++++++++++++++++ .../GHSA-pfxg-46gm-p35h.json | 42 ++++++++++++++++ .../GHSA-q527-gcw3-86jr.json | 38 ++++++++++++++ .../GHSA-r864-28pw-8682.json | 38 ++++++++++++++ .../GHSA-xvx4-v362-295f.json | 38 ++++++++++++++ .../GHSA-xwcj-grfm-xm6q.json | 38 ++++++++++++++ .../GHSA-xx8r-3wgj-j632.json | 38 ++++++++++++++ 27 files changed, 1057 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-45gh-j7vr-755q/GHSA-45gh-j7vr-755q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-49rr-2fpg-hfw9/GHSA-49rr-2fpg-hfw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4g4w-jrfj-2m5p/GHSA-4g4w-jrfj-2m5p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4jjw-9p2j-2v46/GHSA-4jjw-9p2j-2v46.json create mode 100644 advisories/unreviewed/2024/11/GHSA-67mq-mrh8-wj53/GHSA-67mq-mrh8-wj53.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6j2p-q7p9-hmxw/GHSA-6j2p-q7p9-hmxw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6j5p-p5gv-2c73/GHSA-6j5p-p5gv-2c73.json create mode 100644 advisories/unreviewed/2024/11/GHSA-75r8-6x58-82p6/GHSA-75r8-6x58-82p6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8j32-3852-6cwg/GHSA-8j32-3852-6cwg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c43q-432c-pfx8/GHSA-c43q-432c-pfx8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c7vx-2f2q-xpfw/GHSA-c7vx-2f2q-xpfw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c7xg-c3jr-78wp/GHSA-c7xg-c3jr-78wp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gqjr-4mgj-g55g/GHSA-gqjr-4mgj-g55g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hpvm-q8v2-j94r/GHSA-hpvm-q8v2-j94r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mg8m-g8m2-pgf8/GHSA-mg8m-g8m2-pgf8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mq5w-grf9-5rp9/GHSA-mq5w-grf9-5rp9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p932-x66g-q6cc/GHSA-p932-x66g-q6cc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pfxg-46gm-p35h/GHSA-pfxg-46gm-p35h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r864-28pw-8682/GHSA-r864-28pw-8682.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xvx4-v362-295f/GHSA-xvx4-v362-295f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xwcj-grfm-xm6q/GHSA-xwcj-grfm-xm6q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json diff --git a/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json b/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json new file mode 100644 index 00000000000..d6e4d0147e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j54-3gcc-fxxg", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:01Z", + "aliases": [ + "CVE-2024-5917" + ], + "details": "A server-side request forgery in PAN-OS software enables an unauthenticated attacker to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5917" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45gh-j7vr-755q/GHSA-45gh-j7vr-755q.json b/advisories/unreviewed/2024/11/GHSA-45gh-j7vr-755q/GHSA-45gh-j7vr-755q.json new file mode 100644 index 00000000000..9200ca06334 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-45gh-j7vr-755q/GHSA-45gh-j7vr-755q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45gh-j7vr-755q", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-50305" + ], + "details": "Valid Host header field can cause Apache Traffic Server to crash on some platforms.\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.\n\nUsers are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50305" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0y" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-49rr-2fpg-hfw9/GHSA-49rr-2fpg-hfw9.json b/advisories/unreviewed/2024/11/GHSA-49rr-2fpg-hfw9/GHSA-49rr-2fpg-hfw9.json new file mode 100644 index 00000000000..5fb54f1341e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-49rr-2fpg-hfw9/GHSA-49rr-2fpg-hfw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49rr-2fpg-hfw9", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-45253" + ], + "details": "Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45253" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g4w-jrfj-2m5p/GHSA-4g4w-jrfj-2m5p.json b/advisories/unreviewed/2024/11/GHSA-4g4w-jrfj-2m5p/GHSA-4g4w-jrfj-2m5p.json new file mode 100644 index 00000000000..361d7f7dd16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4g4w-jrfj-2m5p/GHSA-4g4w-jrfj-2m5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g4w-jrfj-2m5p", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-47916" + ], + "details": "Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47916" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4jjw-9p2j-2v46/GHSA-4jjw-9p2j-2v46.json b/advisories/unreviewed/2024/11/GHSA-4jjw-9p2j-2v46/GHSA-4jjw-9p2j-2v46.json new file mode 100644 index 00000000000..98af04bcb50 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jjw-9p2j-2v46/GHSA-4jjw-9p2j-2v46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jjw-9p2j-2v46", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-9472" + ], + "details": "A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.\n\n\nPalo Alto Networks VM-Series, Cloud NGFW, and Prisma Access are not affected.\n\n\nThis issue only affects PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series running these specific versions of PAN-OS:\n\n * 10.2.7-h12\n * 10.2.8-h10\n * 10.2.9-h9\n * 10.2.9-h11\n * 10.2.10-h2\n * 10.2.10-h3\n * 10.2.11\n * 10.2.11-h1\n * 10.2.11-h2\n * 10.2.11-h3\n * 11.1.2-h9\n * 11.1.2-h12\n * 11.1.3-h2\n * 11.1.3-h4\n * 11.1.3-h6\n * 11.2.2\n * 11.2.2-h1", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9472" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-9472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-67mq-mrh8-wj53/GHSA-67mq-mrh8-wj53.json b/advisories/unreviewed/2024/11/GHSA-67mq-mrh8-wj53/GHSA-67mq-mrh8-wj53.json new file mode 100644 index 00000000000..e7a8e825eb4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-67mq-mrh8-wj53/GHSA-67mq-mrh8-wj53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67mq-mrh8-wj53", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-45099" + ], + "details": "IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45099" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6j2p-q7p9-hmxw/GHSA-6j2p-q7p9-hmxw.json b/advisories/unreviewed/2024/11/GHSA-6j2p-q7p9-hmxw/GHSA-6j2p-q7p9-hmxw.json new file mode 100644 index 00000000000..0f60fbe26b7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6j2p-q7p9-hmxw/GHSA-6j2p-q7p9-hmxw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2p-q7p9-hmxw", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:01Z", + "aliases": [ + "CVE-2024-50306" + ], + "details": "Unchecked return value can allow Apache Traffic Server to retain privileges on startup.\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.\n\nUsers are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50306" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0y" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-252" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6j5p-p5gv-2c73/GHSA-6j5p-p5gv-2c73.json b/advisories/unreviewed/2024/11/GHSA-6j5p-p5gv-2c73/GHSA-6j5p-p5gv-2c73.json new file mode 100644 index 00000000000..ceca6a3c635 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6j5p-p5gv-2c73/GHSA-6j5p-p5gv-2c73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j5p-p5gv-2c73", + "modified": "2024-11-14T12:31:03Z", + "published": "2024-11-14T12:31:03Z", + "aliases": [ + "CVE-2024-45642" + ], + "details": "IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45642" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-942" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-75r8-6x58-82p6/GHSA-75r8-6x58-82p6.json b/advisories/unreviewed/2024/11/GHSA-75r8-6x58-82p6/GHSA-75r8-6x58-82p6.json new file mode 100644 index 00000000000..83af34d6700 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-75r8-6x58-82p6/GHSA-75r8-6x58-82p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75r8-6x58-82p6", + "modified": "2024-11-14T12:31:03Z", + "published": "2024-11-14T12:31:03Z", + "aliases": [ + "CVE-2024-45670" + ], + "details": "IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45670" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172206" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json b/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json new file mode 100644 index 00000000000..98f2a6ceb18 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77jf-qvrc-2mmc", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-2552" + ], + "details": "A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2552" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-2552" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json b/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json new file mode 100644 index 00000000000..f6f5fecc340 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h98-97f3-2x3x", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-2551" + ], + "details": "A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2551" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-2551" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8j32-3852-6cwg/GHSA-8j32-3852-6cwg.json b/advisories/unreviewed/2024/11/GHSA-8j32-3852-6cwg/GHSA-8j32-3852-6cwg.json new file mode 100644 index 00000000000..f033f3cb204 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8j32-3852-6cwg/GHSA-8j32-3852-6cwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j32-3852-6cwg", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-47914" + ], + "details": "VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47914" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c43q-432c-pfx8/GHSA-c43q-432c-pfx8.json b/advisories/unreviewed/2024/11/GHSA-c43q-432c-pfx8/GHSA-c43q-432c-pfx8.json new file mode 100644 index 00000000000..f5b6d79acc3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c43q-432c-pfx8/GHSA-c43q-432c-pfx8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c43q-432c-pfx8", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-38479" + ], + "details": "Improper Input Validation vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5.\n\nUsers are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38479" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0y" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c7vx-2f2q-xpfw/GHSA-c7vx-2f2q-xpfw.json b/advisories/unreviewed/2024/11/GHSA-c7vx-2f2q-xpfw/GHSA-c7vx-2f2q-xpfw.json new file mode 100644 index 00000000000..6c6c0aec015 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c7vx-2f2q-xpfw/GHSA-c7vx-2f2q-xpfw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7vx-2f2q-xpfw", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-10571" + ], + "details": "The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10571" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/chart-builder/tags/2.9.6/admin/partials/charts/actions/chart-builder-charts-actions-options.php?rev=3184238" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d4837258-c749-4194-926c-22b67e20c1fc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c7xg-c3jr-78wp/GHSA-c7xg-c3jr-78wp.json b/advisories/unreviewed/2024/11/GHSA-c7xg-c3jr-78wp/GHSA-c7xg-c3jr-78wp.json new file mode 100644 index 00000000000..ddd143b0753 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c7xg-c3jr-78wp/GHSA-c7xg-c3jr-78wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7xg-c3jr-78wp", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-9693" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9693" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/497449" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T11:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gqjr-4mgj-g55g/GHSA-gqjr-4mgj-g55g.json b/advisories/unreviewed/2024/11/GHSA-gqjr-4mgj-g55g/GHSA-gqjr-4mgj-g55g.json new file mode 100644 index 00000000000..fa1e23c35de --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gqjr-4mgj-g55g/GHSA-gqjr-4mgj-g55g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqjr-4mgj-g55g", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2023-4458" + ], + "details": "A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-4458" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325516" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-590" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hpvm-q8v2-j94r/GHSA-hpvm-q8v2-j94r.json b/advisories/unreviewed/2024/11/GHSA-hpvm-q8v2-j94r/GHSA-hpvm-q8v2-j94r.json new file mode 100644 index 00000000000..2532a8da8bf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hpvm-q8v2-j94r/GHSA-hpvm-q8v2-j94r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpvm-q8v2-j94r", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2023-4134" + ], + "details": "A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4134" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-4134" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2221700" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json b/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json new file mode 100644 index 00000000000..64f9209c2fe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m359-59cc-2426", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:01Z", + "aliases": [ + "CVE-2024-5919" + ], + "details": "A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5919" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mg8m-g8m2-pgf8/GHSA-mg8m-g8m2-pgf8.json b/advisories/unreviewed/2024/11/GHSA-mg8m-g8m2-pgf8/GHSA-mg8m-g8m2-pgf8.json new file mode 100644 index 00000000000..2e76ff8eff6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mg8m-g8m2-pgf8/GHSA-mg8m-g8m2-pgf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg8m-g8m2-pgf8", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-45254" + ], + "details": "VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45254" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mq5w-grf9-5rp9/GHSA-mq5w-grf9-5rp9.json b/advisories/unreviewed/2024/11/GHSA-mq5w-grf9-5rp9/GHSA-mq5w-grf9-5rp9.json new file mode 100644 index 00000000000..61d59604560 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mq5w-grf9-5rp9/GHSA-mq5w-grf9-5rp9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq5w-grf9-5rp9", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-3447" + ], + "details": "A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3447" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3447" + }, + { + "type": "WEB", + "url": "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58813" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274123" + }, + { + "type": "WEB", + "url": "https://patchew.org/QEMU/20240404085549.16987-1-philmd@linaro.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p932-x66g-q6cc/GHSA-p932-x66g-q6cc.json b/advisories/unreviewed/2024/11/GHSA-p932-x66g-q6cc/GHSA-p932-x66g-q6cc.json new file mode 100644 index 00000000000..aea3839f6cf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p932-x66g-q6cc/GHSA-p932-x66g-q6cc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p932-x66g-q6cc", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2024-8180" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8180" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2654010" + }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#html-injection-in-vulnerability-code-flow-could-lead-to-xss-on-self-hosted-instances" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480720" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pfxg-46gm-p35h/GHSA-pfxg-46gm-p35h.json b/advisories/unreviewed/2024/11/GHSA-pfxg-46gm-p35h/GHSA-pfxg-46gm-p35h.json new file mode 100644 index 00000000000..256204c1231 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pfxg-46gm-p35h/GHSA-pfxg-46gm-p35h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfxg-46gm-p35h", + "modified": "2024-11-14T12:31:03Z", + "published": "2024-11-14T12:31:03Z", + "aliases": [ + "CVE-2024-7730" + ], + "details": "A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7730" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7730" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json b/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json new file mode 100644 index 00000000000..5f5ab05ea5e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q527-gcw3-86jr", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-2550" + ], + "details": "A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2550" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-2550" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r864-28pw-8682/GHSA-r864-28pw-8682.json b/advisories/unreviewed/2024/11/GHSA-r864-28pw-8682/GHSA-r864-28pw-8682.json new file mode 100644 index 00000000000..e340c5bc0cc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r864-28pw-8682/GHSA-r864-28pw-8682.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r864-28pw-8682", + "modified": "2024-11-14T12:31:02Z", + "published": "2024-11-14T12:31:02Z", + "aliases": [ + "CVE-2022-31668" + ], + "details": "Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/goharbor/harbor/security/advisories/GHSA-3wpx-625q-22j7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31668" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xvx4-v362-295f/GHSA-xvx4-v362-295f.json b/advisories/unreviewed/2024/11/GHSA-xvx4-v362-295f/GHSA-xvx4-v362-295f.json new file mode 100644 index 00000000000..a9ea56e6b99 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xvx4-v362-295f/GHSA-xvx4-v362-295f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvx4-v362-295f", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:01Z", + "aliases": [ + "CVE-2024-5918" + ], + "details": "An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you \"Allow Authentication with User Credentials OR Client Certificate.\"", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5918" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5918" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwcj-grfm-xm6q/GHSA-xwcj-grfm-xm6q.json b/advisories/unreviewed/2024/11/GHSA-xwcj-grfm-xm6q/GHSA-xwcj-grfm-xm6q.json new file mode 100644 index 00000000000..a9e55b71491 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xwcj-grfm-xm6q/GHSA-xwcj-grfm-xm6q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwcj-grfm-xm6q", + "modified": "2024-11-14T12:31:00Z", + "published": "2024-11-14T12:31:00Z", + "aliases": [ + "CVE-2024-47915" + ], + "details": "VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47915" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json b/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json new file mode 100644 index 00000000000..4f10fc76343 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx8r-3wgj-j632", + "modified": "2024-11-14T12:31:01Z", + "published": "2024-11-14T12:31:01Z", + "aliases": [ + "CVE-2024-5920" + ], + "details": "A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5920" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5920" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-14T10:15:09Z" + } +} \ No newline at end of file