Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-15 06:32:55 +00:00
parent 8aa2a61a68
commit d849db6887
66 changed files with 1057 additions and 127 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qx3r-xm4v-rgrh",
"modified": "2022-05-02T03:43:30Z",
"modified": "2024-02-15T06:31:31Z",
"published": "2022-05-02T03:43:30Z",
"aliases": [
"CVE-2009-3278"
],
"details": "The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -37,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-338"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jpv-w64v-mgr2",
"modified": "2024-02-01T03:30:22Z",
"modified": "2024-02-15T06:31:32Z",
"published": "2023-11-02T09:30:18Z",
"aliases": [
"CVE-2023-46595"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2862-59r4-c989",
"modified": "2024-02-08T15:30:26Z",
"modified": "2024-02-15T06:31:34Z",
"published": "2024-02-08T09:30:40Z",
"aliases": [
"CVE-2024-23452"
],
"details": "Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request.\n\nVulnerability Cause Description\n\nThe http_parser does not comply with the RFC-7230 HTTP 1.1 specification.\n\nAttack scenario:\nIf a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting.\nOne particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server. \n\nSolution:\nYou can choose one solution from below:\n1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0\n 2. Apply this patch:  https://github.com/apache/brpc/pull/2518 \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
"CWE-444"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-08T09:15:46Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2j3h-78mv-5phm",
"modified": "2024-02-13T00:30:27Z",
"modified": "2024-02-15T06:31:35Z",
"published": "2024-02-13T00:30:27Z",
"aliases": [
"CVE-2024-23760"
],
"details": "Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-12T22:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34vw-rxxh-698f",
"modified": "2024-02-08T18:30:39Z",
"modified": "2024-02-15T06:31:34Z",
"published": "2024-02-08T18:30:39Z",
"aliases": [
"CVE-2024-24321"
],
"details": "An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -24,11 +27,11 @@
},
{
"type": "WEB",
"url": "https://www.dlink.com/"
"url": "https://www.dlink.com"
},
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin/"
"url": "https://www.dlink.com/en/security-bulletin"
},
{
"type": "WEB",
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-08T18:15:08Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35qh-7f6c-rjf7",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:35Z",
"aliases": [
"CVE-2024-1488"
],
"details": "A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1488"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1488"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2264183"
}
],
"database_specific": {
"cwe_ids": [
"CWE-15"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T05:15:10Z"
}
}
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m2v-36rg-mxhc",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2021-29633"
],
"details": "Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29633"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T06:15:44Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mpr-9r86-mfv2",
"modified": "2024-02-14T18:30:25Z",
"modified": "2024-02-15T06:31:35Z",
"published": "2024-02-14T18:30:25Z",
"aliases": [
"CVE-2024-25215"
],
"details": "Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-14T15:15:09Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q8j-579q-jx44",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2022-23090"
],
"details": "The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case.\n\nAn attacker may cause the reference count to overflow, leading to a use after free (UAF).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23090"
},
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T06:15:45Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45qp-5fqj-668c",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2021-29637"
],
"details": "Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29637"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T06:15:44Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qxf-cfrr-vxjg",
"modified": "2024-02-15T06:31:35Z",
"published": "2024-02-15T06:31:35Z",
"aliases": [
"CVE-2024-25559"
],
"details": "URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25559"
},
{
"type": "WEB",
"url": "https://developer.a-blogcms.jp/blog/news/JVN-48966481.html"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN48966481"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T05:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vg6-rmxw-vq23",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2024-25941"
],
"details": "The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail.\n\nAttacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by \"pstat -t\" may be leaked.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25941"
},
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T05:15:11Z"
}
}
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-307"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66rh-g7jv-6752",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2022-23091"
],
"details": "A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause.\n\nAn unprivileged local user process can maintain a mapping of a page after it is freed, allowing that process to read private data belonging to other processes or the kernel.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23091"
},
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:11.vm.asc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T06:15:45Z"
}
}
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-256"
"CWE-256",
"CWE-522"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77vw-jrxp-2648",
"modified": "2024-02-09T15:31:27Z",
"modified": "2024-02-15T06:31:35Z",
"published": "2024-02-09T15:31:27Z",
"aliases": [
"CVE-2024-25448"
],
"details": "An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-09T15:15:09Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7p28-5p54-rq49",
"modified": "2024-02-15T06:31:36Z",
"published": "2024-02-15T06:31:36Z",
"aliases": [
"CVE-2022-23093"
],
"details": "ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a \"quoted packet,\" which represents the packet that generated an ICMP error. The quoted packet again has an IP header and an ICMP header.\n\nThe pr_pack() copies received IP and ICMP headers into stack buffers for further processing. In so doing, it fails to take into account the possible presence of IP option headers following the IP header in either the response or the quoted packet. When IP options are present, pr_pack() overflows the destination buffer by up to 40 bytes.\n\nThe memory safety bugs described above can be triggered by a remote host, causing the ping program to crash.\n\nThe ping process runs in a capability mode sandbox on all affected versions of FreeBSD and is thus very constrained in how it can interact with the rest of the system at the point where the bug can occur.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23093"
},
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:15.ping.asc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T06:15:45Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xg3-5hhv-932f",
"modified": "2024-02-15T06:31:35Z",
"published": "2024-02-15T06:31:35Z",
"aliases": [
"CVE-2022-23088"
],
"details": "The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer.\n\nWhile a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23088"
},
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:07.wifi_meshid.asc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T05:15:09Z"
}
}
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-319",
"CWE-614"
],
"severity": "MODERATE",

Some files were not shown because too many files have changed in this diff Show More