From d888696ca01a113fcbd21fe5b117b3f4d6d7ccb9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Aug 2024 12:32:09 +0000 Subject: [PATCH] Publish Advisories GHSA-384m-rpvv-4rw6 GHSA-5943-48f3-6wx5 GHSA-88qp-7q8w-jhw6 GHSA-vf38-34c2-p6j8 GHSA-28pw-27gw-65v8 GHSA-52jj-6w68-3m25 GHSA-8jcj-v53m-3592 GHSA-hrx4-73fv-h4mx --- .../GHSA-384m-rpvv-4rw6.json | 9 +++- .../GHSA-5943-48f3-6wx5.json | 7 ++- .../GHSA-88qp-7q8w-jhw6.json | 6 ++- .../GHSA-vf38-34c2-p6j8.json | 6 ++- .../GHSA-28pw-27gw-65v8.json | 38 +++++++++++++ .../GHSA-52jj-6w68-3m25.json | 38 +++++++++++++ .../GHSA-8jcj-v53m-3592.json | 54 +++++++++++++++++++ .../GHSA-hrx4-73fv-h4mx.json | 42 +++++++++++++++ 8 files changed, 195 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8jcj-v53m-3592/GHSA-8jcj-v53m-3592.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hrx4-73fv-h4mx/GHSA-hrx4-73fv-h4mx.json diff --git a/advisories/unreviewed/2024/02/GHSA-384m-rpvv-4rw6/GHSA-384m-rpvv-4rw6.json b/advisories/unreviewed/2024/02/GHSA-384m-rpvv-4rw6/GHSA-384m-rpvv-4rw6.json index 688fd398525..8ee40884d1b 100644 --- a/advisories/unreviewed/2024/02/GHSA-384m-rpvv-4rw6/GHSA-384m-rpvv-4rw6.json +++ b/advisories/unreviewed/2024/02/GHSA-384m-rpvv-4rw6/GHSA-384m-rpvv-4rw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-384m-rpvv-4rw6", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-08-27T12:30:44Z", "published": "2024-02-23T09:30:38Z", "aliases": [ "CVE-2024-0563" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0563" }, + { + "type": "WEB", + "url": "https://product.m-files.com/security-advisories/cve-2024-0563" + }, { "type": "WEB", "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2024-0563" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5943-48f3-6wx5/GHSA-5943-48f3-6wx5.json b/advisories/unreviewed/2024/04/GHSA-5943-48f3-6wx5/GHSA-5943-48f3-6wx5.json index 4ca7ddc900a..c012135244a 100644 --- a/advisories/unreviewed/2024/04/GHSA-5943-48f3-6wx5/GHSA-5943-48f3-6wx5.json +++ b/advisories/unreviewed/2024/04/GHSA-5943-48f3-6wx5/GHSA-5943-48f3-6wx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5943-48f3-6wx5", - "modified": "2024-04-26T06:30:35Z", + "modified": "2024-08-27T12:30:44Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-4056" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4056" }, + { + "type": "WEB", + "url": "https://product.m-files.com/security-advisories/cve-2024-4056" + }, { "type": "WEB", "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2024-4056" @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-88qp-7q8w-jhw6/GHSA-88qp-7q8w-jhw6.json b/advisories/unreviewed/2024/07/GHSA-88qp-7q8w-jhw6/GHSA-88qp-7q8w-jhw6.json index ae88d5eddbb..eadde1d36d1 100644 --- a/advisories/unreviewed/2024/07/GHSA-88qp-7q8w-jhw6/GHSA-88qp-7q8w-jhw6.json +++ b/advisories/unreviewed/2024/07/GHSA-88qp-7q8w-jhw6/GHSA-88qp-7q8w-jhw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88qp-7q8w-jhw6", - "modified": "2024-08-08T21:32:01Z", + "modified": "2024-08-27T12:30:44Z", "published": "2024-07-29T15:30:36Z", "aliases": [ "CVE-2024-6881" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6881" }, + { + "type": "WEB", + "url": "https://product.m-files.com/security-advisories/cve-2024-6881" + }, { "type": "WEB", "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2024-6881" diff --git a/advisories/unreviewed/2024/07/GHSA-vf38-34c2-p6j8/GHSA-vf38-34c2-p6j8.json b/advisories/unreviewed/2024/07/GHSA-vf38-34c2-p6j8/GHSA-vf38-34c2-p6j8.json index 8248ab86737..3fd03ff4b00 100644 --- a/advisories/unreviewed/2024/07/GHSA-vf38-34c2-p6j8/GHSA-vf38-34c2-p6j8.json +++ b/advisories/unreviewed/2024/07/GHSA-vf38-34c2-p6j8/GHSA-vf38-34c2-p6j8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vf38-34c2-p6j8", - "modified": "2024-08-08T21:32:01Z", + "modified": "2024-08-27T12:30:44Z", "published": "2024-07-29T15:30:35Z", "aliases": [ "CVE-2024-6124" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6124" }, + { + "type": "WEB", + "url": "https://product.m-files.com/security-advisories/cve-2024-6124" + }, { "type": "WEB", "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2024-6124" diff --git a/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json b/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json new file mode 100644 index 00000000000..7e376431b01 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28pw-27gw-65v8", + "modified": "2024-08-27T12:30:44Z", + "published": "2024-08-27T12:30:44Z", + "aliases": [ + "CVE-2024-6789" + ], + "details": "A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 allows authenticated user to read files", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6789" + }, + { + "type": "WEB", + "url": "https://product.m-files.com/security-advisories/cve-2024-6789" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json b/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json new file mode 100644 index 00000000000..620a88367ec --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52jj-6w68-3m25", + "modified": "2024-08-27T12:30:44Z", + "published": "2024-08-27T12:30:44Z", + "aliases": [ + "CVE-2024-8207" + ], + "details": "In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared libraries when the server binary is started, potentially resulting in the unintended actor gaining full control over the MongoDB server process. This issue affects MongoDB Server v5.0 versions prior to 5.0.14 and MongoDB Server v6.0 versions prior to 6.0.3.\n\nRequired Configuration: Only environments with Linux as the underlying operating system is affected by this issue", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8207" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-69507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-114" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T12:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8jcj-v53m-3592/GHSA-8jcj-v53m-3592.json b/advisories/unreviewed/2024/08/GHSA-8jcj-v53m-3592/GHSA-8jcj-v53m-3592.json new file mode 100644 index 00000000000..cc0e200303b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8jcj-v53m-3592/GHSA-8jcj-v53m-3592.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jcj-v53m-3592", + "modified": "2024-08-27T12:30:44Z", + "published": "2024-08-27T12:30:44Z", + "aliases": [ + "CVE-2024-7791" + ], + "details": "The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the Post Grid widget in all versions up to, and including, 1.4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7791" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/post-grid/post-grid.php#L1891" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3141892" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3141892/#file2" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/xpro-elementor-addons/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c6025dd5-a1d7-48cc-90b3-f020d3d2298b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hrx4-73fv-h4mx/GHSA-hrx4-73fv-h4mx.json b/advisories/unreviewed/2024/08/GHSA-hrx4-73fv-h4mx/GHSA-hrx4-73fv-h4mx.json new file mode 100644 index 00000000000..3403e630e0b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hrx4-73fv-h4mx/GHSA-hrx4-73fv-h4mx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrx4-73fv-h4mx", + "modified": "2024-08-27T12:30:44Z", + "published": "2024-08-27T12:30:44Z", + "aliases": [ + "CVE-2024-8197" + ], + "details": "The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.03. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8197" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/88cacd47-d900-478c-b833-c6c55fd4b082" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/48d6d4c1-cc87-4c2c-9fbb-90af62f576aa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T11:15:05Z" + } +} \ No newline at end of file