Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-10-15 15:31:55 +00:00
parent f5f2c8079c
commit da65dfa8a1
37 changed files with 445 additions and 24 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q6r-hx29-59m5",
"modified": "2024-10-15T12:30:35Z",
"modified": "2024-10-15T15:30:44Z",
"published": "2023-09-20T09:30:22Z",
"aliases": [
"CVE-2023-22644"
@@ -21,6 +21,10 @@
],
"references": [
{
"type": "WEB",
"url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-622h-h2p8-743x"
},
{
"type": "WEB",
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-9ghh-mmcq-8phc"
@@ -36,10 +40,15 @@
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22650"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32188"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1270",
"CWE-287",
"CWE-532"
],
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-122",
"CWE-787"
],
@@ -36,6 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-121",
"CWE-787"
],
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-122",
"CWE-787"
],
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-121",
"CWE-787"
],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27vg-qjpq-w479",
"modified": "2024-10-10T03:30:45Z",
"modified": "2024-10-15T15:30:45Z",
"published": "2024-10-10T03:30:45Z",
"aliases": [
"CVE-2024-8987"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wg5-x88w-52fj",
"modified": "2024-10-09T18:31:43Z",
"modified": "2024-10-15T15:30:45Z",
"published": "2024-10-09T18:31:43Z",
"aliases": [
"CVE-2024-9466"
],
"details": "A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red"
@@ -28,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312",
"CWE-532"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x4w-v43m-f5m7",
"modified": "2024-10-11T18:32:49Z",
"modified": "2024-10-15T15:30:49Z",
"published": "2024-10-11T18:32:49Z",
"aliases": [
"CVE-2024-47489"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47ww-vfc5-5gxw",
"modified": "2024-10-10T03:30:46Z",
"modified": "2024-10-15T15:30:45Z",
"published": "2024-10-10T03:30:46Z",
"aliases": [
"CVE-2024-9057"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-537j-q568-qwrw",
"modified": "2024-10-11T15:30:33Z",
"modified": "2024-10-15T15:30:48Z",
"published": "2024-10-11T15:30:33Z",
"aliases": [
"CVE-2024-8755"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-201"
],
"severity": "MODERATE",
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55qg-f678-jcg9",
"modified": "2024-10-15T15:30:54Z",
"published": "2024-10-15T15:30:54Z",
"aliases": [
"CVE-2024-48278"
],
"details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48278"
},
{
"type": "WEB",
"url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/CSRF%20-%20Profile.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T13:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5645-gr78-qx8w",
"modified": "2024-10-04T18:31:11Z",
"modified": "2024-10-15T15:30:45Z",
"published": "2024-10-04T18:31:11Z",
"aliases": [
"CVE-2024-38039"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-80"
],
"severity": "MODERATE",
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jgw-rgmm-7cv6",
"modified": "2024-10-15T15:30:56Z",
"published": "2024-10-15T15:30:56Z",
"aliases": [
"CVE-2024-9979"
],
"details": "A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9979"
},
{
"type": "WEB",
"url": "https://github.com/PyO3/pyo3/pull/4590"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9979"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318646"
},
{
"type": "WEB",
"url": "https://crates.io/crates/pyo3"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2024-0378.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T14:15:05Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6rfh-8xcw-f6f2",
"modified": "2024-10-15T15:30:55Z",
"published": "2024-10-15T15:30:55Z",
"aliases": [
"CVE-2024-48282"
],
"details": "A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48282"
},
{
"type": "WEB",
"url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Forget%20Password.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T13:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75jw-84pf-jxc9",
"modified": "2024-10-15T15:30:54Z",
"published": "2024-10-15T15:30:54Z",
"aliases": [
"CVE-2024-48280"
],
"details": "A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48280"
},
{
"type": "WEB",
"url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Bw%20Date%20Report%20%28%20fromdate%29.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T13:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79v4-xhfm-cr97",
"modified": "2024-10-11T18:32:49Z",
"modified": "2024-10-15T15:30:49Z",
"published": "2024-10-11T18:32:49Z",
"aliases": [
"CVE-2024-47491"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-994f-pcw4-m52m",
"modified": "2024-10-15T15:30:55Z",
"published": "2024-10-15T15:30:55Z",
"aliases": [
"CVE-2024-48283"
],
"details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48283"
},
{
"type": "WEB",
"url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Search.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T13:15:11Z"
}
}
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f2c-45xq-c486",
"modified": "2024-10-09T18:31:43Z",
"modified": "2024-10-15T15:30:45Z",
"published": "2024-10-09T18:31:43Z",
"aliases": [
"CVE-2024-9465"
],
"details": "An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red"

Some files were not shown because too many files have changed in this diff Show More