Publish Advisories

GHSA-p67c-35g3-9pqc
GHSA-4395-qwxq-qcc7
GHSA-4p75-m8gf-m966
GHSA-52jj-4q75-g96j
GHSA-75gh-r85f-8vjg
GHSA-779j-fcpp-pwc7
GHSA-823f-vx3m-4692
GHSA-8ggh-gmc9-j7xp
GHSA-9mp6-9h4v-jqg2
GHSA-fpjq-wfvr-wx93
GHSA-m82v-cwh2-mrvc
GHSA-mg6v-q43w-88rw
GHSA-p4vx-3hhc-h6c9
GHSA-rqr4-mc25-2cvq
GHSA-v7h7-9h84-r622
GHSA-wm6m-893q-83gj
This commit is contained in:
advisory-database[bot]
2024-06-21 00:35:00 +00:00
parent 3abe8a4a54
commit db7967be7f
16 changed files with 529 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p67c-35g3-9pqc",
"modified": "2024-05-01T18:30:36Z",
"modified": "2024-06-21T00:33:10Z",
"published": "2024-03-12T18:31:15Z",
"aliases": [
"CVE-2024-2182"
@@ -49,6 +49,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-2182"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4035"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1394"
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4395-qwxq-qcc7",
"modified": "2024-06-21T00:33:13Z",
"published": "2024-06-21T00:33:13Z",
"aliases": [
"CVE-2024-6212"
],
"details": "A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6212"
},
{
"type": "WEB",
"url": "https://docs.google.com/document/d/1tl9-EAxUR64Og9zS-nyUx3YtG1V32Monkvq-h39tjpw/edit?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.269276"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.269276"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.359229"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:10Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p75-m8gf-m966",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35161"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35161"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52jj-4q75-g96j",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35156"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35156"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75gh-r85f-8vjg",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35162"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35162"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-779j-fcpp-pwc7",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35160"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35160"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-823f-vx3m-4692",
"modified": "2024-06-21T00:33:10Z",
"published": "2024-06-21T00:33:10Z",
"aliases": [
"CVE-2024-32943"
],
"details": "An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32943"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-799"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-20T23:15:51Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8ggh-gmc9-j7xp",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35155"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35155"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mp6-9h4v-jqg2",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35158"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35158"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpjq-wfvr-wx93",
"modified": "2024-06-21T00:33:10Z",
"published": "2024-06-21T00:33:10Z",
"aliases": [
"CVE-2024-5746"
],
"details": "A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to GitHub Enterprise Server as a user with the Site Administrator role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.12.5, 3.11.11, 3.10.13, and 3.9.16. This vulnerability was reported via the GitHub Bug Bounty program.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5746"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.13"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.11"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.5"
},
{
"type": "WEB",
"url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.16"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-20T22:15:16Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m82v-cwh2-mrvc",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35157"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35157"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mg6v-q43w-88rw",
"modified": "2024-06-21T00:33:11Z",
"published": "2024-06-21T00:33:11Z",
"aliases": [
"CVE-2019-15798"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15798"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4vx-3hhc-h6c9",
"modified": "2024-06-21T00:33:09Z",
"published": "2024-06-21T00:33:09Z",
"aliases": [
"CVE-2024-37183"
],
"details": "Plain text credentials and session ID can be captured with a network sniffer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37183"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-20T22:15:15Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqr4-mc25-2cvq",
"modified": "2024-06-21T00:33:11Z",
"published": "2024-06-21T00:33:11Z",
"aliases": [
"CVE-2024-35246"
],
"details": "An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35246"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-799"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-20T23:15:52Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7h7-9h84-r622",
"modified": "2024-06-21T00:33:11Z",
"published": "2024-06-21T00:33:11Z",
"aliases": [
"CVE-2019-15797"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15797"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wm6m-893q-83gj",
"modified": "2024-06-21T00:33:12Z",
"published": "2024-06-21T00:33:12Z",
"aliases": [
"CVE-2020-35159"
],
"details": "Rejected reason: CVE ID was once reserved, but never used.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35159"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T00:15:09Z"
}
}