mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-p67c-35g3-9pqc GHSA-4395-qwxq-qcc7 GHSA-4p75-m8gf-m966 GHSA-52jj-4q75-g96j GHSA-75gh-r85f-8vjg GHSA-779j-fcpp-pwc7 GHSA-823f-vx3m-4692 GHSA-8ggh-gmc9-j7xp GHSA-9mp6-9h4v-jqg2 GHSA-fpjq-wfvr-wx93 GHSA-m82v-cwh2-mrvc GHSA-mg6v-q43w-88rw GHSA-p4vx-3hhc-h6c9 GHSA-rqr4-mc25-2cvq GHSA-v7h7-9h84-r622 GHSA-wm6m-893q-83gj
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p67c-35g3-9pqc",
|
||||
"modified": "2024-05-01T18:30:36Z",
|
||||
"modified": "2024-06-21T00:33:10Z",
|
||||
"published": "2024-03-12T18:31:15Z",
|
||||
"aliases": [
|
||||
"CVE-2024-2182"
|
||||
@@ -49,6 +49,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-2182"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:4035"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:1394"
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4395-qwxq-qcc7",
|
||||
"modified": "2024-06-21T00:33:13Z",
|
||||
"published": "2024-06-21T00:33:13Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6212"
|
||||
],
|
||||
"details": "A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6212"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.google.com/document/d/1tl9-EAxUR64Og9zS-nyUx3YtG1V32Monkvq-h39tjpw/edit?usp=sharing"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.269276"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.269276"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?submit.359229"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4p75-m8gf-m966",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35161"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35161"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-52jj-4q75-g96j",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35156"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35156"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-75gh-r85f-8vjg",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35162"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35162"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-779j-fcpp-pwc7",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35160"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35160"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-823f-vx3m-4692",
|
||||
"modified": "2024-06-21T00:33:10Z",
|
||||
"published": "2024-06-21T00:33:10Z",
|
||||
"aliases": [
|
||||
"CVE-2024-32943"
|
||||
],
|
||||
"details": "An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32943"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-799"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T23:15:51Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8ggh-gmc9-j7xp",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35155"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35155"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9mp6-9h4v-jqg2",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35158"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35158"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fpjq-wfvr-wx93",
|
||||
"modified": "2024-06-21T00:33:10Z",
|
||||
"published": "2024-06-21T00:33:10Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5746"
|
||||
],
|
||||
"details": "A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to GitHub Enterprise Server as a user with the Site Administrator role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.12.5, 3.11.11, 3.10.13, and 3.9.16. This vulnerability was reported via the GitHub Bug Bounty program.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5746"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.13"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.11"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.5"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.16"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-918"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T22:15:16Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m82v-cwh2-mrvc",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35157"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35157"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mg6v-q43w-88rw",
|
||||
"modified": "2024-06-21T00:33:11Z",
|
||||
"published": "2024-06-21T00:33:11Z",
|
||||
"aliases": [
|
||||
"CVE-2019-15798"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15798"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p4vx-3hhc-h6c9",
|
||||
"modified": "2024-06-21T00:33:09Z",
|
||||
"published": "2024-06-21T00:33:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37183"
|
||||
],
|
||||
"details": "Plain text credentials and session ID can be captured with a network sniffer.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37183"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-319"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T22:15:15Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rqr4-mc25-2cvq",
|
||||
"modified": "2024-06-21T00:33:11Z",
|
||||
"published": "2024-06-21T00:33:11Z",
|
||||
"aliases": [
|
||||
"CVE-2024-35246"
|
||||
],
|
||||
"details": "An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35246"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-799"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-20T23:15:52Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v7h7-9h84-r622",
|
||||
"modified": "2024-06-21T00:33:11Z",
|
||||
"published": "2024-06-21T00:33:11Z",
|
||||
"aliases": [
|
||||
"CVE-2019-15797"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15797"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wm6m-893q-83gj",
|
||||
"modified": "2024-06-21T00:33:12Z",
|
||||
"published": "2024-06-21T00:33:12Z",
|
||||
"aliases": [
|
||||
"CVE-2020-35159"
|
||||
],
|
||||
"details": "Rejected reason: CVE ID was once reserved, but never used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35159"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-06-21T00:15:09Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user