diff --git a/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json b/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json index 4147d6bd887..b514dce6b76 100644 --- a/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json +++ b/advisories/unreviewed/2024/03/GHSA-p67c-35g3-9pqc/GHSA-p67c-35g3-9pqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p67c-35g3-9pqc", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-06-21T00:33:10Z", "published": "2024-03-12T18:31:15Z", "aliases": [ "CVE-2024-2182" @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-2182" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4035" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1394" diff --git a/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json b/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json new file mode 100644 index 00000000000..c9bcc3479dd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4395-qwxq-qcc7", + "modified": "2024-06-21T00:33:13Z", + "published": "2024-06-21T00:33:13Z", + "aliases": [ + "CVE-2024-6212" + ], + "details": "A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6212" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1tl9-EAxUR64Og9zS-nyUx3YtG1V32Monkvq-h39tjpw/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json b/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json new file mode 100644 index 00000000000..30e3a97531e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p75-m8gf-m966", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35161" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35161" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json b/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json new file mode 100644 index 00000000000..49f107af8a3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52jj-4q75-g96j", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35156" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35156" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json b/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json new file mode 100644 index 00000000000..22db3b7606e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75gh-r85f-8vjg", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35162" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35162" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json b/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json new file mode 100644 index 00000000000..fd7129bb99f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-779j-fcpp-pwc7", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35160" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35160" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json b/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json new file mode 100644 index 00000000000..a86c6f3bd5b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-823f-vx3m-4692", + "modified": "2024-06-21T00:33:10Z", + "published": "2024-06-21T00:33:10Z", + "aliases": [ + "CVE-2024-32943" + ], + "details": "An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32943" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json b/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json new file mode 100644 index 00000000000..48e0991db5b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ggh-gmc9-j7xp", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35155" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35155" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json b/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json new file mode 100644 index 00000000000..d870328a982 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mp6-9h4v-jqg2", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35158" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35158" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json b/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json new file mode 100644 index 00000000000..85d7d108980 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpjq-wfvr-wx93", + "modified": "2024-06-21T00:33:10Z", + "published": "2024-06-21T00:33:10Z", + "aliases": [ + "CVE-2024-5746" + ], + "details": "A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to GitHub Enterprise Server as a user with the Site Administrator role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.12.5, 3.11.11, 3.10.13, and 3.9.16. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5746" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.13" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.16" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json b/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json new file mode 100644 index 00000000000..13cdbf5bdb1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m82v-cwh2-mrvc", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35157" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35157" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json b/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json new file mode 100644 index 00000000000..4dd22ab672c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg6v-q43w-88rw", + "modified": "2024-06-21T00:33:11Z", + "published": "2024-06-21T00:33:11Z", + "aliases": [ + "CVE-2019-15798" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15798" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json b/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json new file mode 100644 index 00000000000..5f1f44b3df6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vx-3hhc-h6c9", + "modified": "2024-06-21T00:33:09Z", + "published": "2024-06-21T00:33:09Z", + "aliases": [ + "CVE-2024-37183" + ], + "details": "Plain text credentials and session ID can be captured with a network sniffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37183" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json b/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json new file mode 100644 index 00000000000..f9c90687e35 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqr4-mc25-2cvq", + "modified": "2024-06-21T00:33:11Z", + "published": "2024-06-21T00:33:11Z", + "aliases": [ + "CVE-2024-35246" + ], + "details": "An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35246" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-20T23:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json b/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json new file mode 100644 index 00000000000..a09daf07436 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7h7-9h84-r622", + "modified": "2024-06-21T00:33:11Z", + "published": "2024-06-21T00:33:11Z", + "aliases": [ + "CVE-2019-15797" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15797" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json b/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json new file mode 100644 index 00000000000..2a9f7dbf36d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm6m-893q-83gj", + "modified": "2024-06-21T00:33:12Z", + "published": "2024-06-21T00:33:12Z", + "aliases": [ + "CVE-2020-35159" + ], + "details": "Rejected reason: CVE ID was once reserved, but never used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35159" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T00:15:09Z" + } +} \ No newline at end of file