From dc9592114c2508918c3a1dcf39bcd1bb0909b36e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 Feb 2024 18:31:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-m7xj-ccqc-p4g2.json | 266 +++++++++++------- .../GHSA-vgh3-mwxq-rcp8.json | 6 +- .../GHSA-hmq6-2xj3-79w5.json | 3 +- .../GHSA-799h-8vpw-vp7q.json | 4 +- .../GHSA-882v-v6g5-f7qr.json | 4 +- .../GHSA-4jrv-6m77-vrhq.json | 6 +- .../GHSA-f35j-mfvw-p857.json | 6 +- .../GHSA-p5vr-h433-qhqr.json | 6 +- .../GHSA-x9c6-9g9w-hg73.json | 6 +- .../GHSA-3323-4cph-j8c7.json | 46 +++ .../GHSA-3qrv-r8v8-pmw7.json | 6 +- .../GHSA-5j67-qqcw-qpc2.json | 46 +++ .../GHSA-5j6p-376x-h7gg.json | 46 +++ .../GHSA-94q5-q5cp-xvh6.json | 46 +++ .../GHSA-9rvx-gm3h-fh8c.json | 46 +++ .../GHSA-f7wr-8w9m-h29x.json | 46 +++ .../GHSA-fp58-4rhj-2q23.json | 46 +++ .../GHSA-fv4p-ghwr-3g9x.json | 2 +- .../GHSA-h8wv-9h96-m4hr.json | 38 +++ .../GHSA-hrqx-cgrg-w5g9.json | 2 +- .../GHSA-j6hx-p9qx-hf8r.json | 46 +++ .../GHSA-jhwv-44fv-jwp5.json | 6 +- .../GHSA-mp9p-399h-gx5m.json | 46 +++ .../GHSA-qfrv-fmc5-hmmh.json | 38 +++ .../GHSA-rc6h-qwj9-2c53.json | 47 ++++ .../GHSA-v7cx-w2mc-c39f.json | 46 +++ .../GHSA-whh8-fjgc-qp73.json | 42 +++ .../GHSA-wrwv-3pqq-rr32.json | 2 +- 28 files changed, 831 insertions(+), 119 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json (53%) create mode 100644 advisories/unreviewed/2024/02/GHSA-3323-4cph-j8c7/GHSA-3323-4cph-j8c7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5j67-qqcw-qpc2/GHSA-5j67-qqcw-qpc2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5j6p-376x-h7gg/GHSA-5j6p-376x-h7gg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-94q5-q5cp-xvh6/GHSA-94q5-q5cp-xvh6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9rvx-gm3h-fh8c/GHSA-9rvx-gm3h-fh8c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-f7wr-8w9m-h29x/GHSA-f7wr-8w9m-h29x.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fp58-4rhj-2q23/GHSA-fp58-4rhj-2q23.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j6hx-p9qx-hf8r/GHSA-j6hx-p9qx-hf8r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mp9p-399h-gx5m/GHSA-mp9p-399h-gx5m.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rc6h-qwj9-2c53/GHSA-rc6h-qwj9-2c53.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v7cx-w2mc-c39f/GHSA-v7cx-w2mc-c39f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json diff --git a/advisories/unreviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json b/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json similarity index 53% rename from advisories/unreviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json rename to advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json index fb39adb1beb..f2012bf45da 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json +++ b/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json @@ -1,27 +1,101 @@ { "schema_version": "1.4.0", "id": "GHSA-m7xj-ccqc-p4g2", - "modified": "2022-05-01T23:55:04Z", + "modified": "2024-02-23T18:30:24Z", "published": "2022-05-01T23:55:04Z", "aliases": [ "CVE-2008-2938" ], + "summary": "Apache Tomcat Directory Traversal vulnerability", "details": "Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.1.0" + }, + { + "fixed": "4.1.39" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 4.1.37" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.5.0" + }, + { + "fixed": "5.5.27" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 5.5.26" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.0.0" + }, + { + "fixed": "6.0.18" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 6.0.16" + } + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-2938" }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/c55ad56ed72ee1dbfe790bc5492d4df74e3e754f" + }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44411" }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/tomcat" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E" @@ -46,10 +120,94 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" + }, { "type": "WEB", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10587" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20080827130946/http://securityreason.com/securityalert/4148" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201124623/http://secunia.com/advisories/31639" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201124633/http://secunia.com/advisories/31891" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201124638/http://secunia.com/advisories/32120" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201124957/http://secunia.com/advisories/31982" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201125002/http://secunia.com/advisories/32266" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090201141000/http://secunia.com/advisories/32222" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090207111236/http://secunia.com/advisories/33797" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090308065055/http://secunia.com/advisories/31865" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20100516085845/http://secunia.com/advisories/37297" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20110711210039/http://rhn.redhat.com/errata/RHSA-2008-0862.html" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20110713233239/http://rhn.redhat.com/errata/RHSA-2008-0648.html" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20110713234158/http://rhn.redhat.com/errata/RHSA-2008-0864.html" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140628064423/http://www.securityfocus.com/archive/1/495318/100/0/threaded" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140628064448/http://www.securityfocus.com/archive/1/507729/100/0/threaded" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140826163457/http://www.securityfocus.com/bid/30633" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140826171227/http://www.securitytracker.com/id?1020665" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140826232500/http://www.securityfocus.com/bid/31681" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140827130327/http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200612070417/http://marc.info/?l=bugtraq&m=123376588623823&w=2" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/6229" @@ -66,10 +224,6 @@ "type": "WEB", "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html" }, - { - "type": "WEB", - "url": "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" - }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html" @@ -78,50 +232,6 @@ "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" }, - { - "type": "WEB", - "url": "http://marc.info/?l=bugtraq&m=123376588623823&w=2" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/31639" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/31865" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/31891" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/31982" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/32120" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/32222" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/32266" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/33797" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37297" - }, - { - "type": "WEB", - "url": "http://securityreason.com/securityalert/4148" - }, { "type": "WEB", "url": "http://support.apple.com/kb/HT3216" @@ -149,58 +259,6 @@ { "type": "WEB", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:188" - }, - { - "type": "WEB", - "url": "http://www.redhat.com/support/errata/RHSA-2008-0648.html" - }, - { - "type": "WEB", - "url": "http://www.redhat.com/support/errata/RHSA-2008-0862.html" - }, - { - "type": "WEB", - "url": "http://www.redhat.com/support/errata/RHSA-2008-0864.html" - }, - { - "type": "WEB", - "url": "http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/495318/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/507729/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/30633" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/31681" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1020665" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2008/2343" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2008/2780" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2008/2823" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/0320" } ], "database_specific": { @@ -208,8 +266,8 @@ "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-02-23T18:30:24Z", "nvd_published_at": "2008-08-13T00:41:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-vgh3-mwxq-rcp8/GHSA-vgh3-mwxq-rcp8.json b/advisories/github-reviewed/2024/02/GHSA-vgh3-mwxq-rcp8/GHSA-vgh3-mwxq-rcp8.json index bc95b80ac4c..b3407628551 100644 --- a/advisories/github-reviewed/2024/02/GHSA-vgh3-mwxq-rcp8/GHSA-vgh3-mwxq-rcp8.json +++ b/advisories/github-reviewed/2024/02/GHSA-vgh3-mwxq-rcp8/GHSA-vgh3-mwxq-rcp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgh3-mwxq-rcp8", - "modified": "2024-02-01T20:52:34Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-02-01T03:30:22Z", "aliases": [ "CVE-2024-0831" @@ -55,6 +55,10 @@ { "type": "PACKAGE", "url": "https://github.com/hashicorp/vault" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-hmq6-2xj3-79w5/GHSA-hmq6-2xj3-79w5.json b/advisories/unreviewed/2022/04/GHSA-hmq6-2xj3-79w5/GHSA-hmq6-2xj3-79w5.json index 058bcb3b5bb..ea4a071403a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hmq6-2xj3-79w5/GHSA-hmq6-2xj3-79w5.json +++ b/advisories/unreviewed/2022/04/GHSA-hmq6-2xj3-79w5/GHSA-hmq6-2xj3-79w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hmq6-2xj3-79w5", - "modified": "2022-04-21T00:00:58Z", + "modified": "2024-02-23T18:30:58Z", "published": "2022-04-13T00:00:29Z", "aliases": [ "CVE-2021-32040" @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json b/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json index 0f14c04aa2c..9a1c5be32fa 100644 --- a/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json +++ b/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-799h-8vpw-vp7q", - "modified": "2023-08-01T18:30:26Z", + "modified": "2024-02-23T18:30:59Z", "published": "2023-07-21T21:30:31Z", "aliases": [ "CVE-2023-25841" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-21T19:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-882v-v6g5-f7qr/GHSA-882v-v6g5-f7qr.json b/advisories/unreviewed/2023/08/GHSA-882v-v6g5-f7qr/GHSA-882v-v6g5-f7qr.json index dfa8c527cff..a9fdceb2e28 100644 --- a/advisories/unreviewed/2023/08/GHSA-882v-v6g5-f7qr/GHSA-882v-v6g5-f7qr.json +++ b/advisories/unreviewed/2023/08/GHSA-882v-v6g5-f7qr/GHSA-882v-v6g5-f7qr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-882v-v6g5-f7qr", - "modified": "2023-08-28T18:30:52Z", + "modified": "2024-02-23T18:30:58Z", "published": "2023-08-22T21:30:26Z", "aliases": [ "CVE-2021-34193" @@ -74,7 +74,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-22T19:16:20Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json b/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json index c1de89e4a7d..dcdba5f1975 100644 --- a/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json +++ b/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jrv-6m77-vrhq", - "modified": "2024-01-15T21:30:24Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-01-15T21:30:24Z", "aliases": [ "CVE-2024-0565" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258518" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0002" + }, { "type": "WEB", "url": "https://www.spinics.net/lists/stable-commits/msg328851.html" diff --git a/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json b/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json index 64e60ad59dd..0a742b3edee 100644 --- a/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json +++ b/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f35j-mfvw-p857", - "modified": "2024-01-03T18:30:51Z", + "modified": "2024-02-23T18:30:58Z", "published": "2024-01-03T18:30:51Z", "aliases": [ "CVE-2023-6004" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0004" + }, { "type": "WEB", "url": "https://www.libssh.org/security/advisories/CVE-2023-6004.txt" diff --git a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json index 1b9ac3de720..761c43b8f9f 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json +++ b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5vr-h433-qhqr", - "modified": "2024-02-15T09:30:35Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-6779" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202402-01" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0006" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" diff --git a/advisories/unreviewed/2024/01/GHSA-x9c6-9g9w-hg73/GHSA-x9c6-9g9w-hg73.json b/advisories/unreviewed/2024/01/GHSA-x9c6-9g9w-hg73/GHSA-x9c6-9g9w-hg73.json index b3e1c67d59f..905ba30fbc5 100644 --- a/advisories/unreviewed/2024/01/GHSA-x9c6-9g9w-hg73/GHSA-x9c6-9g9w-hg73.json +++ b/advisories/unreviewed/2024/01/GHSA-x9c6-9g9w-hg73/GHSA-x9c6-9g9w-hg73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9c6-9g9w-hg73", - "modified": "2024-01-12T21:30:19Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-01-12T21:30:19Z", "aliases": [ "CVE-2023-6683" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254825" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-3323-4cph-j8c7/GHSA-3323-4cph-j8c7.json b/advisories/unreviewed/2024/02/GHSA-3323-4cph-j8c7/GHSA-3323-4cph-j8c7.json new file mode 100644 index 00000000000..2dc0a234564 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3323-4cph-j8c7/GHSA-3323-4cph-j8c7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3323-4cph-j8c7", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1825" + ], + "details": "A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This affects an unknown part of the component User Registration Page. The manipulation of the argument address with the input leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254613 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1825" + }, + { + "type": "WEB", + "url": "https://docs.qq.com/doc/DYndSY3V4UXh4dHFC" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254613" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json b/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json index a4b1e25fe55..bb86b8da51e 100644 --- a/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json +++ b/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qrv-r8v8-pmw7", - "modified": "2024-02-06T18:30:21Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-02-06T18:30:21Z", "aliases": [ "CVE-2024-1048" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256827" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0007" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/02/06/3" diff --git a/advisories/unreviewed/2024/02/GHSA-5j67-qqcw-qpc2/GHSA-5j67-qqcw-qpc2.json b/advisories/unreviewed/2024/02/GHSA-5j67-qqcw-qpc2/GHSA-5j67-qqcw-qpc2.json new file mode 100644 index 00000000000..128bfa90774 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5j67-qqcw-qpc2/GHSA-5j67-qqcw-qpc2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j67-qqcw-qpc2", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1823" + ], + "details": "A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php of the component Backend. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254611.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1823" + }, + { + "type": "WEB", + "url": "https://docs.qq.com/doc/DYll0ZEFKcUdGYlNr" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254611" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5j6p-376x-h7gg/GHSA-5j6p-376x-h7gg.json b/advisories/unreviewed/2024/02/GHSA-5j6p-376x-h7gg/GHSA-5j6p-376x-h7gg.json new file mode 100644 index 00000000000..db8f7318824 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5j6p-376x-h7gg/GHSA-5j6p-376x-h7gg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j6p-376x-h7gg", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1827" + ], + "details": "A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file Source/librarian/user/teacher/login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254615.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1827" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/3.2Library%20System%20In%20PHP%20-%20SQL%20Injection-teacher_login.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254615" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-94q5-q5cp-xvh6/GHSA-94q5-q5cp-xvh6.json b/advisories/unreviewed/2024/02/GHSA-94q5-q5cp-xvh6/GHSA-94q5-q5cp-xvh6.json new file mode 100644 index 00000000000..200f77dba06 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-94q5-q5cp-xvh6/GHSA-94q5-q5cp-xvh6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94q5-q5cp-xvh6", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1829" + ], + "details": "A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Source/librarian/user/student/registration.php. The manipulation of the argument email/regno/phone/username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254617 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1829" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/3.4Library%20System%20In%20PHP%20-%20SQL%20Injection-student_reg.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254617" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254617" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9rvx-gm3h-fh8c/GHSA-9rvx-gm3h-fh8c.json b/advisories/unreviewed/2024/02/GHSA-9rvx-gm3h-fh8c/GHSA-9rvx-gm3h-fh8c.json new file mode 100644 index 00000000000..75d00992ee8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9rvx-gm3h-fh8c/GHSA-9rvx-gm3h-fh8c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rvx-gm3h-fh8c", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1826" + ], + "details": "A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-254614 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1826" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/3Library%20System%20In%20PHP%20-%20SQL%20Injection-student_login.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254614" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254614" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f7wr-8w9m-h29x/GHSA-f7wr-8w9m-h29x.json b/advisories/unreviewed/2024/02/GHSA-f7wr-8w9m-h29x/GHSA-f7wr-8w9m-h29x.json new file mode 100644 index 00000000000..a8fbdc79125 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f7wr-8w9m-h29x/GHSA-f7wr-8w9m-h29x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7wr-8w9m-h29x", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1824" + ], + "details": "A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254612.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1824" + }, + { + "type": "WEB", + "url": "https://docs.qq.com/doc/DYk9QcHVFRENObWtj" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254612" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fp58-4rhj-2q23/GHSA-fp58-4rhj-2q23.json b/advisories/unreviewed/2024/02/GHSA-fp58-4rhj-2q23/GHSA-fp58-4rhj-2q23.json new file mode 100644 index 00000000000..2fe33997783 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fp58-4rhj-2q23/GHSA-fp58-4rhj-2q23.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp58-4rhj-2q23", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1821" + ], + "details": "A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file police_add.php. The manipulation of the argument police_name/police_id/police_spec/password leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254609 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1821" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/2Crime%20Reporting%20System%20-%20SQL%20Injection-police_add.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254609" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254609" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json b/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json index 547825873e0..5050048ee23 100644 --- a/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json +++ b/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json b/advisories/unreviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json new file mode 100644 index 00000000000..2bda5c0f20d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h8wv-9h96-m4hr/GHSA-h8wv-9h96-m4hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8wv-9h96-m4hr", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-27319" + ], + "details": "Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27319" + }, + { + "type": "WEB", + "url": "https://github.com/onnx/onnx/commit/08a399ba75a805b7813ab8936b91d0e274b08287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json b/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json index 89feb0f9126..792209fde09 100644 --- a/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json +++ b/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-j6hx-p9qx-hf8r/GHSA-j6hx-p9qx-hf8r.json b/advisories/unreviewed/2024/02/GHSA-j6hx-p9qx-hf8r/GHSA-j6hx-p9qx-hf8r.json new file mode 100644 index 00000000000..4d57ed19c9b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j6hx-p9qx-hf8r/GHSA-j6hx-p9qx-hf8r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6hx-p9qx-hf8r", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1828" + ], + "details": "A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. Affected is an unknown function of the file Source/librarian/user/teacher/registration.php. The manipulation of the argument email/idno/phone/username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254616.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1828" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/3.3Library%20System%20In%20PHP%20-%20SQL%20Injection-teacher_reg.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254616" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254616" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json b/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json index 32a8d160d14..86467f4102f 100644 --- a/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json +++ b/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhwv-44fv-jwp5", - "modified": "2024-02-15T03:30:20Z", + "modified": "2024-02-23T18:30:59Z", "published": "2024-02-05T09:30:28Z", "aliases": [ "CVE-2024-22667" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240223-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-mp9p-399h-gx5m/GHSA-mp9p-399h-gx5m.json b/advisories/unreviewed/2024/02/GHSA-mp9p-399h-gx5m/GHSA-mp9p-399h-gx5m.json new file mode 100644 index 00000000000..d29441a1495 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mp9p-399h-gx5m/GHSA-mp9p-399h-gx5m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp9p-399h-gx5m", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1820" + ], + "details": "A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254608.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1820" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/02/1Crime%20Reporting%20System%20-%20SQL%20Injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254608" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json b/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json new file mode 100644 index 00000000000..f7ec9095013 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qfrv-fmc5-hmmh/GHSA-qfrv-fmc5-hmmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfrv-fmc5-hmmh", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2023-51392" + ], + "details": "Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51392" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm000001BKm6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rc6h-qwj9-2c53/GHSA-rc6h-qwj9-2c53.json b/advisories/unreviewed/2024/02/GHSA-rc6h-qwj9-2c53/GHSA-rc6h-qwj9-2c53.json new file mode 100644 index 00000000000..680a085a5b0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rc6h-qwj9-2c53/GHSA-rc6h-qwj9-2c53.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc6h-qwj9-2c53", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-23320" + ], + "details": "Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.\n\nThis issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it.\n\nThis issue affects Apache DolphinScheduler: until 3.2.1.\n\nUsers are recommended to upgrade to version 3.2.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23320" + }, + { + "type": "WEB", + "url": "https://github.com/apache/dolphinscheduler/pull/15487" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/25qhfvlksozzp6j9y8ozznvjdjp3lxqq" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/p7rwzdgrztdfps8x1bwx646f1mn0x6cp" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/tnf99qoc6tlnwrny4t1zk6mfszgdsokm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v7cx-w2mc-c39f/GHSA-v7cx-w2mc-c39f.json b/advisories/unreviewed/2024/02/GHSA-v7cx-w2mc-c39f/GHSA-v7cx-w2mc-c39f.json new file mode 100644 index 00000000000..16820328b6c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v7cx-w2mc-c39f/GHSA-v7cx-w2mc-c39f.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7cx-w2mc-c39f", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-1822" + ], + "details": "A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unknown function of the file user-bookings.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-254610 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1822" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1ulzFlRqsex39dDUOFU2LbmphrQblSAwn/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254610" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json b/advisories/unreviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json new file mode 100644 index 00000000000..6b88e1ed828 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-whh8-fjgc-qp73/GHSA-whh8-fjgc-qp73.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whh8-fjgc-qp73", + "modified": "2024-02-23T18:30:59Z", + "published": "2024-02-23T18:30:59Z", + "aliases": [ + "CVE-2024-27318" + ], + "details": "Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27318" + }, + { + "type": "WEB", + "url": "https://github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-23T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json b/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json index 99f35135b57..513f6c0e7fb 100644 --- a/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json +++ b/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false,