From dca914a012e9d34a99425bfce98929ed06871131 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 12:32:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-29wp-p54c-r4v7.json | 38 ++++++++++++++ .../GHSA-2w24-rmxp-xpr3.json | 38 ++++++++++++++ .../GHSA-3wf4-68gx-mph8.json | 42 ++++++++++++++++ .../GHSA-4jvm-jp36-77cr.json | 38 ++++++++++++++ .../GHSA-9qrv-rvg6-cq37.json | 46 +++++++++++++++++ .../GHSA-cq5f-wv7p-5gfc.json | 35 +++++++++++++ .../GHSA-fj5v-9mxj-77qc.json | 38 ++++++++++++++ .../GHSA-fjq9-452g-jg3q.json | 35 +++++++++++++ .../GHSA-g34v-qr57-mvrm.json | 38 ++++++++++++++ .../GHSA-gjfh-x4fj-rg67.json | 38 ++++++++++++++ .../GHSA-gv5h-5655-h4mv.json | 50 +++++++++++++++++++ .../GHSA-h47w-8rm3-hpwp.json | 38 ++++++++++++++ .../GHSA-hx7j-rvm5-9vw9.json | 38 ++++++++++++++ .../GHSA-jf42-2pw2-333x.json | 46 +++++++++++++++++ .../GHSA-jhv7-gf64-j752.json | 38 ++++++++++++++ .../GHSA-jq6r-jfg5-r4xg.json | 46 +++++++++++++++++ .../GHSA-jw5r-wxx3-rm98.json | 38 ++++++++++++++ .../GHSA-mfgc-pq48-8r3j.json | 38 ++++++++++++++ .../GHSA-mg54-p2wj-5ph7.json | 35 +++++++++++++ .../GHSA-qvf5-hvjx-wm27.json | 35 +++++++++++++ .../GHSA-vqm5-gf2r-4jjf.json | 38 ++++++++++++++ .../GHSA-wgw9-vmg5-8928.json | 38 ++++++++++++++ .../GHSA-wp87-pj42-93xr.json | 38 ++++++++++++++ .../GHSA-x3x9-349x-2485.json | 35 +++++++++++++ .../GHSA-xcpr-7mr4-h4xq.json | 35 +++++++++++++ .../GHSA-xqwp-cfr5-f9gr.json | 38 ++++++++++++++ 26 files changed, 1010 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-29wp-p54c-r4v7/GHSA-29wp-p54c-r4v7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2w24-rmxp-xpr3/GHSA-2w24-rmxp-xpr3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4jvm-jp36-77cr/GHSA-4jvm-jp36-77cr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fj5v-9mxj-77qc/GHSA-fj5v-9mxj-77qc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g34v-qr57-mvrm/GHSA-g34v-qr57-mvrm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gjfh-x4fj-rg67/GHSA-gjfh-x4fj-rg67.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h47w-8rm3-hpwp/GHSA-h47w-8rm3-hpwp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hx7j-rvm5-9vw9/GHSA-hx7j-rvm5-9vw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jf42-2pw2-333x/GHSA-jf42-2pw2-333x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jhv7-gf64-j752/GHSA-jhv7-gf64-j752.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jq6r-jfg5-r4xg/GHSA-jq6r-jfg5-r4xg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jw5r-wxx3-rm98/GHSA-jw5r-wxx3-rm98.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vqm5-gf2r-4jjf/GHSA-vqm5-gf2r-4jjf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wgw9-vmg5-8928/GHSA-wgw9-vmg5-8928.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wp87-pj42-93xr/GHSA-wp87-pj42-93xr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x3x9-349x-2485/GHSA-x3x9-349x-2485.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xqwp-cfr5-f9gr/GHSA-xqwp-cfr5-f9gr.json diff --git a/advisories/unreviewed/2024/11/GHSA-29wp-p54c-r4v7/GHSA-29wp-p54c-r4v7.json b/advisories/unreviewed/2024/11/GHSA-29wp-p54c-r4v7/GHSA-29wp-p54c-r4v7.json new file mode 100644 index 00000000000..30eac5fb911 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-29wp-p54c-r4v7/GHSA-29wp-p54c-r4v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29wp-p54c-r4v7", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42391" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42391" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2w24-rmxp-xpr3/GHSA-2w24-rmxp-xpr3.json b/advisories/unreviewed/2024/11/GHSA-2w24-rmxp-xpr3/GHSA-2w24-rmxp-xpr3.json new file mode 100644 index 00000000000..2383bf5760c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2w24-rmxp-xpr3/GHSA-2w24-rmxp-xpr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w24-rmxp-xpr3", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42383" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42383" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json b/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json new file mode 100644 index 00000000000..faf03149369 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wf4-68gx-mph8", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-11023" + ], + "details": "Firebase JavaScript SDK utilizes a \"FIREBASE_DEFAULTS\" cookie to store configuration data, including an \"_authTokenSyncURL\" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the \"_authTokenSyncURL\" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11023" + }, + { + "type": "WEB", + "url": "https://github.com/firebase/firebase-js-sdk/pull/8056" + }, + { + "type": "WEB", + "url": "https://firebase.google.com/support/release-notes/js#version_1090_-_march_14_2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T11:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4jvm-jp36-77cr/GHSA-4jvm-jp36-77cr.json b/advisories/unreviewed/2024/11/GHSA-4jvm-jp36-77cr/GHSA-4jvm-jp36-77cr.json new file mode 100644 index 00000000000..86d19757b90 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jvm-jp36-77cr/GHSA-4jvm-jp36-77cr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jvm-jp36-77cr", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-41971" + ], + "details": "A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41971" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json b/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json new file mode 100644 index 00000000000..ff97ecad05b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qrv-rvg6-cq37", + "modified": "2024-11-18T12:30:41Z", + "published": "2024-11-18T12:30:41Z", + "aliases": [ + "CVE-2023-39180" + ], + "details": "A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39180" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-39180" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2326531" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-589" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json b/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json new file mode 100644 index 00000000000..cdb44d52ac2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq5f-wv7p-5gfc", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-48896" + ], + "details": "A vulnerability was found in Moodle. It is possible for users with the \"send message\" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48896" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318822" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fj5v-9mxj-77qc/GHSA-fj5v-9mxj-77qc.json b/advisories/unreviewed/2024/11/GHSA-fj5v-9mxj-77qc/GHSA-fj5v-9mxj-77qc.json new file mode 100644 index 00000000000..d54469793cb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fj5v-9mxj-77qc/GHSA-fj5v-9mxj-77qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj5v-9mxj-77qc", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42385" + ], + "details": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42385" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-140" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json b/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json new file mode 100644 index 00000000000..8d1eb3b1db7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjq9-452g-jg3q", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-48898" + ], + "details": "A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48898" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318820" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g34v-qr57-mvrm/GHSA-g34v-qr57-mvrm.json b/advisories/unreviewed/2024/11/GHSA-g34v-qr57-mvrm/GHSA-g34v-qr57-mvrm.json new file mode 100644 index 00000000000..5e5c68ebfc7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g34v-qr57-mvrm/GHSA-g34v-qr57-mvrm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g34v-qr57-mvrm", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42387" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42387" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gjfh-x4fj-rg67/GHSA-gjfh-x4fj-rg67.json b/advisories/unreviewed/2024/11/GHSA-gjfh-x4fj-rg67/GHSA-gjfh-x4fj-rg67.json new file mode 100644 index 00000000000..976f71c2127 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gjfh-x4fj-rg67/GHSA-gjfh-x4fj-rg67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjfh-x4fj-rg67", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42386" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42386" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json b/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json new file mode 100644 index 00000000000..fa6b9d80c2a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5h-5655-h4mv", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-11319" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11319" + }, + { + "type": "WEB", + "url": "https://github.com/django-cms/django-cms/commit/241d1cbe47a68f5d271ce4d27ad5e32e2c360ec3" + }, + { + "type": "WEB", + "url": "https://iltosec.com/blog/post/django-cms-413-stored-xss-vulnerability-exploiting-the-page-title-field" + }, + { + "type": "WEB", + "url": "https://www.django-cms.org/en/blog/2024/11/13/django-cms-security-update" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1859" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h47w-8rm3-hpwp/GHSA-h47w-8rm3-hpwp.json b/advisories/unreviewed/2024/11/GHSA-h47w-8rm3-hpwp/GHSA-h47w-8rm3-hpwp.json new file mode 100644 index 00000000000..10283585dc4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h47w-8rm3-hpwp/GHSA-h47w-8rm3-hpwp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h47w-8rm3-hpwp", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-41974" + ], + "details": "A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41974" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hx7j-rvm5-9vw9/GHSA-hx7j-rvm5-9vw9.json b/advisories/unreviewed/2024/11/GHSA-hx7j-rvm5-9vw9/GHSA-hx7j-rvm5-9vw9.json new file mode 100644 index 00000000000..8bcc5393772 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hx7j-rvm5-9vw9/GHSA-hx7j-rvm5-9vw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx7j-rvm5-9vw9", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-41972" + ], + "details": "A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41972" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jf42-2pw2-333x/GHSA-jf42-2pw2-333x.json b/advisories/unreviewed/2024/11/GHSA-jf42-2pw2-333x/GHSA-jf42-2pw2-333x.json new file mode 100644 index 00000000000..2b10d501d61 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jf42-2pw2-333x/GHSA-jf42-2pw2-333x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf42-2pw2-333x", + "modified": "2024-11-18T12:30:41Z", + "published": "2024-11-18T12:30:41Z", + "aliases": [ + "CVE-2023-39176" + ], + "details": "A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39176" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-39176" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2326503" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jhv7-gf64-j752/GHSA-jhv7-gf64-j752.json b/advisories/unreviewed/2024/11/GHSA-jhv7-gf64-j752/GHSA-jhv7-gf64-j752.json new file mode 100644 index 00000000000..a547bcc8884 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jhv7-gf64-j752/GHSA-jhv7-gf64-j752.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv7-gf64-j752", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42384" + ], + "details": "Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42384" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42384" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jq6r-jfg5-r4xg/GHSA-jq6r-jfg5-r4xg.json b/advisories/unreviewed/2024/11/GHSA-jq6r-jfg5-r4xg/GHSA-jq6r-jfg5-r4xg.json new file mode 100644 index 00000000000..d10a58ae3ff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jq6r-jfg5-r4xg/GHSA-jq6r-jfg5-r4xg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq6r-jfg5-r4xg", + "modified": "2024-11-18T12:30:41Z", + "published": "2024-11-18T12:30:41Z", + "aliases": [ + "CVE-2023-39179" + ], + "details": "A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39179" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-39179" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2326529" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jw5r-wxx3-rm98/GHSA-jw5r-wxx3-rm98.json b/advisories/unreviewed/2024/11/GHSA-jw5r-wxx3-rm98/GHSA-jw5r-wxx3-rm98.json new file mode 100644 index 00000000000..adb0e82fc5e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jw5r-wxx3-rm98/GHSA-jw5r-wxx3-rm98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw5r-wxx3-rm98", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-41973" + ], + "details": "A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41973" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json b/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json new file mode 100644 index 00000000000..fd3df19797a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfgc-pq48-8r3j", + "modified": "2024-11-18T12:30:41Z", + "published": "2024-11-18T12:30:41Z", + "aliases": [ + "CVE-2024-41970" + ], + "details": "A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41970" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json b/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json new file mode 100644 index 00000000000..5e37c0af9fa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg54-p2wj-5ph7", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-48901" + ], + "details": "A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48901" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318817" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json b/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json new file mode 100644 index 00000000000..a5461dd5292 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvf5-hvjx-wm27", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-52317" + ], + "details": "Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests \ncould lead to request and/or response mix-up between users.\n\nThis issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.\n\nUsers are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52317" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/ty376mrxy1mmxtw3ogo53nc9l3co3dfs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vqm5-gf2r-4jjf/GHSA-vqm5-gf2r-4jjf.json b/advisories/unreviewed/2024/11/GHSA-vqm5-gf2r-4jjf/GHSA-vqm5-gf2r-4jjf.json new file mode 100644 index 00000000000..569abeb4a1a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vqm5-gf2r-4jjf/GHSA-vqm5-gf2r-4jjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqm5-gf2r-4jjf", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42388" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42388" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wgw9-vmg5-8928/GHSA-wgw9-vmg5-8928.json b/advisories/unreviewed/2024/11/GHSA-wgw9-vmg5-8928/GHSA-wgw9-vmg5-8928.json new file mode 100644 index 00000000000..f24d43af996 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wgw9-vmg5-8928/GHSA-wgw9-vmg5-8928.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgw9-vmg5-8928", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42390" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42390" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wp87-pj42-93xr/GHSA-wp87-pj42-93xr.json b/advisories/unreviewed/2024/11/GHSA-wp87-pj42-93xr/GHSA-wp87-pj42-93xr.json new file mode 100644 index 00000000000..a3377d8bc5c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wp87-pj42-93xr/GHSA-wp87-pj42-93xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp87-pj42-93xr", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42389" + ], + "details": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42389" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x3x9-349x-2485/GHSA-x3x9-349x-2485.json b/advisories/unreviewed/2024/11/GHSA-x3x9-349x-2485/GHSA-x3x9-349x-2485.json new file mode 100644 index 00000000000..8265ab288ab --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x3x9-349x-2485/GHSA-x3x9-349x-2485.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3x9-349x-2485", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-48897" + ], + "details": "A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48897" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318821" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json b/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json new file mode 100644 index 00000000000..e9899d511fd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcpr-7mr4-h4xq", + "modified": "2024-11-18T12:30:43Z", + "published": "2024-11-18T12:30:43Z", + "aliases": [ + "CVE-2024-52316" + ], + "details": "Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.\n\nUsers are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52316" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/lopzlqh91jj9n334g02om08sbysdb928" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-391" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xqwp-cfr5-f9gr/GHSA-xqwp-cfr5-f9gr.json b/advisories/unreviewed/2024/11/GHSA-xqwp-cfr5-f9gr/GHSA-xqwp-cfr5-f9gr.json new file mode 100644 index 00000000000..7bfbeb0a588 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xqwp-cfr5-f9gr/GHSA-xqwp-cfr5-f9gr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqwp-cfr5-f9gr", + "modified": "2024-11-18T12:30:42Z", + "published": "2024-11-18T12:30:42Z", + "aliases": [ + "CVE-2024-42392" + ], + "details": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42392" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-140" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T10:15:08Z" + } +} \ No newline at end of file