From de2ee2d9a9740bc291d4ab2811c1301c38543d2a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Feb 2024 09:31:43 +0000 Subject: [PATCH] Publish Advisories GHSA-2cjh-75gp-34gc GHSA-6hrp-c93c-rq8p GHSA-p947-jxh9-g736 GHSA-pvg3-4m54-rhwj --- .../GHSA-2cjh-75gp-34gc.json | 35 +++++++++++++++ .../GHSA-6hrp-c93c-rq8p.json | 35 +++++++++++++++ .../GHSA-p947-jxh9-g736.json | 35 +++++++++++++++ .../GHSA-pvg3-4m54-rhwj.json | 43 +++++++++++++++++++ 4 files changed, 148 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-2cjh-75gp-34gc/GHSA-2cjh-75gp-34gc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p947-jxh9-g736/GHSA-p947-jxh9-g736.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pvg3-4m54-rhwj/GHSA-pvg3-4m54-rhwj.json diff --git a/advisories/unreviewed/2024/02/GHSA-2cjh-75gp-34gc/GHSA-2cjh-75gp-34gc.json b/advisories/unreviewed/2024/02/GHSA-2cjh-75gp-34gc/GHSA-2cjh-75gp-34gc.json new file mode 100644 index 00000000000..94846154a25 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2cjh-75gp-34gc/GHSA-2cjh-75gp-34gc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cjh-75gp-34gc", + "modified": "2024-02-01T09:30:18Z", + "published": "2024-02-01T09:30:18Z", + "aliases": [ + "CVE-2024-22859" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22859" + }, + { + "type": "WEB", + "url": "https://github.com/livewire/livewire/commit/5d887316f2aaf83c0e380ac5e72766f19700fa3b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json b/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json new file mode 100644 index 00000000000..c6e91b0c76d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hrp-c93c-rq8p", + "modified": "2024-02-01T09:30:18Z", + "published": "2024-02-01T09:30:18Z", + "aliases": [ + "CVE-2024-24548" + ], + "details": "Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payment EX.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24548" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN41129639/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p947-jxh9-g736/GHSA-p947-jxh9-g736.json b/advisories/unreviewed/2024/02/GHSA-p947-jxh9-g736/GHSA-p947-jxh9-g736.json new file mode 100644 index 00000000000..c54c409a147 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p947-jxh9-g736/GHSA-p947-jxh9-g736.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p947-jxh9-g736", + "modified": "2024-02-01T09:30:18Z", + "published": "2024-02-01T09:30:18Z", + "aliases": [ + "CVE-2023-37621" + ], + "details": "An issue in Fronius Datalogger Web v.2.0.5-4, allows remote attackers to obtain sensitive information via a crafted request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37621" + }, + { + "type": "WEB", + "url": "https://github.com/MY0723/CNVD-2022-27366__CVE-2023-37621" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T09:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pvg3-4m54-rhwj/GHSA-pvg3-4m54-rhwj.json b/advisories/unreviewed/2024/02/GHSA-pvg3-4m54-rhwj/GHSA-pvg3-4m54-rhwj.json new file mode 100644 index 00000000000..95824f6b937 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pvg3-4m54-rhwj/GHSA-pvg3-4m54-rhwj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvg3-4m54-rhwj", + "modified": "2024-02-01T09:30:18Z", + "published": "2024-02-01T09:30:18Z", + "aliases": [ + "CVE-2023-51939" + ], + "details": "An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51939" + }, + { + "type": "WEB", + "url": "https://github.com/relic-toolkit/relic/issues/284" + }, + { + "type": "WEB", + "url": "https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f" + }, + { + "type": "WEB", + "url": "https://github.com/liang-junkai/Relic-bbs-fault-injection" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T07:15:08Z" + } +} \ No newline at end of file