Publish Advisories

GHSA-w3j5-q8f2-3cqq
GHSA-m77w-6vjw-wh2f
GHSA-2v9x-x358-276j
GHSA-4jff-4ww9-2jm5
GHSA-4x8h-5jjw-88xr
GHSA-67vv-989w-hhr5
GHSA-7gfq-fv5r-j8r5
GHSA-mqv6-97c7-49r4
This commit is contained in:
advisory-database[bot]
2024-02-22 21:31:06 +00:00
parent 15fc6bfb71
commit def42e3567
8 changed files with 265 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3j5-q8f2-3cqq",
"modified": "2023-12-08T22:45:01Z",
"modified": "2024-02-22T21:29:35Z",
"published": "2022-05-14T01:10:16Z",
"aliases": [
"CVE-2016-8745"
@@ -122,6 +122,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-8745"
},
{
"type": "WEB",
"url": "https://github.com/apache/tomcat/commit/143bb466cf96a89e791b7db5626055ea819dad89"
},
{
"type": "WEB",
"url": "https://github.com/apache/tomcat/commit/16a57bc885e212839f1d717b94b01d154a36943a"
},
{
"type": "WEB",
"url": "https://github.com/apache/tomcat/commit/cbc9b18a845d3c8c053ac293dffda6c6c19dd92b"
},
{
"type": "WEB",
"url": "https://github.com/apache/tomcat80/commit/3dd2fec73e0de1edc1d3eb1c52a01255fdfc84e7"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2017:0455"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m77w-6vjw-wh2f",
"modified": "2023-12-21T15:30:31Z",
"modified": "2024-02-22T21:30:28Z",
"published": "2023-10-03T18:30:23Z",
"aliases": [
"CVE-2023-4911"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v9x-x358-276j",
"modified": "2024-02-22T21:30:32Z",
"published": "2024-02-22T21:30:32Z",
"aliases": [
"CVE-2024-22547"
],
"details": "WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22547"
},
{
"type": "WEB",
"url": "https://github.com/WarmBrew/web_vul/blob/main/wayos/wayos.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T19:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jff-4ww9-2jm5",
"modified": "2024-02-22T21:30:33Z",
"published": "2024-02-22T21:30:33Z",
"aliases": [
"CVE-2024-1750"
],
"details": "A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254532. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1750"
},
{
"type": "WEB",
"url": "https://note.zhaoj.in/share/OrBH8zLKUPOA"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.254532"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.254532"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T20:15:56Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4x8h-5jjw-88xr",
"modified": "2024-02-22T21:30:33Z",
"published": "2024-02-22T21:30:33Z",
"aliases": [
"CVE-2024-25369"
],
"details": "A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25369"
},
{
"type": "WEB",
"url": "https://github.com/liyako/vulnerability/blob/main/POC/FUEL%20CMS%20Reflected%20Cross-Site%20Scripting%20%28XSS%29.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T20:15:56Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67vv-989w-hhr5",
"modified": "2024-02-22T21:30:33Z",
"published": "2024-02-22T21:30:32Z",
"aliases": [
"CVE-2024-25385"
],
"details": "An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25385"
},
{
"type": "WEB",
"url": "https://github.com/noirotm/flvmeta/issues/23"
},
{
"type": "WEB",
"url": "https://github.com/hanxuer/crashes/blob/main/flvmeta/01/readme.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T19:15:09Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gfq-fv5r-j8r5",
"modified": "2024-02-22T21:30:33Z",
"published": "2024-02-22T21:30:33Z",
"aliases": [
"CVE-2024-1749"
],
"details": "A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Software 2.9. This issue affects some unknown processing of the file /dashboard/message of the component Message Page. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254531. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1749"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1oM1h3E9G17lgkbSnhq7FQjfAtEojDNFo/view?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.254531"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.254531"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T20:15:56Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqv6-97c7-49r4",
"modified": "2024-02-22T21:30:33Z",
"published": "2024-02-22T21:30:33Z",
"aliases": [
"CVE-2024-1748"
],
"details": "A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The manipulation leads to deserialization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-254530 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1748"
},
{
"type": "WEB",
"url": "https://github.com/bayuncao/vul-cve-13"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.254530"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.254530"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T20:15:56Z"
}
}