diff --git a/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json b/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json index 271d26a73c6..31d0bd7c742 100644 --- a/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json +++ b/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3j5-q8f2-3cqq", - "modified": "2023-12-08T22:45:01Z", + "modified": "2024-02-22T21:29:35Z", "published": "2022-05-14T01:10:16Z", "aliases": [ "CVE-2016-8745" @@ -122,6 +122,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-8745" }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/143bb466cf96a89e791b7db5626055ea819dad89" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/16a57bc885e212839f1d717b94b01d154a36943a" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/cbc9b18a845d3c8c053ac293dffda6c6c19dd92b" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat80/commit/3dd2fec73e0de1edc1d3eb1c52a01255fdfc84e7" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2017:0455" diff --git a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json index 0afebfa8b13..1f288733b1e 100644 --- a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json +++ b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m77w-6vjw-wh2f", - "modified": "2023-12-21T15:30:31Z", + "modified": "2024-02-22T21:30:28Z", "published": "2023-10-03T18:30:23Z", "aliases": [ "CVE-2023-4911" diff --git a/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json new file mode 100644 index 00000000000..7fcc3208de3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v9x-x358-276j", + "modified": "2024-02-22T21:30:32Z", + "published": "2024-02-22T21:30:32Z", + "aliases": [ + "CVE-2024-22547" + ], + "details": "WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22547" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/wayos/wayos.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json new file mode 100644 index 00000000000..7cbe5cfabd3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jff-4ww9-2jm5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1750" + ], + "details": "A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254532. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1750" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/OrBH8zLKUPOA" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254532" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json new file mode 100644 index 00000000000..c1f3a4ccd49 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x8h-5jjw-88xr", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-25369" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25369" + }, + { + "type": "WEB", + "url": "https://github.com/liyako/vulnerability/blob/main/POC/FUEL%20CMS%20Reflected%20Cross-Site%20Scripting%20%28XSS%29.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json new file mode 100644 index 00000000000..c15235db598 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vv-989w-hhr5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:32Z", + "aliases": [ + "CVE-2024-25385" + ], + "details": "An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25385" + }, + { + "type": "WEB", + "url": "https://github.com/noirotm/flvmeta/issues/23" + }, + { + "type": "WEB", + "url": "https://github.com/hanxuer/crashes/blob/main/flvmeta/01/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json new file mode 100644 index 00000000000..0b8a0a93033 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gfq-fv5r-j8r5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1749" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Software 2.9. This issue affects some unknown processing of the file /dashboard/message of the component Message Page. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254531. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1749" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1oM1h3E9G17lgkbSnhq7FQjfAtEojDNFo/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254531" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254531" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json new file mode 100644 index 00000000000..8d1ceaafa6c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqv6-97c7-49r4", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1748" + ], + "details": "A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The manipulation leads to deserialization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-254530 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1748" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254530" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254530" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file