From def42e356717a278369815b0adf58b7bb8f79ce0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 22 Feb 2024 21:31:06 +0000 Subject: [PATCH] Publish Advisories GHSA-w3j5-q8f2-3cqq GHSA-m77w-6vjw-wh2f GHSA-2v9x-x358-276j GHSA-4jff-4ww9-2jm5 GHSA-4x8h-5jjw-88xr GHSA-67vv-989w-hhr5 GHSA-7gfq-fv5r-j8r5 GHSA-mqv6-97c7-49r4 --- .../GHSA-w3j5-q8f2-3cqq.json | 18 +++++++- .../GHSA-m77w-6vjw-wh2f.json | 2 +- .../GHSA-2v9x-x358-276j.json | 35 ++++++++++++++ .../GHSA-4jff-4ww9-2jm5.json | 46 +++++++++++++++++++ .../GHSA-4x8h-5jjw-88xr.json | 35 ++++++++++++++ .../GHSA-67vv-989w-hhr5.json | 39 ++++++++++++++++ .../GHSA-7gfq-fv5r-j8r5.json | 46 +++++++++++++++++++ .../GHSA-mqv6-97c7-49r4.json | 46 +++++++++++++++++++ 8 files changed, 265 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json diff --git a/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json b/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json index 271d26a73c6..31d0bd7c742 100644 --- a/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json +++ b/advisories/github-reviewed/2022/05/GHSA-w3j5-q8f2-3cqq/GHSA-w3j5-q8f2-3cqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3j5-q8f2-3cqq", - "modified": "2023-12-08T22:45:01Z", + "modified": "2024-02-22T21:29:35Z", "published": "2022-05-14T01:10:16Z", "aliases": [ "CVE-2016-8745" @@ -122,6 +122,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-8745" }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/143bb466cf96a89e791b7db5626055ea819dad89" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/16a57bc885e212839f1d717b94b01d154a36943a" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/cbc9b18a845d3c8c053ac293dffda6c6c19dd92b" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat80/commit/3dd2fec73e0de1edc1d3eb1c52a01255fdfc84e7" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2017:0455" diff --git a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json index 0afebfa8b13..1f288733b1e 100644 --- a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json +++ b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m77w-6vjw-wh2f", - "modified": "2023-12-21T15:30:31Z", + "modified": "2024-02-22T21:30:28Z", "published": "2023-10-03T18:30:23Z", "aliases": [ "CVE-2023-4911" diff --git a/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json new file mode 100644 index 00000000000..7fcc3208de3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v9x-x358-276j", + "modified": "2024-02-22T21:30:32Z", + "published": "2024-02-22T21:30:32Z", + "aliases": [ + "CVE-2024-22547" + ], + "details": "WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22547" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/wayos/wayos.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json new file mode 100644 index 00000000000..7cbe5cfabd3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jff-4ww9-2jm5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1750" + ], + "details": "A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254532. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1750" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/OrBH8zLKUPOA" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254532" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json new file mode 100644 index 00000000000..c1f3a4ccd49 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x8h-5jjw-88xr", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-25369" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25369" + }, + { + "type": "WEB", + "url": "https://github.com/liyako/vulnerability/blob/main/POC/FUEL%20CMS%20Reflected%20Cross-Site%20Scripting%20%28XSS%29.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json new file mode 100644 index 00000000000..c15235db598 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vv-989w-hhr5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:32Z", + "aliases": [ + "CVE-2024-25385" + ], + "details": "An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25385" + }, + { + "type": "WEB", + "url": "https://github.com/noirotm/flvmeta/issues/23" + }, + { + "type": "WEB", + "url": "https://github.com/hanxuer/crashes/blob/main/flvmeta/01/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json new file mode 100644 index 00000000000..0b8a0a93033 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gfq-fv5r-j8r5", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1749" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Software 2.9. This issue affects some unknown processing of the file /dashboard/message of the component Message Page. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254531. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1749" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1oM1h3E9G17lgkbSnhq7FQjfAtEojDNFo/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254531" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254531" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json new file mode 100644 index 00000000000..8d1ceaafa6c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqv6-97c7-49r4", + "modified": "2024-02-22T21:30:33Z", + "published": "2024-02-22T21:30:33Z", + "aliases": [ + "CVE-2024-1748" + ], + "details": "A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The manipulation leads to deserialization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-254530 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1748" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254530" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254530" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-22T20:15:56Z" + } +} \ No newline at end of file