From df53d34a387b773587e6790a504d8a98a916b6b3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Apr 2024 03:32:08 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-c43m-486j-j32p.json | 20 ++++++++- .../GHSA-5rrv-52wj-qgfg.json | 6 ++- .../GHSA-6q5p-rp5c-wmph.json | 6 ++- .../GHSA-23c8-gv7j-76hv.json | 38 +++++++++++++++++ .../GHSA-2mcw-fg5h-w8g7.json | 42 +++++++++++++++++++ .../GHSA-4qwp-4p88-ww2v.json | 42 +++++++++++++++++++ .../GHSA-5fhg-238q-4c3r.json | 38 +++++++++++++++++ .../GHSA-5xm4-9p77-7mjp.json | 38 +++++++++++++++++ .../GHSA-6wx8-g7xc-9qp2.json | 38 +++++++++++++++++ .../GHSA-76f8-6hfx-w3xj.json | 38 +++++++++++++++++ .../GHSA-7ghv-4mjc-99wp.json | 38 +++++++++++++++++ .../GHSA-85c2-wjfm-h4fw.json | 38 +++++++++++++++++ .../GHSA-8c8m-p9jj-3j4j.json | 38 +++++++++++++++++ .../GHSA-8mqr-jgw7-9phj.json | 38 +++++++++++++++++ .../GHSA-9frh-fcfq-fv6f.json | 38 +++++++++++++++++ .../GHSA-9w6g-r3rj-g5xg.json | 38 +++++++++++++++++ .../GHSA-c3p2-8x6x-wvh2.json | 38 +++++++++++++++++ .../GHSA-f8vm-c6wx-cc8g.json | 38 +++++++++++++++++ .../GHSA-g23v-56px-8cqm.json | 38 +++++++++++++++++ .../GHSA-hghh-938v-wffr.json | 38 +++++++++++++++++ .../GHSA-hrj8-px4x-vh25.json | 38 +++++++++++++++++ .../GHSA-hv6v-2647-5j76.json | 38 +++++++++++++++++ .../GHSA-hvhj-8mqf-w2rh.json | 38 +++++++++++++++++ .../GHSA-j3pf-jvpq-m354.json | 38 +++++++++++++++++ .../GHSA-mr7r-xrwf-p8ph.json | 38 +++++++++++++++++ .../GHSA-qg29-wgvq-qrjr.json | 42 +++++++++++++++++++ .../GHSA-rjv9-5c65-673q.json | 38 +++++++++++++++++ .../GHSA-rv7j-2mm5-9fv2.json | 38 +++++++++++++++++ .../GHSA-v4qv-r5g6-wxrp.json | 42 +++++++++++++++++++ .../GHSA-v829-2px7-7w8w.json | 38 +++++++++++++++++ .../GHSA-w4r6-cjx2-64gc.json | 42 +++++++++++++++++++ .../GHSA-wmqf-xv94-hx62.json | 42 +++++++++++++++++++ .../GHSA-ww6m-hg6p-rm96.json | 38 +++++++++++++++++ .../GHSA-x9r4-wx9q-2r6r.json | 38 +++++++++++++++++ 34 files changed, 1230 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hghh-938v-wffr/GHSA-hghh-938v-wffr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qg29-wgvq-qrjr/GHSA-qg29-wgvq-qrjr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w4r6-cjx2-64gc/GHSA-w4r6-cjx2-64gc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wmqf-xv94-hx62/GHSA-wmqf-xv94-hx62.json create mode 100644 advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json diff --git a/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json b/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json index dc08f713845..28628c8e918 100644 --- a/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json +++ b/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c43m-486j-j32p", - "modified": "2022-10-01T00:00:21Z", + "modified": "2024-04-19T03:31:02Z", "published": "2022-09-29T00:00:18Z", "aliases": [ "CVE-2022-31629" @@ -29,6 +29,22 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV" @@ -56,7 +72,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5rrv-52wj-qgfg/GHSA-5rrv-52wj-qgfg.json b/advisories/unreviewed/2024/03/GHSA-5rrv-52wj-qgfg/GHSA-5rrv-52wj-qgfg.json index f77b1d6c2ed..e3a676447df 100644 --- a/advisories/unreviewed/2024/03/GHSA-5rrv-52wj-qgfg/GHSA-5rrv-52wj-qgfg.json +++ b/advisories/unreviewed/2024/03/GHSA-5rrv-52wj-qgfg/GHSA-5rrv-52wj-qgfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rrv-52wj-qgfg", - "modified": "2024-03-20T18:30:37Z", + "modified": "2024-04-19T03:31:02Z", "published": "2024-03-20T18:30:37Z", "aliases": [ "CVE-2023-50967" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://github.com/latchset/jose" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OOBFVMOAV732C7PY74AHJ62ZNKT3ISZ6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json index 56c5d9a1927..a2fb05225bd 100644 --- a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json +++ b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q5p-rp5c-wmph", - "modified": "2024-04-09T21:31:55Z", + "modified": "2024-04-19T03:31:02Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2024-22857" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.cybersecurity-help.cz/vdb/SB2024022842" + }, + { + "type": "WEB", + "url": "https://www.ebryx.com/blogs/arbitrary-code-execution-in-zlog-cve-2024-22857" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json b/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json new file mode 100644 index 00000000000..d34d9f0a824 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23c8-gv7j-76hv", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24991" + ], + "details": "A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24991" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json b/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json new file mode 100644 index 00000000000..7ede1c98bd1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mcw-fg5h-w8g7", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3598" + ], + "details": "The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3598" + }, + { + "type": "WEB", + "url": "https://wpmet.com/plugin/elementskit" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a9e4b14f-0f55-47bc-8e40-19b262e50561?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json b/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json new file mode 100644 index 00000000000..e288ae3d120 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qwp-4p88-ww2v", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3560" + ], + "details": "The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3560" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3072233%40learnpress&new=3072233%40learnpress&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8ea002da-bf37-4c6d-a46e-4f0e7f8968ad?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json b/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json new file mode 100644 index 00000000000..0c96aaa7527 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fhg-238q-4c3r", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-27977" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27977" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json b/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json new file mode 100644 index 00000000000..7d6ce9ce02a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xm4-9p77-7mjp", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-29204" + ], + "details": "A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29204" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json new file mode 100644 index 00000000000..a6d57b79251 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wx8-g7xc-9qp2", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-22061" + ], + "details": "A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22061" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json new file mode 100644 index 00000000000..326c8f814f4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76f8-6hfx-w3xj", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-23530" + ], + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23530" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json new file mode 100644 index 00000000000..4c2e7340dad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghv-4mjc-99wp", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-23532" + ], + "details": "An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23532" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json new file mode 100644 index 00000000000..9b5f6bf80d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85c2-wjfm-h4fw", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-23529" + ], + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23529" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json new file mode 100644 index 00000000000..2458f06010a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c8m-p9jj-3j4j", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-23528" + ], + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23528" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json b/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json new file mode 100644 index 00000000000..329f818dc57 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mqr-jgw7-9phj", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24997" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24997" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json b/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json new file mode 100644 index 00000000000..1e86a5c4beb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9frh-fcfq-fv6f", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-23535" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23535" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json new file mode 100644 index 00000000000..b83c2977463 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w6g-r3rj-g5xg", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-23526" + ], + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23526" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json new file mode 100644 index 00000000000..9bdeb39900b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3p2-8x6x-wvh2", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24993" + ], + "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24993" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json b/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json new file mode 100644 index 00000000000..1ccdd1b0bc4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vm-c6wx-cc8g", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24994" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24994" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json b/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json new file mode 100644 index 00000000000..904d7e40678 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g23v-56px-8cqm", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-27978" + ], + "details": "A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27978" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hghh-938v-wffr/GHSA-hghh-938v-wffr.json b/advisories/unreviewed/2024/04/GHSA-hghh-938v-wffr/GHSA-hghh-938v-wffr.json new file mode 100644 index 00000000000..1966cd530c2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hghh-938v-wffr/GHSA-hghh-938v-wffr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hghh-938v-wffr", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24998" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24998" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json b/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json new file mode 100644 index 00000000000..18f8ea62bd1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrj8-px4x-vh25", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-27976" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27976" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json b/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json new file mode 100644 index 00000000000..fa24a68b509 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv6v-2647-5j76", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24999" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24999" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json b/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json new file mode 100644 index 00000000000..ce920908d5c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvhj-8mqf-w2rh", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24996" + ], + "details": "A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24996" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json b/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json new file mode 100644 index 00000000000..8a423a0e2c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3pf-jvpq-m354", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-27984" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27984" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json b/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json new file mode 100644 index 00000000000..94b3914ad18 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr7r-xrwf-p8ph", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-27975" + ], + "details": "An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27975" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qg29-wgvq-qrjr/GHSA-qg29-wgvq-qrjr.json b/advisories/unreviewed/2024/04/GHSA-qg29-wgvq-qrjr/GHSA-qg29-wgvq-qrjr.json new file mode 100644 index 00000000000..d209e749718 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qg29-wgvq-qrjr/GHSA-qg29-wgvq-qrjr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg29-wgvq-qrjr", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3731" + ], + "details": "The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3731" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3072688/customer-reviews-woocommerce/trunk/includes/reminders/class-cr-reminders-log-table.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3489038-2833-4080-b802-5733afab5de8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json b/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json new file mode 100644 index 00000000000..c1cb7a0e4b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjv9-5c65-673q", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-25000" + ], + "details": "A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25000" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json new file mode 100644 index 00000000000..271569bc5bf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv7j-2mm5-9fv2", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-23534" + ], + "details": "An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23534" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json b/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json new file mode 100644 index 00000000000..444d3283de0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4qv-r5g6-wxrp", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3615" + ], + "details": "The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3615" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3072498%40media-library-plus&new=3072498%40media-library-plus&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5f550bac-b047-4276-bde5-c15bfd4ceb49?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json new file mode 100644 index 00000000000..b1a4503142f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v829-2px7-7w8w", + "modified": "2024-04-19T03:31:02Z", + "published": "2024-04-19T03:31:02Z", + "aliases": [ + "CVE-2024-23531" + ], + "details": "An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23531" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w4r6-cjx2-64gc/GHSA-w4r6-cjx2-64gc.json b/advisories/unreviewed/2024/04/GHSA-w4r6-cjx2-64gc/GHSA-w4r6-cjx2-64gc.json new file mode 100644 index 00000000000..f3520a1c1ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w4r6-cjx2-64gc/GHSA-w4r6-cjx2-64gc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4r6-cjx2-64gc", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3600" + ], + "details": "The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3600" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3071296%40poll-maker&new=3071296%40poll-maker&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fec015e1-7f64-4917-a242-90bd1135f680?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wmqf-xv94-hx62/GHSA-wmqf-xv94-hx62.json b/advisories/unreviewed/2024/04/GHSA-wmqf-xv94-hx62/GHSA-wmqf-xv94-hx62.json new file mode 100644 index 00000000000..f82ad73798b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wmqf-xv94-hx62/GHSA-wmqf-xv94-hx62.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmqf-xv94-hx62", + "modified": "2024-04-19T03:31:04Z", + "published": "2024-04-19T03:31:04Z", + "aliases": [ + "CVE-2024-3818" + ], + "details": "The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's \"Social Icons\" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3818" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3072932/essential-blocks/tags/4.5.10/blocks/social/src/components/depricated-social-links-1.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b226067-0287-4f7e-9415-dc3c83f2fd27?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json new file mode 100644 index 00000000000..8cdeac8d6f5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww6m-hg6p-rm96", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-23533" + ], + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23533" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json new file mode 100644 index 00000000000..f7e942ccb85 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9r4-wx9q-2r6r", + "modified": "2024-04-19T03:31:03Z", + "published": "2024-04-19T03:31:03Z", + "aliases": [ + "CVE-2024-24995" + ], + "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24995" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T02:15:09Z" + } +} \ No newline at end of file