From e04e827c0fc0228e90532c6f41a605572b33b866 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 Aug 2024 18:33:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9g2x-mr5w-6mrm.json | 2 +- .../GHSA-259r-2fr5-87c3.json | 1 + .../GHSA-44qr-8pf6-6q33.json | 11 ++-- .../GHSA-4p3v-h475-6j2m.json | 11 ++-- .../GHSA-77vw-jrxp-2648.json | 1 + .../GHSA-ggw3-6ch2-q6vf.json | 11 ++-- .../GHSA-h54m-6vwp-4wpq.json | 11 ++-- .../GHSA-m98g-cw9w-r9qw.json | 14 ++++- .../GHSA-2625-j643-gg22.json | 11 ++-- .../GHSA-383m-3rgc-734c.json | 9 ++-- .../GHSA-9cm6-r59j-22jc.json | 11 ++-- .../GHSA-9phc-8693-5w9q.json | 11 ++-- .../GHSA-jh7g-4fx4-rhh4.json | 11 ++-- .../GHSA-pw4q-cgcg-f9p5.json | 11 ++-- .../GHSA-273h-mfpf-cvq6.json | 3 +- .../GHSA-5mvf-mw2h-9f35.json | 11 ++-- .../GHSA-5xg5-ffcr-c2cc.json | 11 ++-- .../GHSA-9xpc-qh7h-4926.json | 11 ++-- .../GHSA-cq4f-h5g8-8r5h.json | 11 ++-- .../GHSA-f558-fw4f-vm2c.json | 11 ++-- .../GHSA-g59j-h2pg-qp5r.json | 11 ++-- .../GHSA-gc8r-pxj9-hhx3.json | 6 ++- .../GHSA-grhv-62hf-9jg3.json | 11 ++-- .../GHSA-q884-jcxw-49wr.json | 11 ++-- .../GHSA-v47w-h9mw-wj4f.json | 11 ++-- .../GHSA-vjh8-wgcx-46j4.json | 11 ++-- .../GHSA-wrfr-rmr8-j7gx.json | 11 ++-- .../GHSA-c7wc-g87j-82j8.json | 11 ++-- .../GHSA-wf46-934q-8fhp.json | 11 ++-- .../GHSA-2p7q-76m8-h2pg.json | 11 ++-- .../GHSA-4cm7-5r54-q82c.json | 54 +++++++++++++++++++ .../GHSA-53h7-ghj7-7gh9.json | 9 ++-- .../GHSA-5mg4-xpj4-crpr.json | 38 +++++++++++++ .../GHSA-6c55-p332-pqhh.json | 38 +++++++++++++ .../GHSA-6j4x-5vg8-wc8v.json | 38 +++++++++++++ .../GHSA-76qm-c9j2-wm6v.json | 6 ++- .../GHSA-7cjv-5xcp-6cwv.json | 43 +++++++++++++++ .../GHSA-9r73-v3pv-4xj4.json | 43 +++++++++++++++ .../GHSA-f5w7-hc7v-f8j6.json | 38 +++++++++++++ .../GHSA-f776-8qvr-rf72.json | 54 +++++++++++++++++++ .../GHSA-ff2j-rwgx-m3hr.json | 38 +++++++++++++ .../GHSA-fq29-72jg-5hrj.json | 35 ++++++++++++ .../GHSA-fqr9-v44c-j829.json | 38 +++++++++++++ .../GHSA-fwg4-px6f-6fj8.json | 38 +++++++++++++ .../GHSA-gx44-2gg6-xj9m.json | 38 +++++++++++++ .../GHSA-j72m-4pgw-w3qv.json | 3 +- .../GHSA-jg97-797c-2q53.json | 38 +++++++++++++ .../GHSA-jp5m-m368-79vw.json | 38 +++++++++++++ .../GHSA-mcjx-2c4v-mvg9.json | 9 ++-- .../GHSA-mgfj-pw53-g28v.json | 38 +++++++++++++ .../GHSA-mw37-8h7c-93hw.json | 35 ++++++++++++ .../GHSA-p4jg-pm94-8pxc.json | 38 +++++++++++++ .../GHSA-pcf4-rwp2-6pv4.json | 3 +- .../GHSA-ppwh-v8g5-pg9c.json | 35 ++++++++++++ .../GHSA-pvj4-5rhw-5cww.json | 2 +- .../GHSA-q632-7v8j-586g.json | 11 ++-- .../GHSA-q636-fx55-gfr2.json | 9 ++-- .../GHSA-qj78-v57f-v8c2.json | 38 +++++++++++++ .../GHSA-qp2p-3fr2-8j54.json | 38 +++++++++++++ .../GHSA-qr5p-m4c8-89vq.json | 38 +++++++++++++ .../GHSA-v3qq-5wj9-8242.json | 38 +++++++++++++ .../GHSA-wgh2-2342-mm46.json | 38 +++++++++++++ .../GHSA-wvmh-96f5-wjw2.json | 38 +++++++++++++ .../GHSA-x9qv-64rq-2vc3.json | 38 +++++++++++++ .../GHSA-xv4g-g9fh-fqrj.json | 9 ++-- 65 files changed, 1252 insertions(+), 119 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-4cm7-5r54-q82c/GHSA-4cm7-5r54-q82c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5mg4-xpj4-crpr/GHSA-5mg4-xpj4-crpr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6c55-p332-pqhh/GHSA-6c55-p332-pqhh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6j4x-5vg8-wc8v/GHSA-6j4x-5vg8-wc8v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7cjv-5xcp-6cwv/GHSA-7cjv-5xcp-6cwv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f5w7-hc7v-f8j6/GHSA-f5w7-hc7v-f8j6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f776-8qvr-rf72/GHSA-f776-8qvr-rf72.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ff2j-rwgx-m3hr/GHSA-ff2j-rwgx-m3hr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fqr9-v44c-j829/GHSA-fqr9-v44c-j829.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fwg4-px6f-6fj8/GHSA-fwg4-px6f-6fj8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gx44-2gg6-xj9m/GHSA-gx44-2gg6-xj9m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jg97-797c-2q53/GHSA-jg97-797c-2q53.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jp5m-m368-79vw/GHSA-jp5m-m368-79vw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mgfj-pw53-g28v/GHSA-mgfj-pw53-g28v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mw37-8h7c-93hw/GHSA-mw37-8h7c-93hw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p4jg-pm94-8pxc/GHSA-p4jg-pm94-8pxc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qj78-v57f-v8c2/GHSA-qj78-v57f-v8c2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qr5p-m4c8-89vq/GHSA-qr5p-m4c8-89vq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v3qq-5wj9-8242/GHSA-v3qq-5wj9-8242.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wgh2-2342-mm46/GHSA-wgh2-2342-mm46.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wvmh-96f5-wjw2/GHSA-wvmh-96f5-wjw2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x9qv-64rq-2vc3/GHSA-x9qv-64rq-2vc3.json diff --git a/advisories/unreviewed/2023/03/GHSA-9g2x-mr5w-6mrm/GHSA-9g2x-mr5w-6mrm.json b/advisories/unreviewed/2023/03/GHSA-9g2x-mr5w-6mrm/GHSA-9g2x-mr5w-6mrm.json index 8d4f08a2d58..ec83c17438d 100644 --- a/advisories/unreviewed/2023/03/GHSA-9g2x-mr5w-6mrm/GHSA-9g2x-mr5w-6mrm.json +++ b/advisories/unreviewed/2023/03/GHSA-9g2x-mr5w-6mrm/GHSA-9g2x-mr5w-6mrm.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-259r-2fr5-87c3/GHSA-259r-2fr5-87c3.json b/advisories/unreviewed/2024/02/GHSA-259r-2fr5-87c3/GHSA-259r-2fr5-87c3.json index ce0b5cc2e25..6986bb6740f 100644 --- a/advisories/unreviewed/2024/02/GHSA-259r-2fr5-87c3/GHSA-259r-2fr5-87c3.json +++ b/advisories/unreviewed/2024/02/GHSA-259r-2fr5-87c3/GHSA-259r-2fr5-87c3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-44qr-8pf6-6q33/GHSA-44qr-8pf6-6q33.json b/advisories/unreviewed/2024/02/GHSA-44qr-8pf6-6q33/GHSA-44qr-8pf6-6q33.json index b73fa8d80a6..8131b5c39ad 100644 --- a/advisories/unreviewed/2024/02/GHSA-44qr-8pf6-6q33/GHSA-44qr-8pf6-6q33.json +++ b/advisories/unreviewed/2024/02/GHSA-44qr-8pf6-6q33/GHSA-44qr-8pf6-6q33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44qr-8pf6-6q33", - "modified": "2024-02-13T06:30:28Z", + "modified": "2024-08-19T18:32:01Z", "published": "2024-02-13T06:30:28Z", "aliases": [ "CVE-2022-48623" ], "details": "The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T05:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json index 85be1d00b7a..2e4c6fc18ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json +++ b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4p3v-h475-6j2m", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-50808" ], "details": "Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T18:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-77vw-jrxp-2648/GHSA-77vw-jrxp-2648.json b/advisories/unreviewed/2024/02/GHSA-77vw-jrxp-2648/GHSA-77vw-jrxp-2648.json index ad60a365016..43754b5dc2a 100644 --- a/advisories/unreviewed/2024/02/GHSA-77vw-jrxp-2648/GHSA-77vw-jrxp-2648.json +++ b/advisories/unreviewed/2024/02/GHSA-77vw-jrxp-2648/GHSA-77vw-jrxp-2648.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-ggw3-6ch2-q6vf/GHSA-ggw3-6ch2-q6vf.json b/advisories/unreviewed/2024/04/GHSA-ggw3-6ch2-q6vf/GHSA-ggw3-6ch2-q6vf.json index d234ed5ffd9..cded1ab3771 100644 --- a/advisories/unreviewed/2024/04/GHSA-ggw3-6ch2-q6vf/GHSA-ggw3-6ch2-q6vf.json +++ b/advisories/unreviewed/2024/04/GHSA-ggw3-6ch2-q6vf/GHSA-ggw3-6ch2-q6vf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggw3-6ch2-q6vf", - "modified": "2024-04-01T15:30:29Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-04-01T15:30:29Z", "aliases": [ "CVE-2024-30871" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T13:17:40Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h54m-6vwp-4wpq/GHSA-h54m-6vwp-4wpq.json b/advisories/unreviewed/2024/04/GHSA-h54m-6vwp-4wpq/GHSA-h54m-6vwp-4wpq.json index 2942dbc7d4c..5a458c41605 100644 --- a/advisories/unreviewed/2024/04/GHSA-h54m-6vwp-4wpq/GHSA-h54m-6vwp-4wpq.json +++ b/advisories/unreviewed/2024/04/GHSA-h54m-6vwp-4wpq/GHSA-h54m-6vwp-4wpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h54m-6vwp-4wpq", - "modified": "2024-04-01T18:30:56Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-04-01T18:30:56Z", "aliases": [ "CVE-2024-30860" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T16:15:31Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json index fb544d8d2b0..92439d9c0c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json +++ b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m98g-cw9w-r9qw", - "modified": "2024-08-15T21:31:19Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-32358" @@ -25,6 +25,18 @@ "type": "WEB", "url": "https://gist.github.com/rootlili/a6b6c89591f4773857ae81b7ca5898bc" }, + { + "type": "WEB", + "url": "https://gitee.com/JPressProjects/jpress/releases/tag/v5.1.0" + }, + { + "type": "WEB", + "url": "https://github.com/JPressProjects/jpress/releases/tag/v5.1.0" + }, + { + "type": "WEB", + "url": "https://www.jpress.cn/download" + }, { "type": "WEB", "url": "https://www.wolai.com/catr00t/2LujDzjjcrAjUYpWtcusXD" diff --git a/advisories/unreviewed/2024/05/GHSA-2625-j643-gg22/GHSA-2625-j643-gg22.json b/advisories/unreviewed/2024/05/GHSA-2625-j643-gg22/GHSA-2625-j643-gg22.json index 3f8485d5f85..e9862d227ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-2625-j643-gg22/GHSA-2625-j643-gg22.json +++ b/advisories/unreviewed/2024/05/GHSA-2625-j643-gg22/GHSA-2625-j643-gg22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2625-j643-gg22", - "modified": "2024-05-31T21:30:54Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-31T21:30:54Z", "aliases": [ "CVE-2024-36844" ], "details": "libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-31T20:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-383m-3rgc-734c/GHSA-383m-3rgc-734c.json b/advisories/unreviewed/2024/05/GHSA-383m-3rgc-734c/GHSA-383m-3rgc-734c.json index 2b96486c10e..98eff4e8940 100644 --- a/advisories/unreviewed/2024/05/GHSA-383m-3rgc-734c/GHSA-383m-3rgc-734c.json +++ b/advisories/unreviewed/2024/05/GHSA-383m-3rgc-734c/GHSA-383m-3rgc-734c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-383m-3rgc-734c", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32505" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json index da1bd59cf9f..d9053e3ecd6 100644 --- a/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json +++ b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9cm6-r59j-22jc", - "modified": "2024-05-22T15:31:01Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-22T15:31:01Z", "aliases": [ "CVE-2024-35561" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9phc-8693-5w9q/GHSA-9phc-8693-5w9q.json b/advisories/unreviewed/2024/05/GHSA-9phc-8693-5w9q/GHSA-9phc-8693-5w9q.json index 69efd50ffde..673d23dfa76 100644 --- a/advisories/unreviewed/2024/05/GHSA-9phc-8693-5w9q/GHSA-9phc-8693-5w9q.json +++ b/advisories/unreviewed/2024/05/GHSA-9phc-8693-5w9q/GHSA-9phc-8693-5w9q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9phc-8693-5w9q", - "modified": "2024-05-23T18:30:56Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-23T18:30:55Z", "aliases": [ "CVE-2024-35085" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jh7g-4fx4-rhh4/GHSA-jh7g-4fx4-rhh4.json b/advisories/unreviewed/2024/05/GHSA-jh7g-4fx4-rhh4/GHSA-jh7g-4fx4-rhh4.json index 2af036efe31..d676d4cf89b 100644 --- a/advisories/unreviewed/2024/05/GHSA-jh7g-4fx4-rhh4/GHSA-jh7g-4fx4-rhh4.json +++ b/advisories/unreviewed/2024/05/GHSA-jh7g-4fx4-rhh4/GHSA-jh7g-4fx4-rhh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh7g-4fx4-rhh4", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-35011" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pw4q-cgcg-f9p5/GHSA-pw4q-cgcg-f9p5.json b/advisories/unreviewed/2024/05/GHSA-pw4q-cgcg-f9p5/GHSA-pw4q-cgcg-f9p5.json index 9d03f3da8ca..b9f65b75a99 100644 --- a/advisories/unreviewed/2024/05/GHSA-pw4q-cgcg-f9p5/GHSA-pw4q-cgcg-f9p5.json +++ b/advisories/unreviewed/2024/05/GHSA-pw4q-cgcg-f9p5/GHSA-pw4q-cgcg-f9p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw4q-cgcg-f9p5", - "modified": "2024-05-16T15:31:37Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-05-16T15:31:37Z", "aliases": [ "CVE-2024-34957" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T15:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-273h-mfpf-cvq6/GHSA-273h-mfpf-cvq6.json b/advisories/unreviewed/2024/06/GHSA-273h-mfpf-cvq6/GHSA-273h-mfpf-cvq6.json index 0d5b69a619a..8827857cc58 100644 --- a/advisories/unreviewed/2024/06/GHSA-273h-mfpf-cvq6/GHSA-273h-mfpf-cvq6.json +++ b/advisories/unreviewed/2024/06/GHSA-273h-mfpf-cvq6/GHSA-273h-mfpf-cvq6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-762" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-5mvf-mw2h-9f35/GHSA-5mvf-mw2h-9f35.json b/advisories/unreviewed/2024/06/GHSA-5mvf-mw2h-9f35/GHSA-5mvf-mw2h-9f35.json index e8f1b8f8e18..35a4f965d57 100644 --- a/advisories/unreviewed/2024/06/GHSA-5mvf-mw2h-9f35/GHSA-5mvf-mw2h-9f35.json +++ b/advisories/unreviewed/2024/06/GHSA-5mvf-mw2h-9f35/GHSA-5mvf-mw2h-9f35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mvf-mw2h-9f35", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47585" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory leak in __add_inode_ref()\n\nLine 1169 (#3) allocates a memory chunk for victim_name by kmalloc(),\nbut when the function returns in line 1184 (#4) victim_name allocated\nby line 1169 (#3) is not freed, which will lead to a memory leak.\nThere is a similar snippet of code in this function as allocating a memory\nchunk for victim_name in line 1104 (#1) as well as releasing the memory\nin line 1116 (#2).\n\nWe should kfree() victim_name when the return value of backref_in_log()\nis less than zero and before the function returns in line 1184 (#4).\n\n1057 static inline int __add_inode_ref(struct btrfs_trans_handle *trans,\n1058 \t\t\t\t struct btrfs_root *root,\n1059 \t\t\t\t struct btrfs_path *path,\n1060 \t\t\t\t struct btrfs_root *log_root,\n1061 \t\t\t\t struct btrfs_inode *dir,\n1062 \t\t\t\t struct btrfs_inode *inode,\n1063 \t\t\t\t u64 inode_objectid, u64 parent_objectid,\n1064 \t\t\t\t u64 ref_index, char *name, int namelen,\n1065 \t\t\t\t int *search_done)\n1066 {\n\n1104 \tvictim_name = kmalloc(victim_name_len, GFP_NOFS);\n\t// #1: kmalloc (victim_name-1)\n1105 \tif (!victim_name)\n1106 \t\treturn -ENOMEM;\n\n1112\tret = backref_in_log(log_root, &search_key,\n1113\t\t\tparent_objectid, victim_name,\n1114\t\t\tvictim_name_len);\n1115\tif (ret < 0) {\n1116\t\tkfree(victim_name); // #2: kfree (victim_name-1)\n1117\t\treturn ret;\n1118\t} else if (!ret) {\n\n1169 \tvictim_name = kmalloc(victim_name_len, GFP_NOFS);\n\t// #3: kmalloc (victim_name-2)\n1170 \tif (!victim_name)\n1171 \t\treturn -ENOMEM;\n\n1180 \tret = backref_in_log(log_root, &search_key,\n1181 \t\t\tparent_objectid, victim_name,\n1182 \t\t\tvictim_name_len);\n1183 \tif (ret < 0) {\n1184 \t\treturn ret; // #4: missing kfree (victim_name-2)\n1185 \t} else if (!ret) {\n\n1241 \treturn 0;\n1242 }", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5xg5-ffcr-c2cc/GHSA-5xg5-ffcr-c2cc.json b/advisories/unreviewed/2024/06/GHSA-5xg5-ffcr-c2cc/GHSA-5xg5-ffcr-c2cc.json index 8ecb872f655..cbb345c0465 100644 --- a/advisories/unreviewed/2024/06/GHSA-5xg5-ffcr-c2cc/GHSA-5xg5-ffcr-c2cc.json +++ b/advisories/unreviewed/2024/06/GHSA-5xg5-ffcr-c2cc/GHSA-5xg5-ffcr-c2cc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5xg5-ffcr-c2cc", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47596" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix use-after-free bug in hclgevf_send_mbx_msg\n\nCurrently, the hns3_remove function firstly uninstall client instance,\nand then uninstall acceletion engine device. The netdevice is freed in\nclient instance uninstall process, but acceletion engine device uninstall\nprocess still use it to trace runtime information. This causes a use after\nfree problem.\n\nSo fixes it by check the instance register state to avoid use after free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9xpc-qh7h-4926/GHSA-9xpc-qh7h-4926.json b/advisories/unreviewed/2024/06/GHSA-9xpc-qh7h-4926/GHSA-9xpc-qh7h-4926.json index 66c5ecf7eaf..a0a1539343d 100644 --- a/advisories/unreviewed/2024/06/GHSA-9xpc-qh7h-4926/GHSA-9xpc-qh7h-4926.json +++ b/advisories/unreviewed/2024/06/GHSA-9xpc-qh7h-4926/GHSA-9xpc-qh7h-4926.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xpc-qh7h-4926", - "modified": "2024-06-10T18:31:06Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-06-10T18:31:06Z", "aliases": [ "CVE-2024-31613" ], "details": "BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name=\"head_code\" or name=\"foot_code.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T16:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json b/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json index 350651b178f..a07c3fdd0a0 100644 --- a/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json +++ b/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq4f-h5g8-8r5h", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48735" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: Fix UAF of leds class devs at unbinding\n\nThe LED class devices that are created by HD-audio codec drivers are\nregistered via devm_led_classdev_register() and associated with the\nHD-audio codec device. Unfortunately, it turned out that the devres\nrelease doesn't work for this case; namely, since the codec resource\nrelease happens before the devm call chain, it triggers a NULL\ndereference or a UAF for a stale set_brightness_delay callback.\n\nFor fixing the bug, this patch changes the LED class device register\nand unregister in a manual manner without devres, keeping the\ninstances in hda_gen_spec.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json b/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json index cc4fe62aa0d..16fc3d35b68 100644 --- a/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json +++ b/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f558-fw4f-vm2c", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48740" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix double free of cond_list on error paths\n\nOn error path from cond_read_list() and duplicate_policydb_cond_list()\nthe cond_list_destroy() gets called a second time in caller functions,\nresulting in NULL pointer deref. Fix this by resetting the\ncond_list_len to 0 in cond_list_destroy(), making subsequent calls a\nnoop.\n\nAlso consistently reset the cond_list pointer to NULL after freeing.\n\n[PM: fix line lengths in the description]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json b/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json index ee0e9649e6d..c03dea1f04f 100644 --- a/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json +++ b/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g59j-h2pg-qp5r", - "modified": "2024-07-05T09:33:44Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-19T09:31:17Z", "aliases": [ "CVE-2024-36978" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: sch_multiq: fix possible OOB write in multiq_tune()\n\nq->bands will be assigned to qopt->bands to execute subsequent code logic\nafter kmalloc. So the old q->bands should not be used in kmalloc.\nOtherwise, an out-of-bounds write will occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T07:15:46Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json b/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json index 7dcc70385e7..9c6d8ca13c7 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json +++ b/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc8r-pxj9-hhx3", - "modified": "2024-07-17T06:30:47Z", + "modified": "2024-08-19T18:32:02Z", "published": "2024-06-05T18:30:37Z", "aliases": [ "CVE-2024-5037" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4484" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5200" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5037" diff --git a/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json b/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json index ea6654c795d..cd101107502 100644 --- a/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json +++ b/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grhv-62hf-9jg3", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48733" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free after failure to create a snapshot\n\nAt ioctl.c:create_snapshot(), we allocate a pending snapshot structure and\nthen attach it to the transaction's list of pending snapshots. After that\nwe call btrfs_commit_transaction(), and if that returns an error we jump\nto 'fail' label, where we kfree() the pending snapshot structure. This can\nresult in a later use-after-free of the pending snapshot:\n\n1) We allocated the pending snapshot and added it to the transaction's\n list of pending snapshots;\n\n2) We call btrfs_commit_transaction(), and it fails either at the first\n call to btrfs_run_delayed_refs() or btrfs_start_dirty_block_groups().\n In both cases, we don't abort the transaction and we release our\n transaction handle. We jump to the 'fail' label and free the pending\n snapshot structure. We return with the pending snapshot still in the\n transaction's list;\n\n3) Another task commits the transaction. This time there's no error at\n all, and then during the transaction commit it accesses a pointer\n to the pending snapshot structure that the snapshot creation task\n has already freed, resulting in a user-after-free.\n\nThis issue could actually be detected by smatch, which produced the\nfollowing warning:\n\n fs/btrfs/ioctl.c:843 create_snapshot() warn: '&pending_snapshot->list' not removed from list\n\nSo fix this by not having the snapshot creation ioctl directly add the\npending snapshot to the transaction's list. Instead add the pending\nsnapshot to the transaction handle, and then at btrfs_commit_transaction()\nwe add the snapshot to the list only when we can guarantee that any error\nreturned after that point will result in a transaction abort, in which\ncase the ioctl code can safely free the pending snapshot and no one can\naccess it anymore.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-q884-jcxw-49wr/GHSA-q884-jcxw-49wr.json b/advisories/unreviewed/2024/06/GHSA-q884-jcxw-49wr/GHSA-q884-jcxw-49wr.json index fd7ede17e3a..5ccfaee2e3b 100644 --- a/advisories/unreviewed/2024/06/GHSA-q884-jcxw-49wr/GHSA-q884-jcxw-49wr.json +++ b/advisories/unreviewed/2024/06/GHSA-q884-jcxw-49wr/GHSA-q884-jcxw-49wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q884-jcxw-49wr", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47597" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet_diag: fix kernel-infoleak for UDP sockets\n\nKMSAN reported a kernel-infoleak [1], that can exploited\nby unpriv users.\n\nAfter analysis it turned out UDP was not initializing\nr->idiag_expires. Other users of inet_sk_diag_fill()\nmight make the same mistake in the future, so fix this\nin inet_sk_diag_fill().\n\n[1]\nBUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:121 [inline]\nBUG: KMSAN: kernel-infoleak in copyout lib/iov_iter.c:156 [inline]\nBUG: KMSAN: kernel-infoleak in _copy_to_iter+0x69d/0x25c0 lib/iov_iter.c:670\n instrument_copy_to_user include/linux/instrumented.h:121 [inline]\n copyout lib/iov_iter.c:156 [inline]\n _copy_to_iter+0x69d/0x25c0 lib/iov_iter.c:670\n copy_to_iter include/linux/uio.h:155 [inline]\n simple_copy_to_iter+0xf3/0x140 net/core/datagram.c:519\n __skb_datagram_iter+0x2cb/0x1280 net/core/datagram.c:425\n skb_copy_datagram_iter+0xdc/0x270 net/core/datagram.c:533\n skb_copy_datagram_msg include/linux/skbuff.h:3657 [inline]\n netlink_recvmsg+0x660/0x1c60 net/netlink/af_netlink.c:1974\n sock_recvmsg_nosec net/socket.c:944 [inline]\n sock_recvmsg net/socket.c:962 [inline]\n sock_read_iter+0x5a9/0x630 net/socket.c:1035\n call_read_iter include/linux/fs.h:2156 [inline]\n new_sync_read fs/read_write.c:400 [inline]\n vfs_read+0x1631/0x1980 fs/read_write.c:481\n ksys_read+0x28c/0x520 fs/read_write.c:619\n __do_sys_read fs/read_write.c:629 [inline]\n __se_sys_read fs/read_write.c:627 [inline]\n __x64_sys_read+0xdb/0x120 fs/read_write.c:627\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nUninit was created at:\n slab_post_alloc_hook mm/slab.h:524 [inline]\n slab_alloc_node mm/slub.c:3251 [inline]\n __kmalloc_node_track_caller+0xe0c/0x1510 mm/slub.c:4974\n kmalloc_reserve net/core/skbuff.c:354 [inline]\n __alloc_skb+0x545/0xf90 net/core/skbuff.c:426\n alloc_skb include/linux/skbuff.h:1126 [inline]\n netlink_dump+0x3d5/0x16a0 net/netlink/af_netlink.c:2245\n __netlink_dump_start+0xd1c/0xee0 net/netlink/af_netlink.c:2370\n netlink_dump_start include/linux/netlink.h:254 [inline]\n inet_diag_handler_cmd+0x2e7/0x400 net/ipv4/inet_diag.c:1343\n sock_diag_rcv_msg+0x24a/0x620\n netlink_rcv_skb+0x447/0x800 net/netlink/af_netlink.c:2491\n sock_diag_rcv+0x63/0x80 net/core/sock_diag.c:276\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0x1095/0x1360 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x16f3/0x1870 net/netlink/af_netlink.c:1916\n sock_sendmsg_nosec net/socket.c:704 [inline]\n sock_sendmsg net/socket.c:724 [inline]\n sock_write_iter+0x594/0x690 net/socket.c:1057\n do_iter_readv_writev+0xa7f/0xc70\n do_iter_write+0x52c/0x1500 fs/read_write.c:851\n vfs_writev fs/read_write.c:924 [inline]\n do_writev+0x63f/0xe30 fs/read_write.c:967\n __do_sys_writev fs/read_write.c:1040 [inline]\n __se_sys_writev fs/read_write.c:1037 [inline]\n __x64_sys_writev+0xe5/0x120 fs/read_write.c:1037\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nBytes 68-71 of 312 are uninitialized\nMemory access of size 312 starts at ffff88812ab54000\nData copied to user address 0000000020001440\n\nCPU: 1 PID: 6365 Comm: syz-executor801 Not tainted 5.16.0-rc3-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json b/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json index f0b97bcb42e..7e70da9e85e 100644 --- a/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json +++ b/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v47w-h9mw-wj4f", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48741" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix NULL pointer dereference in copy up warning\n\nThis patch is fixing a NULL pointer dereference to get a recently\nintroduced warning message working.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json b/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json index 93de922c58e..1467179a770 100644 --- a/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json +++ b/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjh8-wgcx-46j4", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48732" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix off by one in BIOS boundary checking\n\nBounds checking when parsing init scripts embedded in the BIOS reject\naccess to the last byte. This causes driver initialization to fail on\nApple eMac's with GeForce 2 MX GPUs, leaving the system with no working\nconsole.\n\nThis is probably only seen on OpenFirmware machines like PowerPC Macs\nbecause the BIOS image provided by OF is only the used parts of the ROM,\nnot a power-of-two blocks read from PCI directly so PCs always have\nempty bytes at the end that are never accessed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-193" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json b/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json index e181c219c1c..cb2d8de5eac 100644 --- a/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json +++ b/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfr-rmr8-j7gx", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48734" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock between quota disable and qgroup rescan worker\n\nQuota disable ioctl starts a transaction before waiting for the qgroup\nrescan worker completes. However, this wait can be infinite and results\nin deadlock because of circular dependency among the quota disable\nioctl, the qgroup rescan worker and the other task with transaction such\nas block group relocation task.\n\nThe deadlock happens with the steps following:\n\n1) Task A calls ioctl to disable quota. It starts a transaction and\n waits for qgroup rescan worker completes.\n2) Task B such as block group relocation task starts a transaction and\n joins to the transaction that task A started. Then task B commits to\n the transaction. In this commit, task B waits for a commit by task A.\n3) Task C as the qgroup rescan worker starts its job and starts a\n transaction. In this transaction start, task C waits for completion\n of the transaction that task A started and task B committed.\n\nThis deadlock was found with fstests test case btrfs/115 and a zoned\nnull_blk device. The test case enables and disables quota, and the\nblock group reclaim was triggered during the quota disable by chance.\nThe deadlock was also observed by running quota enable and disable in\nparallel with 'btrfs balance' command on regular null_blk devices.\n\nAn example report of the deadlock:\n\n [372.469894] INFO: task kworker/u16:6:103 blocked for more than 122 seconds.\n [372.479944] Not tainted 5.16.0-rc8 #7\n [372.485067] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n [372.493898] task:kworker/u16:6 state:D stack: 0 pid: 103 ppid: 2 flags:0x00004000\n [372.503285] Workqueue: btrfs-qgroup-rescan btrfs_work_helper [btrfs]\n [372.510782] Call Trace:\n [372.514092] \n [372.521684] __schedule+0xb56/0x4850\n [372.530104] ? io_schedule_timeout+0x190/0x190\n [372.538842] ? lockdep_hardirqs_on+0x7e/0x100\n [372.547092] ? _raw_spin_unlock_irqrestore+0x3e/0x60\n [372.555591] schedule+0xe0/0x270\n [372.561894] btrfs_commit_transaction+0x18bb/0x2610 [btrfs]\n [372.570506] ? btrfs_apply_pending_changes+0x50/0x50 [btrfs]\n [372.578875] ? free_unref_page+0x3f2/0x650\n [372.585484] ? finish_wait+0x270/0x270\n [372.591594] ? release_extent_buffer+0x224/0x420 [btrfs]\n [372.599264] btrfs_qgroup_rescan_worker+0xc13/0x10c0 [btrfs]\n [372.607157] ? lock_release+0x3a9/0x6d0\n [372.613054] ? btrfs_qgroup_account_extent+0xda0/0xda0 [btrfs]\n [372.620960] ? do_raw_spin_lock+0x11e/0x250\n [372.627137] ? rwlock_bug.part.0+0x90/0x90\n [372.633215] ? lock_is_held_type+0xe4/0x140\n [372.639404] btrfs_work_helper+0x1ae/0xa90 [btrfs]\n [372.646268] process_one_work+0x7e9/0x1320\n [372.652321] ? lock_release+0x6d0/0x6d0\n [372.658081] ? pwq_dec_nr_in_flight+0x230/0x230\n [372.664513] ? rwlock_bug.part.0+0x90/0x90\n [372.670529] worker_thread+0x59e/0xf90\n [372.676172] ? process_one_work+0x1320/0x1320\n [372.682440] kthread+0x3b9/0x490\n [372.687550] ? _raw_spin_unlock_irq+0x24/0x50\n [372.693811] ? set_kthread_struct+0x100/0x100\n [372.700052] ret_from_fork+0x22/0x30\n [372.705517] \n [372.709747] INFO: task btrfs-transacti:2347 blocked for more than 123 seconds.\n [372.729827] Not tainted 5.16.0-rc8 #7\n [372.745907] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n [372.767106] task:btrfs-transacti state:D stack: 0 pid: 2347 ppid: 2 flags:0x00004000\n [372.787776] Call Trace:\n [372.801652] \n [372.812961] __schedule+0xb56/0x4850\n [372.830011] ? io_schedule_timeout+0x190/0x190\n [372.852547] ? lockdep_hardirqs_on+0x7e/0x100\n [372.871761] ? _raw_spin_unlock_irqrestore+0x3e/0x60\n [372.886792] schedule+0xe0/0x270\n [372.901685] wait_current_trans+0x22c/0x310 [btrfs]\n [372.919743] ? btrfs_put_transaction+0x3d0/0x3d0 [btrfs]\n [372.938923] ? finish_wait+0x270/0x270\n [372.959085] ? join_transaction+0xc7\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c7wc-g87j-82j8/GHSA-c7wc-g87j-82j8.json b/advisories/unreviewed/2024/07/GHSA-c7wc-g87j-82j8/GHSA-c7wc-g87j-82j8.json index 34a6df71253..bc51cfaef39 100644 --- a/advisories/unreviewed/2024/07/GHSA-c7wc-g87j-82j8/GHSA-c7wc-g87j-82j8.json +++ b/advisories/unreviewed/2024/07/GHSA-c7wc-g87j-82j8/GHSA-c7wc-g87j-82j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c7wc-g87j-82j8", - "modified": "2024-07-09T21:30:39Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-07-09T21:30:39Z", "aliases": [ "CVE-2024-31326" ], "details": "In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-783" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T21:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wf46-934q-8fhp/GHSA-wf46-934q-8fhp.json b/advisories/unreviewed/2024/07/GHSA-wf46-934q-8fhp/GHSA-wf46-934q-8fhp.json index 6cce82d7f28..70c74cf77a8 100644 --- a/advisories/unreviewed/2024/07/GHSA-wf46-934q-8fhp/GHSA-wf46-934q-8fhp.json +++ b/advisories/unreviewed/2024/07/GHSA-wf46-934q-8fhp/GHSA-wf46-934q-8fhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wf46-934q-8fhp", - "modified": "2024-07-05T21:31:44Z", + "modified": "2024-08-19T18:32:03Z", "published": "2024-07-05T21:31:44Z", "aliases": [ "CVE-2024-39021" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://127.0.0.1:80/admin/vpsApiData_deal.php?mudi=del", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T19:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json b/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json index 832a96ab27a..8a2c0aea37e 100644 --- a/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json +++ b/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p7q-76m8-h2pg", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-19T18:32:06Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42843" ], "details": "Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4cm7-5r54-q82c/GHSA-4cm7-5r54-q82c.json b/advisories/unreviewed/2024/08/GHSA-4cm7-5r54-q82c/GHSA-4cm7-5r54-q82c.json new file mode 100644 index 00000000000..0dc85be589d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4cm7-5r54-q82c/GHSA-4cm7-5r54-q82c.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cm7-5r54-q82c", + "modified": "2024-08-19T18:32:09Z", + "published": "2024-08-19T18:32:09Z", + "aliases": [ + "CVE-2024-7924" + ], + "details": "A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7924" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/zzcms/zzcms%20list.php%20Directory%20traversal.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391876" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json index 29eca8546e0..9165abb0b29 100644 --- a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json +++ b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53h7-ghj7-7gh9", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-19T18:32:06Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42677" ], "details": "An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T14:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5mg4-xpj4-crpr/GHSA-5mg4-xpj4-crpr.json b/advisories/unreviewed/2024/08/GHSA-5mg4-xpj4-crpr/GHSA-5mg4-xpj4-crpr.json new file mode 100644 index 00000000000..bf854e2dad1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5mg4-xpj4-crpr/GHSA-5mg4-xpj4-crpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mg4-xpj4-crpr", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43281" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43281" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/void-elementor-post-grid-addon-for-elementor-page-builder/wordpress-void-elementor-post-grid-addon-for-elementor-page-builder-plugin-2-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6c55-p332-pqhh/GHSA-6c55-p332-pqhh.json b/advisories/unreviewed/2024/08/GHSA-6c55-p332-pqhh/GHSA-6c55-p332-pqhh.json new file mode 100644 index 00000000000..7b8b2d0dd37 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6c55-p332-pqhh/GHSA-6c55-p332-pqhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c55-p332-pqhh", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43236" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-ecommerce-paypal/wordpress-easy-paypal-stripe-buy-now-button-plugin-1-9-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6j4x-5vg8-wc8v/GHSA-6j4x-5vg8-wc8v.json b/advisories/unreviewed/2024/08/GHSA-6j4x-5vg8-wc8v/GHSA-6j4x-5vg8-wc8v.json new file mode 100644 index 00000000000..f2dcfc47d39 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6j4x-5vg8-wc8v/GHSA-6j4x-5vg8-wc8v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j4x-5vg8-wc8v", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43252" + ], + "details": "Deserialization of Untrusted Data vulnerability in Crew HRM allows Object Injection.This issue affects Crew HRM: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hr-management/wordpress-crew-hrm-plugin-1-1-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json b/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json index 44b494ced85..9f0499ca1d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json +++ b/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76qm-c9j2-wm6v", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-19T18:32:05Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-5651" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5651" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5453" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5651" diff --git a/advisories/unreviewed/2024/08/GHSA-7cjv-5xcp-6cwv/GHSA-7cjv-5xcp-6cwv.json b/advisories/unreviewed/2024/08/GHSA-7cjv-5xcp-6cwv/GHSA-7cjv-5xcp-6cwv.json new file mode 100644 index 00000000000..794a199f8f5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7cjv-5xcp-6cwv/GHSA-7cjv-5xcp-6cwv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cjv-5xcp-6cwv", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-42658" + ], + "details": "An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42658" + }, + { + "type": "WEB", + "url": "https://github.com/sudo-subho/CVE-2024-42658" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/in/subhodeep-baroi-397629252" + }, + { + "type": "WEB", + "url": "https://x.com/sudo_subho" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json b/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json new file mode 100644 index 00000000000..0491dc10137 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r73-v3pv-4xj4", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-42657" + ], + "details": "An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42657" + }, + { + "type": "WEB", + "url": "https://github.com/sudo-subho/CVE-2024-42657" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/in/subhodeep-baroi-397629252" + }, + { + "type": "WEB", + "url": "https://x.com/sudo_subho" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f5w7-hc7v-f8j6/GHSA-f5w7-hc7v-f8j6.json b/advisories/unreviewed/2024/08/GHSA-f5w7-hc7v-f8j6/GHSA-f5w7-hc7v-f8j6.json new file mode 100644 index 00000000000..677329ba1fb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f5w7-hc7v-f8j6/GHSA-f5w7-hc7v-f8j6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5w7-hc7v-f8j6", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43242" + ], + "details": "Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/indeed-membership-pro/wordpress-indeed-ultimate-membership-pro-plugin-12-6-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f776-8qvr-rf72/GHSA-f776-8qvr-rf72.json b/advisories/unreviewed/2024/08/GHSA-f776-8qvr-rf72/GHSA-f776-8qvr-rf72.json new file mode 100644 index 00000000000..faaae3869ad --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f776-8qvr-rf72/GHSA-f776-8qvr-rf72.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f776-8qvr-rf72", + "modified": "2024-08-19T18:32:09Z", + "published": "2024-08-19T18:32:09Z", + "aliases": [ + "CVE-2024-7925" + ], + "details": "A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7925" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/zzcms/information_leak/Zenmus%20ekinfo.php%20had%20an%20information%20leak.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.392121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ff2j-rwgx-m3hr/GHSA-ff2j-rwgx-m3hr.json b/advisories/unreviewed/2024/08/GHSA-ff2j-rwgx-m3hr/GHSA-ff2j-rwgx-m3hr.json new file mode 100644 index 00000000000..6d480eca641 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ff2j-rwgx-m3hr/GHSA-ff2j-rwgx-m3hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff2j-rwgx-m3hr", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43245" + ], + "details": "Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-jobsearch/wordpress-jobsearch-plugin-2-3-4-unauthenticated-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json b/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json new file mode 100644 index 00000000000..1c68abf748b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq29-72jg-5hrj", + "modified": "2024-08-19T18:32:07Z", + "published": "2024-08-19T18:32:07Z", + "aliases": [ + "CVE-2024-32928" + ], + "details": "The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32928" + }, + { + "type": "WEB", + "url": "https://support.google.com/product-documentation/answer/14771247?hl=en&ref_topic=12974021&sjid=9111851316942032590-NA#zippy=" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fqr9-v44c-j829/GHSA-fqr9-v44c-j829.json b/advisories/unreviewed/2024/08/GHSA-fqr9-v44c-j829/GHSA-fqr9-v44c-j829.json new file mode 100644 index 00000000000..4915dfc2b89 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fqr9-v44c-j829/GHSA-fqr9-v44c-j829.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqr9-v44c-j829", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43261" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/compute-links/wordpress-compute-links-plugin-1-2-1-remote-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fwg4-px6f-6fj8/GHSA-fwg4-px6f-6fj8.json b/advisories/unreviewed/2024/08/GHSA-fwg4-px6f-6fj8/GHSA-fwg4-px6f-6fj8.json new file mode 100644 index 00000000000..eebdab40694 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fwg4-px6f-6fj8/GHSA-fwg4-px6f-6fj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwg4-px6f-6fj8", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43221" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclusion.This issue affects JetGridBuilder: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43221" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jetgridbuilder/wordpress-jetgridbuilder-plugin-1-1-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gx44-2gg6-xj9m/GHSA-gx44-2gg6-xj9m.json b/advisories/unreviewed/2024/08/GHSA-gx44-2gg6-xj9m/GHSA-gx44-2gg6-xj9m.json new file mode 100644 index 00000000000..08dabe71051 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gx44-2gg6-xj9m/GHSA-gx44-2gg6-xj9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx44-2gg6-xj9m", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43271" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allows PHP Local File Inclusion.This issue affects Woo Products Widgets For Elementor: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-products-widgets-for-elementor/wordpress-widgets-for-woocommerce-products-on-elementor-plugin-2-0-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j72m-4pgw-w3qv/GHSA-j72m-4pgw-w3qv.json b/advisories/unreviewed/2024/08/GHSA-j72m-4pgw-w3qv/GHSA-j72m-4pgw-w3qv.json index 839effeef4a..66b931cc77d 100644 --- a/advisories/unreviewed/2024/08/GHSA-j72m-4pgw-w3qv/GHSA-j72m-4pgw-w3qv.json +++ b/advisories/unreviewed/2024/08/GHSA-j72m-4pgw-w3qv/GHSA-j72m-4pgw-w3qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j72m-4pgw-w3qv", - "modified": "2024-08-14T15:31:18Z", + "modified": "2024-08-19T18:32:05Z", "published": "2024-08-14T15:31:18Z", "aliases": [ "CVE-2024-39792" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-672", "CWE-825" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-jg97-797c-2q53/GHSA-jg97-797c-2q53.json b/advisories/unreviewed/2024/08/GHSA-jg97-797c-2q53/GHSA-jg97-797c-2q53.json new file mode 100644 index 00000000000..ddf03147a28 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jg97-797c-2q53/GHSA-jg97-797c-2q53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg97-797c-2q53", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43272" + ], + "details": "Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icegram/wordpress-icegram-engage-plugin-3-1-24-unauthenticated-unpublished-campaign-viewer-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jp5m-m368-79vw/GHSA-jp5m-m368-79vw.json b/advisories/unreviewed/2024/08/GHSA-jp5m-m368-79vw/GHSA-jp5m-m368-79vw.json new file mode 100644 index 00000000000..8e4b4a13acc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jp5m-m368-79vw/GHSA-jp5m-m368-79vw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp5m-m368-79vw", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43248" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bitformpro/wordpress-bit-form-pro-plugin-2-6-4-unauthenticated-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json index 9b32ac7b64d..ed332fc1f97 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json +++ b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcjx-2c4v-mvg9", - "modified": "2024-08-07T00:30:47Z", + "modified": "2024-08-19T18:32:05Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7518" ], "details": "Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:56Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mgfj-pw53-g28v/GHSA-mgfj-pw53-g28v.json b/advisories/unreviewed/2024/08/GHSA-mgfj-pw53-g28v/GHSA-mgfj-pw53-g28v.json new file mode 100644 index 00000000000..5aa77c8470e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mgfj-pw53-g28v/GHSA-mgfj-pw53-g28v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgfj-pw53-g28v", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43249" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bitformpro/wordpress-bit-form-pro-plugin-2-6-4-authenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mw37-8h7c-93hw/GHSA-mw37-8h7c-93hw.json b/advisories/unreviewed/2024/08/GHSA-mw37-8h7c-93hw/GHSA-mw37-8h7c-93hw.json new file mode 100644 index 00000000000..bb4d874573f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mw37-8h7c-93hw/GHSA-mw37-8h7c-93hw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw37-8h7c-93hw", + "modified": "2024-08-19T18:32:07Z", + "published": "2024-08-19T18:32:07Z", + "aliases": [ + "CVE-2024-32927" + ], + "details": "In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32927" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p4jg-pm94-8pxc/GHSA-p4jg-pm94-8pxc.json b/advisories/unreviewed/2024/08/GHSA-p4jg-pm94-8pxc/GHSA-p4jg-pm94-8pxc.json new file mode 100644 index 00000000000..db732b9b620 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p4jg-pm94-8pxc/GHSA-p4jg-pm94-8pxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4jg-pm94-8pxc", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43280" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/salon-booking-system/wordpress-salon-booking-system-plugin-10-8-1-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pcf4-rwp2-6pv4/GHSA-pcf4-rwp2-6pv4.json b/advisories/unreviewed/2024/08/GHSA-pcf4-rwp2-6pv4/GHSA-pcf4-rwp2-6pv4.json index 4c5833d08da..c8a102907f9 100644 --- a/advisories/unreviewed/2024/08/GHSA-pcf4-rwp2-6pv4/GHSA-pcf4-rwp2-6pv4.json +++ b/advisories/unreviewed/2024/08/GHSA-pcf4-rwp2-6pv4/GHSA-pcf4-rwp2-6pv4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json b/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json new file mode 100644 index 00000000000..84b0f17323b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppwh-v8g5-pg9c", + "modified": "2024-08-19T18:32:07Z", + "published": "2024-08-19T18:32:07Z", + "aliases": [ + "CVE-2024-42633" + ], + "details": "A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42633" + }, + { + "type": "WEB", + "url": "https://github.com/goldds96/Report/blob/main/Linksys/E1500/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pvj4-5rhw-5cww/GHSA-pvj4-5rhw-5cww.json b/advisories/unreviewed/2024/08/GHSA-pvj4-5rhw-5cww/GHSA-pvj4-5rhw-5cww.json index eb3913e6f00..38fc28461d8 100644 --- a/advisories/unreviewed/2024/08/GHSA-pvj4-5rhw-5cww/GHSA-pvj4-5rhw-5cww.json +++ b/advisories/unreviewed/2024/08/GHSA-pvj4-5rhw-5cww/GHSA-pvj4-5rhw-5cww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pvj4-5rhw-5cww", - "modified": "2024-08-14T15:31:18Z", + "modified": "2024-08-19T18:32:05Z", "published": "2024-08-14T15:31:18Z", "aliases": [ "CVE-2024-39809" diff --git a/advisories/unreviewed/2024/08/GHSA-q632-7v8j-586g/GHSA-q632-7v8j-586g.json b/advisories/unreviewed/2024/08/GHSA-q632-7v8j-586g/GHSA-q632-7v8j-586g.json index 2e2db0dfd65..46e5a3581ed 100644 --- a/advisories/unreviewed/2024/08/GHSA-q632-7v8j-586g/GHSA-q632-7v8j-586g.json +++ b/advisories/unreviewed/2024/08/GHSA-q632-7v8j-586g/GHSA-q632-7v8j-586g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q632-7v8j-586g", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-08-19T18:32:07Z", "published": "2024-08-19T06:30:54Z", "aliases": [ "CVE-2024-44083" ], "details": "ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T04:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json b/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json index f8de109db6e..980c5a615df 100644 --- a/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json +++ b/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q636-fx55-gfr2", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-08-19T18:32:07Z", "published": "2024-08-19T06:30:54Z", "aliases": [ "CVE-2024-6451" ], "details": "AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of \"logs_path\", allowing Administrators to change log filetypes from .log to .php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T06:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qj78-v57f-v8c2/GHSA-qj78-v57f-v8c2.json b/advisories/unreviewed/2024/08/GHSA-qj78-v57f-v8c2/GHSA-qj78-v57f-v8c2.json new file mode 100644 index 00000000000..9ae98176de3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qj78-v57f-v8c2/GHSA-qj78-v57f-v8c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj78-v57f-v8c2", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43247" + ], + "details": "Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/whmpress/wordpress-whmpress-plugin-6-2-revision-5-subscriber-arbitrary-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json b/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json new file mode 100644 index 00000000000..c48f366372b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp2p-3fr2-8j54", + "modified": "2024-08-19T18:32:07Z", + "published": "2024-08-19T18:32:07Z", + "aliases": [ + "CVE-2024-6348" + ], + "details": "Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:H/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6348" + }, + { + "type": "WEB", + "url": "https://asrg.io/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qr5p-m4c8-89vq/GHSA-qr5p-m4c8-89vq.json b/advisories/unreviewed/2024/08/GHSA-qr5p-m4c8-89vq/GHSA-qr5p-m4c8-89vq.json new file mode 100644 index 00000000000..cceab1dd306 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qr5p-m4c8-89vq/GHSA-qr5p-m4c8-89vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr5p-m4c8-89vq", + "modified": "2024-08-19T18:32:09Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43250" + ], + "details": "Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bitformpro/wordpress-bit-form-pro-plugin-2-6-4-authenticated-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v3qq-5wj9-8242/GHSA-v3qq-5wj9-8242.json b/advisories/unreviewed/2024/08/GHSA-v3qq-5wj9-8242/GHSA-v3qq-5wj9-8242.json new file mode 100644 index 00000000000..d68c4088f67 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v3qq-5wj9-8242/GHSA-v3qq-5wj9-8242.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3qq-5wj9-8242", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43240" + ], + "details": "Improper Privilege Management vulnerability in azzaroco Ultimate Membership Pro allows Privilege Escalation.This issue affects Ultimate Membership Pro: from n/a through 12.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/indeed-membership-pro/wordpress-indeed-ultimate-membership-pro-plugin-12-6-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wgh2-2342-mm46/GHSA-wgh2-2342-mm46.json b/advisories/unreviewed/2024/08/GHSA-wgh2-2342-mm46/GHSA-wgh2-2342-mm46.json new file mode 100644 index 00000000000..c44df7f7bdb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wgh2-2342-mm46/GHSA-wgh2-2342-mm46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgh2-2342-mm46", + "modified": "2024-08-19T18:32:07Z", + "published": "2024-08-19T18:32:07Z", + "aliases": [ + "CVE-2024-37099" + ], + "details": "Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37099" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-3-14-1-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wvmh-96f5-wjw2/GHSA-wvmh-96f5-wjw2.json b/advisories/unreviewed/2024/08/GHSA-wvmh-96f5-wjw2/GHSA-wvmh-96f5-wjw2.json new file mode 100644 index 00000000000..37368ff41cd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wvmh-96f5-wjw2/GHSA-wvmh-96f5-wjw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvmh-96f5-wjw2", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43232" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/timeline-and-history-slider/wordpress-timeline-and-history-slider-plugin-2-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x9qv-64rq-2vc3/GHSA-x9qv-64rq-2vc3.json b/advisories/unreviewed/2024/08/GHSA-x9qv-64rq-2vc3/GHSA-x9qv-64rq-2vc3.json new file mode 100644 index 00000000000..3343349c8c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x9qv-64rq-2vc3/GHSA-x9qv-64rq-2vc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9qv-64rq-2vc3", + "modified": "2024-08-19T18:32:08Z", + "published": "2024-08-19T18:32:08Z", + "aliases": [ + "CVE-2024-43256" + ], + "details": "Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leopard-wordpress-offload-media/wordpress-leopard-wordpress-offload-media-plugin-2-0-36-subscriber-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-19T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xv4g-g9fh-fqrj/GHSA-xv4g-g9fh-fqrj.json b/advisories/unreviewed/2024/08/GHSA-xv4g-g9fh-fqrj/GHSA-xv4g-g9fh-fqrj.json index 10fce381fe8..bbcb74e7f41 100644 --- a/advisories/unreviewed/2024/08/GHSA-xv4g-g9fh-fqrj/GHSA-xv4g-g9fh-fqrj.json +++ b/advisories/unreviewed/2024/08/GHSA-xv4g-g9fh-fqrj/GHSA-xv4g-g9fh-fqrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv4g-g9fh-fqrj", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-08-19T18:32:07Z", "published": "2024-08-19T06:30:54Z", "aliases": [ "CVE-2024-6330" ], "details": "The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T06:15:05Z"