From e3f7d2776f072db5df6ba891be27ca5f031ff1f1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Oct 2024 15:32:01 +0000 Subject: [PATCH] Publish Advisories GHSA-6wvf-f2vw-3425 GHSA-vg57-hwh2-c85p GHSA-27jf-22p2-6vq4 GHSA-mh66-32q9-mpj8 GHSA-c4ch-cv96-r58v GHSA-9f68-5hcg-8ww5 GHSA-4qww-pqq9-xrw5 GHSA-7555-3222-qmcm GHSA-fg4m-w584-q5x8 GHSA-fmxj-97w3-xq3m GHSA-p79g-j2j8-9wqw GHSA-qh7m-p5jw-2wvg GHSA-3qhf-rfv2-rc83 GHSA-ccfh-v7cp-3943 GHSA-fr4c-ch83-r968 GHSA-p43x-m8vx-c7fm --- .../GHSA-6wvf-f2vw-3425.json | 6 ++- .../GHSA-vg57-hwh2-c85p.json | 1 + .../GHSA-27jf-22p2-6vq4.json | 1 + .../GHSA-mh66-32q9-mpj8.json | 2 +- .../GHSA-c4ch-cv96-r58v.json | 2 +- .../GHSA-9f68-5hcg-8ww5.json | 1 + .../GHSA-4qww-pqq9-xrw5.json | 9 ++-- .../GHSA-7555-3222-qmcm.json | 9 ++-- .../GHSA-fg4m-w584-q5x8.json | 3 +- .../GHSA-fmxj-97w3-xq3m.json | 3 +- .../GHSA-p79g-j2j8-9wqw.json | 9 ++-- .../GHSA-qh7m-p5jw-2wvg.json | 9 ++-- .../GHSA-3qhf-rfv2-rc83.json | 42 +++++++++++++++ .../GHSA-ccfh-v7cp-3943.json | 38 +++++++++++++ .../GHSA-fr4c-ch83-r968.json | 2 +- .../GHSA-p43x-m8vx-c7fm.json | 54 +++++++++++++++++++ 16 files changed, 173 insertions(+), 18 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3qhf-rfv2-rc83/GHSA-3qhf-rfv2-rc83.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ccfh-v7cp-3943/GHSA-ccfh-v7cp-3943.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p43x-m8vx-c7fm/GHSA-p43x-m8vx-c7fm.json diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index 729821478b5..43f975275e2 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-10-02T12:30:31Z", + "modified": "2024-10-03T15:30:47Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -142,6 +142,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7187" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:7182" diff --git a/advisories/unreviewed/2023/07/GHSA-vg57-hwh2-c85p/GHSA-vg57-hwh2-c85p.json b/advisories/unreviewed/2023/07/GHSA-vg57-hwh2-c85p/GHSA-vg57-hwh2-c85p.json index 93f79cc982d..e1bd86245b6 100644 --- a/advisories/unreviewed/2023/07/GHSA-vg57-hwh2-c85p/GHSA-vg57-hwh2-c85p.json +++ b/advisories/unreviewed/2023/07/GHSA-vg57-hwh2-c85p/GHSA-vg57-hwh2-c85p.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/08/GHSA-27jf-22p2-6vq4/GHSA-27jf-22p2-6vq4.json b/advisories/unreviewed/2023/08/GHSA-27jf-22p2-6vq4/GHSA-27jf-22p2-6vq4.json index ed4bde3ad0c..e3dfa342186 100644 --- a/advisories/unreviewed/2023/08/GHSA-27jf-22p2-6vq4/GHSA-27jf-22p2-6vq4.json +++ b/advisories/unreviewed/2023/08/GHSA-27jf-22p2-6vq4/GHSA-27jf-22p2-6vq4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-248", "CWE-703", "CWE-755" ], diff --git a/advisories/unreviewed/2023/08/GHSA-mh66-32q9-mpj8/GHSA-mh66-32q9-mpj8.json b/advisories/unreviewed/2023/08/GHSA-mh66-32q9-mpj8/GHSA-mh66-32q9-mpj8.json index 36373357bc5..d658d867876 100644 --- a/advisories/unreviewed/2023/08/GHSA-mh66-32q9-mpj8/GHSA-mh66-32q9-mpj8.json +++ b/advisories/unreviewed/2023/08/GHSA-mh66-32q9-mpj8/GHSA-mh66-32q9-mpj8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json index f3aa8cdee14..767d7c45bd3 100644 --- a/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json +++ b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json @@ -61,7 +61,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-113" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9f68-5hcg-8ww5/GHSA-9f68-5hcg-8ww5.json b/advisories/unreviewed/2024/08/GHSA-9f68-5hcg-8ww5/GHSA-9f68-5hcg-8ww5.json index 75f7c914d28..8191bd0581f 100644 --- a/advisories/unreviewed/2024/08/GHSA-9f68-5hcg-8ww5/GHSA-9f68-5hcg-8ww5.json +++ b/advisories/unreviewed/2024/08/GHSA-9f68-5hcg-8ww5/GHSA-9f68-5hcg-8ww5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-918", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json b/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json index 68c51433d55..d87f6326c79 100644 --- a/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json +++ b/advisories/unreviewed/2024/09/GHSA-4qww-pqq9-xrw5/GHSA-4qww-pqq9-xrw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qww-pqq9-xrw5", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T15:30:47Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44970" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized consumed strides without\nunlinking the WQE again.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7555-3222-qmcm/GHSA-7555-3222-qmcm.json b/advisories/unreviewed/2024/09/GHSA-7555-3222-qmcm/GHSA-7555-3222-qmcm.json index 7bb29eca7d4..1160ad80546 100644 --- a/advisories/unreviewed/2024/09/GHSA-7555-3222-qmcm/GHSA-7555-3222-qmcm.json +++ b/advisories/unreviewed/2024/09/GHSA-7555-3222-qmcm/GHSA-7555-3222-qmcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7555-3222-qmcm", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-03T15:30:50Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46864" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/hyperv: fix kexec crash due to VP assist page corruption\n\ncommit 9636be85cc5b (\"x86/hyperv: Fix hyperv_pcpu_input_arg handling when\nCPUs go online/offline\") introduces a new cpuhp state for hyperv\ninitialization.\n\ncpuhp_setup_state() returns the state number if state is\nCPUHP_AP_ONLINE_DYN or CPUHP_BP_PREPARE_DYN and 0 for all other states.\nFor the hyperv case, since a new cpuhp state was introduced it would\nreturn 0. However, in hv_machine_shutdown(), the cpuhp_remove_state() call\nis conditioned upon \"hyperv_init_cpuhp > 0\". This will never be true and\nso hv_cpu_die() won't be called on all CPUs. This means the VP assist page\nwon't be reset. When the kexec kernel tries to setup the VP assist page\nagain, the hypervisor corrupts the memory region of the old VP assist page\ncausing a panic in case the kexec kernel is using that memory elsewhere.\nThis was originally fixed in commit dfe94d4086e4 (\"x86/hyperv: Fix kexec\npanic/hang issues\").\n\nGet rid of hyperv_init_cpuhp entirely since we are no longer using a\ndynamic cpuhp state and use CPUHP_AP_HYPERV_ONLINE directly with\ncpuhp_remove_state().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json b/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json index 83ed5f8b6f3..57e402e9a59 100644 --- a/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json +++ b/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json b/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json index 6654e15e788..b4074848aec 100644 --- a/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json +++ b/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json b/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json index 276085437fd..e693b127014 100644 --- a/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json +++ b/advisories/unreviewed/2024/09/GHSA-p79g-j2j8-9wqw/GHSA-p79g-j2j8-9wqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p79g-j2j8-9wqw", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T15:30:47Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44973" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: do not call do_slab_free for kfence object\n\nIn 782f8906f805 the freeing of kfence objects was moved from deep\ninside do_slab_free to the wrapper functions outside. This is a nice\nchange, but unfortunately it missed one spot in __kmem_cache_free_bulk.\n\nThis results in a crash like this:\n\nBUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840\n\nslab_err (mm/slub.c:1129)\nfree_to_partial_list (mm/slub.c:? mm/slub.c:4036)\nslab_pad_check (mm/slub.c:864 mm/slub.c:1290)\ncheck_slab (mm/slub.c:?)\nfree_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)\nkmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)\nnapi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)\n\nAll the other callers to do_slab_free appear to be ok.\n\nAdd a kfence_free check in __kmem_cache_free_bulk to avoid the crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json b/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json index 9d86de9a891..a4413cb0935 100644 --- a/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json +++ b/advisories/unreviewed/2024/09/GHSA-qh7m-p5jw-2wvg/GHSA-qh7m-p5jw-2wvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh7m-p5jw-2wvg", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T15:30:47Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44975" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: fix panic caused by partcmd_update\n\nWe find a bug as below:\nBUG: unable to handle page fault for address: 00000003\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 358 Comm: bash Tainted: G W I 6.6.0-10893-g60d6\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/4\nRIP: 0010:partition_sched_domains_locked+0x483/0x600\nCode: 01 48 85 d2 74 0d 48 83 05 29 3f f8 03 01 f3 48 0f bc c2 89 c0 48 9\nRSP: 0018:ffffc90000fdbc58 EFLAGS: 00000202\nRAX: 0000000100000003 RBX: ffff888100b3dfa0 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000002fe80\nRBP: ffff888100b3dfb0 R08: 0000000000000001 R09: 0000000000000000\nR10: ffffc90000fdbcb0 R11: 0000000000000004 R12: 0000000000000002\nR13: ffff888100a92b48 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f44a5425740(0000) GS:ffff888237d80000(0000) knlGS:0000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000100030973 CR3: 000000010722c000 CR4: 00000000000006e0\nCall Trace:\n \n ? show_regs+0x8c/0xa0\n ? __die_body+0x23/0xa0\n ? __die+0x3a/0x50\n ? page_fault_oops+0x1d2/0x5c0\n ? partition_sched_domains_locked+0x483/0x600\n ? search_module_extables+0x2a/0xb0\n ? search_exception_tables+0x67/0x90\n ? kernelmode_fixup_or_oops+0x144/0x1b0\n ? __bad_area_nosemaphore+0x211/0x360\n ? up_read+0x3b/0x50\n ? bad_area_nosemaphore+0x1a/0x30\n ? exc_page_fault+0x890/0xd90\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? __lock_acquire.constprop.0+0x24f/0x8d0\n ? asm_exc_page_fault+0x26/0x30\n ? partition_sched_domains_locked+0x483/0x600\n ? partition_sched_domains_locked+0xf0/0x600\n rebuild_sched_domains_locked+0x806/0xdc0\n update_partition_sd_lb+0x118/0x130\n cpuset_write_resmask+0xffc/0x1420\n cgroup_file_write+0xb2/0x290\n kernfs_fop_write_iter+0x194/0x290\n new_sync_write+0xeb/0x160\n vfs_write+0x16f/0x1d0\n ksys_write+0x81/0x180\n __x64_sys_write+0x21/0x30\n x64_sys_call+0x2f25/0x4630\n do_syscall_64+0x44/0xb0\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\nRIP: 0033:0x7f44a553c887\n\nIt can be reproduced with cammands:\ncd /sys/fs/cgroup/\nmkdir test\ncd test/\necho +cpuset > ../cgroup.subtree_control\necho root > cpuset.cpus.partition\ncat /sys/fs/cgroup/cpuset.cpus.effective\n0-3\necho 0-3 > cpuset.cpus // taking away all cpus from root\n\nThis issue is caused by the incorrect rebuilding of scheduling domains.\nIn this scenario, test/cpuset.cpus.partition should be an invalid root\nand should not trigger the rebuilding of scheduling domains. When calling\nupdate_parent_effective_cpumask with partcmd_update, if newmask is not\nnull, it should recheck newmask whether there are cpus is available\nfor parect/cs that has tasks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3qhf-rfv2-rc83/GHSA-3qhf-rfv2-rc83.json b/advisories/unreviewed/2024/10/GHSA-3qhf-rfv2-rc83/GHSA-3qhf-rfv2-rc83.json new file mode 100644 index 00000000000..a856e1912e0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3qhf-rfv2-rc83/GHSA-3qhf-rfv2-rc83.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qhf-rfv2-rc83", + "modified": "2024-10-03T15:30:50Z", + "published": "2024-10-03T15:30:50Z", + "aliases": [ + "CVE-2024-9100" + ], + "details": "Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9100" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/analytics-plus/CVE-2024-9100.html" + }, + { + "type": "WEB", + "url": "https://www.zoho.com/analytics/onpremise/CVE-2024-9100.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ccfh-v7cp-3943/GHSA-ccfh-v7cp-3943.json b/advisories/unreviewed/2024/10/GHSA-ccfh-v7cp-3943/GHSA-ccfh-v7cp-3943.json new file mode 100644 index 00000000000..0a019a343db --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ccfh-v7cp-3943/GHSA-ccfh-v7cp-3943.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccfh-v7cp-3943", + "modified": "2024-10-03T15:30:50Z", + "published": "2024-10-03T15:30:50Z", + "aliases": [ + "CVE-2024-5803" + ], + "details": "The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5803" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json b/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json index b497f13b383..b10da0615c5 100644 --- a/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json +++ b/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-p43x-m8vx-c7fm/GHSA-p43x-m8vx-c7fm.json b/advisories/unreviewed/2024/10/GHSA-p43x-m8vx-c7fm/GHSA-p43x-m8vx-c7fm.json new file mode 100644 index 00000000000..435cc62fcad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p43x-m8vx-c7fm/GHSA-p43x-m8vx-c7fm.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p43x-m8vx-c7fm", + "modified": "2024-10-03T15:30:50Z", + "published": "2024-10-03T15:30:50Z", + "aliases": [ + "CVE-2024-9460" + ], + "details": "A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9460" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.417052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T15:15:15Z" + } +} \ No newline at end of file