Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-09 21:32:04 +00:00
parent 473e3532dc
commit e4eadd119e
53 changed files with 1289 additions and 72 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8fg4-j562-mjrc",
"modified": "2024-03-06T22:13:38Z",
"modified": "2024-09-09T21:31:26Z",
"published": "2019-01-25T16:19:01Z",
"aliases": [
"CVE-2017-15720"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
@@ -59,6 +63,10 @@
"type": "PACKAGE",
"url": "https://github.com/apache/airflow"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2019-147.yaml"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/ade4d54ebf614f68dc81a08891755e60ea58ba88e0209233eeea5f57@%3Cdev.airflow.apache.org%3E"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp9j-rghq-8jhh",
"modified": "2021-04-05T13:49:09Z",
"modified": "2024-09-09T21:30:38Z",
"published": "2022-02-09T21:59:42Z",
"aliases": [
"CVE-2020-10744"
@@ -12,9 +12,32 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "ansible"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.10.0a1"
},
{
"fixed": "2.10.0rc1"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
@@ -28,7 +51,7 @@
"introduced": "0"
},
{
"last_affected": "2.9.9"
"fixed": "2.9.12"
}
]
}
@@ -40,9 +63,37 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10744"
},
{
"type": "WEB",
"url": "https://github.com/ansible/ansible/issues/69782"
},
{
"type": "WEB",
"url": "https://github.com/ansible/ansible/commit/77d0effcc5b2da1ef23e4ba32986a9759c27c10d"
},
{
"type": "WEB",
"url": "https://github.com/ansible/ansible/commit/84afa8e90cd168ff13208c8eae3e533ce7e21e1f"
},
{
"type": "WEB",
"url": "https://github.com/ansible/ansible/commit/ffd3757fc35468a97791e452e7f2d14c3e3fcb80"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10744"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-vp9j-rghq-8jhh"
},
{
"type": "PACKAGE",
"url": "https://github.com/ansible/ansible"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-208.yaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmrm-8fx4-66x7",
"modified": "2024-06-21T15:52:29Z",
"modified": "2024-09-09T21:31:22Z",
"published": "2024-06-18T12:30:42Z",
"withdrawn": "2024-06-21T15:51:43Z",
"aliases": [
@@ -41,6 +41,34 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5967"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6493"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6494"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6495"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6497"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6499"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6500"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6501"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-5967"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wm9-24qg-m5qj",
"modified": "2024-09-03T21:57:40Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2024-09-03T21:31:12Z",
"aliases": [
"CVE-2024-4629"
@@ -47,6 +47,34 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4629"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6493"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6494"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6495"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6497"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6499"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6500"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6501"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4629"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92m3-4hrq-4449",
"modified": "2023-11-08T00:30:20Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2023-10-31T00:30:59Z",
"aliases": [
"CVE-2022-39172"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jrv-g44v-qxwj",
"modified": "2023-12-29T06:30:29Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2023-12-29T06:30:29Z",
"aliases": [
"CVE-2023-51429"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q565-26vc-vpx8",
"modified": "2024-01-04T00:30:19Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2023-12-25T09:30:21Z",
"aliases": [
"CVE-2022-34268"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjxw-62pr-vrfg",
"modified": "2024-01-03T21:30:31Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2023-51772"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x4h-m49h-pxr3",
"modified": "2024-09-09T21:31:22Z",
"published": "2024-09-09T21:31:22Z",
"aliases": [
"CVE-2024-24510"
],
"details": "Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24510"
},
{
"type": "WEB",
"url": "https://github.com/Alinto/sogo/commit/21468700718ed71774eaf2979ee59330fc569424"
},
{
"type": "WEB",
"url": "https://book.hacktricks.xyz/pentesting-web/xs-search/css-injection"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T19:15:13Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54cp-27ww-4fm3",
"modified": "2024-09-09T21:31:23Z",
"published": "2024-09-09T21:31:23Z",
"aliases": [
"CVE-2024-44085"
],
"details": "ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44085"
},
{
"type": "WEB",
"url": "https://www.onlyoffice.com"
},
{
"type": "WEB",
"url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.txt"
},
{
"type": "WEB",
"url": "https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyoffice-docs-syss-2023-027"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T20:15:04Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57rh-gr4v-j5f6",
"modified": "2024-09-09T21:31:22Z",
"published": "2024-09-09T21:31:22Z",
"aliases": [
"CVE-2024-7318"
],
"details": "A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute.\nA one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7318"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6503"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-7318"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301876"
}
],
"database_specific": {
"cwe_ids": [
"CWE-324"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T19:15:14Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jxg-jmvx-5hw9",
"modified": "2024-09-09T21:31:23Z",
"published": "2024-09-09T21:31:23Z",
"aliases": [
"CVE-2024-42500"
],
"details": "HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42500"
},
{
"type": "WEB",
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbux04697en_us&docLocale=en_US"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T20:15:04Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xmf-5w3g-qm87",
"modified": "2024-09-06T18:31:31Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2024-09-06T18:31:31Z",
"aliases": [
"CVE-2024-8509"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8509"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6487"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-8509"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-726x-rvqx-m6j6",
"modified": "2024-09-09T18:30:31Z",
"modified": "2024-09-09T21:31:22Z",
"published": "2024-09-09T18:30:31Z",
"aliases": [
"CVE-2024-44335"
],
"details": "D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T18:15:03Z"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-83xf-jp6f-5ghc",
"modified": "2024-09-09T21:31:23Z",
"published": "2024-09-09T21:31:23Z",
"aliases": [
"CVE-2024-8610"
],
"details": "A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8610"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1mB2ZNyWJDqJaZZro4qiMqovRO_qo4pss/view?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.276840"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.276840"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.404867"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T21:15:13Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92qf-v5hc-8737",
"modified": "2024-09-09T18:30:31Z",
"modified": "2024-09-09T21:31:22Z",
"published": "2024-09-09T18:30:31Z",
"aliases": [
"CVE-2024-44334"
],
"details": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-09T18:15:03Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ccp-4gjg-264g",
"modified": "2024-09-07T18:30:23Z",
"modified": "2024-09-09T21:31:21Z",
"published": "2024-09-07T18:30:23Z",
"aliases": [
"CVE-2023-30583"
],
"details": "fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-07T16:15:02Z"

Some files were not shown because too many files have changed in this diff Show More