diff --git a/advisories/github-reviewed/2019/01/GHSA-8fg4-j562-mjrc/GHSA-8fg4-j562-mjrc.json b/advisories/github-reviewed/2019/01/GHSA-8fg4-j562-mjrc/GHSA-8fg4-j562-mjrc.json index 4390b227577..e94cdb3b9ea 100644 --- a/advisories/github-reviewed/2019/01/GHSA-8fg4-j562-mjrc/GHSA-8fg4-j562-mjrc.json +++ b/advisories/github-reviewed/2019/01/GHSA-8fg4-j562-mjrc/GHSA-8fg4-j562-mjrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8fg4-j562-mjrc", - "modified": "2024-03-06T22:13:38Z", + "modified": "2024-09-09T21:31:26Z", "published": "2019-01-25T16:19:01Z", "aliases": [ "CVE-2017-15720" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -59,6 +63,10 @@ "type": "PACKAGE", "url": "https://github.com/apache/airflow" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2019-147.yaml" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/ade4d54ebf614f68dc81a08891755e60ea58ba88e0209233eeea5f57@%3Cdev.airflow.apache.org%3E" diff --git a/advisories/github-reviewed/2022/02/GHSA-vp9j-rghq-8jhh/GHSA-vp9j-rghq-8jhh.json b/advisories/github-reviewed/2022/02/GHSA-vp9j-rghq-8jhh/GHSA-vp9j-rghq-8jhh.json index fa11a281536..dba225084ac 100644 --- a/advisories/github-reviewed/2022/02/GHSA-vp9j-rghq-8jhh/GHSA-vp9j-rghq-8jhh.json +++ b/advisories/github-reviewed/2022/02/GHSA-vp9j-rghq-8jhh/GHSA-vp9j-rghq-8jhh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vp9j-rghq-8jhh", - "modified": "2021-04-05T13:49:09Z", + "modified": "2024-09-09T21:30:38Z", "published": "2022-02-09T21:59:42Z", "aliases": [ "CVE-2020-10744" @@ -12,9 +12,32 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L" } ], "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "ansible" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.10.0a1" + }, + { + "fixed": "2.10.0rc1" + } + ] + } + ] + }, { "package": { "ecosystem": "PyPI", @@ -28,7 +51,7 @@ "introduced": "0" }, { - "last_affected": "2.9.9" + "fixed": "2.9.12" } ] } @@ -40,9 +63,37 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10744" }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/issues/69782" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/77d0effcc5b2da1ef23e4ba32986a9759c27c10d" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/84afa8e90cd168ff13208c8eae3e533ce7e21e1f" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/ffd3757fc35468a97791e452e7f2d14c3e3fcb80" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10744" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-vp9j-rghq-8jhh" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ansible/ansible" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-208.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/06/GHSA-gmrm-8fx4-66x7/GHSA-gmrm-8fx4-66x7.json b/advisories/github-reviewed/2024/06/GHSA-gmrm-8fx4-66x7/GHSA-gmrm-8fx4-66x7.json index 88e6046c794..90e9b8c0437 100644 --- a/advisories/github-reviewed/2024/06/GHSA-gmrm-8fx4-66x7/GHSA-gmrm-8fx4-66x7.json +++ b/advisories/github-reviewed/2024/06/GHSA-gmrm-8fx4-66x7/GHSA-gmrm-8fx4-66x7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmrm-8fx4-66x7", - "modified": "2024-06-21T15:52:29Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-06-18T12:30:42Z", "withdrawn": "2024-06-21T15:51:43Z", "aliases": [ @@ -41,6 +41,34 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5967" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6493" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6494" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6495" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6497" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6499" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6500" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6501" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5967" diff --git a/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json b/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json index 0dc8138471a..6913e69a721 100644 --- a/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json +++ b/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wm9-24qg-m5qj", - "modified": "2024-09-03T21:57:40Z", + "modified": "2024-09-09T21:31:21Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-4629" @@ -47,6 +47,34 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4629" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6493" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6494" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6495" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6497" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6499" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6500" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6501" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4629" diff --git a/advisories/unreviewed/2023/10/GHSA-6g6h-7v62-4x32/GHSA-6g6h-7v62-4x32.json b/advisories/unreviewed/2023/10/GHSA-6g6h-7v62-4x32/GHSA-6g6h-7v62-4x32.json index 741eab83d2e..a874e4827c7 100644 --- a/advisories/unreviewed/2023/10/GHSA-6g6h-7v62-4x32/GHSA-6g6h-7v62-4x32.json +++ b/advisories/unreviewed/2023/10/GHSA-6g6h-7v62-4x32/GHSA-6g6h-7v62-4x32.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-92m3-4hrq-4449/GHSA-92m3-4hrq-4449.json b/advisories/unreviewed/2023/10/GHSA-92m3-4hrq-4449/GHSA-92m3-4hrq-4449.json index 5b7547a11cd..19a3c167603 100644 --- a/advisories/unreviewed/2023/10/GHSA-92m3-4hrq-4449/GHSA-92m3-4hrq-4449.json +++ b/advisories/unreviewed/2023/10/GHSA-92m3-4hrq-4449/GHSA-92m3-4hrq-4449.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92m3-4hrq-4449", - "modified": "2023-11-08T00:30:20Z", + "modified": "2024-09-09T21:31:21Z", "published": "2023-10-31T00:30:59Z", "aliases": [ "CVE-2022-39172" diff --git a/advisories/unreviewed/2023/10/GHSA-w3x6-r727-hr8f/GHSA-w3x6-r727-hr8f.json b/advisories/unreviewed/2023/10/GHSA-w3x6-r727-hr8f/GHSA-w3x6-r727-hr8f.json index 0f459a5e050..e1cbd5f44e1 100644 --- a/advisories/unreviewed/2023/10/GHSA-w3x6-r727-hr8f/GHSA-w3x6-r727-hr8f.json +++ b/advisories/unreviewed/2023/10/GHSA-w3x6-r727-hr8f/GHSA-w3x6-r727-hr8f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-2347-6p44-pr5m/GHSA-2347-6p44-pr5m.json b/advisories/unreviewed/2023/12/GHSA-2347-6p44-pr5m/GHSA-2347-6p44-pr5m.json index ae059644226..6d0fff9de05 100644 --- a/advisories/unreviewed/2023/12/GHSA-2347-6p44-pr5m/GHSA-2347-6p44-pr5m.json +++ b/advisories/unreviewed/2023/12/GHSA-2347-6p44-pr5m/GHSA-2347-6p44-pr5m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json b/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json index 92d35919faa..0e62c1b4569 100644 --- a/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json +++ b/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jrv-g44v-qxwj", - "modified": "2023-12-29T06:30:29Z", + "modified": "2024-09-09T21:31:21Z", "published": "2023-12-29T06:30:29Z", "aliases": [ "CVE-2023-51429" diff --git a/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json b/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json index cdfeb6ffc0f..5ae3915758c 100644 --- a/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json +++ b/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q565-26vc-vpx8", - "modified": "2024-01-04T00:30:19Z", + "modified": "2024-09-09T21:31:21Z", "published": "2023-12-25T09:30:21Z", "aliases": [ "CVE-2022-34268" diff --git a/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json index 53983778738..80dedc179af 100644 --- a/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json +++ b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vjxw-62pr-vrfg", - "modified": "2024-01-03T21:30:31Z", + "modified": "2024-09-09T21:31:21Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2023-51772" diff --git a/advisories/unreviewed/2024/09/GHSA-3x4h-m49h-pxr3/GHSA-3x4h-m49h-pxr3.json b/advisories/unreviewed/2024/09/GHSA-3x4h-m49h-pxr3/GHSA-3x4h-m49h-pxr3.json new file mode 100644 index 00000000000..8999defc46b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3x4h-m49h-pxr3/GHSA-3x4h-m49h-pxr3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x4h-m49h-pxr3", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-24510" + ], + "details": "Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24510" + }, + { + "type": "WEB", + "url": "https://github.com/Alinto/sogo/commit/21468700718ed71774eaf2979ee59330fc569424" + }, + { + "type": "WEB", + "url": "https://book.hacktricks.xyz/pentesting-web/xs-search/css-injection" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json new file mode 100644 index 00000000000..c67917a8f33 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54cp-27ww-4fm3", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44085" + ], + "details": "ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44085" + }, + { + "type": "WEB", + "url": "https://www.onlyoffice.com" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyoffice-docs-syss-2023-027" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-57rh-gr4v-j5f6/GHSA-57rh-gr4v-j5f6.json b/advisories/unreviewed/2024/09/GHSA-57rh-gr4v-j5f6/GHSA-57rh-gr4v-j5f6.json new file mode 100644 index 00000000000..76dbd23a075 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-57rh-gr4v-j5f6/GHSA-57rh-gr4v-j5f6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57rh-gr4v-j5f6", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-7318" + ], + "details": "A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute.\nA one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7318" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6503" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7318" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301876" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-324" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5jxg-jmvx-5hw9/GHSA-5jxg-jmvx-5hw9.json b/advisories/unreviewed/2024/09/GHSA-5jxg-jmvx-5hw9/GHSA-5jxg-jmvx-5hw9.json new file mode 100644 index 00000000000..74621a80fd9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5jxg-jmvx-5hw9/GHSA-5jxg-jmvx-5hw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jxg-jmvx-5hw9", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-42500" + ], + "details": "HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42500" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbux04697en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5xmf-5w3g-qm87/GHSA-5xmf-5w3g-qm87.json b/advisories/unreviewed/2024/09/GHSA-5xmf-5w3g-qm87/GHSA-5xmf-5w3g-qm87.json index 2a0bc6da18d..a025d11632d 100644 --- a/advisories/unreviewed/2024/09/GHSA-5xmf-5w3g-qm87/GHSA-5xmf-5w3g-qm87.json +++ b/advisories/unreviewed/2024/09/GHSA-5xmf-5w3g-qm87/GHSA-5xmf-5w3g-qm87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xmf-5w3g-qm87", - "modified": "2024-09-06T18:31:31Z", + "modified": "2024-09-09T21:31:21Z", "published": "2024-09-06T18:31:31Z", "aliases": [ "CVE-2024-8509" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8509" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6487" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8509" diff --git a/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json b/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json index 43db20ab51d..b7a4bf3cc49 100644 --- a/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json +++ b/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-726x-rvqx-m6j6", - "modified": "2024-09-09T18:30:31Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-09T18:30:31Z", "aliases": [ "CVE-2024-44335" ], "details": "D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-83xf-jp6f-5ghc/GHSA-83xf-jp6f-5ghc.json b/advisories/unreviewed/2024/09/GHSA-83xf-jp6f-5ghc/GHSA-83xf-jp6f-5ghc.json new file mode 100644 index 00000000000..c4a5fe2cb57 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-83xf-jp6f-5ghc/GHSA-83xf-jp6f-5ghc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83xf-jp6f-5ghc", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-8610" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8610" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1mB2ZNyWJDqJaZZro4qiMqovRO_qo4pss/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276840" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276840" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.404867" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json b/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json index 40cc169e4eb..3a7a4f8d4f3 100644 --- a/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json +++ b/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92qf-v5hc-8737", - "modified": "2024-09-09T18:30:31Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-09T18:30:31Z", "aliases": [ "CVE-2024-44334" ], "details": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9ccp-4gjg-264g/GHSA-9ccp-4gjg-264g.json b/advisories/unreviewed/2024/09/GHSA-9ccp-4gjg-264g/GHSA-9ccp-4gjg-264g.json index 38ef1ff90fa..6edcef4cd13 100644 --- a/advisories/unreviewed/2024/09/GHSA-9ccp-4gjg-264g/GHSA-9ccp-4gjg-264g.json +++ b/advisories/unreviewed/2024/09/GHSA-9ccp-4gjg-264g/GHSA-9ccp-4gjg-264g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9ccp-4gjg-264g", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:21Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-30583" ], "details": "fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json b/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json new file mode 100644 index 00000000000..404bbc74360 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mq4-v89w-jpc7", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-6795" + ], + "details": "In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. \n\nAn attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content \n\nand/or perform administrative operations including shutting down the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6795" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9w8j-43xw-xc7m/GHSA-9w8j-43xw-xc7m.json b/advisories/unreviewed/2024/09/GHSA-9w8j-43xw-xc7m/GHSA-9w8j-43xw-xc7m.json index ccd5ba78e5d..b7fcd507e62 100644 --- a/advisories/unreviewed/2024/09/GHSA-9w8j-43xw-xc7m/GHSA-9w8j-43xw-xc7m.json +++ b/advisories/unreviewed/2024/09/GHSA-9w8j-43xw-xc7m/GHSA-9w8j-43xw-xc7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w8j-43xw-xc7m", - "modified": "2024-09-08T06:30:32Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:32Z", "aliases": [ "CVE-2024-6853" ], "details": "The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json new file mode 100644 index 00000000000..3a6c70f6d48 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4p9-95wg-q39w", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44411" + ], + "details": "D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44411" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DI-8300A1/CVE-2024-44411" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DI-8300A1/DI-8300A1-2.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c595-v5xp-gv8w/GHSA-c595-v5xp-gv8w.json b/advisories/unreviewed/2024/09/GHSA-c595-v5xp-gv8w/GHSA-c595-v5xp-gv8w.json index 060bdce97a1..f7519f041cc 100644 --- a/advisories/unreviewed/2024/09/GHSA-c595-v5xp-gv8w/GHSA-c595-v5xp-gv8w.json +++ b/advisories/unreviewed/2024/09/GHSA-c595-v5xp-gv8w/GHSA-c595-v5xp-gv8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c595-v5xp-gv8w", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-30587" ], "details": "A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector).\n\nBy exploiting the Worker class's ability to create an \"internal worker\" with the kIsInternal Symbol, attackers can modify the isInternal value when an inspector is attached within the Worker constructor before initializing a new WorkerImpl. This vulnerability exclusively affects Node.js users employing the permission model mechanism.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json new file mode 100644 index 00000000000..23c31370495 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6f5-vg46-h8r2", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44410" + ], + "details": "D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44410" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DI-8300A1/CVE-2024-44410" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DI-8300A1/DI-8300A1.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwrj-j635-2m7w/GHSA-cwrj-j635-2m7w.json b/advisories/unreviewed/2024/09/GHSA-cwrj-j635-2m7w/GHSA-cwrj-j635-2m7w.json index f234b4df286..60d97ffa01d 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwrj-j635-2m7w/GHSA-cwrj-j635-2m7w.json +++ b/advisories/unreviewed/2024/09/GHSA-cwrj-j635-2m7w/GHSA-cwrj-j635-2m7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwrj-j635-2m7w", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:21Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-30582" ], "details": "A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the fs.watchFile API. As a result, malicious actors can monitor files that they do not have explicit read access to.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json b/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json new file mode 100644 index 00000000000..bf42f606be0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx4g-pmv3-xm3p", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-27365" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_blockack_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27365" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27365" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cxj4-jr7v-6ccc/GHSA-cxj4-jr7v-6ccc.json b/advisories/unreviewed/2024/09/GHSA-cxj4-jr7v-6ccc/GHSA-cxj4-jr7v-6ccc.json new file mode 100644 index 00000000000..b45d889e24f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cxj4-jr7v-6ccc/GHSA-cxj4-jr7v-6ccc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxj4-jr7v-6ccc", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-8611" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8611" + }, + { + "type": "WEB", + "url": "https://github.com/elegant228/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276841" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276841" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.404875" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f4wh-359g-4pq7/GHSA-f4wh-359g-4pq7.json b/advisories/unreviewed/2024/09/GHSA-f4wh-359g-4pq7/GHSA-f4wh-359g-4pq7.json new file mode 100644 index 00000000000..c054a7388ab --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f4wh-359g-4pq7/GHSA-f4wh-359g-4pq7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4wh-359g-4pq7", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44902" + ], + "details": "A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44902" + }, + { + "type": "WEB", + "url": "https://github.com/fru1ts/CVE-2024-44902" + }, + { + "type": "WEB", + "url": "http://thinkphp.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json b/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json new file mode 100644 index 00000000000..02b05a4a344 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj8w-h44c-988h", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27368" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_received_frame_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27368" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json b/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json new file mode 100644 index 00000000000..18dc08b1cc0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpv4-p5w2-xgfg", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27383" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check on default_ies coming from userspace, which can lead to a heap overwrite.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27383" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g4gc-rh26-m3p5/GHSA-g4gc-rh26-m3p5.json b/advisories/unreviewed/2024/09/GHSA-g4gc-rh26-m3p5/GHSA-g4gc-rh26-m3p5.json new file mode 100644 index 00000000000..a1796c032b9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g4gc-rh26-m3p5/GHSA-g4gc-rh26-m3p5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4gc-rh26-m3p5", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-7260" + ], + "details": "An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it redirects to a malicious server. This issue can result in a victim inadvertently trusting the destination of the redirect, potentially leading to a successful phishing attack or other types of attacks.\n\nOnce a crafted URL is made, it can be sent to a Keycloak admin via email for example. This will trigger this vulnerability when the user visits the page and clicks the link. A malicious actor can use this to target users they know are Keycloak admins for further attacks. It may also be possible to bypass other domain-related security checks, such as supplying this as a OAuth redirect uri. The malicious actor can further obfuscate the redirect_uri using URL encoding, to hide the text of the actual malicious website domain.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7260" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6503" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7260" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301875" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g957-78r7-x4w5/GHSA-g957-78r7-x4w5.json b/advisories/unreviewed/2024/09/GHSA-g957-78r7-x4w5/GHSA-g957-78r7-x4w5.json new file mode 100644 index 00000000000..acdb2ff22a3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g957-78r7-x4w5/GHSA-g957-78r7-x4w5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g957-78r7-x4w5", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44724" + ], + "details": "AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44724" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json b/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json new file mode 100644 index 00000000000..bd915e2fca8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2g3-9wm9-c3jc", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27387" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27387" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27387" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j76j-rqwj-jmvv/GHSA-j76j-rqwj-jmvv.json b/advisories/unreviewed/2024/09/GHSA-j76j-rqwj-jmvv/GHSA-j76j-rqwj-jmvv.json new file mode 100644 index 00000000000..d1f6b20b47a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j76j-rqwj-jmvv/GHSA-j76j-rqwj-jmvv.json @@ -0,0 +1,78 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j76j-rqwj-jmvv", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-7341" + ], + "details": "A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7341" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6493" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6494" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6495" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6497" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6499" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6500" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6501" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6503" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7341" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2302064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jpgc-8hrm-hvwj/GHSA-jpgc-8hrm-hvwj.json b/advisories/unreviewed/2024/09/GHSA-jpgc-8hrm-hvwj/GHSA-jpgc-8hrm-hvwj.json index 7a7235433e1..e39f78a3d61 100644 --- a/advisories/unreviewed/2024/09/GHSA-jpgc-8hrm-hvwj/GHSA-jpgc-8hrm-hvwj.json +++ b/advisories/unreviewed/2024/09/GHSA-jpgc-8hrm-hvwj/GHSA-jpgc-8hrm-hvwj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jpgc-8hrm-hvwj", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-30584" ], "details": "A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file permissions.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mf53-vhfr-cjjw/GHSA-mf53-vhfr-cjjw.json b/advisories/unreviewed/2024/09/GHSA-mf53-vhfr-cjjw/GHSA-mf53-vhfr-cjjw.json index 3fc335085e3..a1eefc6655c 100644 --- a/advisories/unreviewed/2024/09/GHSA-mf53-vhfr-cjjw/GHSA-mf53-vhfr-cjjw.json +++ b/advisories/unreviewed/2024/09/GHSA-mf53-vhfr-cjjw/GHSA-mf53-vhfr-cjjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf53-vhfr-cjjw", - "modified": "2024-09-08T06:30:33Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:33Z", "aliases": [ "CVE-2024-6859" ], "details": "The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json b/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json index 3afa34c3361..466aa330e7c 100644 --- a/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json +++ b/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmmq-786f-84xq", - "modified": "2024-09-09T18:30:30Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-09T18:30:30Z", "aliases": [ "CVE-2024-44721" ], "details": "SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json b/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json new file mode 100644 index 00000000000..dd05fe1a7be --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmr8-xr7x-rrxw", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27366" + ], + "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_done_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27366" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27366" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json b/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json new file mode 100644 index 00000000000..2ae8429e228 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxf9-pg49-g3hg", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27364" + ], + "details": "An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_roamed_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27364" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27364" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p2ww-p57h-w5m7/GHSA-p2ww-p57h-w5m7.json b/advisories/unreviewed/2024/09/GHSA-p2ww-p57h-w5m7/GHSA-p2ww-p57h-w5m7.json index fe808fad8e4..f1ff2f264f4 100644 --- a/advisories/unreviewed/2024/09/GHSA-p2ww-p57h-w5m7/GHSA-p2ww-p57h-w5m7.json +++ b/advisories/unreviewed/2024/09/GHSA-p2ww-p57h-w5m7/GHSA-p2ww-p57h-w5m7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-p726-6587-94ph/GHSA-p726-6587-94ph.json b/advisories/unreviewed/2024/09/GHSA-p726-6587-94ph/GHSA-p726-6587-94ph.json index 0930dc08347..767c9a43e82 100644 --- a/advisories/unreviewed/2024/09/GHSA-p726-6587-94ph/GHSA-p726-6587-94ph.json +++ b/advisories/unreviewed/2024/09/GHSA-p726-6587-94ph/GHSA-p726-6587-94ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p726-6587-94ph", - "modified": "2024-09-08T06:30:33Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:33Z", "aliases": [ "CVE-2024-6856" ], "details": "The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json b/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json index 0fa5cc4604d..994f820bea3 100644 --- a/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json +++ b/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phhc-p9jg-cvj3", - "modified": "2024-09-09T18:30:31Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-09T18:30:31Z", "aliases": [ "CVE-2024-44849" ], "details": "Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T18:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q77r-qvf6-47wr/GHSA-q77r-qvf6-47wr.json b/advisories/unreviewed/2024/09/GHSA-q77r-qvf6-47wr/GHSA-q77r-qvf6-47wr.json new file mode 100644 index 00000000000..9bd0e1958ac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q77r-qvf6-47wr/GHSA-q77r-qvf6-47wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q77r-qvf6-47wr", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-6796" + ], + "details": "In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6796" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q7wh-m245-cv47/GHSA-q7wh-m245-cv47.json b/advisories/unreviewed/2024/09/GHSA-q7wh-m245-cv47/GHSA-q7wh-m245-cv47.json index c96499dbe99..e9f1475a479 100644 --- a/advisories/unreviewed/2024/09/GHSA-q7wh-m245-cv47/GHSA-q7wh-m245-cv47.json +++ b/advisories/unreviewed/2024/09/GHSA-q7wh-m245-cv47/GHSA-q7wh-m245-cv47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7wh-m245-cv47", - "modified": "2024-09-08T06:30:32Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:32Z", "aliases": [ "CVE-2024-6852" ], "details": "The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json b/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json new file mode 100644 index 00000000000..bd0dbf5f32d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcqr-8g6q-fmc3", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2023-50883" + ], + "details": "ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50883" + }, + { + "type": "WEB", + "url": "https://www.onlyoffice.com" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-027.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/cross-site-scripting-schwachstelle-in-onlyoffice-docs-syss-2023-027" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rpgh-j58g-qrc4/GHSA-rpgh-j58g-qrc4.json b/advisories/unreviewed/2024/09/GHSA-rpgh-j58g-qrc4/GHSA-rpgh-j58g-qrc4.json new file mode 100644 index 00000000000..a7c24523061 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rpgh-j58g-qrc4/GHSA-rpgh-j58g-qrc4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpgh-j58g-qrc4", + "modified": "2024-09-09T21:31:23Z", + "published": "2024-09-09T21:31:23Z", + "aliases": [ + "CVE-2024-44725" + ], + "details": "AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44725" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/69" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vqjc-v52h-6f2g/GHSA-vqjc-v52h-6f2g.json b/advisories/unreviewed/2024/09/GHSA-vqjc-v52h-6f2g/GHSA-vqjc-v52h-6f2g.json index 81c1a341af8..0b3dfaf3c98 100644 --- a/advisories/unreviewed/2024/09/GHSA-vqjc-v52h-6f2g/GHSA-vqjc-v52h-6f2g.json +++ b/advisories/unreviewed/2024/09/GHSA-vqjc-v52h-6f2g/GHSA-vqjc-v52h-6f2g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqjc-v52h-6f2g", - "modified": "2024-09-08T06:30:32Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:32Z", "aliases": [ "CVE-2024-6855" ], "details": "The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json new file mode 100644 index 00000000000..1252127bc6c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw78-5596-vx6r", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-42759" + ], + "details": "An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42759" + }, + { + "type": "WEB", + "url": "https://csflabs.github.io/cve/2024/09/06/cve-2024-42759-approval-of-your-own-ticket-with-BFLA.html" + }, + { + "type": "WEB", + "url": "https://ellevo.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wj24-gwh6-mgh8/GHSA-wj24-gwh6-mgh8.json b/advisories/unreviewed/2024/09/GHSA-wj24-gwh6-mgh8/GHSA-wj24-gwh6-mgh8.json index 5c8c1ddef1f..a2cccb777de 100644 --- a/advisories/unreviewed/2024/09/GHSA-wj24-gwh6-mgh8/GHSA-wj24-gwh6-mgh8.json +++ b/advisories/unreviewed/2024/09/GHSA-wj24-gwh6-mgh8/GHSA-wj24-gwh6-mgh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wj24-gwh6-mgh8", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-39333" ], "details": "Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module.\n\nThis vulnerability affects users of any active release line of Node.js. The vulnerable feature is only available if Node.js is started with the `--experimental-wasm-modules` command line option.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json b/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json new file mode 100644 index 00000000000..f2a57564a2a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6fj-x43r-fcg6", + "modified": "2024-09-09T21:31:22Z", + "published": "2024-09-09T21:31:22Z", + "aliases": [ + "CVE-2024-27367" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_ind(), there is no input validation check on a length coming from userspace, which can lead to integer overflow and a potential heap over-read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27367" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27367" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xfgw-qcmv-354j/GHSA-xfgw-qcmv-354j.json b/advisories/unreviewed/2024/09/GHSA-xfgw-qcmv-354j/GHSA-xfgw-qcmv-354j.json index a705bb973d9..d267167f995 100644 --- a/advisories/unreviewed/2024/09/GHSA-xfgw-qcmv-354j/GHSA-xfgw-qcmv-354j.json +++ b/advisories/unreviewed/2024/09/GHSA-xfgw-qcmv-354j/GHSA-xfgw-qcmv-354j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfgw-qcmv-354j", - "modified": "2024-09-07T18:30:23Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-07T18:30:23Z", "aliases": [ "CVE-2023-46809" ], "details": "Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-385" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-07T16:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xwhw-83c9-38cf/GHSA-xwhw-83c9-38cf.json b/advisories/unreviewed/2024/09/GHSA-xwhw-83c9-38cf/GHSA-xwhw-83c9-38cf.json index d2cb980328f..5cb9189fd8c 100644 --- a/advisories/unreviewed/2024/09/GHSA-xwhw-83c9-38cf/GHSA-xwhw-83c9-38cf.json +++ b/advisories/unreviewed/2024/09/GHSA-xwhw-83c9-38cf/GHSA-xwhw-83c9-38cf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwhw-83c9-38cf", - "modified": "2024-09-08T06:30:33Z", + "modified": "2024-09-09T21:31:22Z", "published": "2024-09-08T06:30:33Z", "aliases": [ "CVE-2024-6924" ], "details": "The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z"