From e53dcc849904b2a2c3137b1550dad79979e0e49e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 14 Mar 2024 21:31:44 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-53v4-42fg-g287.json | 14 +++++- .../GHSA-4gm2-r6xm-jqxh.json | 2 +- .../GHSA-5wvr-c5h8-vf7f.json | 2 +- .../GHSA-6rxj-38xv-j69g.json | 6 ++- .../GHSA-9vwf-r222-fcvc.json | 2 +- .../GHSA-gg87-xrj2-3r8m.json | 2 +- .../GHSA-gpq7-5wgv-cqmg.json | 2 +- .../GHSA-rf35-pm73-38q6.json | 2 +- .../GHSA-rwf8-4gv4-8fmw.json | 6 ++- .../GHSA-wc9w-8x8g-533g.json | 6 ++- .../GHSA-3hp3-h35p-gqg4.json | 11 +++-- .../GHSA-3m37-qf9f-22vv.json | 11 +++-- .../GHSA-63f3-2rgp-79qx.json | 11 +++-- .../GHSA-6f72-79f8-3qcp.json | 11 +++-- .../GHSA-84fp-h279-ggmw.json | 11 +++-- .../GHSA-wvjr-h8mr-f8gw.json | 11 +++-- .../GHSA-2qqg-5pcx-4jv3.json | 35 ++++++++++++++ .../GHSA-4rxr-8xrx-9rf3.json | 9 ++-- .../GHSA-525f-hw88-w4m8.json | 11 +++-- .../GHSA-5c5p-qh6w-cqq9.json | 9 ++-- .../GHSA-5c89-5mrj-8h62.json | 42 +++++++++++++++++ .../GHSA-6f82-qgq9-9h8f.json | 9 ++-- .../GHSA-74jf-w8p5-9492.json | 38 +++++++++++++++ .../GHSA-75qq-7gc3-2xjr.json | 11 +++-- .../GHSA-9w9w-6vpx-x9q3.json | 11 +++-- .../GHSA-chrr-r69v-42vf.json | 39 ++++++++++++++++ .../GHSA-cq6x-28cg-mph3.json | 38 +++++++++++++++ .../GHSA-f892-3gpj-v83f.json | 35 ++++++++++++++ .../GHSA-g7wq-4cvg-g624.json | 38 +++++++++++++++ .../GHSA-gqfr-84mj-fvqr.json | 35 ++++++++++++++ .../GHSA-j4hp-4mqq-mv7f.json | 46 +++++++++++++++++++ .../GHSA-j6q4-78q3-g22f.json | 9 ++-- .../GHSA-m88g-7rcv-6rcx.json | 9 ++-- .../GHSA-mp7h-h4mw-vrgf.json | 42 +++++++++++++++++ .../GHSA-qg9g-p9q2-wjvw.json | 9 ++-- .../GHSA-rfrv-rc39-gxfp.json | 42 +++++++++++++++++ .../GHSA-vgq4-3x26-93jq.json | 9 ++-- .../GHSA-xc3v-gxv5-4x7q.json | 38 +++++++++++++++ 38 files changed, 607 insertions(+), 67 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-2qqg-5pcx-4jv3/GHSA-2qqg-5pcx-4jv3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json create mode 100644 advisories/unreviewed/2024/03/GHSA-74jf-w8p5-9492/GHSA-74jf-w8p5-9492.json create mode 100644 advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cq6x-28cg-mph3/GHSA-cq6x-28cg-mph3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f892-3gpj-v83f/GHSA-f892-3gpj-v83f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g7wq-4cvg-g624/GHSA-g7wq-4cvg-g624.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gqfr-84mj-fvqr/GHSA-gqfr-84mj-fvqr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mp7h-h4mw-vrgf/GHSA-mp7h-h4mw-vrgf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rfrv-rc39-gxfp/GHSA-rfrv-rc39-gxfp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xc3v-gxv5-4x7q/GHSA-xc3v-gxv5-4x7q.json diff --git a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json index 85a0c4a1219..eb36b9a33d3 100644 --- a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json +++ b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53v4-42fg-g287", - "modified": "2024-02-16T15:30:26Z", + "modified": "2024-03-14T21:30:03Z", "published": "2023-11-28T18:30:23Z", "aliases": [ "CVE-2022-41678" @@ -63,10 +63,22 @@ "type": "WEB", "url": "https://github.com/apache/activemq/pull/958" }, + { + "type": "WEB", + "url": "https://github.com/apache/activemq/commit/5c8d457d9" + }, { "type": "WEB", "url": "https://github.com/apache/activemq/commit/6120169e563b55323352431dfe9ac67a8b4de6c2" }, + { + "type": "WEB", + "url": "https://github.com/apache/activemq/commit/bf65929fd" + }, + { + "type": "WEB", + "url": "https://github.com/apache/activemq/commit/d8ce1d9ff" + }, { "type": "WEB", "url": "https://activemq.apache.org/security-advisories.data/CVE-2022-41678-announcement.txt" diff --git a/advisories/unreviewed/2022/05/GHSA-4gm2-r6xm-jqxh/GHSA-4gm2-r6xm-jqxh.json b/advisories/unreviewed/2022/05/GHSA-4gm2-r6xm-jqxh/GHSA-4gm2-r6xm-jqxh.json index c869163253f..c165620a7ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gm2-r6xm-jqxh/GHSA-4gm2-r6xm-jqxh.json +++ b/advisories/unreviewed/2022/05/GHSA-4gm2-r6xm-jqxh/GHSA-4gm2-r6xm-jqxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gm2-r6xm-jqxh", - "modified": "2022-05-25T00:00:23Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-17T00:01:27Z", "aliases": [ "CVE-2022-1386" diff --git a/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json b/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json index e270f9cf9a3..45d33e0929b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json +++ b/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wvr-c5h8-vf7f", - "modified": "2022-05-14T03:05:21Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-14T03:05:21Z", "aliases": [ "CVE-2017-16529" diff --git a/advisories/unreviewed/2022/05/GHSA-6rxj-38xv-j69g/GHSA-6rxj-38xv-j69g.json b/advisories/unreviewed/2022/05/GHSA-6rxj-38xv-j69g/GHSA-6rxj-38xv-j69g.json index 9e5c146e60c..6f84f774305 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rxj-38xv-j69g/GHSA-6rxj-38xv-j69g.json +++ b/advisories/unreviewed/2022/05/GHSA-6rxj-38xv-j69g/GHSA-6rxj-38xv-j69g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rxj-38xv-j69g", - "modified": "2022-05-17T03:23:41Z", + "modified": "2024-03-14T21:30:49Z", "published": "2022-05-17T03:23:41Z", "aliases": [ "CVE-2012-2143" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=816956" }, + { + "type": "WEB", + "url": "http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34" + }, { "type": "WEB", "url": "http://git.php.net/?p=php-src.git;a=commit;h=aab49e934de1fff046e659cbec46e3d053b41c34" diff --git a/advisories/unreviewed/2022/05/GHSA-9vwf-r222-fcvc/GHSA-9vwf-r222-fcvc.json b/advisories/unreviewed/2022/05/GHSA-9vwf-r222-fcvc/GHSA-9vwf-r222-fcvc.json index 9a004aff272..50649a21031 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vwf-r222-fcvc/GHSA-9vwf-r222-fcvc.json +++ b/advisories/unreviewed/2022/05/GHSA-9vwf-r222-fcvc/GHSA-9vwf-r222-fcvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vwf-r222-fcvc", - "modified": "2022-05-14T03:32:53Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-14T03:32:53Z", "aliases": [ "CVE-2017-16528" diff --git a/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json b/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json index c35d1a258ba..cd5338032c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json +++ b/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg87-xrj2-3r8m", - "modified": "2022-05-14T02:03:29Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-14T02:03:29Z", "aliases": [ "CVE-2017-10661" diff --git a/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json b/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json index 5cc815adbdc..b4c7936af0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json +++ b/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gpq7-5wgv-cqmg", - "modified": "2022-05-14T03:05:20Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-14T03:05:20Z", "aliases": [ "CVE-2017-16527" diff --git a/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json b/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json index 318c94fe4d0..cda1d20ca49 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json +++ b/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf35-pm73-38q6", - "modified": "2022-05-14T03:05:20Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-14T03:05:20Z", "aliases": [ "CVE-2017-16532" diff --git a/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json b/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json index e10592859c6..367a2976e2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json +++ b/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwf8-4gv4-8fmw", - "modified": "2022-05-17T03:11:57Z", + "modified": "2024-03-14T21:30:50Z", "published": "2022-05-17T03:11:57Z", "aliases": [ "CVE-2015-2666" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1204722" }, + { + "type": "WEB", + "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4" + }, { "type": "WEB", "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4" diff --git a/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json b/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json index 134e397efb1..57f6474972f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json +++ b/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wc9w-8x8g-533g", - "modified": "2022-05-13T01:26:24Z", + "modified": "2024-03-14T21:30:49Z", "published": "2022-05-13T01:26:24Z", "aliases": [ "CVE-2014-9529" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99641" }, + { + "type": "WEB", + "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a3a8784454692dd72e5d5d34dcdab17b4420e74c" + }, { "type": "WEB", "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a3a8784454692dd72e5d5d34dcdab17b4420e74c" diff --git a/advisories/unreviewed/2024/02/GHSA-3hp3-h35p-gqg4/GHSA-3hp3-h35p-gqg4.json b/advisories/unreviewed/2024/02/GHSA-3hp3-h35p-gqg4/GHSA-3hp3-h35p-gqg4.json index 5af903414af..1537b54907b 100644 --- a/advisories/unreviewed/2024/02/GHSA-3hp3-h35p-gqg4/GHSA-3hp3-h35p-gqg4.json +++ b/advisories/unreviewed/2024/02/GHSA-3hp3-h35p-gqg4/GHSA-3hp3-h35p-gqg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3hp3-h35p-gqg4", - "modified": "2024-02-22T18:30:28Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-22T18:30:28Z", "aliases": [ "CVE-2023-52443" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: avoid crash when parsed profile name is empty\n\nWhen processing a packed profile in unpack_profile() described like\n\n \"profile :ns::samba-dcerpcd /usr/lib*/samba/{,samba/}samba-dcerpcd {...}\"\n\na string \":samba-dcerpcd\" is unpacked as a fully-qualified name and then\npassed to aa_splitn_fqname().\n\naa_splitn_fqname() treats \":samba-dcerpcd\" as only containing a namespace.\nThus it returns NULL for tmpname, meanwhile tmpns is non-NULL. Later\naa_alloc_profile() crashes as the new profile name is NULL now.\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 6 PID: 1657 Comm: apparmor_parser Not tainted 6.7.0-rc2-dirty #16\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\nRIP: 0010:strlen+0x1e/0xa0\nCall Trace:\n \n ? strlen+0x1e/0xa0\n aa_policy_init+0x1bb/0x230\n aa_alloc_profile+0xb1/0x480\n unpack_profile+0x3bc/0x4960\n aa_unpack+0x309/0x15e0\n aa_replace_profiles+0x213/0x33c0\n policy_update+0x261/0x370\n profile_replace+0x20e/0x2a0\n vfs_write+0x2af/0xe00\n ksys_write+0x126/0x250\n do_syscall_64+0x46/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n \n---[ end trace 0000000000000000 ]---\nRIP: 0010:strlen+0x1e/0xa0\n\nIt seems such behaviour of aa_splitn_fqname() is expected and checked in\nother places where it is called (e.g. aa_remove_profiles). Well, there\nis an explicit comment \"a ns name without a following profile is allowed\"\ninside.\n\nAFAICS, nothing can prevent unpacked \"name\" to be in form like\n\":samba-dcerpcd\" - it is passed from userspace.\n\nDeny the whole profile set replacement in such case and inform user with\nEPROTO and an explaining message.\n\nFound by Linux Verification Center (linuxtesting.org).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3m37-qf9f-22vv/GHSA-3m37-qf9f-22vv.json b/advisories/unreviewed/2024/02/GHSA-3m37-qf9f-22vv/GHSA-3m37-qf9f-22vv.json index 10148c1f4c7..8e94c31a43c 100644 --- a/advisories/unreviewed/2024/02/GHSA-3m37-qf9f-22vv/GHSA-3m37-qf9f-22vv.json +++ b/advisories/unreviewed/2024/02/GHSA-3m37-qf9f-22vv/GHSA-3m37-qf9f-22vv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m37-qf9f-22vv", - "modified": "2024-02-22T18:30:29Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-22T18:30:29Z", "aliases": [ "CVE-2023-52446" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a race condition between btf_put() and map_free()\n\nWhen running `./test_progs -j` in my local vm with latest kernel,\nI once hit a kasan error like below:\n\n [ 1887.184724] BUG: KASAN: slab-use-after-free in bpf_rb_root_free+0x1f8/0x2b0\n [ 1887.185599] Read of size 4 at addr ffff888106806910 by task kworker/u12:2/2830\n [ 1887.186498]\n [ 1887.186712] CPU: 3 PID: 2830 Comm: kworker/u12:2 Tainted: G OEL 6.7.0-rc3-00699-g90679706d486-dirty #494\n [ 1887.188034] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n [ 1887.189618] Workqueue: events_unbound bpf_map_free_deferred\n [ 1887.190341] Call Trace:\n [ 1887.190666] \n [ 1887.190949] dump_stack_lvl+0xac/0xe0\n [ 1887.191423] ? nf_tcp_handle_invalid+0x1b0/0x1b0\n [ 1887.192019] ? panic+0x3c0/0x3c0\n [ 1887.192449] print_report+0x14f/0x720\n [ 1887.192930] ? preempt_count_sub+0x1c/0xd0\n [ 1887.193459] ? __virt_addr_valid+0xac/0x120\n [ 1887.194004] ? bpf_rb_root_free+0x1f8/0x2b0\n [ 1887.194572] kasan_report+0xc3/0x100\n [ 1887.195085] ? bpf_rb_root_free+0x1f8/0x2b0\n [ 1887.195668] bpf_rb_root_free+0x1f8/0x2b0\n [ 1887.196183] ? __bpf_obj_drop_impl+0xb0/0xb0\n [ 1887.196736] ? preempt_count_sub+0x1c/0xd0\n [ 1887.197270] ? preempt_count_sub+0x1c/0xd0\n [ 1887.197802] ? _raw_spin_unlock+0x1f/0x40\n [ 1887.198319] bpf_obj_free_fields+0x1d4/0x260\n [ 1887.198883] array_map_free+0x1a3/0x260\n [ 1887.199380] bpf_map_free_deferred+0x7b/0xe0\n [ 1887.199943] process_scheduled_works+0x3a2/0x6c0\n [ 1887.200549] worker_thread+0x633/0x890\n [ 1887.201047] ? __kthread_parkme+0xd7/0xf0\n [ 1887.201574] ? kthread+0x102/0x1d0\n [ 1887.202020] kthread+0x1ab/0x1d0\n [ 1887.202447] ? pr_cont_work+0x270/0x270\n [ 1887.202954] ? kthread_blkcg+0x50/0x50\n [ 1887.203444] ret_from_fork+0x34/0x50\n [ 1887.203914] ? kthread_blkcg+0x50/0x50\n [ 1887.204397] ret_from_fork_asm+0x11/0x20\n [ 1887.204913] \n [ 1887.204913] \n [ 1887.205209]\n [ 1887.205416] Allocated by task 2197:\n [ 1887.205881] kasan_set_track+0x3f/0x60\n [ 1887.206366] __kasan_kmalloc+0x6e/0x80\n [ 1887.206856] __kmalloc+0xac/0x1a0\n [ 1887.207293] btf_parse_fields+0xa15/0x1480\n [ 1887.207836] btf_parse_struct_metas+0x566/0x670\n [ 1887.208387] btf_new_fd+0x294/0x4d0\n [ 1887.208851] __sys_bpf+0x4ba/0x600\n [ 1887.209292] __x64_sys_bpf+0x41/0x50\n [ 1887.209762] do_syscall_64+0x4c/0xf0\n [ 1887.210222] entry_SYSCALL_64_after_hwframe+0x63/0x6b\n [ 1887.210868]\n [ 1887.211074] Freed by task 36:\n [ 1887.211460] kasan_set_track+0x3f/0x60\n [ 1887.211951] kasan_save_free_info+0x28/0x40\n [ 1887.212485] ____kasan_slab_free+0x101/0x180\n [ 1887.213027] __kmem_cache_free+0xe4/0x210\n [ 1887.213514] btf_free+0x5b/0x130\n [ 1887.213918] rcu_core+0x638/0xcc0\n [ 1887.214347] __do_softirq+0x114/0x37e\n\nThe error happens at bpf_rb_root_free+0x1f8/0x2b0:\n\n 00000000000034c0 :\n ; {\n 34c0: f3 0f 1e fa endbr64\n 34c4: e8 00 00 00 00 callq 0x34c9 \n 34c9: 55 pushq %rbp\n 34ca: 48 89 e5 movq %rsp, %rbp\n ...\n ; if (rec && rec->refcount_off >= 0 &&\n 36aa: 4d 85 ed testq %r13, %r13\n 36ad: 74 a9 je 0x3658 \n 36af: 49 8d 7d 10 leaq 0x10(%r13), %rdi\n 36b3: e8 00 00 00 00 callq 0x36b8 \n <==== kasan function\n 36b8: 45 8b 7d 10 movl 0x10(%r13), %r15d\n <==== use-after-free load\n 36bc: 45 85 ff testl %r15d, %r15d\n 36bf: 78 8c js 0x364d \n\nSo the problem \n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json index 4ca930271aa..f1e592a10b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json +++ b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-63f3-2rgp-79qx", - "modified": "2024-02-28T03:30:30Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26585" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix race between tx work scheduling and socket close\n\nSimilarly to previous commit, the submitting thread (recvmsg/sendmsg)\nmay exit as soon as the async crypto handler calls complete().\nReorder scheduling the work before calling complete().\nThis seems more logical in the first place, as it's\nthe inverse order of what the submitting thread will do.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6f72-79f8-3qcp/GHSA-6f72-79f8-3qcp.json b/advisories/unreviewed/2024/02/GHSA-6f72-79f8-3qcp/GHSA-6f72-79f8-3qcp.json index 0475f2a3f46..22c546e0485 100644 --- a/advisories/unreviewed/2024/02/GHSA-6f72-79f8-3qcp/GHSA-6f72-79f8-3qcp.json +++ b/advisories/unreviewed/2024/02/GHSA-6f72-79f8-3qcp/GHSA-6f72-79f8-3qcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f72-79f8-3qcp", - "modified": "2024-02-22T18:30:29Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-22T18:30:29Z", "aliases": [ "CVE-2023-52444" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid dirent corruption\n\nAs Al reported in link[1]:\n\nf2fs_rename()\n...\n\tif (old_dir != new_dir && !whiteout)\n\t\tf2fs_set_link(old_inode, old_dir_entry,\n\t\t\t\t\told_dir_page, new_dir);\n\telse\n\t\tf2fs_put_page(old_dir_page, 0);\n\nYou want correct inumber in the \"..\" link. And cross-directory\nrename does move the source to new parent, even if you'd been asked\nto leave a whiteout in the old place.\n\n[1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/\n\nWith below testcase, it may cause dirent corruption, due to it missed\nto call f2fs_set_link() to update \"..\" link to new directory.\n- mkdir -p dir/foo\n- renameat2 -w dir/foo bar\n\n[ASSERT] (__chk_dots_dentries:1421) --> Bad inode number[0x4] for '..', parent parent ino is [0x3]\n[FSCK] other corrupted bugs [Fail]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-84fp-h279-ggmw/GHSA-84fp-h279-ggmw.json b/advisories/unreviewed/2024/02/GHSA-84fp-h279-ggmw/GHSA-84fp-h279-ggmw.json index 158362f658e..67a5c877ac4 100644 --- a/advisories/unreviewed/2024/02/GHSA-84fp-h279-ggmw/GHSA-84fp-h279-ggmw.json +++ b/advisories/unreviewed/2024/02/GHSA-84fp-h279-ggmw/GHSA-84fp-h279-ggmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84fp-h279-ggmw", - "modified": "2024-02-22T18:30:29Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-22T18:30:29Z", "aliases": [ "CVE-2023-52445" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pvrusb2: fix use after free on context disconnection\n\nUpon module load, a kthread is created targeting the\npvr2_context_thread_func function, which may call pvr2_context_destroy\nand thus call kfree() on the context object. However, that might happen\nbefore the usb hub_event handler is able to notify the driver. This\npatch adds a sanity check before the invalid read reported by syzbot,\nwithin the context disconnection call stack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-wvjr-h8mr-f8gw/GHSA-wvjr-h8mr-f8gw.json b/advisories/unreviewed/2024/02/GHSA-wvjr-h8mr-f8gw/GHSA-wvjr-h8mr-f8gw.json index a02a79705b8..46543d0a970 100644 --- a/advisories/unreviewed/2024/02/GHSA-wvjr-h8mr-f8gw/GHSA-wvjr-h8mr-f8gw.json +++ b/advisories/unreviewed/2024/02/GHSA-wvjr-h8mr-f8gw/GHSA-wvjr-h8mr-f8gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvjr-h8mr-f8gw", - "modified": "2024-02-22T18:30:29Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-02-22T18:30:29Z", "aliases": [ "CVE-2023-52447" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Defer the free of inner map when necessary\n\nWhen updating or deleting an inner map in map array or map htab, the map\nmay still be accessed by non-sleepable program or sleepable program.\nHowever bpf_map_fd_put_ptr() decreases the ref-counter of the inner map\ndirectly through bpf_map_put(), if the ref-counter is the last one\n(which is true for most cases), the inner map will be freed by\nops->map_free() in a kworker. But for now, most .map_free() callbacks\ndon't use synchronize_rcu() or its variants to wait for the elapse of a\nRCU grace period, so after the invocation of ops->map_free completes,\nthe bpf program which is accessing the inner map may incur\nuse-after-free problem.\n\nFix the free of inner map by invoking bpf_map_free_deferred() after both\none RCU grace period and one tasks trace RCU grace period if the inner\nmap has been removed from the outer map before. The deferment is\naccomplished by using call_rcu() or call_rcu_tasks_trace() when\nreleasing the last ref-counter of bpf map. The newly-added rcu_head\nfield in bpf_map shares the same storage space with work field to\nreduce the size of bpf_map.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T17:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2qqg-5pcx-4jv3/GHSA-2qqg-5pcx-4jv3.json b/advisories/unreviewed/2024/03/GHSA-2qqg-5pcx-4jv3/GHSA-2qqg-5pcx-4jv3.json new file mode 100644 index 00000000000..4644873ded1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2qqg-5pcx-4jv3/GHSA-2qqg-5pcx-4jv3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qqg-5pcx-4jv3", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-28423" + ], + "details": "Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28423" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-15" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json b/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json index bb0d921aa95..ec7f5a71447 100644 --- a/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json +++ b/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rxr-8xrx-9rf3", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23270" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-525f-hw88-w4m8/GHSA-525f-hw88-w4m8.json b/advisories/unreviewed/2024/03/GHSA-525f-hw88-w4m8/GHSA-525f-hw88-w4m8.json index 39e127a8d7e..1cc2ccf71ca 100644 --- a/advisories/unreviewed/2024/03/GHSA-525f-hw88-w4m8/GHSA-525f-hw88-w4m8.json +++ b/advisories/unreviewed/2024/03/GHSA-525f-hw88-w4m8/GHSA-525f-hw88-w4m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-525f-hw88-w4m8", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23275" ], "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5c5p-qh6w-cqq9/GHSA-5c5p-qh6w-cqq9.json b/advisories/unreviewed/2024/03/GHSA-5c5p-qh6w-cqq9/GHSA-5c5p-qh6w-cqq9.json index 853c9147eb9..df61644af12 100644 --- a/advisories/unreviewed/2024/03/GHSA-5c5p-qh6w-cqq9/GHSA-5c5p-qh6w-cqq9.json +++ b/advisories/unreviewed/2024/03/GHSA-5c5p-qh6w-cqq9/GHSA-5c5p-qh6w-cqq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c5p-qh6w-cqq9", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23272" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. A user may gain access to protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json b/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json new file mode 100644 index 00000000000..5ef526eed4a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c89-5mrj-8h62", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-22346" + ], + "details": "Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22346" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/280203" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7140499" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json b/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json index 6014b29ef42..08e8a4126dc 100644 --- a/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json +++ b/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f82-qgq9-9h8f", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23276" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-74jf-w8p5-9492/GHSA-74jf-w8p5-9492.json b/advisories/unreviewed/2024/03/GHSA-74jf-w8p5-9492/GHSA-74jf-w8p5-9492.json new file mode 100644 index 00000000000..3e117f838c1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-74jf-w8p5-9492/GHSA-74jf-w8p5-9492.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74jf-w8p5-9492", + "modified": "2024-03-14T21:30:50Z", + "published": "2024-03-14T21:30:50Z", + "aliases": [ + "CVE-2023-48987" + ], + "details": "Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48987" + }, + { + "type": "WEB", + "url": "https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T09:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-75qq-7gc3-2xjr/GHSA-75qq-7gc3-2xjr.json b/advisories/unreviewed/2024/03/GHSA-75qq-7gc3-2xjr/GHSA-75qq-7gc3-2xjr.json index 43688d4a50e..bbdf693eae8 100644 --- a/advisories/unreviewed/2024/03/GHSA-75qq-7gc3-2xjr/GHSA-75qq-7gc3-2xjr.json +++ b/advisories/unreviewed/2024/03/GHSA-75qq-7gc3-2xjr/GHSA-75qq-7gc3-2xjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75qq-7gc3-2xjr", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23268" ], "details": "An injection issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9w9w-6vpx-x9q3/GHSA-9w9w-6vpx-x9q3.json b/advisories/unreviewed/2024/03/GHSA-9w9w-6vpx-x9q3/GHSA-9w9w-6vpx-x9q3.json index 9ca8faa3192..f49f47476a3 100644 --- a/advisories/unreviewed/2024/03/GHSA-9w9w-6vpx-x9q3/GHSA-9w9w-6vpx-x9q3.json +++ b/advisories/unreviewed/2024/03/GHSA-9w9w-6vpx-x9q3/GHSA-9w9w-6vpx-x9q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w9w-6vpx-x9q3", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23274" ], "details": "An injection issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json new file mode 100644 index 00000000000..0515f5771ac --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chrr-r69v-42vf", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2023-42938" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42938" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214091" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214091" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cq6x-28cg-mph3/GHSA-cq6x-28cg-mph3.json b/advisories/unreviewed/2024/03/GHSA-cq6x-28cg-mph3/GHSA-cq6x-28cg-mph3.json new file mode 100644 index 00000000000..78434062015 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cq6x-28cg-mph3/GHSA-cq6x-28cg-mph3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq6x-28cg-mph3", + "modified": "2024-03-14T21:30:50Z", + "published": "2024-03-14T21:30:50Z", + "aliases": [ + "CVE-2023-48985" + ], + "details": "Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48985" + }, + { + "type": "WEB", + "url": "https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T09:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f892-3gpj-v83f/GHSA-f892-3gpj-v83f.json b/advisories/unreviewed/2024/03/GHSA-f892-3gpj-v83f/GHSA-f892-3gpj-v83f.json new file mode 100644 index 00000000000..1a4aeead887 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f892-3gpj-v83f/GHSA-f892-3gpj-v83f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f892-3gpj-v83f", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-28425" + ], + "details": "greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28425" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g7wq-4cvg-g624/GHSA-g7wq-4cvg-g624.json b/advisories/unreviewed/2024/03/GHSA-g7wq-4cvg-g624/GHSA-g7wq-4cvg-g624.json new file mode 100644 index 00000000000..eb643175d76 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g7wq-4cvg-g624/GHSA-g7wq-4cvg-g624.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7wq-4cvg-g624", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:50Z", + "aliases": [ + "CVE-2023-48986" + ], + "details": "Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48986" + }, + { + "type": "WEB", + "url": "https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T09:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gqfr-84mj-fvqr/GHSA-gqfr-84mj-fvqr.json b/advisories/unreviewed/2024/03/GHSA-gqfr-84mj-fvqr/GHSA-gqfr-84mj-fvqr.json new file mode 100644 index 00000000000..c811c322ce8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gqfr-84mj-fvqr/GHSA-gqfr-84mj-fvqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqfr-84mj-fvqr", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-28424" + ], + "details": "zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28424" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json b/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json new file mode 100644 index 00000000000..00374ea3e2a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4hp-4mqq-mv7f", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-2256" + ], + "details": "The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact_button and bw_button shortcodes in all versions up to, and including, 4.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2256" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3049746%40oik&new=3049746%40oik&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.oik-plugins.com/shortcode_example/bw_contact_button-security-fix" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1266c6df-214b-4b6b-8f1d-a67385469bf5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j6q4-78q3-g22f/GHSA-j6q4-78q3-g22f.json b/advisories/unreviewed/2024/03/GHSA-j6q4-78q3-g22f/GHSA-j6q4-78q3-g22f.json index cfe47d10589..e90489c3838 100644 --- a/advisories/unreviewed/2024/03/GHSA-j6q4-78q3-g22f/GHSA-j6q4-78q3-g22f.json +++ b/advisories/unreviewed/2024/03/GHSA-j6q4-78q3-g22f/GHSA-j6q4-78q3-g22f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6q4-78q3-g22f", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23277" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m88g-7rcv-6rcx/GHSA-m88g-7rcv-6rcx.json b/advisories/unreviewed/2024/03/GHSA-m88g-7rcv-6rcx/GHSA-m88g-7rcv-6rcx.json index 7dfdeadf79c..357104eacfc 100644 --- a/advisories/unreviewed/2024/03/GHSA-m88g-7rcv-6rcx/GHSA-m88g-7rcv-6rcx.json +++ b/advisories/unreviewed/2024/03/GHSA-m88g-7rcv-6rcx/GHSA-m88g-7rcv-6rcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m88g-7rcv-6rcx", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23266" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mp7h-h4mw-vrgf/GHSA-mp7h-h4mw-vrgf.json b/advisories/unreviewed/2024/03/GHSA-mp7h-h4mw-vrgf/GHSA-mp7h-h4mw-vrgf.json new file mode 100644 index 00000000000..0e846ed0e63 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mp7h-h4mw-vrgf/GHSA-mp7h-h4mw-vrgf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp7h-h4mw-vrgf", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-27265" + ], + "details": "IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27265" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/284564" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7140678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json b/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json index 708dcf1c1f1..9414bbc332d 100644 --- a/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json +++ b/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qg9g-p9q2-wjvw", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23273" ], "details": "This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rfrv-rc39-gxfp/GHSA-rfrv-rc39-gxfp.json b/advisories/unreviewed/2024/03/GHSA-rfrv-rc39-gxfp/GHSA-rfrv-rc39-gxfp.json new file mode 100644 index 00000000000..8a627bcd7b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rfrv-rc39-gxfp/GHSA-rfrv-rc39-gxfp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfrv-rc39-gxfp", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-27266" + ], + "details": "IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27266" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/284566" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7141270" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vgq4-3x26-93jq/GHSA-vgq4-3x26-93jq.json b/advisories/unreviewed/2024/03/GHSA-vgq4-3x26-93jq/GHSA-vgq4-3x26-93jq.json index 81427193a7d..f3bcbbc91d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-vgq4-3x26-93jq/GHSA-vgq4-3x26-93jq.json +++ b/advisories/unreviewed/2024/03/GHSA-vgq4-3x26-93jq/GHSA-vgq4-3x26-93jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgq4-3x26-93jq", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-03-14T21:30:51Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23267" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xc3v-gxv5-4x7q/GHSA-xc3v-gxv5-4x7q.json b/advisories/unreviewed/2024/03/GHSA-xc3v-gxv5-4x7q/GHSA-xc3v-gxv5-4x7q.json new file mode 100644 index 00000000000..ac4272b7c92 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xc3v-gxv5-4x7q/GHSA-xc3v-gxv5-4x7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc3v-gxv5-4x7q", + "modified": "2024-03-14T21:30:51Z", + "published": "2024-03-14T21:30:51Z", + "aliases": [ + "CVE-2024-0860" + ], + "details": "\nThe affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0860" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-14T21:15:50Z" + } +} \ No newline at end of file