diff --git a/advisories/unreviewed/2024/11/GHSA-23pj-rvrr-6499/GHSA-23pj-rvrr-6499.json b/advisories/unreviewed/2024/11/GHSA-23pj-rvrr-6499/GHSA-23pj-rvrr-6499.json index b072fef6ef2..4104b6909d8 100644 --- a/advisories/unreviewed/2024/11/GHSA-23pj-rvrr-6499/GHSA-23pj-rvrr-6499.json +++ b/advisories/unreviewed/2024/11/GHSA-23pj-rvrr-6499/GHSA-23pj-rvrr-6499.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json b/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json index a11f391acf5..d887c881b38 100644 --- a/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json +++ b/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27gg-q2pj-f574", - "modified": "2024-11-26T09:30:49Z", + "modified": "2024-11-26T12:41:36Z", "published": "2024-11-26T09:30:49Z", "aliases": [ "CVE-2024-32151" ], "details": "User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ "CWE-257" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T08:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json b/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json index 2d144104bcd..83a06f7324f 100644 --- a/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json +++ b/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2php-gcq2-fxqp", - "modified": "2024-11-26T09:30:49Z", + "modified": "2024-11-26T12:41:36Z", "published": "2024-11-26T09:30:49Z", "aliases": [ "CVE-2024-33605" ], "details": "Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T08:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2qj2-g5q3-xw3g/GHSA-2qj2-g5q3-xw3g.json b/advisories/unreviewed/2024/11/GHSA-2qj2-g5q3-xw3g/GHSA-2qj2-g5q3-xw3g.json index 5a59b6a43a8..ba1790a1613 100644 --- a/advisories/unreviewed/2024/11/GHSA-2qj2-g5q3-xw3g/GHSA-2qj2-g5q3-xw3g.json +++ b/advisories/unreviewed/2024/11/GHSA-2qj2-g5q3-xw3g/GHSA-2qj2-g5q3-xw3g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-37p2-jq47-hjhr/GHSA-37p2-jq47-hjhr.json b/advisories/unreviewed/2024/11/GHSA-37p2-jq47-hjhr/GHSA-37p2-jq47-hjhr.json new file mode 100644 index 00000000000..766c0cb8767 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-37p2-jq47-hjhr/GHSA-37p2-jq47-hjhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37p2-jq47-hjhr", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50370" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the \"cfg_cmd_set_eth_conf\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50370" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50370" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3gvm-h59h-xc2f/GHSA-3gvm-h59h-xc2f.json b/advisories/unreviewed/2024/11/GHSA-3gvm-h59h-xc2f/GHSA-3gvm-h59h-xc2f.json new file mode 100644 index 00000000000..065acd0f81d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3gvm-h59h-xc2f/GHSA-3gvm-h59h-xc2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gvm-h59h-xc2f", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50363" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"mp_apply\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50363" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3rjc-6hx2-f4rh/GHSA-3rjc-6hx2-f4rh.json b/advisories/unreviewed/2024/11/GHSA-3rjc-6hx2-f4rh/GHSA-3rjc-6hx2-f4rh.json new file mode 100644 index 00000000000..c279319bdc8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3rjc-6hx2-f4rh/GHSA-3rjc-6hx2-f4rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rjc-6hx2-f4rh", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50367" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"sta_log_htm\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50367" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50367" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3rqm-q78j-4f7q/GHSA-3rqm-q78j-4f7q.json b/advisories/unreviewed/2024/11/GHSA-3rqm-q78j-4f7q/GHSA-3rqm-q78j-4f7q.json new file mode 100644 index 00000000000..2baf71d74f1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3rqm-q78j-4f7q/GHSA-3rqm-q78j-4f7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rqm-q78j-4f7q", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50366" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"applications_apply\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50366" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50366" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4253-j7xf-mm3q/GHSA-4253-j7xf-mm3q.json b/advisories/unreviewed/2024/11/GHSA-4253-j7xf-mm3q/GHSA-4253-j7xf-mm3q.json new file mode 100644 index 00000000000..25d6236330a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4253-j7xf-mm3q/GHSA-4253-j7xf-mm3q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4253-j7xf-mm3q", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-11032" + ], + "details": "The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11032" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-parsidate/tags/5.1.1/includes/general.php#L76" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3195986/wp-parsidate/trunk/includes/general.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-parsidate/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/72383bd3-82b4-4aea-9a1c-277ad06e2500?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4mvc-4mwc-p7gv/GHSA-4mvc-4mwc-p7gv.json b/advisories/unreviewed/2024/11/GHSA-4mvc-4mwc-p7gv/GHSA-4mvc-4mwc-p7gv.json new file mode 100644 index 00000000000..03e58ead08b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4mvc-4mwc-p7gv/GHSA-4mvc-4mwc-p7gv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mvc-4mwc-p7gv", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50369" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"multiple_ssid_htm\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50369" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json b/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json new file mode 100644 index 00000000000..34e979136e3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qc3-fmcj-w66w", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-47250" + ], + "details": "Out-of-bounds Read vulnerability in Apache NimBLE.\n\nMissing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent.\nThis issue requires broken or bogus Bluetooth controller and thus severity is considered low.\nThis issue affects Apache NimBLE: through 1.7.0.\n\n\nUsers are recommended to upgrade to version 1.8.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47250" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/zdb50spojlqbn0yxd866mbzqjt2vpt85" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-562q-w435-phv9/GHSA-562q-w435-phv9.json b/advisories/unreviewed/2024/11/GHSA-562q-w435-phv9/GHSA-562q-w435-phv9.json new file mode 100644 index 00000000000..fc17712bee4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-562q-w435-phv9/GHSA-562q-w435-phv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-562q-w435-phv9", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50362" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"connection_profile_apply\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50362" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-57xx-24q7-xwfr/GHSA-57xx-24q7-xwfr.json b/advisories/unreviewed/2024/11/GHSA-57xx-24q7-xwfr/GHSA-57xx-24q7-xwfr.json new file mode 100644 index 00000000000..ae78bc223ba --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-57xx-24q7-xwfr/GHSA-57xx-24q7-xwfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xx-24q7-xwfr", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-50361" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"certificate_file_remove\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50361" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50361" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-63vx-53jv-f5hf/GHSA-63vx-53jv-f5hf.json b/advisories/unreviewed/2024/11/GHSA-63vx-53jv-f5hf/GHSA-63vx-53jv-f5hf.json new file mode 100644 index 00000000000..a8193a3036d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-63vx-53jv-f5hf/GHSA-63vx-53jv-f5hf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63vx-53jv-f5hf", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50373" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the \"restore_config_from_utility\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50373" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json b/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json new file mode 100644 index 00000000000..17ad1e011d3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vqg-wm4f-f8vx", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-38832" + ], + "details": "VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38832" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-755x-386x-p26p/GHSA-755x-386x-p26p.json b/advisories/unreviewed/2024/11/GHSA-755x-386x-p26p/GHSA-755x-386x-p26p.json new file mode 100644 index 00000000000..a3e80f22fe5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-755x-386x-p26p/GHSA-755x-386x-p26p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-755x-386x-p26p", + "modified": "2024-11-26T12:41:36Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-11680" + ], + "details": "ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11680" + }, + { + "type": "WEB", + "url": "https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744" + }, + { + "type": "WEB", + "url": "https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/projectsend-bypass" + }, + { + "type": "WEB", + "url": "https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json b/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json new file mode 100644 index 00000000000..85703aeedff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mjq-fcrm-26pg", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-38831" + ], + "details": "VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38831" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json b/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json new file mode 100644 index 00000000000..9a913f88984 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88h9-qf46-pmjc", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-38830" + ], + "details": "VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38830" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json b/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json new file mode 100644 index 00000000000..5c993ea3f07 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-966f-2c6j-qj89", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-51569" + ], + "details": "Out-of-bounds Read vulnerability in Apache NimBLE.\n\nMissing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory.\nThis issue requires broken or bogus Bluetooth controller and thus severity is considered low.\nThis issue affects Apache NimBLE: through 1.7.0.\n\n\nUsers are recommended to upgrade to version 1.8.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51569" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/q0vs5rddx1lho30xnpsrvpzgxqmywnhs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9q6m-jvw2-h293/GHSA-9q6m-jvw2-h293.json b/advisories/unreviewed/2024/11/GHSA-9q6m-jvw2-h293/GHSA-9q6m-jvw2-h293.json new file mode 100644 index 00000000000..469335599c9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9q6m-jvw2-h293/GHSA-9q6m-jvw2-h293.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6m-jvw2-h293", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50376" + ], + "details": "A CWE-79 \"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50376" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cp7q-35hm-7jxh/GHSA-cp7q-35hm-7jxh.json b/advisories/unreviewed/2024/11/GHSA-cp7q-35hm-7jxh/GHSA-cp7q-35hm-7jxh.json new file mode 100644 index 00000000000..93e60cd8257 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cp7q-35hm-7jxh/GHSA-cp7q-35hm-7jxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp7q-35hm-7jxh", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50364" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"export_log\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50364" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f4h2-jrxj-q4vg/GHSA-f4h2-jrxj-q4vg.json b/advisories/unreviewed/2024/11/GHSA-f4h2-jrxj-q4vg/GHSA-f4h2-jrxj-q4vg.json new file mode 100644 index 00000000000..98f0439304c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f4h2-jrxj-q4vg/GHSA-f4h2-jrxj-q4vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4h2-jrxj-q4vg", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50374" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the \"capture_packages\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50374" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json b/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json new file mode 100644 index 00000000000..bd1b77c43b5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f94q-ffqr-x638", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-47248" + ], + "details": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.\n\nSpecially crafted MESH message could result in memory corruption when non-default build configuration is used.\nThis issue affects Apache NimBLE: through 1.7.0.\n\nUsers are recommended to upgrade to version 1.8.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47248" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/z8m7jqh54xybf9kz8q2l3tz92zsj7tmz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f95v-2gx6-353h/GHSA-f95v-2gx6-353h.json b/advisories/unreviewed/2024/11/GHSA-f95v-2gx6-353h/GHSA-f95v-2gx6-353h.json new file mode 100644 index 00000000000..fbd6126d34b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f95v-2gx6-353h/GHSA-f95v-2gx6-353h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f95v-2gx6-353h", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50365" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"lan_apply\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50365" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json b/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json new file mode 100644 index 00000000000..92d44ef56c5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw6g-5qw9-p3mx", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-47249" + ], + "details": "Improper Validation of Array Index vulnerability in Apache NimBLE.\n\nLack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash.\nThis issue requires broken or bogus Bluetooth controller and thus severity is considered low.\nThis issue affects Apache NimBLE: through 1.7.0.\n\nUsers are recommended to upgrade to version 1.8.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47249" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/7ckxw6481dp68ons627pjcb27c75n0mq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hc9r-884c-8q5p/GHSA-hc9r-884c-8q5p.json b/advisories/unreviewed/2024/11/GHSA-hc9r-884c-8q5p/GHSA-hc9r-884c-8q5p.json new file mode 100644 index 00000000000..91eb8993378 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hc9r-884c-8q5p/GHSA-hc9r-884c-8q5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc9r-884c-8q5p", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50372" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the \"backup_config_to_utility\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50372" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json b/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json new file mode 100644 index 00000000000..0a7b37eccf3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2m4-2g99-6625", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-38834" + ], + "details": "VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38834" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mcvc-qm8h-qxxw/GHSA-mcvc-qm8h-qxxw.json b/advisories/unreviewed/2024/11/GHSA-mcvc-qm8h-qxxw/GHSA-mcvc-qm8h-qxxw.json new file mode 100644 index 00000000000..7545873b245 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mcvc-qm8h-qxxw/GHSA-mcvc-qm8h-qxxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcvc-qm8h-qxxw", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50371" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the \"wlan_scan\" operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50371" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mf8w-vg63-44j5/GHSA-mf8w-vg63-44j5.json b/advisories/unreviewed/2024/11/GHSA-mf8w-vg63-44j5/GHSA-mf8w-vg63-44j5.json new file mode 100644 index 00000000000..629a1bc564a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mf8w-vg63-44j5/GHSA-mf8w-vg63-44j5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf8w-vg63-44j5", + "modified": "2024-11-26T12:41:36Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-11024" + ], + "details": "The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11024" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192531/apppresser" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/43cb0399-4add-43d5-863c-30e11803bd90?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-230" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:21:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json b/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json new file mode 100644 index 00000000000..a53393cbfef --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mff4-qp47-8h8q", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-38833" + ], + "details": "VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38833" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mfqv-qjxh-rprm/GHSA-mfqv-qjxh-rprm.json b/advisories/unreviewed/2024/11/GHSA-mfqv-qjxh-rprm/GHSA-mfqv-qjxh-rprm.json new file mode 100644 index 00000000000..4121d19c270 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mfqv-qjxh-rprm/GHSA-mfqv-qjxh-rprm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfqv-qjxh-rprm", + "modified": "2024-11-26T12:41:36Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-50358" + ], + "details": "A CWE-15 \"External Control of System or Configuration Setting\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50358" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50358" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:21:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mm43-7g2p-x3m9/GHSA-mm43-7g2p-x3m9.json b/advisories/unreviewed/2024/11/GHSA-mm43-7g2p-x3m9/GHSA-mm43-7g2p-x3m9.json new file mode 100644 index 00000000000..476b2e538f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mm43-7g2p-x3m9/GHSA-mm43-7g2p-x3m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm43-7g2p-x3m9", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50375" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default \"edgserver\" service enabled on the access point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50375" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmw6-g53r-v83q/GHSA-pmw6-g53r-v83q.json b/advisories/unreviewed/2024/11/GHSA-pmw6-g53r-v83q/GHSA-pmw6-g53r-v83q.json new file mode 100644 index 00000000000..29f7b3ce867 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pmw6-g53r-v83q/GHSA-pmw6-g53r-v83q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmw6-g53r-v83q", + "modified": "2024-11-26T12:41:36Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-10579" + ], + "details": "The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the preview_module() function in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view unpublished forms.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10579" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-popup/tags/7.8.5/inc/hustle-modules-common-admin-ajax.php#L189" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-popup/trunk/inc/hustle-modules-common-admin-ajax.php#L189" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ebd96d9c-c1ab-4a53-a52a-9fc2541482f2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:21:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json b/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json new file mode 100644 index 00000000000..9c7b267c069 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq42-5fqr-w8cx", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-8899" + ], + "details": "The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8899" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3193980/jeg-elementor-kit" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4efc9c47-321a-4635-943f-785ffc34d851?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json b/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json index 2be3233f79b..0a4d6e33dec 100644 --- a/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json +++ b/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq4w-jf35-7pmx", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-26T12:41:33Z", "published": "2024-11-20T12:30:35Z", "aliases": [ "CVE-2024-10382" diff --git a/advisories/unreviewed/2024/11/GHSA-r262-2rmj-2h3m/GHSA-r262-2rmj-2h3m.json b/advisories/unreviewed/2024/11/GHSA-r262-2rmj-2h3m/GHSA-r262-2rmj-2h3m.json index ff12e7da743..9681a535896 100644 --- a/advisories/unreviewed/2024/11/GHSA-r262-2rmj-2h3m/GHSA-r262-2rmj-2h3m.json +++ b/advisories/unreviewed/2024/11/GHSA-r262-2rmj-2h3m/GHSA-r262-2rmj-2h3m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rfw8-876c-83jf/GHSA-rfw8-876c-83jf.json b/advisories/unreviewed/2024/11/GHSA-rfw8-876c-83jf/GHSA-rfw8-876c-83jf.json new file mode 100644 index 00000000000..24b0c857ed8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfw8-876c-83jf/GHSA-rfw8-876c-83jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfw8-876c-83jf", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-50359" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"scan_ap\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50359" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50359" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rwm2-x5gh-97pr/GHSA-rwm2-x5gh-97pr.json b/advisories/unreviewed/2024/11/GHSA-rwm2-x5gh-97pr/GHSA-rwm2-x5gh-97pr.json new file mode 100644 index 00000000000..d474ade9092 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rwm2-x5gh-97pr/GHSA-rwm2-x5gh-97pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwm2-x5gh-97pr", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50368" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"basic_htm\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50368" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v29x-3ch7-rm49/GHSA-v29x-3ch7-rm49.json b/advisories/unreviewed/2024/11/GHSA-v29x-3ch7-rm49/GHSA-v29x-3ch7-rm49.json new file mode 100644 index 00000000000..9a36618c501 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v29x-3ch7-rm49/GHSA-v29x-3ch7-rm49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v29x-3ch7-rm49", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-50360" + ], + "details": "A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"snmp_apply\" API which are not properly sanitized before being concatenated to OS level commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50360" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vjgf-5h8j-h29j/GHSA-vjgf-5h8j-h29j.json b/advisories/unreviewed/2024/11/GHSA-vjgf-5h8j-h29j/GHSA-vjgf-5h8j-h29j.json new file mode 100644 index 00000000000..920bf0bd02c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vjgf-5h8j-h29j/GHSA-vjgf-5h8j-h29j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjgf-5h8j-h29j", + "modified": "2024-11-26T12:41:37Z", + "published": "2024-11-26T12:41:37Z", + "aliases": [ + "CVE-2024-50377" + ], + "details": "A CWE-798 \"Use of Hard-coded Credentials\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality that by default encrypts the archives using a static password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50377" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:22:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vm82-4pmf-6cv6/GHSA-vm82-4pmf-6cv6.json b/advisories/unreviewed/2024/11/GHSA-vm82-4pmf-6cv6/GHSA-vm82-4pmf-6cv6.json index 6ac7debe842..7853164921a 100644 --- a/advisories/unreviewed/2024/11/GHSA-vm82-4pmf-6cv6/GHSA-vm82-4pmf-6cv6.json +++ b/advisories/unreviewed/2024/11/GHSA-vm82-4pmf-6cv6/GHSA-vm82-4pmf-6cv6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-w45w-2j52-4v45/GHSA-w45w-2j52-4v45.json b/advisories/unreviewed/2024/11/GHSA-w45w-2j52-4v45/GHSA-w45w-2j52-4v45.json index 5c9be5753b7..dd5a4ed0d5e 100644 --- a/advisories/unreviewed/2024/11/GHSA-w45w-2j52-4v45/GHSA-w45w-2j52-4v45.json +++ b/advisories/unreviewed/2024/11/GHSA-w45w-2j52-4v45/GHSA-w45w-2j52-4v45.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-x6vh-jq8p-r5c5/GHSA-x6vh-jq8p-r5c5.json b/advisories/unreviewed/2024/11/GHSA-x6vh-jq8p-r5c5/GHSA-x6vh-jq8p-r5c5.json new file mode 100644 index 00000000000..a05ed863831 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x6vh-jq8p-r5c5/GHSA-x6vh-jq8p-r5c5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6vh-jq8p-r5c5", + "modified": "2024-11-26T12:41:36Z", + "published": "2024-11-26T12:41:36Z", + "aliases": [ + "CVE-2024-10308" + ], + "details": "The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdown widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10308" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3193980/jeg-elementor-kit" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/98aed079-672c-43bb-a5eb-faf8ffc04b71?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T11:15:16Z" + } +} \ No newline at end of file