Publish Advisories

GHSA-35qh-7f6c-rjf7
GHSA-mj26-h3p5-rj2m
GHSA-2xjp-r9f7-cm2x
GHSA-398q-xwvh-4mpj
GHSA-3r6v-762w-v9rw
GHSA-4pmj-qpm8-x7gv
GHSA-5235-m374-99w3
GHSA-5xrw-g5h5-j2r6
GHSA-686q-7454-35qj
GHSA-863q-738r-33x7
GHSA-c5c5-3vp7-2qj2
GHSA-cg49-m89q-2j7q
GHSA-f8fm-x537-w56p
GHSA-fqm6-c2wr-r94m
GHSA-hh4j-jwjv-8726
GHSA-jh84-mrjc-wxm4
GHSA-p27g-6xm5-rqrf
GHSA-p9jg-5w2m-vgg8
GHSA-rx56-hv52-ppxp
GHSA-v84w-53rg-fgrf
GHSA-v92x-m54x-rp94
GHSA-x854-759p-6c5g
GHSA-xh5q-pch5-g3xq
This commit is contained in:
advisory-database[bot]
2025-01-31 00:32:15 +00:00
parent ecb5b28968
commit e74c19f0f6
23 changed files with 520 additions and 24 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35qh-7f6c-rjf7",
"modified": "2024-05-08T09:30:50Z",
"modified": "2025-01-31T00:30:43Z",
"published": "2024-02-15T06:31:35Z",
"aliases": [
"CVE-2024-1488"
@@ -51,6 +51,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2696"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:0837"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1488"
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-173"
"CWE-173",
"CWE-290"
],
"severity": "LOW",
"github_reviewed": false,
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xjp-r9f7-cm2x",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2023-6195"
],
"details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6195"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2249268"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/432276"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:08Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-398q-xwvh-4mpj",
"modified": "2025-01-27T18:32:01Z",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-27T18:32:01Z",
"aliases": [
"CVE-2024-57276"
],
"details": "In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-428"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-27T17:15:16Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3r6v-762w-v9rw",
"modified": "2025-01-30T18:32:09Z",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-30T18:32:09Z",
"aliases": [
"CVE-2025-24099"
],
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T17:15:18Z"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pmj-qpm8-x7gv",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23962"
],
"details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23962"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-847"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5235-m374-99w3",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23963"
],
"details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the PBAP_DecodeVCARD function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23963"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-850"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xrw-g5h5-j2r6",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-1211"
],
"details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1211"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2323594"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/440313"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:08Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-686q-7454-35qj",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23928"
],
"details": "This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the telematics functionality, which operates over HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23928"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1045"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-863q-738r-33x7",
"modified": "2025-01-09T21:31:32Z",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-09T21:31:32Z",
"aliases": [
"CVE-2024-13308"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-09T21:15:28Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c5c5-3vp7-2qj2",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23937"
],
"details": "This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the debug interface. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23937"
},
{
"type": "WEB",
"url": "https://community.silabs.com/a45Vm0000000Atp"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-869"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg49-m89q-2j7q",
"modified": "2025-01-31T00:30:45Z",
"published": "2025-01-31T00:30:45Z",
"aliases": [
"CVE-2025-24336"
],
"details": "SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24336"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN23839833"
},
{
"type": "WEB",
"url": "https://ocf.or.jp/about/download/sxflibrary"
}
],
"database_specific": {
"cwe_ids": [
"CWE-237"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:20Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8fm-x537-w56p",
"modified": "2025-01-31T00:30:45Z",
"published": "2025-01-31T00:30:45Z",
"aliases": [
"CVE-2024-24731"
],
"details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the http_download command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24731"
},
{
"type": "WEB",
"url": "https://community.silabs.com/a45Vm0000000Atp"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-870"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:10Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqm6-c2wr-r94m",
"modified": "2025-01-31T00:30:45Z",
"published": "2025-01-31T00:30:45Z",
"aliases": [
"CVE-2024-23973"
],
"details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. \n\nThe specific flaw exists within the handling of HTTP GET requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23973"
},
{
"type": "WEB",
"url": "https://community.silabs.com/a45Vm0000000Atp"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-873"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:10Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh4j-jwjv-8726",
"modified": "2025-01-09T09:31:41Z",
"modified": "2025-01-31T00:30:43Z",
"published": "2025-01-07T18:30:50Z",
"aliases": [
"CVE-2025-0241"
],
"details": "When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-401"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T16:15:38Z"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh84-mrjc-wxm4",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23930"
],
"details": "This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the Media service, which listens on TCP port 42000 by default. The issue results from improper handling of error conditions. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23930"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1043"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p27g-6xm5-rqrf",
"modified": "2025-01-09T21:31:31Z",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-09T21:31:31Z",
"aliases": [
"CVE-2024-13269"
],
"details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-201"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-09T20:15:35Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9jg-5w2m-vgg8",
"modified": "2025-01-09T21:31:32Z",
"modified": "2025-01-31T00:30:44Z",
"published": "2025-01-09T21:31:32Z",
"aliases": [
"CVE-2024-13309"
],
"details": "Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-287"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-09T21:15:28Z"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rx56-hv52-ppxp",
"modified": "2025-01-31T00:30:45Z",
"published": "2025-01-31T00:30:45Z",
"aliases": [
"CVE-2024-23970"
],
"details": "This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23970"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1052"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v84w-53rg-fgrf",
"modified": "2025-01-31T00:30:45Z",
"published": "2025-01-31T00:30:44Z",
"aliases": [
"CVE-2024-23968"
],
"details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23968"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1050"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-31T00:15:09Z"
}
}

Some files were not shown because too many files have changed in this diff Show More