From eab4740bc6626f2893f886742c0ff50e5eab936e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 May 2024 03:31:56 +0000 Subject: [PATCH] Publish Advisories GHSA-874v-pj72-92f3 GHSA-x5m7-63c6-fx79 GHSA-fg9q-5cw2-p6r9 GHSA-7pwr-cfrc-px4f GHSA-23vg-8xc3-j64m GHSA-3h5f-xp24-j3p4 GHSA-594v-v6mq-rw7x GHSA-f8vp-w697-m42g GHSA-p6mc-xxvv-r37f GHSA-px8m-3p25-24qw GHSA-q262-3hfr-f5q4 GHSA-rpc3-mw2p-39mj --- .../GHSA-874v-pj72-92f3.json | 6 ++- .../GHSA-x5m7-63c6-fx79.json | 6 ++- .../GHSA-fg9q-5cw2-p6r9.json | 6 ++- .../GHSA-7pwr-cfrc-px4f.json | 10 ++++- .../GHSA-23vg-8xc3-j64m.json | 42 +++++++++++++++++++ .../GHSA-3h5f-xp24-j3p4.json | 38 +++++++++++++++++ .../GHSA-594v-v6mq-rw7x.json | 38 +++++++++++++++++ .../GHSA-f8vp-w697-m42g.json | 38 +++++++++++++++++ .../GHSA-p6mc-xxvv-r37f.json | 38 +++++++++++++++++ .../GHSA-px8m-3p25-24qw.json | 38 +++++++++++++++++ .../GHSA-q262-3hfr-f5q4.json | 42 +++++++++++++++++++ .../GHSA-rpc3-mw2p-39mj.json | 38 +++++++++++++++++ 12 files changed, 336 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-23vg-8xc3-j64m/GHSA-23vg-8xc3-j64m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-594v-v6mq-rw7x/GHSA-594v-v6mq-rw7x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f8vp-w697-m42g/GHSA-f8vp-w697-m42g.json create mode 100644 advisories/unreviewed/2024/05/GHSA-p6mc-xxvv-r37f/GHSA-p6mc-xxvv-r37f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-px8m-3p25-24qw/GHSA-px8m-3p25-24qw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rpc3-mw2p-39mj/GHSA-rpc3-mw2p-39mj.json diff --git a/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json b/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json index c6b93d4a4d4..ca6a5af0c61 100644 --- a/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json +++ b/advisories/github-reviewed/2024/03/GHSA-874v-pj72-92f3/GHSA-874v-pj72-92f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-874v-pj72-92f3", - "modified": "2024-05-01T21:30:30Z", + "modified": "2024-05-08T03:30:37Z", "published": "2024-03-28T17:53:52Z", "aliases": [ "CVE-2024-1753" @@ -134,6 +134,10 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2055" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2049" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json index f002b87e2ca..9c6371780f8 100644 --- a/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json +++ b/advisories/github-reviewed/2024/04/GHSA-x5m7-63c6-fx79/GHSA-x5m7-63c6-fx79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5m7-63c6-fx79", - "modified": "2024-04-26T09:30:34Z", + "modified": "2024-05-08T03:30:37Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-1139" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1887" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2047" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1139" diff --git a/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json b/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json index b265513aaa8..86a7e382e84 100644 --- a/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json +++ b/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fg9q-5cw2-p6r9", - "modified": "2024-04-26T21:31:10Z", + "modified": "2024-05-08T03:30:37Z", "published": "2024-03-07T21:30:21Z", "aliases": [ "CVE-2024-1725" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1891" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2047" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1725" diff --git a/advisories/unreviewed/2024/04/GHSA-7pwr-cfrc-px4f/GHSA-7pwr-cfrc-px4f.json b/advisories/unreviewed/2024/04/GHSA-7pwr-cfrc-px4f/GHSA-7pwr-cfrc-px4f.json index 3e2e1237de3..993e9d9d509 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pwr-cfrc-px4f/GHSA-7pwr-cfrc-px4f.json +++ b/advisories/unreviewed/2024/04/GHSA-7pwr-cfrc-px4f/GHSA-7pwr-cfrc-px4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pwr-cfrc-px4f", - "modified": "2024-04-30T21:30:31Z", + "modified": "2024-05-08T03:30:37Z", "published": "2024-04-18T21:30:31Z", "aliases": [ "CVE-2023-3758" @@ -56,6 +56,14 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RV3HIZI3SURBUQKSOOL3XE64OOBQ2HTK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEP62IDS7A55D5UHM6GH7QZ7SQFOAPVF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XMORAO2BDDA5YX4ZLMXDZ7SM6KU47SY5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-23vg-8xc3-j64m/GHSA-23vg-8xc3-j64m.json b/advisories/unreviewed/2024/05/GHSA-23vg-8xc3-j64m/GHSA-23vg-8xc3-j64m.json new file mode 100644 index 00000000000..7776428affb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-23vg-8xc3-j64m/GHSA-23vg-8xc3-j64m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23vg-8xc3-j64m", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-4393" + ], + "details": "The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4393" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-connect/tags/1.2/openid/openid.php#L575" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2882d9dd-0c73-4c9a-99cb-d10900503103?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json b/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json new file mode 100644 index 00000000000..55eb22dc7e4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h5f-xp24-j3p4", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-2860" + ], + "details": "The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.\n ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2860" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-594v-v6mq-rw7x/GHSA-594v-v6mq-rw7x.json b/advisories/unreviewed/2024/05/GHSA-594v-v6mq-rw7x/GHSA-594v-v6mq-rw7x.json new file mode 100644 index 00000000000..b13e7ebf682 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-594v-v6mq-rw7x/GHSA-594v-v6mq-rw7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-594v-v6mq-rw7x", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-4456" + ], + "details": "In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4456" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2024-04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f8vp-w697-m42g/GHSA-f8vp-w697-m42g.json b/advisories/unreviewed/2024/05/GHSA-f8vp-w697-m42g/GHSA-f8vp-w697-m42g.json new file mode 100644 index 00000000000..3977983cb58 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f8vp-w697-m42g/GHSA-f8vp-w697-m42g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vp-w697-m42g", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-4162" + ], + "details": "A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4162" + }, + { + "type": "WEB", + "url": "https://www3.panasonic.biz/ac/e/fasys/software_info/eco/tol_kwwatcher.jsp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p6mc-xxvv-r37f/GHSA-p6mc-xxvv-r37f.json b/advisories/unreviewed/2024/05/GHSA-p6mc-xxvv-r37f/GHSA-p6mc-xxvv-r37f.json new file mode 100644 index 00000000000..6a40f670ca5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p6mc-xxvv-r37f/GHSA-p6mc-xxvv-r37f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6mc-xxvv-r37f", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-1930" + ], + "details": "No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions.\n\nThere is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1930" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/03/04/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-px8m-3p25-24qw/GHSA-px8m-3p25-24qw.json b/advisories/unreviewed/2024/05/GHSA-px8m-3p25-24qw/GHSA-px8m-3p25-24qw.json new file mode 100644 index 00000000000..287499b7755 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-px8m-3p25-24qw/GHSA-px8m-3p25-24qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px8m-3p25-24qw", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-1929" + ], + "details": "Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity via Configuration Dictionary.\n\nThere are issues with the D-Bus interface long before Polkit is invoked. The `org.rpm.dnf.v0.SessionManager.open_session` method takes a key/value map of configuration entries. A sub-entry in this map, placed under the \"config\" key, is another key/value map. The configuration values found in it will be forwarded as configuration overrides to the `libdnf5::Base` configuration. \n\nPractically all libdnf5 configuration aspects can be influenced here. Already when opening the session via D-Bus, the libdnf5 will be initialized using these override configuration values. There is no sanity checking of the content of this \"config\" map, which is untrusted data. It is possible to make the library loading a plug-in shared library under control of an unprivileged user, hence achieving root access. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1929" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/03/04/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json new file mode 100644 index 00000000000..758fa2e7cd9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q262-3hfr-f5q4", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-4418" + ], + "details": "A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being \"freed\" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4418" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-4418" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2278616" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rpc3-mw2p-39mj/GHSA-rpc3-mw2p-39mj.json b/advisories/unreviewed/2024/05/GHSA-rpc3-mw2p-39mj/GHSA-rpc3-mw2p-39mj.json new file mode 100644 index 00000000000..a617fed7fa0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rpc3-mw2p-39mj/GHSA-rpc3-mw2p-39mj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpc3-mw2p-39mj", + "modified": "2024-05-08T03:30:37Z", + "published": "2024-05-08T03:30:37Z", + "aliases": [ + "CVE-2024-2746" + ], + "details": "Incomplete fix for CVE-2024-1929\n\nThe problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unprivileged users, which allowed a\nlocal root exploit by tricking the daemon into loading a user controlled \"plugin\". All of this happened before Polkit authentication was even started.\n\nThe dnf5 library code does not check whether non-root users control the directory in question. \n\nOn one hand, this poses a Denial-of-Service attack vector by making the daemonoperate on a blocking file (e.g. named FIFO special file) or a very large file\nthat causes an out-of-memory situation (e.g. /dev/zero). On the other hand, this can be used to let the daemon process privileged files like /etc/shadow.\nThe file in question is parsed as an INI file. Error diagnostics resulting from parsing privileged files could cause information leaks, if these diagnostics\nare accessible to unprivileged users. In the case of libdnf5, no such user accessible diagnostics should exist, though.\n\nAlso, a local attacker can place a valid repository configuration file in this directory. This configuration file allows to specify\na plethora of additional configuration options. This makes various additional code paths in libdnf5 accessible to the attacker. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2746" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/03/5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T02:15:09Z" + } +} \ No newline at end of file