From ebf48a24bbd7f173c35f05dc90184c285f8bea4e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 23 Sep 2024 18:31:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-g5jq-hrmx-g9ph.json | 2 +- .../GHSA-97pf-794f-gmgm.json | 2 +- .../GHSA-qf5j-mx4g-56pf.json | 2 +- .../GHSA-x676-9gf4-jg53.json | 1 + .../GHSA-xwf2-9m25-2hpf.json | 2 +- .../GHSA-7w82-8h79-m4wp.json | 7 ++- .../GHSA-gv63-8gqg-3525.json | 9 +++- .../GHSA-23qc-7hjx-vwmv.json | 42 ++++++++++++++++++ .../GHSA-2gm9-phpp-rvm3.json | 2 +- .../GHSA-2h8m-mjqv-x98p.json | 11 +++-- .../GHSA-2hj6-cwhm-rfg9.json | 11 +++-- .../GHSA-39rx-hmmc-q5pv.json | 38 ++++++++++++++++ .../GHSA-4366-c9hw-r9qg.json | 11 +++-- .../GHSA-473p-xqgv-xxw3.json | 9 ++-- .../GHSA-58mw-2g79-hjm6.json | 11 +++-- .../GHSA-632r-423p-9jx4.json | 11 +++-- .../GHSA-6cx3-28wh-wjwv.json | 1 + .../GHSA-6f62-3596-g6w7.json | 11 +++-- .../GHSA-6gcw-xcpf-vr88.json | 7 ++- .../GHSA-6vq9-c7rm-r447.json | 11 +++-- .../GHSA-725j-ffcc-fc53.json | 11 +++-- .../GHSA-76f7-g9hr-v32c.json | 11 +++-- .../GHSA-7hr2-9rf8-gx6q.json | 11 +++-- .../GHSA-7jvh-4mqp-gf66.json | 43 +++++++++++++++++++ .../GHSA-86wc-gr98-6p59.json | 9 ++-- .../GHSA-8qj3-h82r-hcwc.json | 9 ++-- .../GHSA-9398-9vm3-q46v.json | 1 + .../GHSA-9f66-cv49-738x.json | 11 +++-- .../GHSA-9p6f-43f7-gmq3.json | 11 +++-- .../GHSA-c83g-2v28-2jp8.json | 11 +++-- .../GHSA-cpj4-mrcc-fc7h.json | 38 ++++++++++++++++ .../GHSA-f99c-r797-v657.json | 11 +++-- .../GHSA-fhq8-gx6w-r3rj.json | 38 ++++++++++++++++ .../GHSA-h5qj-jjhh-95x5.json | 9 ++-- .../GHSA-h9h6-4wfq-8vwm.json | 38 ++++++++++++++++ .../GHSA-h9ph-w4hg-9mjw.json | 11 +++-- .../GHSA-hc48-m7gp-vcrj.json | 39 +++++++++++++++++ .../GHSA-jm9x-rx9x-wpqj.json | 38 ++++++++++++++++ .../GHSA-mf8x-9rcg-p86q.json | 11 +++-- .../GHSA-mxj5-w2rm-4rhf.json | 11 +++-- .../GHSA-pwh3-mj55-39cv.json | 6 ++- .../GHSA-q6vw-x86f-x8m4.json | 38 ++++++++++++++++ .../GHSA-qchx-h2pq-fhfp.json | 6 ++- .../GHSA-qrrh-7fhh-g486.json | 11 +++-- .../GHSA-qv7g-5jm3-2q8q.json | 11 +++-- .../GHSA-rm2h-fhqm-923f.json | 11 +++-- .../GHSA-rqgx-3q58-h4h3.json | 11 +++-- .../GHSA-rxmx-cgf3-gfph.json | 43 +++++++++++++++++++ .../GHSA-vgm9-qpvf-cp5w.json | 11 +++-- .../GHSA-vh32-2cmq-5xpc.json | 11 +++-- .../GHSA-vh3x-525m-jp4r.json | 3 +- .../GHSA-vm34-2mcq-j9q8.json | 43 +++++++++++++++++++ .../GHSA-w5jc-3vgp-f4c9.json | 11 +++-- .../GHSA-w6wg-4287-f4wf.json | 11 +++-- .../GHSA-wg8v-xr35-c5fj.json | 43 +++++++++++++++++++ .../GHSA-wq22-3j46-hjmw.json | 9 ++-- .../GHSA-ww64-xcqm-5jhf.json | 38 ++++++++++++++++ .../GHSA-xh89-f5vr-hmhw.json | 11 +++-- 58 files changed, 770 insertions(+), 131 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-23qc-7hjx-vwmv/GHSA-23qc-7hjx-vwmv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-39rx-hmmc-q5pv/GHSA-39rx-hmmc-q5pv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cpj4-mrcc-fc7h/GHSA-cpj4-mrcc-fc7h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fhq8-gx6w-r3rj/GHSA-fhq8-gx6w-r3rj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h9h6-4wfq-8vwm/GHSA-h9h6-4wfq-8vwm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q6vw-x86f-x8m4/GHSA-q6vw-x86f-x8m4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vm34-2mcq-j9q8/GHSA-vm34-2mcq-j9q8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-ww64-xcqm-5jhf/GHSA-ww64-xcqm-5jhf.json diff --git a/advisories/unreviewed/2022/10/GHSA-g5jq-hrmx-g9ph/GHSA-g5jq-hrmx-g9ph.json b/advisories/unreviewed/2022/10/GHSA-g5jq-hrmx-g9ph/GHSA-g5jq-hrmx-g9ph.json index 2a444ef0585..0c80d9c2e22 100644 --- a/advisories/unreviewed/2022/10/GHSA-g5jq-hrmx-g9ph/GHSA-g5jq-hrmx-g9ph.json +++ b/advisories/unreviewed/2022/10/GHSA-g5jq-hrmx-g9ph/GHSA-g5jq-hrmx-g9ph.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-97pf-794f-gmgm/GHSA-97pf-794f-gmgm.json b/advisories/unreviewed/2023/09/GHSA-97pf-794f-gmgm/GHSA-97pf-794f-gmgm.json index b31bb66da82..e397050b504 100644 --- a/advisories/unreviewed/2023/09/GHSA-97pf-794f-gmgm/GHSA-97pf-794f-gmgm.json +++ b/advisories/unreviewed/2023/09/GHSA-97pf-794f-gmgm/GHSA-97pf-794f-gmgm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-qf5j-mx4g-56pf/GHSA-qf5j-mx4g-56pf.json b/advisories/unreviewed/2023/10/GHSA-qf5j-mx4g-56pf/GHSA-qf5j-mx4g-56pf.json index 8a15ff5f195..9a139002052 100644 --- a/advisories/unreviewed/2023/10/GHSA-qf5j-mx4g-56pf/GHSA-qf5j-mx4g-56pf.json +++ b/advisories/unreviewed/2023/10/GHSA-qf5j-mx4g-56pf/GHSA-qf5j-mx4g-56pf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-x676-9gf4-jg53/GHSA-x676-9gf4-jg53.json b/advisories/unreviewed/2023/10/GHSA-x676-9gf4-jg53/GHSA-x676-9gf4-jg53.json index de7fa302e08..186b9a5e8cf 100644 --- a/advisories/unreviewed/2023/10/GHSA-x676-9gf4-jg53/GHSA-x676-9gf4-jg53.json +++ b/advisories/unreviewed/2023/10/GHSA-x676-9gf4-jg53/GHSA-x676-9gf4-jg53.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-617" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-xwf2-9m25-2hpf/GHSA-xwf2-9m25-2hpf.json b/advisories/unreviewed/2023/10/GHSA-xwf2-9m25-2hpf/GHSA-xwf2-9m25-2hpf.json index 4f6a989ab6f..098a4dbb4f8 100644 --- a/advisories/unreviewed/2023/10/GHSA-xwf2-9m25-2hpf/GHSA-xwf2-9m25-2hpf.json +++ b/advisories/unreviewed/2023/10/GHSA-xwf2-9m25-2hpf/GHSA-xwf2-9m25-2hpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwf2-9m25-2hpf", - "modified": "2023-11-14T03:30:53Z", + "modified": "2024-09-23T18:30:32Z", "published": "2023-10-01T03:30:18Z", "aliases": [ "CVE-2023-43907" diff --git a/advisories/unreviewed/2024/06/GHSA-7w82-8h79-m4wp/GHSA-7w82-8h79-m4wp.json b/advisories/unreviewed/2024/06/GHSA-7w82-8h79-m4wp/GHSA-7w82-8h79-m4wp.json index b8424d016a7..6dd6547365d 100644 --- a/advisories/unreviewed/2024/06/GHSA-7w82-8h79-m4wp/GHSA-7w82-8h79-m4wp.json +++ b/advisories/unreviewed/2024/06/GHSA-7w82-8h79-m4wp/GHSA-7w82-8h79-m4wp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w82-8h79-m4wp", - "modified": "2024-06-17T18:31:35Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-06-17T18:31:35Z", "aliases": [ "CVE-2024-6056" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -40,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/07/GHSA-gv63-8gqg-3525/GHSA-gv63-8gqg-3525.json b/advisories/unreviewed/2024/07/GHSA-gv63-8gqg-3525/GHSA-gv63-8gqg-3525.json index 4ab0081155d..9022bd2525f 100644 --- a/advisories/unreviewed/2024/07/GHSA-gv63-8gqg-3525/GHSA-gv63-8gqg-3525.json +++ b/advisories/unreviewed/2024/07/GHSA-gv63-8gqg-3525/GHSA-gv63-8gqg-3525.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv63-8gqg-3525", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-6326" ], "details": "An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-23qc-7hjx-vwmv/GHSA-23qc-7hjx-vwmv.json b/advisories/unreviewed/2024/09/GHSA-23qc-7hjx-vwmv/GHSA-23qc-7hjx-vwmv.json new file mode 100644 index 00000000000..1b1606a528f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-23qc-7hjx-vwmv/GHSA-23qc-7hjx-vwmv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23qc-7hjx-vwmv", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-34331" + ], + "details": "A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34331" + }, + { + "type": "WEB", + "url": "https://kb.parallels.com/129860" + }, + { + "type": "WEB", + "url": "https://khronokernel.com/macos/2024/05/30/CVE-2024-34331.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2gm9-phpp-rvm3/GHSA-2gm9-phpp-rvm3.json b/advisories/unreviewed/2024/09/GHSA-2gm9-phpp-rvm3/GHSA-2gm9-phpp-rvm3.json index 05cdb69a363..4ec4d1db221 100644 --- a/advisories/unreviewed/2024/09/GHSA-2gm9-phpp-rvm3/GHSA-2gm9-phpp-rvm3.json +++ b/advisories/unreviewed/2024/09/GHSA-2gm9-phpp-rvm3/GHSA-2gm9-phpp-rvm3.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2h8m-mjqv-x98p/GHSA-2h8m-mjqv-x98p.json b/advisories/unreviewed/2024/09/GHSA-2h8m-mjqv-x98p/GHSA-2h8m-mjqv-x98p.json index fb92765221e..e22078ab962 100644 --- a/advisories/unreviewed/2024/09/GHSA-2h8m-mjqv-x98p/GHSA-2h8m-mjqv-x98p.json +++ b/advisories/unreviewed/2024/09/GHSA-2h8m-mjqv-x98p/GHSA-2h8m-mjqv-x98p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h8m-mjqv-x98p", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46773" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator pbn_div before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 1 DIVIDE_BY_ZERO issue reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json b/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json index 4d4fd154784..747d6bf58c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json +++ b/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hj6-cwhm-rfg9", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46103" ], "details": "SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-39rx-hmmc-q5pv/GHSA-39rx-hmmc-q5pv.json b/advisories/unreviewed/2024/09/GHSA-39rx-hmmc-q5pv/GHSA-39rx-hmmc-q5pv.json new file mode 100644 index 00000000000..7a826841196 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-39rx-hmmc-q5pv/GHSA-39rx-hmmc-q5pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39rx-hmmc-q5pv", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-41228" + ], + "details": "A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41228" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cafan/68ed2d065a4b9c1c37c70a18077ad27b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4366-c9hw-r9qg/GHSA-4366-c9hw-r9qg.json b/advisories/unreviewed/2024/09/GHSA-4366-c9hw-r9qg/GHSA-4366-c9hw-r9qg.json index 1b1aa72fe89..2b2bf9eabf1 100644 --- a/advisories/unreviewed/2024/09/GHSA-4366-c9hw-r9qg/GHSA-4366-c9hw-r9qg.json +++ b/advisories/unreviewed/2024/09/GHSA-4366-c9hw-r9qg/GHSA-4366-c9hw-r9qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4366-c9hw-r9qg", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46762" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Fix possible access to a freed kirqfd instance\n\nNothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and\nprivcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd\ncreated and added to the irqfds_list by privcmd_irqfd_assign() may get\nremoved by another thread executing privcmd_irqfd_deassign(), while the\nformer is still using it after dropping the locks.\n\nThis can lead to a situation where an already freed kirqfd instance may\nbe accessed and cause kernel oops.\n\nUse SRCU locking to prevent the same, as is done for the KVM\nimplementation for irqfds.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json index 6896ae1f7f3..1d9874b2c6a 100644 --- a/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json +++ b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-473p-xqgv-xxw3", - "modified": "2024-09-17T21:30:33Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-09-17T21:30:33Z", "aliases": [ "CVE-2024-8909" ], "details": "Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-58mw-2g79-hjm6/GHSA-58mw-2g79-hjm6.json b/advisories/unreviewed/2024/09/GHSA-58mw-2g79-hjm6/GHSA-58mw-2g79-hjm6.json index a4ad9510266..3f0715b402a 100644 --- a/advisories/unreviewed/2024/09/GHSA-58mw-2g79-hjm6/GHSA-58mw-2g79-hjm6.json +++ b/advisories/unreviewed/2024/09/GHSA-58mw-2g79-hjm6/GHSA-58mw-2g79-hjm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58mw-2g79-hjm6", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46759" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adc128d818) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-632r-423p-9jx4/GHSA-632r-423p-9jx4.json b/advisories/unreviewed/2024/09/GHSA-632r-423p-9jx4/GHSA-632r-423p-9jx4.json index d5360eb9d8f..e755a17161f 100644 --- a/advisories/unreviewed/2024/09/GHSA-632r-423p-9jx4/GHSA-632r-423p-9jx4.json +++ b/advisories/unreviewed/2024/09/GHSA-632r-423p-9jx4/GHSA-632r-423p-9jx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-632r-423p-9jx4", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46779" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Free pvr_vm_gpuva after unlink\n\nThis caused a measurable memory leak. Although the individual\nallocations are small, the leaks occurs in a high-usage codepath\n(remapping or unmapping device memory) so they add up quickly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json b/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json index 266b4290674..e504ffbd367 100644 --- a/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json +++ b/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-6f62-3596-g6w7/GHSA-6f62-3596-g6w7.json b/advisories/unreviewed/2024/09/GHSA-6f62-3596-g6w7/GHSA-6f62-3596-g6w7.json index c8258dd7a4e..c46a6ebbb8b 100644 --- a/advisories/unreviewed/2024/09/GHSA-6f62-3596-g6w7/GHSA-6f62-3596-g6w7.json +++ b/advisories/unreviewed/2024/09/GHSA-6f62-3596-g6w7/GHSA-6f62-3596-g6w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f62-3596-g6w7", - "modified": "2024-09-22T03:30:30Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-22T03:30:30Z", "aliases": [ "CVE-2024-47220" ], "details": "An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., \"GET /admin HTTP/1.1\\r\\n\" inside of a \"POST /user HTTP/1.1\\r\\n\" request. NOTE: the supplier's position is \"Webrick should not be used in production.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-22T01:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json b/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json index 9e2adf7f253..e9987083c2d 100644 --- a/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json +++ b/advisories/unreviewed/2024/09/GHSA-6gcw-xcpf-vr88/GHSA-6gcw-xcpf-vr88.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6gcw-xcpf-vr88", - "modified": "2024-09-19T18:30:52Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8651" ], "details": "A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-6vq9-c7rm-r447/GHSA-6vq9-c7rm-r447.json b/advisories/unreviewed/2024/09/GHSA-6vq9-c7rm-r447/GHSA-6vq9-c7rm-r447.json index a64db5b6dfc..12f5a2cac39 100644 --- a/advisories/unreviewed/2024/09/GHSA-6vq9-c7rm-r447/GHSA-6vq9-c7rm-r447.json +++ b/advisories/unreviewed/2024/09/GHSA-6vq9-c7rm-r447/GHSA-6vq9-c7rm-r447.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vq9-c7rm-r447", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46760" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: usb: schedule rx work after everything is set up\n\nRight now it's possible to hit NULL pointer dereference in\nrtw_rx_fill_rx_status on hw object and/or its fields because\ninitialization routine can start getting USB replies before\nrtw_dev is fully setup.\n\nThe stack trace looks like this:\n\nrtw_rx_fill_rx_status\nrtw8821c_query_rx_desc\nrtw_usb_rx_handler\n...\nqueue_work\nrtw_usb_read_port_complete\n...\nusb_submit_urb\nrtw_usb_rx_resubmit\nrtw_usb_init_rx\nrtw_usb_probe\n\nSo while we do the async stuff rtw_usb_probe continues and calls\nrtw_register_hw, which does all kinds of initialization (e.g.\nvia ieee80211_register_hw) that rtw_rx_fill_rx_status relies on.\n\nFix this by moving the first usb_submit_urb after everything\nis set up.\n\nFor me, this bug manifested as:\n[ 8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped\n[ 8.910904] rtw_8821cu 1-1:1.2: hw->conf.chandef.chan NULL in rtw_rx_fill_rx_status\nbecause I'm using Larry's backport of rtw88 driver with the NULL\nchecks in rtw_rx_fill_rx_status.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-725j-ffcc-fc53/GHSA-725j-ffcc-fc53.json b/advisories/unreviewed/2024/09/GHSA-725j-ffcc-fc53/GHSA-725j-ffcc-fc53.json index fa7c5c69e4e..bd5180ba5cd 100644 --- a/advisories/unreviewed/2024/09/GHSA-725j-ffcc-fc53/GHSA-725j-ffcc-fc53.json +++ b/advisories/unreviewed/2024/09/GHSA-725j-ffcc-fc53/GHSA-725j-ffcc-fc53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-725j-ffcc-fc53", - "modified": "2024-09-22T03:30:30Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-22T03:30:30Z", "aliases": [ "CVE-2024-47226" ], "details": "A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the \"Configuration History\" feature of the \"Admin\" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the \"Top banner\" field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-22T02:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json b/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json index 82ca3c8d5af..ad7b955f268 100644 --- a/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json +++ b/advisories/unreviewed/2024/09/GHSA-76f7-g9hr-v32c/GHSA-76f7-g9hr-v32c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76f7-g9hr-v32c", - "modified": "2024-09-17T21:30:33Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-17T21:30:33Z", "aliases": [ "CVE-2024-8907" ], "details": "Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json b/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json index c1d3461d703..87520dcd404 100644 --- a/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json +++ b/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hr2-9rf8-gx6q", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46772" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check denominator crb_pipes before used\n\n[WHAT & HOW]\nA denominator cannot be 0, and is checked before used.\n\nThis fixes 2 DIVIDE_BY_ZERO issues reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json b/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json new file mode 100644 index 00000000000..907530ff326 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jvh-4mqp-gf66", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-40441" + ], + "details": "An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40441" + }, + { + "type": "WEB", + "url": "https://github.com/doccano/auto-labeling-pipeline/releases/tag/v0.1.23" + }, + { + "type": "WEB", + "url": "https://github.com/doccano/doccano/releases/tag/v1.8.4" + }, + { + "type": "WEB", + "url": "https://github.com/gian2dchris/CVEs/tree/main/CVE-2024-40441" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json index ab3f5360d29..d520161df11 100644 --- a/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json +++ b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-86wc-gr98-6p59", - "modified": "2024-09-17T21:30:33Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-09-17T21:30:33Z", "aliases": [ "CVE-2024-8908" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8qj3-h82r-hcwc/GHSA-8qj3-h82r-hcwc.json b/advisories/unreviewed/2024/09/GHSA-8qj3-h82r-hcwc/GHSA-8qj3-h82r-hcwc.json index ae14de3f606..66952c5271f 100644 --- a/advisories/unreviewed/2024/09/GHSA-8qj3-h82r-hcwc/GHSA-8qj3-h82r-hcwc.json +++ b/advisories/unreviewed/2024/09/GHSA-8qj3-h82r-hcwc/GHSA-8qj3-h82r-hcwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qj3-h82r-hcwc", - "modified": "2024-09-21T12:30:44Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-21T12:30:44Z", "aliases": [ "CVE-2024-42323" ], "details": "SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). \n\nThis vulnerability can only be exploited by authorized attackers.\nThis issue affects Apache HertzBeat (incubating): before 1.6.0.\n\nUsers are recommended to upgrade to version 1.6.0, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-21T10:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json b/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json index aec333a6031..eab8bc7554f 100644 --- a/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json +++ b/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-9f66-cv49-738x/GHSA-9f66-cv49-738x.json b/advisories/unreviewed/2024/09/GHSA-9f66-cv49-738x/GHSA-9f66-cv49-738x.json index 3d65d12e1a4..9aee506ee12 100644 --- a/advisories/unreviewed/2024/09/GHSA-9f66-cv49-738x/GHSA-9f66-cv49-738x.json +++ b/advisories/unreviewed/2024/09/GHSA-9f66-cv49-738x/GHSA-9f66-cv49-738x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f66-cv49-738x", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: call nf_unregister_net_hooks() sooner\n\nsyzbot found an use-after-free Read in ila_nf_input [1]\n\nIssue here is that ila_xlat_exit_net() frees the rhashtable,\nthen call nf_unregister_net_hooks().\n\nIt should be done in the reverse way, with a synchronize_rcu().\n\nThis is a good match for a pre_exit() method.\n\n[1]\n BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\nRead of size 4 at addr ffff888064620008 by task ksoftirqd/0/16\n\nCPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n __rhashtable_lookup include/linux/rhashtable.h:604 [inline]\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672\n ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:132 [inline]\n ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]\n ila_nf_input+0x1fe/0x3c0 net/ipv6/ila/ila_xlat.c:190\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook include/linux/netfilter.h:269 [inline]\n NF_HOOK+0x29e/0x450 include/linux/netfilter.h:312\n __netif_receive_skb_one_core net/core/dev.c:5661 [inline]\n __netif_receive_skb+0x1ea/0x650 net/core/dev.c:5775\n process_backlog+0x662/0x15b0 net/core/dev.c:6108\n __napi_poll+0xcb/0x490 net/core/dev.c:6772\n napi_poll net/core/dev.c:6841 [inline]\n net_rx_action+0x89b/0x1240 net/core/dev.c:6963\n handle_softirqs+0x2c4/0x970 kernel/softirq.c:554\n run_ksoftirqd+0xca/0x130 kernel/softirq.c:928\n smpboot_thread_fn+0x544/0xa30 kernel/smpboot.c:164\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x64620\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\npage_type: 0xbfffffff(buddy)\nraw: 00fff00000000000 ffffea0000959608 ffffea00019d9408 0000000000000000\nraw: 0000000000000000 0000000000000003 00000000bfffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 3, migratetype Unmovable, gfp_mask 0x52dc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_ZERO), pid 5242, tgid 5242 (syz-executor), ts 73611328570, free_ts 618981657187\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1493\n prep_new_page mm/page_alloc.c:1501 [inline]\n get_page_from_freelist+0x2e4c/0x2f10 mm/page_alloc.c:3439\n __alloc_pages_noprof+0x256/0x6c0 mm/page_alloc.c:4695\n __alloc_pages_node_noprof include/linux/gfp.h:269 [inline]\n alloc_pages_node_noprof include/linux/gfp.h:296 [inline]\n ___kmalloc_large_node+0x8b/0x1d0 mm/slub.c:4103\n __kmalloc_large_node_noprof+0x1a/0x80 mm/slub.c:4130\n __do_kmalloc_node mm/slub.c:4146 [inline]\n __kmalloc_node_noprof+0x2d2/0x440 mm/slub.c:4164\n __kvmalloc_node_noprof+0x72/0x190 mm/util.c:650\n bucket_table_alloc lib/rhashtable.c:186 [inline]\n rhashtable_init_noprof+0x534/0xa60 lib/rhashtable.c:1071\n ila_xlat_init_net+0xa0/0x110 net/ipv6/ila/ila_xlat.c:613\n ops_ini\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9p6f-43f7-gmq3/GHSA-9p6f-43f7-gmq3.json b/advisories/unreviewed/2024/09/GHSA-9p6f-43f7-gmq3/GHSA-9p6f-43f7-gmq3.json index eaeb6fb46f4..588c04e1d78 100644 --- a/advisories/unreviewed/2024/09/GHSA-9p6f-43f7-gmq3/GHSA-9p6f-43f7-gmq3.json +++ b/advisories/unreviewed/2024/09/GHSA-9p6f-43f7-gmq3/GHSA-9p6f-43f7-gmq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9p6f-43f7-gmq3", - "modified": "2024-09-22T03:30:30Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-22T03:30:30Z", "aliases": [ "CVE-2024-47218" ], "details": "An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-22T01:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json b/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json index 91bc7162ef8..5ef908ea73c 100644 --- a/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json +++ b/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c83g-2v28-2jp8", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46640" ], "details": "SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cpj4-mrcc-fc7h/GHSA-cpj4-mrcc-fc7h.json b/advisories/unreviewed/2024/09/GHSA-cpj4-mrcc-fc7h/GHSA-cpj4-mrcc-fc7h.json new file mode 100644 index 00000000000..e7681b59a6f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cpj4-mrcc-fc7h/GHSA-cpj4-mrcc-fc7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpj4-mrcc-fc7h", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-0001" + ], + "details": "A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0001" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f99c-r797-v657/GHSA-f99c-r797-v657.json b/advisories/unreviewed/2024/09/GHSA-f99c-r797-v657/GHSA-f99c-r797-v657.json index 6dcfcb7c06b..76735645622 100644 --- a/advisories/unreviewed/2024/09/GHSA-f99c-r797-v657/GHSA-f99c-r797-v657.json +++ b/advisories/unreviewed/2024/09/GHSA-f99c-r797-v657/GHSA-f99c-r797-v657.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f99c-r797-v657", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46756" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83627ehf) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fhq8-gx6w-r3rj/GHSA-fhq8-gx6w-r3rj.json b/advisories/unreviewed/2024/09/GHSA-fhq8-gx6w-r3rj/GHSA-fhq8-gx6w-r3rj.json new file mode 100644 index 00000000000..108e9a08d7b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fhq8-gx6w-r3rj/GHSA-fhq8-gx6w-r3rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhq8-gx6w-r3rj", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-0003" + ], + "details": "A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0003" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h5qj-jjhh-95x5/GHSA-h5qj-jjhh-95x5.json b/advisories/unreviewed/2024/09/GHSA-h5qj-jjhh-95x5/GHSA-h5qj-jjhh-95x5.json index 36fcb331f28..68f5c2318b4 100644 --- a/advisories/unreviewed/2024/09/GHSA-h5qj-jjhh-95x5/GHSA-h5qj-jjhh-95x5.json +++ b/advisories/unreviewed/2024/09/GHSA-h5qj-jjhh-95x5/GHSA-h5qj-jjhh-95x5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5qj-jjhh-95x5", - "modified": "2024-09-23T06:30:41Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-23T06:30:41Z", "aliases": [ "CVE-2024-7846" ], "details": "YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T06:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h9h6-4wfq-8vwm/GHSA-h9h6-4wfq-8vwm.json b/advisories/unreviewed/2024/09/GHSA-h9h6-4wfq-8vwm/GHSA-h9h6-4wfq-8vwm.json new file mode 100644 index 00000000000..8a0302dfa97 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h9h6-4wfq-8vwm/GHSA-h9h6-4wfq-8vwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9h6-4wfq-8vwm", + "modified": "2024-09-23T18:30:35Z", + "published": "2024-09-23T18:30:35Z", + "aliases": [ + "CVE-2024-0004" + ], + "details": "A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0004" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json b/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json index 2c8a8bce893..2b3bc49245b 100644 --- a/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json +++ b/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9ph-w4hg-9mjw", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46101" ], "details": "GDidees CMS <= v3.9.1 has a file upload vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json b/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json new file mode 100644 index 00000000000..b111160c1f2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hc48-m7gp-vcrj/GHSA-hc48-m7gp-vcrj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc48-m7gp-vcrj", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2023-46948" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46948" + }, + { + "type": "WEB", + "url": "https://github.com/AzraelsBlade/CVE-2023-46948" + }, + { + "type": "WEB", + "url": "http://temenos.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json b/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json new file mode 100644 index 00000000000..0040a0181f1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jm9x-rx9x-wpqj/GHSA-jm9x-rx9x-wpqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm9x-rx9x-wpqj", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-9014" + ], + "details": "pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9014" + }, + { + "type": "WEB", + "url": "https://github.com/pgadmin-org/pgadmin4/issues/7945" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mf8x-9rcg-p86q/GHSA-mf8x-9rcg-p86q.json b/advisories/unreviewed/2024/09/GHSA-mf8x-9rcg-p86q/GHSA-mf8x-9rcg-p86q.json index 052f9b64a6c..4886a4d0bbc 100644 --- a/advisories/unreviewed/2024/09/GHSA-mf8x-9rcg-p86q/GHSA-mf8x-9rcg-p86q.json +++ b/advisories/unreviewed/2024/09/GHSA-mf8x-9rcg-p86q/GHSA-mf8x-9rcg-p86q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf8x-9rcg-p86q", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46761" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npci/hotplug/pnv_php: Fix hotplug driver crash on Powernv\n\nThe hotplug driver for powerpc (pci/hotplug/pnv_php.c) causes a kernel\ncrash when we try to hot-unplug/disable the PCIe switch/bridge from\nthe PHB.\n\nThe crash occurs because although the MSI data structure has been\nreleased during disable/hot-unplug path and it has been assigned\nwith NULL, still during unregistration the code was again trying to\nexplicitly disable the MSI which causes the NULL pointer dereference and\nkernel crash.\n\nThe patch fixes the check during unregistration path to prevent invoking\npci_disable_msi/msix() since its data structure is already freed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json b/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json index f6d644a5b19..722e1456ba6 100644 --- a/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json +++ b/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxj5-w2rm-4rhf", - "modified": "2024-09-23T15:31:00Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-23T15:31:00Z", "aliases": [ "CVE-2024-46241" ], "details": "PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T13:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json b/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json index 86862ae7b31..2b870d60b3f 100644 --- a/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json +++ b/advisories/unreviewed/2024/09/GHSA-pwh3-mj55-39cv/GHSA-pwh3-mj55-39cv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwh3-mj55-39cv", - "modified": "2024-09-19T18:30:52Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8653" ], "details": "A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-q6vw-x86f-x8m4/GHSA-q6vw-x86f-x8m4.json b/advisories/unreviewed/2024/09/GHSA-q6vw-x86f-x8m4/GHSA-q6vw-x86f-x8m4.json new file mode 100644 index 00000000000..cafe6529eaf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q6vw-x86f-x8m4/GHSA-q6vw-x86f-x8m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6vw-x86f-x8m4", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-0005" + ], + "details": "A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0005" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json b/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json index 376c81b19a2..369af862b36 100644 --- a/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json +++ b/advisories/unreviewed/2024/09/GHSA-qchx-h2pq-fhfp/GHSA-qchx-h2pq-fhfp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qchx-h2pq-fhfp", - "modified": "2024-09-19T18:30:52Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-19T18:30:52Z", "aliases": [ "CVE-2024-8652" ], "details": "A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site.\nThis issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.\n\nApply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-qrrh-7fhh-g486/GHSA-qrrh-7fhh-g486.json b/advisories/unreviewed/2024/09/GHSA-qrrh-7fhh-g486/GHSA-qrrh-7fhh-g486.json index cd2c99b4345..720c62cb95a 100644 --- a/advisories/unreviewed/2024/09/GHSA-qrrh-7fhh-g486/GHSA-qrrh-7fhh-g486.json +++ b/advisories/unreviewed/2024/09/GHSA-qrrh-7fhh-g486/GHSA-qrrh-7fhh-g486.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrrh-7fhh-g486", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46763" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix null-ptr-deref in GRO.\n\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\na host. [0]\n\nThe NULL pointer is sk->sk_user_data, and the offset 8 is of protocol\nin struct fou.\n\nWhen fou_release() is called due to netns dismantle or explicit tunnel\nteardown, udp_tunnel_sock_release() sets NULL to sk->sk_user_data.\nThen, the tunnel socket is destroyed after a single RCU grace period.\n\nSo, in-flight udp4_gro_receive() could find the socket and execute the\nFOU GRO handler, where sk->sk_user_data could be NULL.\n\nLet's use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL\nchecks in FOU GRO handlers.\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0\nSMP PTI\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1\nHardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017\nRIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou]\nCode: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 <0f> b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42\nRSP: 0018:ffffa330c0003d08 EFLAGS: 00010297\nRAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010\nRDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08\nRBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002\nR10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400\nR13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0\nFS: 0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? no_context (arch/x86/mm/fault.c:752)\n ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483)\n ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571)\n ? fou_gro_receive (net/ipv4/fou.c:233) [fou]\n udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559)\n udp4_gro_receive (net/ipv4/udp_offload.c:604)\n inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7))\n dev_gro_receive (net/core/dev.c:6035 (discriminator 4))\n napi_gro_receive (net/core/dev.c:6170)\n ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena]\n ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena]\n napi_poll (net/core/dev.c:6847)\n net_rx_action (net/core/dev.c:6917)\n __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299)\n asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809)\n\n do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77)\n irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435)\n common_interrupt (arch/x86/kernel/irq.c:239)\n asm_common_interrupt (arch/x86/include/asm/idtentry.h:626)\nRIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575)\nCode: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00\nRSP: 0018:ffffffffb5603e58 EFLAGS: 00000246\nRAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900\nRDX: ffff93daee800000 RSI: ffff93d\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qv7g-5jm3-2q8q/GHSA-qv7g-5jm3-2q8q.json b/advisories/unreviewed/2024/09/GHSA-qv7g-5jm3-2q8q/GHSA-qv7g-5jm3-2q8q.json index e441503e940..9f1af5567e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-qv7g-5jm3-2q8q/GHSA-qv7g-5jm3-2q8q.json +++ b/advisories/unreviewed/2024/09/GHSA-qv7g-5jm3-2q8q/GHSA-qv7g-5jm3-2q8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qv7g-5jm3-2q8q", - "modified": "2024-09-22T00:30:49Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-22T00:30:49Z", "aliases": [ "CVE-2024-47210" ], "details": "Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-21T23:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rm2h-fhqm-923f/GHSA-rm2h-fhqm-923f.json b/advisories/unreviewed/2024/09/GHSA-rm2h-fhqm-923f/GHSA-rm2h-fhqm-923f.json index 9179506736f..cd0b3f4f275 100644 --- a/advisories/unreviewed/2024/09/GHSA-rm2h-fhqm-923f/GHSA-rm2h-fhqm-923f.json +++ b/advisories/unreviewed/2024/09/GHSA-rm2h-fhqm-923f/GHSA-rm2h-fhqm-923f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rm2h-fhqm-923f", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: move netif_queue_set_napi to rtnl-protected sections\n\nCurrently, netif_queue_set_napi() is called from ice_vsi_rebuild() that is\nnot rtnl-locked when called from the reset. This creates the need to take\nthe rtnl_lock just for a single function and complicates the\nsynchronization with .ndo_bpf. At the same time, there no actual need to\nfill napi-to-queue information at this exact point.\n\nFill napi-to-queue information when opening the VSI and clear it when the\nVSI is being closed. Those routines are already rtnl-locked.\n\nAlso, rewrite napi-to-queue assignment in a way that prevents inclusion of\nXDP queues, as this leads to out-of-bounds writes, such as one below.\n\n[ +0.000004] BUG: KASAN: slab-out-of-bounds in netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000012] Write of size 8 at addr ffff889881727c80 by task bash/7047\n[ +0.000006] CPU: 24 PID: 7047 Comm: bash Not tainted 6.10.0-rc2+ #2\n[ +0.000004] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000003] Call Trace:\n[ +0.000003] \n[ +0.000002] dump_stack_lvl+0x60/0x80\n[ +0.000007] print_report+0xce/0x630\n[ +0.000007] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ +0.000007] ? __virt_addr_valid+0x1c9/0x2c0\n[ +0.000005] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000003] kasan_report+0xe9/0x120\n[ +0.000004] ? netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000004] netif_queue_set_napi+0x1c2/0x1e0\n[ +0.000005] ice_vsi_close+0x161/0x670 [ice]\n[ +0.000114] ice_dis_vsi+0x22f/0x270 [ice]\n[ +0.000095] ice_pf_dis_all_vsi.constprop.0+0xae/0x1c0 [ice]\n[ +0.000086] ice_prepare_for_reset+0x299/0x750 [ice]\n[ +0.000087] pci_dev_save_and_disable+0x82/0xd0\n[ +0.000006] pci_reset_function+0x12d/0x230\n[ +0.000004] reset_store+0xa0/0x100\n[ +0.000006] ? __pfx_reset_store+0x10/0x10\n[ +0.000002] ? __pfx_mutex_lock+0x10/0x10\n[ +0.000004] ? __check_object_size+0x4c1/0x640\n[ +0.000007] kernfs_fop_write_iter+0x30b/0x4a0\n[ +0.000006] vfs_write+0x5d6/0xdf0\n[ +0.000005] ? fd_install+0x180/0x350\n[ +0.000005] ? __pfx_vfs_write+0x10/0xA10\n[ +0.000004] ? do_fcntl+0x52c/0xcd0\n[ +0.000004] ? kasan_save_track+0x13/0x60\n[ +0.000003] ? kasan_save_free_info+0x37/0x60\n[ +0.000006] ksys_write+0xfa/0x1d0\n[ +0.000003] ? __pfx_ksys_write+0x10/0x10\n[ +0.000002] ? __x64_sys_fcntl+0x121/0x180\n[ +0.000004] ? _raw_spin_lock+0x87/0xe0\n[ +0.000005] do_syscall_64+0x80/0x170\n[ +0.000007] ? _raw_spin_lock+0x87/0xe0\n[ +0.000004] ? __pfx__raw_spin_lock+0x10/0x10\n[ +0.000003] ? file_close_fd_locked+0x167/0x230\n[ +0.000005] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000005] ? do_syscall_64+0x8c/0x170\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? fput+0x1a/0x2c0\n[ +0.000004] ? filp_close+0x19/0x30\n[ +0.000004] ? do_dup2+0x25a/0x4c0\n[ +0.000004] ? __x64_sys_dup2+0x6e/0x2e0\n[ +0.000002] ? syscall_exit_to_user_mode+0x7d/0x220\n[ +0.000004] ? do_syscall_64+0x8c/0x170\n[ +0.000003] ? __count_memcg_events+0x113/0x380\n[ +0.000005] ? handle_mm_fault+0x136/0x820\n[ +0.000005] ? do_user_addr_fault+0x444/0xa80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000004] ? clear_bhb_loop+0x25/0x80\n[ +0.000002] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000005] RIP: 0033:0x7f2033593154", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rqgx-3q58-h4h3/GHSA-rqgx-3q58-h4h3.json b/advisories/unreviewed/2024/09/GHSA-rqgx-3q58-h4h3/GHSA-rqgx-3q58-h4h3.json index f14947118d6..098a416e4b2 100644 --- a/advisories/unreviewed/2024/09/GHSA-rqgx-3q58-h4h3/GHSA-rqgx-3q58-h4h3.json +++ b/advisories/unreviewed/2024/09/GHSA-rqgx-3q58-h4h3/GHSA-rqgx-3q58-h4h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqgx-3q58-h4h3", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46799" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX\n\nIf number of TX queues are set to 1 we get a NULL pointer\ndereference during XDP_TX.\n\n~# ethtool -L eth0 tx 1\n~# ./xdp-trafficgen udp -A -a eth0 -t 2\nTransmitting on eth0 (ifindex 2)\n[ 241.135257] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030\n\nFix this by using actual TX queues instead of max TX queues\nwhen picking the TX channel in am65_cpsw_ndo_xdp_xmit().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json b/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json new file mode 100644 index 00000000000..e5520dbd6be --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxmx-cgf3-gfph", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-40442" + ], + "details": "An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40442" + }, + { + "type": "WEB", + "url": "https://github.com/doccano/auto-labeling-pipeline/releases/tag/v0.1.23" + }, + { + "type": "WEB", + "url": "https://github.com/doccano/doccano/releases/tag/v1.8.4" + }, + { + "type": "WEB", + "url": "https://github.com/gian2dchris/CVEs/tree/main/CVE-2024-40442" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vgm9-qpvf-cp5w/GHSA-vgm9-qpvf-cp5w.json b/advisories/unreviewed/2024/09/GHSA-vgm9-qpvf-cp5w/GHSA-vgm9-qpvf-cp5w.json index 46ab2e72066..9e8eba5e084 100644 --- a/advisories/unreviewed/2024/09/GHSA-vgm9-qpvf-cp5w/GHSA-vgm9-qpvf-cp5w.json +++ b/advisories/unreviewed/2024/09/GHSA-vgm9-qpvf-cp5w/GHSA-vgm9-qpvf-cp5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgm9-qpvf-cp5w", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46758" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm95234) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vh32-2cmq-5xpc/GHSA-vh32-2cmq-5xpc.json b/advisories/unreviewed/2024/09/GHSA-vh32-2cmq-5xpc/GHSA-vh32-2cmq-5xpc.json index e290ad3364a..d739f15f997 100644 --- a/advisories/unreviewed/2024/09/GHSA-vh32-2cmq-5xpc/GHSA-vh32-2cmq-5xpc.json +++ b/advisories/unreviewed/2024/09/GHSA-vh32-2cmq-5xpc/GHSA-vh32-2cmq-5xpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh32-2cmq-5xpc", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46757" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Fix underflows seen when writing limit attributes\n\nDIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large\nnegative number such as -9223372036854775808 is provided by the user.\nFix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json b/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json index 92426ddcd07..982d564cf50 100644 --- a/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json +++ b/advisories/unreviewed/2024/09/GHSA-vh3x-525m-jp4r/GHSA-vh3x-525m-jp4r.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-vm34-2mcq-j9q8/GHSA-vm34-2mcq-j9q8.json b/advisories/unreviewed/2024/09/GHSA-vm34-2mcq-j9q8/GHSA-vm34-2mcq-j9q8.json new file mode 100644 index 00000000000..8e3fdb15886 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vm34-2mcq-j9q8/GHSA-vm34-2mcq-j9q8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm34-2mcq-j9q8", + "modified": "2024-09-23T18:30:34Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-39341" + ], + "details": "Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct IIS webroot path. It includes system configuration parameter names and values with sensitive configuration values encrypted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39341" + }, + { + "type": "WEB", + "url": "https://gist.github.com/VAMorales/21a8700a67d80c263b38e693fd528313" + }, + { + "type": "WEB", + "url": "https://trustedcare.entrust.com/login" + }, + { + "type": "WEB", + "url": "https://www.entrust.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w5jc-3vgp-f4c9/GHSA-w5jc-3vgp-f4c9.json b/advisories/unreviewed/2024/09/GHSA-w5jc-3vgp-f4c9/GHSA-w5jc-3vgp-f4c9.json index ae275e1c4aa..822b7916238 100644 --- a/advisories/unreviewed/2024/09/GHSA-w5jc-3vgp-f4c9/GHSA-w5jc-3vgp-f4c9.json +++ b/advisories/unreviewed/2024/09/GHSA-w5jc-3vgp-f4c9/GHSA-w5jc-3vgp-f4c9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5jc-3vgp-f4c9", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46781" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix missing cleanup on rollforward recovery error\n\nIn an error injection test of a routine for mount-time recovery, KASAN\nfound a use-after-free bug.\n\nIt turned out that if data recovery was performed using partial logs\ncreated by dsync writes, but an error occurred before starting the log\nwriter to create a recovered checkpoint, the inodes whose data had been\nrecovered were left in the ns_dirty_files list of the nilfs object and\nwere not freed.\n\nFix this issue by cleaning up inodes that have read the recovery data if\nthe recovery routine fails midway before the log writer starts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w6wg-4287-f4wf/GHSA-w6wg-4287-f4wf.json b/advisories/unreviewed/2024/09/GHSA-w6wg-4287-f4wf/GHSA-w6wg-4287-f4wf.json index 0e7edd5bd4b..e09b4a66f18 100644 --- a/advisories/unreviewed/2024/09/GHSA-w6wg-4287-f4wf/GHSA-w6wg-4287-f4wf.json +++ b/advisories/unreviewed/2024/09/GHSA-w6wg-4287-f4wf/GHSA-w6wg-4287-f4wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6wg-4287-f4wf", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add netif_device_attach/detach into PF reset flow\n\nEthtool callbacks can be executed while reset is in progress and try to\naccess deleted resources, e.g. getting coalesce settings can result in a\nNULL pointer dereference seen below.\n\nReproduction steps:\nOnce the driver is fully initialized, trigger reset:\n\t# echo 1 > /sys/class/net//device/reset\nwhen reset is in progress try to get coalesce settings using ethtool:\n\t# ethtool -c \n\nBUG: kernel NULL pointer dereference, address: 0000000000000020\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] PREEMPT SMP PTI\nCPU: 11 PID: 19713 Comm: ethtool Tainted: G S 6.10.0-rc7+ #7\nRIP: 0010:ice_get_q_coalesce+0x2e/0xa0 [ice]\nRSP: 0018:ffffbab1e9bcf6a8 EFLAGS: 00010206\nRAX: 000000000000000c RBX: ffff94512305b028 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffff9451c3f2e588 RDI: ffff9451c3f2e588\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffff9451c3f2e580 R11: 000000000000001f R12: ffff945121fa9000\nR13: ffffbab1e9bcf760 R14: 0000000000000013 R15: ffffffff9e65dd40\nFS: 00007faee5fbe740(0000) GS:ffff94546fd80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000020 CR3: 0000000106c2e005 CR4: 00000000001706f0\nCall Trace:\n\nice_get_coalesce+0x17/0x30 [ice]\ncoalesce_prepare_data+0x61/0x80\nethnl_default_doit+0xde/0x340\ngenl_family_rcv_msg_doit+0xf2/0x150\ngenl_rcv_msg+0x1b3/0x2c0\nnetlink_rcv_skb+0x5b/0x110\ngenl_rcv+0x28/0x40\nnetlink_unicast+0x19c/0x290\nnetlink_sendmsg+0x222/0x490\n__sys_sendto+0x1df/0x1f0\n__x64_sys_sendto+0x24/0x30\ndo_syscall_64+0x82/0x160\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7faee60d8e27\n\nCalling netif_device_detach() before reset makes the net core not call\nthe driver when ethtool command is issued, the attempt to execute an\nethtool command during reset will result in the following message:\n\n netlink error: No such device\n\ninstead of NULL pointer dereference. Once reset is done and\nice_rebuild() is executing, the netif_device_attach() is called to allow\nfor ethtool operations to occur again in a safe manner.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json b/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json new file mode 100644 index 00000000000..d0cda6a11d9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wg8v-xr35-c5fj/GHSA-wg8v-xr35-c5fj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg8v-xr35-c5fj", + "modified": "2024-09-23T18:30:35Z", + "published": "2024-09-23T18:30:35Z", + "aliases": [ + "CVE-2024-39342" + ], + "details": "Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software. Combined with the encrypted password that can be obtained from \"WebAPI.cfg.xml\" in CVE-2024-39341, the decryption is trivial and can lead to privilege escalation on the Windows host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39342" + }, + { + "type": "WEB", + "url": "https://gist.github.com/VAMorales/21a8700a67d80c263b38e693fd528313" + }, + { + "type": "WEB", + "url": "https://trustedcare.entrust.com/login" + }, + { + "type": "WEB", + "url": "https://www.entrust.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json b/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json index 0d7c85f9b17..8eb99ff816b 100644 --- a/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json +++ b/advisories/unreviewed/2024/09/GHSA-wq22-3j46-hjmw/GHSA-wq22-3j46-hjmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq22-3j46-hjmw", - "modified": "2024-09-17T21:30:33Z", + "modified": "2024-09-23T18:30:33Z", "published": "2024-09-17T21:30:33Z", "aliases": [ "CVE-2024-8906" ], "details": "Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-ww64-xcqm-5jhf/GHSA-ww64-xcqm-5jhf.json b/advisories/unreviewed/2024/09/GHSA-ww64-xcqm-5jhf/GHSA-ww64-xcqm-5jhf.json new file mode 100644 index 00000000000..5bdf28b21ec --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ww64-xcqm-5jhf/GHSA-ww64-xcqm-5jhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww64-xcqm-5jhf", + "modified": "2024-09-23T18:30:35Z", + "published": "2024-09-23T18:30:34Z", + "aliases": [ + "CVE-2024-0002" + ], + "details": "A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0002" + }, + { + "type": "WEB", + "url": "https://purestorage.com/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json index 004deda4a70..8f1db56581f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json +++ b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xh89-f5vr-hmhw", - "modified": "2024-09-20T18:32:26Z", + "modified": "2024-09-23T18:30:34Z", "published": "2024-09-20T18:32:26Z", "aliases": [ "CVE-2024-46652" ], "details": "Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T16:15:05Z"