From ed55c3bb46267bbab960f1ea9e2f26388318eee3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 13 Sep 2024 00:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-43pr-r6xw-f56v GHSA-jf4r-vjvc-pj36 GHSA-jpgp-pmqh-538w GHSA-v66p-q797-c8vm GHSA-w7wj-5p2p-g7p7 GHSA-22q6-7m3g-6r77 GHSA-35pg-8ph2-rp9c GHSA-c4q5-vjmp-xrgv GHSA-f53w-fw63-qjpw GHSA-g7wm-3q7g-g3q2 GHSA-m2jf-3295-7fpm GHSA-mrr5-8hm7-42xh GHSA-pcxj-w6pv-x9c5 GHSA-qfx3-m2xp-3pcp GHSA-v7mj-q2hh-7r72 GHSA-w8hf-8rpm-xjp2 GHSA-wfg8-6fh4-8fp9 GHSA-x4fw-fhfj-vm7c --- .../GHSA-43pr-r6xw-f56v.json | 2 +- .../GHSA-jf4r-vjvc-pj36.json | 2 +- .../GHSA-jpgp-pmqh-538w.json | 2 +- .../GHSA-v66p-q797-c8vm.json | 11 ++-- .../GHSA-w7wj-5p2p-g7p7.json | 2 +- .../GHSA-22q6-7m3g-6r77.json | 2 +- .../GHSA-35pg-8ph2-rp9c.json | 2 +- .../GHSA-c4q5-vjmp-xrgv.json | 11 ++-- .../GHSA-f53w-fw63-qjpw.json | 2 +- .../GHSA-g7wm-3q7g-g3q2.json | 2 +- .../GHSA-m2jf-3295-7fpm.json | 54 +++++++++++++++++++ .../GHSA-mrr5-8hm7-42xh.json | 11 ++-- .../GHSA-pcxj-w6pv-x9c5.json | 2 +- .../GHSA-qfx3-m2xp-3pcp.json | 2 +- .../GHSA-v7mj-q2hh-7r72.json | 2 +- .../GHSA-w8hf-8rpm-xjp2.json | 2 +- .../GHSA-wfg8-6fh4-8fp9.json | 2 +- .../GHSA-x4fw-fhfj-vm7c.json | 2 +- 18 files changed, 89 insertions(+), 26 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-m2jf-3295-7fpm/GHSA-m2jf-3295-7fpm.json diff --git a/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json b/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json index fe340edbcfe..98018e3f8f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json +++ b/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json b/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json index e27be2e4bea..28dfcd309e3 100644 --- a/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json +++ b/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json b/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json index 5eac217366a..58573bf1fc6 100644 --- a/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json +++ b/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-v66p-q797-c8vm/GHSA-v66p-q797-c8vm.json b/advisories/unreviewed/2024/08/GHSA-v66p-q797-c8vm/GHSA-v66p-q797-c8vm.json index 55d4bc5f9ff..d6580d11405 100644 --- a/advisories/unreviewed/2024/08/GHSA-v66p-q797-c8vm/GHSA-v66p-q797-c8vm.json +++ b/advisories/unreviewed/2024/08/GHSA-v66p-q797-c8vm/GHSA-v66p-q797-c8vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v66p-q797-c8vm", - "modified": "2024-08-28T06:30:31Z", + "modified": "2024-09-13T00:30:47Z", "published": "2024-08-28T06:30:31Z", "aliases": [ "CVE-2024-39771" ], "details": "QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-28T06:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json b/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json index 8b8a9cb6708..0ed7c841166 100644 --- a/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json +++ b/advisories/unreviewed/2024/08/GHSA-w7wj-5p2p-g7p7/GHSA-w7wj-5p2p-g7p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7wj-5p2p-g7p7", - "modified": "2024-08-27T09:30:44Z", + "modified": "2024-09-13T00:30:46Z", "published": "2024-08-27T09:30:44Z", "aliases": [ "CVE-2024-7304" diff --git a/advisories/unreviewed/2024/09/GHSA-22q6-7m3g-6r77/GHSA-22q6-7m3g-6r77.json b/advisories/unreviewed/2024/09/GHSA-22q6-7m3g-6r77/GHSA-22q6-7m3g-6r77.json index 186944c2766..38e70f8f7e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-22q6-7m3g-6r77/GHSA-22q6-7m3g-6r77.json +++ b/advisories/unreviewed/2024/09/GHSA-22q6-7m3g-6r77/GHSA-22q6-7m3g-6r77.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-35pg-8ph2-rp9c/GHSA-35pg-8ph2-rp9c.json b/advisories/unreviewed/2024/09/GHSA-35pg-8ph2-rp9c/GHSA-35pg-8ph2-rp9c.json index 4e9d29e7519..af8b666d362 100644 --- a/advisories/unreviewed/2024/09/GHSA-35pg-8ph2-rp9c/GHSA-35pg-8ph2-rp9c.json +++ b/advisories/unreviewed/2024/09/GHSA-35pg-8ph2-rp9c/GHSA-35pg-8ph2-rp9c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json b/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json index 4b8b98e1fe0..0132418231b 100644 --- a/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json +++ b/advisories/unreviewed/2024/09/GHSA-c4q5-vjmp-xrgv/GHSA-c4q5-vjmp-xrgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4q5-vjmp-xrgv", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-13T00:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-34335" ], "details": "ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T19:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f53w-fw63-qjpw/GHSA-f53w-fw63-qjpw.json b/advisories/unreviewed/2024/09/GHSA-f53w-fw63-qjpw/GHSA-f53w-fw63-qjpw.json index f78686d297f..c5c658e8b8a 100644 --- a/advisories/unreviewed/2024/09/GHSA-f53w-fw63-qjpw/GHSA-f53w-fw63-qjpw.json +++ b/advisories/unreviewed/2024/09/GHSA-f53w-fw63-qjpw/GHSA-f53w-fw63-qjpw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g7wm-3q7g-g3q2/GHSA-g7wm-3q7g-g3q2.json b/advisories/unreviewed/2024/09/GHSA-g7wm-3q7g-g3q2/GHSA-g7wm-3q7g-g3q2.json index 364ff41af7c..7860b2e1c07 100644 --- a/advisories/unreviewed/2024/09/GHSA-g7wm-3q7g-g3q2/GHSA-g7wm-3q7g-g3q2.json +++ b/advisories/unreviewed/2024/09/GHSA-g7wm-3q7g-g3q2/GHSA-g7wm-3q7g-g3q2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-m2jf-3295-7fpm/GHSA-m2jf-3295-7fpm.json b/advisories/unreviewed/2024/09/GHSA-m2jf-3295-7fpm/GHSA-m2jf-3295-7fpm.json new file mode 100644 index 00000000000..433820653da --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m2jf-3295-7fpm/GHSA-m2jf-3295-7fpm.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2jf-3295-7fpm", + "modified": "2024-09-13T00:30:48Z", + "published": "2024-09-13T00:30:48Z", + "aliases": [ + "CVE-2024-8751" + ], + "details": "A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP\naddress over Sopas ET. \nThis can lead to Denial of Service. \nUsers are recommended to upgrade both\nMSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively which fixes this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8751" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-12T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json b/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json index 0b00d9bb61f..5c02b239e59 100644 --- a/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json +++ b/advisories/unreviewed/2024/09/GHSA-mrr5-8hm7-42xh/GHSA-mrr5-8hm7-42xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrr5-8hm7-42xh", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-13T00:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-34334" ], "details": "ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T19:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pcxj-w6pv-x9c5/GHSA-pcxj-w6pv-x9c5.json b/advisories/unreviewed/2024/09/GHSA-pcxj-w6pv-x9c5/GHSA-pcxj-w6pv-x9c5.json index 70d279ef20c..79dc38d012c 100644 --- a/advisories/unreviewed/2024/09/GHSA-pcxj-w6pv-x9c5/GHSA-pcxj-w6pv-x9c5.json +++ b/advisories/unreviewed/2024/09/GHSA-pcxj-w6pv-x9c5/GHSA-pcxj-w6pv-x9c5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-qfx3-m2xp-3pcp/GHSA-qfx3-m2xp-3pcp.json b/advisories/unreviewed/2024/09/GHSA-qfx3-m2xp-3pcp/GHSA-qfx3-m2xp-3pcp.json index 72f4b0cdfbc..02aba739b25 100644 --- a/advisories/unreviewed/2024/09/GHSA-qfx3-m2xp-3pcp/GHSA-qfx3-m2xp-3pcp.json +++ b/advisories/unreviewed/2024/09/GHSA-qfx3-m2xp-3pcp/GHSA-qfx3-m2xp-3pcp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-v7mj-q2hh-7r72/GHSA-v7mj-q2hh-7r72.json b/advisories/unreviewed/2024/09/GHSA-v7mj-q2hh-7r72/GHSA-v7mj-q2hh-7r72.json index 852dc3f7a5b..8356835a8d0 100644 --- a/advisories/unreviewed/2024/09/GHSA-v7mj-q2hh-7r72/GHSA-v7mj-q2hh-7r72.json +++ b/advisories/unreviewed/2024/09/GHSA-v7mj-q2hh-7r72/GHSA-v7mj-q2hh-7r72.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-w8hf-8rpm-xjp2/GHSA-w8hf-8rpm-xjp2.json b/advisories/unreviewed/2024/09/GHSA-w8hf-8rpm-xjp2/GHSA-w8hf-8rpm-xjp2.json index cb1a8940ba4..90b6f8f3d9e 100644 --- a/advisories/unreviewed/2024/09/GHSA-w8hf-8rpm-xjp2/GHSA-w8hf-8rpm-xjp2.json +++ b/advisories/unreviewed/2024/09/GHSA-w8hf-8rpm-xjp2/GHSA-w8hf-8rpm-xjp2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-wfg8-6fh4-8fp9/GHSA-wfg8-6fh4-8fp9.json b/advisories/unreviewed/2024/09/GHSA-wfg8-6fh4-8fp9/GHSA-wfg8-6fh4-8fp9.json index 8a9b07cb4f5..1300650fef2 100644 --- a/advisories/unreviewed/2024/09/GHSA-wfg8-6fh4-8fp9/GHSA-wfg8-6fh4-8fp9.json +++ b/advisories/unreviewed/2024/09/GHSA-wfg8-6fh4-8fp9/GHSA-wfg8-6fh4-8fp9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x4fw-fhfj-vm7c/GHSA-x4fw-fhfj-vm7c.json b/advisories/unreviewed/2024/09/GHSA-x4fw-fhfj-vm7c/GHSA-x4fw-fhfj-vm7c.json index aa34be247ac..8f6545cc6cf 100644 --- a/advisories/unreviewed/2024/09/GHSA-x4fw-fhfj-vm7c/GHSA-x4fw-fhfj-vm7c.json +++ b/advisories/unreviewed/2024/09/GHSA-x4fw-fhfj-vm7c/GHSA-x4fw-fhfj-vm7c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false,