From f1474f9d5f094e27a7a019ee49f32f050d5381ad Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Sep 2024 15:32:05 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rxjp-mfm9-w4wr.json | 88 +++++++++++-------- .../GHSA-4w2g-c9v6-pgv7.json | 3 +- .../GHSA-45cq-w2jp-hqp4.json | 6 +- .../GHSA-c36w-mp78-5hh7.json | 6 +- .../GHSA-6jj2-r9fx-9gjp.json | 2 +- .../GHSA-892w-q9hr-hm9c.json | 2 +- .../GHSA-j2mj-6c7w-rh5m.json | 3 +- .../GHSA-gg49-9gcv-q853.json | 3 +- .../GHSA-786h-39x7-jgmj.json | 5 +- .../GHSA-5h3m-5ghj-mxmp.json | 3 +- .../GHSA-2j44-h693-7vr3.json | 1 + .../GHSA-qqxr-mg6r-r64p.json | 1 + .../GHSA-2j93-f5f2-6wjx.json | 3 +- .../GHSA-2w3g-r4c9-2jp8.json | 3 +- .../GHSA-35m6-rf3v-8cxx.json | 7 +- .../GHSA-rr32-xpf4-hwj6.json | 3 +- .../GHSA-4qgh-57c7-qfq2.json | 5 +- .../GHSA-53jq-549v-3fjg.json | 3 +- .../GHSA-2hc5-mf64-rr7f.json | 2 +- .../GHSA-2jgc-rcc5-7q6j.json | 11 ++- .../GHSA-62hc-56xq-xr7v.json | 2 +- .../GHSA-7gm4-4495-5666.json | 3 +- .../GHSA-7jh5-4v2p-wf2g.json | 58 ++++++++++++ .../GHSA-9mq4-v89w-jpc7.json | 2 +- .../GHSA-c3g9-g75h-v935.json | 58 ++++++++++++ .../GHSA-cx4g-pmv3-xm3p.json | 2 +- .../GHSA-g766-f3jj-h73r.json | 1 + .../GHSA-gmcc-j293-2h95.json | 1 + .../GHSA-j7pq-m5hr-75w6.json | 58 ++++++++++++ .../GHSA-jpqh-5rm6-j8j7.json | 11 ++- .../GHSA-qv7w-6485-fqmq.json | 58 ++++++++++++ .../GHSA-r7mf-5w8w-4x2h.json | 2 +- .../GHSA-rggq-pvh6-78hv.json | 11 ++- .../GHSA-w784-6hh8-995v.json | 6 +- 34 files changed, 359 insertions(+), 74 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-7jh5-4v2p-wf2g/GHSA-7jh5-4v2p-wf2g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c3g9-g75h-v935/GHSA-c3g9-g75h-v935.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j7pq-m5hr-75w6/GHSA-j7pq-m5hr-75w6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qv7w-6485-fqmq/GHSA-qv7w-6485-fqmq.json diff --git a/advisories/github-reviewed/2021/06/GHSA-rxjp-mfm9-w4wr/GHSA-rxjp-mfm9-w4wr.json b/advisories/github-reviewed/2021/06/GHSA-rxjp-mfm9-w4wr/GHSA-rxjp-mfm9-w4wr.json index a1f6ea9fd03..ec59353efd6 100644 --- a/advisories/github-reviewed/2021/06/GHSA-rxjp-mfm9-w4wr/GHSA-rxjp-mfm9-w4wr.json +++ b/advisories/github-reviewed/2021/06/GHSA-rxjp-mfm9-w4wr/GHSA-rxjp-mfm9-w4wr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rxjp-mfm9-w4wr", - "modified": "2024-04-22T22:53:38Z", + "modified": "2024-09-20T15:30:29Z", "published": "2021-06-04T21:15:56Z", "aliases": [ "CVE-2021-31542" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -25,7 +29,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.2.0" + "introduced": "2.2" }, { "fixed": "2.2.21" @@ -44,7 +48,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "3.0.0" + "introduced": "3.0" }, { "fixed": "3.1.9" @@ -63,7 +67,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "3.2.0" + "introduced": "3.2" }, { "fixed": "3.2.1" @@ -92,39 +96,7 @@ }, { "type": "WEB", - "url": "https://docs.djangoproject.com/en/3.2/releases/security" - }, - { - "type": "PACKAGE", - "url": "https://github.com/django/django" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#!forum/django-announce" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#%21forum/django-announce" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00005.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE" + "url": "https://www.djangoproject.com/weblog/2021/may/04/security-releases" }, { "type": "WEB", @@ -132,7 +104,47 @@ }, { "type": "WEB", - "url": "https://www.djangoproject.com/weblog/2021/may/04/security-releases" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00005.html" + }, + { + "type": "WEB", + "url": "https://groups.google.com/forum/#%21forum/django-announce" + }, + { + "type": "WEB", + "url": "https://groups.google.com/forum/#!forum/django-announce" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-7.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/django/django" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-rxjp-mfm9-w4wr" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/3.2/releases/security" }, { "type": "WEB", diff --git a/advisories/unreviewed/2023/07/GHSA-4w2g-c9v6-pgv7/GHSA-4w2g-c9v6-pgv7.json b/advisories/unreviewed/2023/07/GHSA-4w2g-c9v6-pgv7/GHSA-4w2g-c9v6-pgv7.json index d98c2b92523..9ab67d2f487 100644 --- a/advisories/unreviewed/2023/07/GHSA-4w2g-c9v6-pgv7/GHSA-4w2g-c9v6-pgv7.json +++ b/advisories/unreviewed/2023/07/GHSA-4w2g-c9v6-pgv7/GHSA-4w2g-c9v6-pgv7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-426" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-45cq-w2jp-hqp4/GHSA-45cq-w2jp-hqp4.json b/advisories/unreviewed/2023/08/GHSA-45cq-w2jp-hqp4/GHSA-45cq-w2jp-hqp4.json index 328070b7771..326314d7afd 100644 --- a/advisories/unreviewed/2023/08/GHSA-45cq-w2jp-hqp4/GHSA-45cq-w2jp-hqp4.json +++ b/advisories/unreviewed/2023/08/GHSA-45cq-w2jp-hqp4/GHSA-45cq-w2jp-hqp4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45cq-w2jp-hqp4", - "modified": "2024-04-04T06:43:37Z", + "modified": "2024-09-20T15:30:35Z", "published": "2023-08-09T09:30:33Z", "aliases": [ "CVE-2023-24477" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-c36w-mp78-5hh7/GHSA-c36w-mp78-5hh7.json b/advisories/unreviewed/2023/09/GHSA-c36w-mp78-5hh7/GHSA-c36w-mp78-5hh7.json index 47b956bf20b..9986f3abad2 100644 --- a/advisories/unreviewed/2023/09/GHSA-c36w-mp78-5hh7/GHSA-c36w-mp78-5hh7.json +++ b/advisories/unreviewed/2023/09/GHSA-c36w-mp78-5hh7/GHSA-c36w-mp78-5hh7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c36w-mp78-5hh7", - "modified": "2024-04-04T07:43:52Z", + "modified": "2024-09-20T15:30:35Z", "published": "2023-09-19T12:30:30Z", "aliases": [ "CVE-2023-2567" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-6jj2-r9fx-9gjp/GHSA-6jj2-r9fx-9gjp.json b/advisories/unreviewed/2023/10/GHSA-6jj2-r9fx-9gjp/GHSA-6jj2-r9fx-9gjp.json index beb55b77382..a826fb7752d 100644 --- a/advisories/unreviewed/2023/10/GHSA-6jj2-r9fx-9gjp/GHSA-6jj2-r9fx-9gjp.json +++ b/advisories/unreviewed/2023/10/GHSA-6jj2-r9fx-9gjp/GHSA-6jj2-r9fx-9gjp.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-892w-q9hr-hm9c/GHSA-892w-q9hr-hm9c.json b/advisories/unreviewed/2023/10/GHSA-892w-q9hr-hm9c/GHSA-892w-q9hr-hm9c.json index 7c1ab82d0ea..020dad883d4 100644 --- a/advisories/unreviewed/2023/10/GHSA-892w-q9hr-hm9c/GHSA-892w-q9hr-hm9c.json +++ b/advisories/unreviewed/2023/10/GHSA-892w-q9hr-hm9c/GHSA-892w-q9hr-hm9c.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-114" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-j2mj-6c7w-rh5m/GHSA-j2mj-6c7w-rh5m.json b/advisories/unreviewed/2023/10/GHSA-j2mj-6c7w-rh5m/GHSA-j2mj-6c7w-rh5m.json index 9262584dec0..c26952656fb 100644 --- a/advisories/unreviewed/2023/10/GHSA-j2mj-6c7w-rh5m/GHSA-j2mj-6c7w-rh5m.json +++ b/advisories/unreviewed/2023/10/GHSA-j2mj-6c7w-rh5m/GHSA-j2mj-6c7w-rh5m.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-288" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-gg49-9gcv-q853/GHSA-gg49-9gcv-q853.json b/advisories/unreviewed/2023/11/GHSA-gg49-9gcv-q853/GHSA-gg49-9gcv-q853.json index bf668a4cdf4..3c7cdc3d6c6 100644 --- a/advisories/unreviewed/2023/11/GHSA-gg49-9gcv-q853/GHSA-gg49-9gcv-q853.json +++ b/advisories/unreviewed/2023/11/GHSA-gg49-9gcv-q853/GHSA-gg49-9gcv-q853.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg49-9gcv-q853", - "modified": "2023-11-15T00:31:08Z", + "modified": "2024-09-20T15:30:35Z", "published": "2023-11-15T00:31:08Z", "aliases": [ "CVE-2023-43588" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-449", "CWE-691" ], "severity": "LOW", diff --git a/advisories/unreviewed/2023/12/GHSA-786h-39x7-jgmj/GHSA-786h-39x7-jgmj.json b/advisories/unreviewed/2023/12/GHSA-786h-39x7-jgmj/GHSA-786h-39x7-jgmj.json index 86fb01a0f06..7a9a0d9014a 100644 --- a/advisories/unreviewed/2023/12/GHSA-786h-39x7-jgmj/GHSA-786h-39x7-jgmj.json +++ b/advisories/unreviewed/2023/12/GHSA-786h-39x7-jgmj/GHSA-786h-39x7-jgmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-786h-39x7-jgmj", - "modified": "2023-12-14T00:30:26Z", + "modified": "2024-09-20T15:30:35Z", "published": "2023-12-14T00:30:26Z", "aliases": [ "CVE-2023-49646" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5h3m-5ghj-mxmp/GHSA-5h3m-5ghj-mxmp.json b/advisories/unreviewed/2024/01/GHSA-5h3m-5ghj-mxmp/GHSA-5h3m-5ghj-mxmp.json index f6a45de7a22..bea58a44bdd 100644 --- a/advisories/unreviewed/2024/01/GHSA-5h3m-5ghj-mxmp/GHSA-5h3m-5ghj-mxmp.json +++ b/advisories/unreviewed/2024/01/GHSA-5h3m-5ghj-mxmp/GHSA-5h3m-5ghj-mxmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5h3m-5ghj-mxmp", - "modified": "2024-01-13T00:30:25Z", + "modified": "2024-09-20T15:30:35Z", "published": "2024-01-13T00:30:25Z", "aliases": [ "CVE-2023-49647" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-266", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-2j44-h693-7vr3/GHSA-2j44-h693-7vr3.json b/advisories/unreviewed/2024/02/GHSA-2j44-h693-7vr3/GHSA-2j44-h693-7vr3.json index 24e4b398bb7..13972898921 100644 --- a/advisories/unreviewed/2024/02/GHSA-2j44-h693-7vr3/GHSA-2j44-h693-7vr3.json +++ b/advisories/unreviewed/2024/02/GHSA-2j44-h693-7vr3/GHSA-2j44-h693-7vr3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-176", "CWE-20" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-qqxr-mg6r-r64p/GHSA-qqxr-mg6r-r64p.json b/advisories/unreviewed/2024/02/GHSA-qqxr-mg6r-r64p/GHSA-qqxr-mg6r-r64p.json index 36881402dd9..738a9ab57b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-qqxr-mg6r-r64p/GHSA-qqxr-mg6r-r64p.json +++ b/advisories/unreviewed/2024/02/GHSA-qqxr-mg6r-r64p/GHSA-qqxr-mg6r-r64p.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-2j93-f5f2-6wjx/GHSA-2j93-f5f2-6wjx.json b/advisories/unreviewed/2024/03/GHSA-2j93-f5f2-6wjx/GHSA-2j93-f5f2-6wjx.json index 75de97875ee..7e39bf25add 100644 --- a/advisories/unreviewed/2024/03/GHSA-2j93-f5f2-6wjx/GHSA-2j93-f5f2-6wjx.json +++ b/advisories/unreviewed/2024/03/GHSA-2j93-f5f2-6wjx/GHSA-2j93-f5f2-6wjx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-379" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json b/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json index eb6a542c05b..a362be5c452 100644 --- a/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json +++ b/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json b/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json index c1013bd99b3..8e9e975aa15 100644 --- a/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json +++ b/advisories/unreviewed/2024/04/GHSA-35m6-rf3v-8cxx/GHSA-35m6-rf3v-8cxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35m6-rf3v-8cxx", - "modified": "2024-04-10T18:30:47Z", + "modified": "2024-09-20T15:30:36Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-0218" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1286", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json b/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json index 13cca280d51..c88b29b074e 100644 --- a/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json +++ b/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4qgh-57c7-qfq2/GHSA-4qgh-57c7-qfq2.json b/advisories/unreviewed/2024/05/GHSA-4qgh-57c7-qfq2/GHSA-4qgh-57c7-qfq2.json index f8fce7d0933..3620264d4aa 100644 --- a/advisories/unreviewed/2024/05/GHSA-4qgh-57c7-qfq2/GHSA-4qgh-57c7-qfq2.json +++ b/advisories/unreviewed/2024/05/GHSA-4qgh-57c7-qfq2/GHSA-4qgh-57c7-qfq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qgh-57c7-qfq2", - "modified": "2024-05-15T21:31:26Z", + "modified": "2024-09-20T15:30:35Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-27243" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-122" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-53jq-549v-3fjg/GHSA-53jq-549v-3fjg.json b/advisories/unreviewed/2024/05/GHSA-53jq-549v-3fjg/GHSA-53jq-549v-3fjg.json index 8f8bcd94f31..60c9fb7d82e 100644 --- a/advisories/unreviewed/2024/05/GHSA-53jq-549v-3fjg/GHSA-53jq-549v-3fjg.json +++ b/advisories/unreviewed/2024/05/GHSA-53jq-549v-3fjg/GHSA-53jq-549v-3fjg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-345" + "CWE-345", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json b/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json index 93a150a6a1d..fbacac201a4 100644 --- a/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json +++ b/advisories/unreviewed/2024/09/GHSA-2hc5-mf64-rr7f/GHSA-2hc5-mf64-rr7f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2jgc-rcc5-7q6j/GHSA-2jgc-rcc5-7q6j.json b/advisories/unreviewed/2024/09/GHSA-2jgc-rcc5-7q6j/GHSA-2jgc-rcc5-7q6j.json index a2198eee143..475b8a968dc 100644 --- a/advisories/unreviewed/2024/09/GHSA-2jgc-rcc5-7q6j/GHSA-2jgc-rcc5-7q6j.json +++ b/advisories/unreviewed/2024/09/GHSA-2jgc-rcc5-7q6j/GHSA-2jgc-rcc5-7q6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jgc-rcc5-7q6j", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-20T15:30:37Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2024-46959" ], "details": "runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T18:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json b/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json index 9110ae81213..56fb9241e1e 100644 --- a/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json +++ b/advisories/unreviewed/2024/09/GHSA-62hc-56xq-xr7v/GHSA-62hc-56xq-xr7v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7gm4-4495-5666/GHSA-7gm4-4495-5666.json b/advisories/unreviewed/2024/09/GHSA-7gm4-4495-5666/GHSA-7gm4-4495-5666.json index 3d439e269d1..50177152097 100644 --- a/advisories/unreviewed/2024/09/GHSA-7gm4-4495-5666/GHSA-7gm4-4495-5666.json +++ b/advisories/unreviewed/2024/09/GHSA-7gm4-4495-5666/GHSA-7gm4-4495-5666.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7jh5-4v2p-wf2g/GHSA-7jh5-4v2p-wf2g.json b/advisories/unreviewed/2024/09/GHSA-7jh5-4v2p-wf2g/GHSA-7jh5-4v2p-wf2g.json new file mode 100644 index 00000000000..2a0273df90a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7jh5-4v2p-wf2g/GHSA-7jh5-4v2p-wf2g.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jh5-4v2p-wf2g", + "modified": "2024-09-20T15:30:37Z", + "published": "2024-09-20T15:30:37Z", + "aliases": [ + "CVE-2024-9032" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9032" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.410976" + }, + { + "type": "WEB", + "url": "https://www.shawroot.cc/2804.html" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json b/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json index 404bbc74360..f9eba2dc7fd 100644 --- a/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json +++ b/advisories/unreviewed/2024/09/GHSA-9mq4-v89w-jpc7/GHSA-9mq4-v89w-jpc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mq4-v89w-jpc7", - "modified": "2024-09-09T21:31:23Z", + "modified": "2024-09-20T15:30:36Z", "published": "2024-09-09T21:31:23Z", "aliases": [ "CVE-2024-6795" diff --git a/advisories/unreviewed/2024/09/GHSA-c3g9-g75h-v935/GHSA-c3g9-g75h-v935.json b/advisories/unreviewed/2024/09/GHSA-c3g9-g75h-v935/GHSA-c3g9-g75h-v935.json new file mode 100644 index 00000000000..4061aefb697 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c3g9-g75h-v935/GHSA-c3g9-g75h-v935.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3g9-g75h-v935", + "modified": "2024-09-20T15:30:37Z", + "published": "2024-09-20T15:30:37Z", + "aliases": [ + "CVE-2024-9033" + ], + "details": "A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_category. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9033" + }, + { + "type": "WEB", + "url": "https://github.com/para-paradise/webray.com.cn/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Best%20house%20rental%20management%20system%20project%20in%20php%20Stored%20Cross-Site%20Scripting(XSS)%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.410977" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json b/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json index bf42f606be0..41ab9b4e585 100644 --- a/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json +++ b/advisories/unreviewed/2024/09/GHSA-cx4g-pmv3-xm3p/GHSA-cx4g-pmv3-xm3p.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g766-f3jj-h73r/GHSA-g766-f3jj-h73r.json b/advisories/unreviewed/2024/09/GHSA-g766-f3jj-h73r/GHSA-g766-f3jj-h73r.json index 1e54170d81b..351f6139876 100644 --- a/advisories/unreviewed/2024/09/GHSA-g766-f3jj-h73r/GHSA-g766-f3jj-h73r.json +++ b/advisories/unreviewed/2024/09/GHSA-g766-f3jj-h73r/GHSA-g766-f3jj-h73r.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json b/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json index 31338c40794..12020a9caeb 100644 --- a/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json +++ b/advisories/unreviewed/2024/09/GHSA-gmcc-j293-2h95/GHSA-gmcc-j293-2h95.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-j7pq-m5hr-75w6/GHSA-j7pq-m5hr-75w6.json b/advisories/unreviewed/2024/09/GHSA-j7pq-m5hr-75w6/GHSA-j7pq-m5hr-75w6.json new file mode 100644 index 00000000000..73b842f83f4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j7pq-m5hr-75w6/GHSA-j7pq-m5hr-75w6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7pq-m5hr-75w6", + "modified": "2024-09-20T15:30:37Z", + "published": "2024-09-20T15:30:37Z", + "aliases": [ + "CVE-2024-9034" + ], + "details": "A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9034" + }, + { + "type": "WEB", + "url": "https://github.com/keepgoing2077/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278204" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278204" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jpqh-5rm6-j8j7/GHSA-jpqh-5rm6-j8j7.json b/advisories/unreviewed/2024/09/GHSA-jpqh-5rm6-j8j7/GHSA-jpqh-5rm6-j8j7.json index 7a0d3c121d7..061bf02b14c 100644 --- a/advisories/unreviewed/2024/09/GHSA-jpqh-5rm6-j8j7/GHSA-jpqh-5rm6-j8j7.json +++ b/advisories/unreviewed/2024/09/GHSA-jpqh-5rm6-j8j7/GHSA-jpqh-5rm6-j8j7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jpqh-5rm6-j8j7", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-20T15:30:37Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2023-41612" ], "details": "Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qv7w-6485-fqmq/GHSA-qv7w-6485-fqmq.json b/advisories/unreviewed/2024/09/GHSA-qv7w-6485-fqmq/GHSA-qv7w-6485-fqmq.json new file mode 100644 index 00000000000..baa066ccebe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qv7w-6485-fqmq/GHSA-qv7w-6485-fqmq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv7w-6485-fqmq", + "modified": "2024-09-20T15:30:37Z", + "published": "2024-09-20T15:30:37Z", + "aliases": [ + "CVE-2024-9035" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9035" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Kinsomnia/cve/blob/main/sql/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278205" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278205" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json index 491c923616f..c10bf32ae08 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json +++ b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7mf-5w8w-4x2h", - "modified": "2024-09-19T09:36:03Z", + "modified": "2024-09-20T15:30:37Z", "published": "2024-09-19T06:31:36Z", "aliases": [ "CVE-2024-47085" diff --git a/advisories/unreviewed/2024/09/GHSA-rggq-pvh6-78hv/GHSA-rggq-pvh6-78hv.json b/advisories/unreviewed/2024/09/GHSA-rggq-pvh6-78hv/GHSA-rggq-pvh6-78hv.json index 472e1361531..5e8b5fcd4a2 100644 --- a/advisories/unreviewed/2024/09/GHSA-rggq-pvh6-78hv/GHSA-rggq-pvh6-78hv.json +++ b/advisories/unreviewed/2024/09/GHSA-rggq-pvh6-78hv/GHSA-rggq-pvh6-78hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rggq-pvh6-78hv", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-20T15:30:37Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2024-45523" ], "details": "An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.7.x before 12.7.1.38241. An unauthenticated attacker can cause a resource leak by issuing multiple failed login attempts through API SOAP.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T18:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json b/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json index 6bccad01146..438a14476c1 100644 --- a/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json +++ b/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w784-6hh8-995v", - "modified": "2024-09-16T15:32:47Z", + "modified": "2024-09-20T15:30:37Z", "published": "2024-09-16T15:32:47Z", "aliases": [ "CVE-2024-7104" ], "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.This issue affects ww.Winsure: before 4.6.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"