From f17be1ab141be8bb28724dbfb9cd3ab7886c4737 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Sep 2024 12:33:24 +0000 Subject: [PATCH] Publish Advisories GHSA-47qg-3w6c-7g7q GHSA-wwfq-hcph-q6fg GHSA-879f-87ww-wcv6 GHSA-279p-8h87-pr33 GHSA-4jfc-52v4-6x58 GHSA-8539-9wvx-7jmj GHSA-jgg6-4c26-32v5 GHSA-3w9h-5fv2-f86j GHSA-5mjm-rg7p-q2rg GHSA-6vw3-qjc8-x8j8 GHSA-rwxw-p86h-g9q6 GHSA-vm99-jjc2-8hw5 --- .../GHSA-47qg-3w6c-7g7q.json | 1 + .../GHSA-wwfq-hcph-q6fg.json | 3 +- .../GHSA-879f-87ww-wcv6.json | 1 + .../GHSA-279p-8h87-pr33.json | 1 + .../GHSA-4jfc-52v4-6x58.json | 1 + .../GHSA-8539-9wvx-7jmj.json | 1 + .../GHSA-jgg6-4c26-32v5.json | 1 + .../GHSA-3w9h-5fv2-f86j.json | 2 +- .../GHSA-5mjm-rg7p-q2rg.json | 1 + .../GHSA-6vw3-qjc8-x8j8.json | 1 + .../GHSA-rwxw-p86h-g9q6.json | 38 +++++++++++++++++++ .../GHSA-vm99-jjc2-8hw5.json | 38 +++++++++++++++++++ 12 files changed, 87 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vm99-jjc2-8hw5/GHSA-vm99-jjc2-8hw5.json diff --git a/advisories/unreviewed/2022/09/GHSA-47qg-3w6c-7g7q/GHSA-47qg-3w6c-7g7q.json b/advisories/unreviewed/2022/09/GHSA-47qg-3w6c-7g7q/GHSA-47qg-3w6c-7g7q.json index 59e09e27c87..1e9cd831c21 100644 --- a/advisories/unreviewed/2022/09/GHSA-47qg-3w6c-7g7q/GHSA-47qg-3w6c-7g7q.json +++ b/advisories/unreviewed/2022/09/GHSA-47qg-3w6c-7g7q/GHSA-47qg-3w6c-7g7q.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/10/GHSA-wwfq-hcph-q6fg/GHSA-wwfq-hcph-q6fg.json b/advisories/unreviewed/2022/10/GHSA-wwfq-hcph-q6fg/GHSA-wwfq-hcph-q6fg.json index 90cb1d24a98..b5990a33485 100644 --- a/advisories/unreviewed/2022/10/GHSA-wwfq-hcph-q6fg/GHSA-wwfq-hcph-q6fg.json +++ b/advisories/unreviewed/2022/10/GHSA-wwfq-hcph-q6fg/GHSA-wwfq-hcph-q6fg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-879f-87ww-wcv6/GHSA-879f-87ww-wcv6.json b/advisories/unreviewed/2022/12/GHSA-879f-87ww-wcv6/GHSA-879f-87ww-wcv6.json index c60bd83a9d8..2f3ef59194e 100644 --- a/advisories/unreviewed/2022/12/GHSA-879f-87ww-wcv6/GHSA-879f-87ww-wcv6.json +++ b/advisories/unreviewed/2022/12/GHSA-879f-87ww-wcv6/GHSA-879f-87ww-wcv6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "LOW", diff --git a/advisories/unreviewed/2023/01/GHSA-279p-8h87-pr33/GHSA-279p-8h87-pr33.json b/advisories/unreviewed/2023/01/GHSA-279p-8h87-pr33/GHSA-279p-8h87-pr33.json index a1004cff81b..293ceb0a966 100644 --- a/advisories/unreviewed/2023/01/GHSA-279p-8h87-pr33/GHSA-279p-8h87-pr33.json +++ b/advisories/unreviewed/2023/01/GHSA-279p-8h87-pr33/GHSA-279p-8h87-pr33.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-294" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-4jfc-52v4-6x58/GHSA-4jfc-52v4-6x58.json b/advisories/unreviewed/2023/01/GHSA-4jfc-52v4-6x58/GHSA-4jfc-52v4-6x58.json index d937782b9c7..2b4bb902744 100644 --- a/advisories/unreviewed/2023/01/GHSA-4jfc-52v4-6x58/GHSA-4jfc-52v4-6x58.json +++ b/advisories/unreviewed/2023/01/GHSA-4jfc-52v4-6x58/GHSA-4jfc-52v4-6x58.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-294" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-8539-9wvx-7jmj/GHSA-8539-9wvx-7jmj.json b/advisories/unreviewed/2023/01/GHSA-8539-9wvx-7jmj/GHSA-8539-9wvx-7jmj.json index 8aab2575717..d45ee59b685 100644 --- a/advisories/unreviewed/2023/01/GHSA-8539-9wvx-7jmj/GHSA-8539-9wvx-7jmj.json +++ b/advisories/unreviewed/2023/01/GHSA-8539-9wvx-7jmj/GHSA-8539-9wvx-7jmj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-jgg6-4c26-32v5/GHSA-jgg6-4c26-32v5.json b/advisories/unreviewed/2023/01/GHSA-jgg6-4c26-32v5/GHSA-jgg6-4c26-32v5.json index 72e7a2da3be..b90d043bbd7 100644 --- a/advisories/unreviewed/2023/01/GHSA-jgg6-4c26-32v5/GHSA-jgg6-4c26-32v5.json +++ b/advisories/unreviewed/2023/01/GHSA-jgg6-4c26-32v5/GHSA-jgg6-4c26-32v5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-3w9h-5fv2-f86j/GHSA-3w9h-5fv2-f86j.json b/advisories/unreviewed/2023/03/GHSA-3w9h-5fv2-f86j/GHSA-3w9h-5fv2-f86j.json index 978c5bec946..31992f5b64f 100644 --- a/advisories/unreviewed/2023/03/GHSA-3w9h-5fv2-f86j/GHSA-3w9h-5fv2-f86j.json +++ b/advisories/unreviewed/2023/03/GHSA-3w9h-5fv2-f86j/GHSA-3w9h-5fv2-f86j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-5mjm-rg7p-q2rg/GHSA-5mjm-rg7p-q2rg.json b/advisories/unreviewed/2023/03/GHSA-5mjm-rg7p-q2rg/GHSA-5mjm-rg7p-q2rg.json index e6ce462827d..a2121c650fa 100644 --- a/advisories/unreviewed/2023/03/GHSA-5mjm-rg7p-q2rg/GHSA-5mjm-rg7p-q2rg.json +++ b/advisories/unreviewed/2023/03/GHSA-5mjm-rg7p-q2rg/GHSA-5mjm-rg7p-q2rg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-476" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/03/GHSA-6vw3-qjc8-x8j8/GHSA-6vw3-qjc8-x8j8.json b/advisories/unreviewed/2023/03/GHSA-6vw3-qjc8-x8j8/GHSA-6vw3-qjc8-x8j8.json index f699b9ca9f1..11e73d6c23b 100644 --- a/advisories/unreviewed/2023/03/GHSA-6vw3-qjc8-x8j8/GHSA-6vw3-qjc8-x8j8.json +++ b/advisories/unreviewed/2023/03/GHSA-6vw3-qjc8-x8j8/GHSA-6vw3-qjc8-x8j8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json b/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json new file mode 100644 index 00000000000..033ccd2c8e4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxw-p86h-g9q6", + "modified": "2024-09-09T12:31:57Z", + "published": "2024-09-09T12:31:57Z", + "aliases": [ + "CVE-2024-6572" + ], + "details": "Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6572" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17148" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-322" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T10:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vm99-jjc2-8hw5/GHSA-vm99-jjc2-8hw5.json b/advisories/unreviewed/2024/09/GHSA-vm99-jjc2-8hw5/GHSA-vm99-jjc2-8hw5.json new file mode 100644 index 00000000000..ce53d168327 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vm99-jjc2-8hw5/GHSA-vm99-jjc2-8hw5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm99-jjc2-8hw5", + "modified": "2024-09-09T12:31:57Z", + "published": "2024-09-09T12:31:57Z", + "aliases": [ + "CVE-2024-8601" + ], + "details": "This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8601" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T10:15:03Z" + } +} \ No newline at end of file