Publish Advisories

GHSA-6wvf-f2vw-3425
GHSA-mc76-5925-c5p6
GHSA-578w-c832-xrgc
GHSA-fjcx-qrhr-v7rr
GHSA-fq9m-v26v-2m4f
GHSA-wq2p-5pc6-wpgf
This commit is contained in:
advisory-database[bot]
2024-10-31 06:31:43 +00:00
parent 17a0632f53
commit f51bbf2d6b
6 changed files with 154 additions and 4 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wvf-f2vw-3425",
"modified": "2024-10-24T18:30:41Z",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-05-14T18:30:52Z",
"aliases": [
"CVE-2024-3727"
@@ -88,7 +88,7 @@
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0045"
"url": "https://access.redhat.com/errata/RHSA-2024:8425"
},
{
"type": "WEB",
@@ -146,6 +146,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0045"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3718"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc76-5925-c5p6",
"modified": "2024-10-24T18:30:41Z",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-10-01T21:31:34Z",
"aliases": [
"CVE-2024-9341"
@@ -68,6 +68,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8263"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8428"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9341"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-578w-c832-xrgc",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-10-31T06:30:45Z",
"aliases": [
"CVE-2024-9700"
],
"details": "The Forminator Forms Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation on the 'entry_id' user controlled key. This makes it possible for unauthenticated attackers to modify other user's quiz submissions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9700"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.1/library/modules/quizzes/front/front-action.php#L548"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3172942"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fbed35ca-1630-46a4-8b1f-60cc7216f294?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-639"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-31T06:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fjcx-qrhr-v7rr",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-10-31T06:30:45Z",
"aliases": [
"CVE-2024-10392"
],
"details": "The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10392"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3176122/gpt3-ai-content-generator#file508"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cd8a45c9-ca48-4ea6-b34e-f05206f16155?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-31T06:15:04Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq9m-v26v-2m4f",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-10-31T06:30:45Z",
"aliases": [
"CVE-2024-21537"
],
"details": "Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21537"
},
{
"type": "WEB",
"url": "https://github.com/antonk52/lilconfig/pull/48"
},
{
"type": "WEB",
"url": "https://github.com/antonk52/lilconfig/commit/2c68a1ab8764fc74acc46771e1ad39ab07a9b0a7"
},
{
"type": "WEB",
"url": "https://github.com/antonk52/lilconfig/releases/tag/v3.1.1"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-LILCONFIG-6263789"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-31T05:15:04Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq2p-5pc6-wpgf",
"modified": "2024-10-30T09:30:47Z",
"modified": "2024-10-31T06:30:45Z",
"published": "2024-10-15T18:30:50Z",
"aliases": [
"CVE-2024-9676"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8418"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8428"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8437"