From f51bbf2d6b69e7c9c2a833297e28ee095d6f4647 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 31 Oct 2024 06:31:43 +0000 Subject: [PATCH] Publish Advisories GHSA-6wvf-f2vw-3425 GHSA-mc76-5925-c5p6 GHSA-578w-c832-xrgc GHSA-fjcx-qrhr-v7rr GHSA-fq9m-v26v-2m4f GHSA-wq2p-5pc6-wpgf --- .../GHSA-6wvf-f2vw-3425.json | 8 ++- .../GHSA-mc76-5925-c5p6.json | 6 ++- .../GHSA-578w-c832-xrgc.json | 46 +++++++++++++++++ .../GHSA-fjcx-qrhr-v7rr.json | 42 ++++++++++++++++ .../GHSA-fq9m-v26v-2m4f.json | 50 +++++++++++++++++++ .../GHSA-wq2p-5pc6-wpgf.json | 6 ++- 6 files changed, 154 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-578w-c832-xrgc/GHSA-578w-c832-xrgc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fjcx-qrhr-v7rr/GHSA-fjcx-qrhr-v7rr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fq9m-v26v-2m4f/GHSA-fq9m-v26v-2m4f.json diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index cf2504daeea..d0a06f34f9d 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-10-24T18:30:41Z", + "modified": "2024-10-31T06:30:45Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -88,7 +88,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:0045" + "url": "https://access.redhat.com/errata/RHSA-2024:8425" }, { "type": "WEB", @@ -146,6 +146,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0045" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3718" diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index 4ecb3ee6b87..d596ede8d7b 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-10-24T18:30:41Z", + "modified": "2024-10-31T06:30:45Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8263" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8428" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9341" diff --git a/advisories/unreviewed/2024/10/GHSA-578w-c832-xrgc/GHSA-578w-c832-xrgc.json b/advisories/unreviewed/2024/10/GHSA-578w-c832-xrgc/GHSA-578w-c832-xrgc.json new file mode 100644 index 00000000000..cb03a53f022 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-578w-c832-xrgc/GHSA-578w-c832-xrgc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-578w-c832-xrgc", + "modified": "2024-10-31T06:30:45Z", + "published": "2024-10-31T06:30:45Z", + "aliases": [ + "CVE-2024-9700" + ], + "details": "The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation on the 'entry_id' user controlled key. This makes it possible for unauthenticated attackers to modify other user's quiz submissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9700" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.1/library/modules/quizzes/front/front-action.php#L548" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3172942" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fbed35ca-1630-46a4-8b1f-60cc7216f294?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fjcx-qrhr-v7rr/GHSA-fjcx-qrhr-v7rr.json b/advisories/unreviewed/2024/10/GHSA-fjcx-qrhr-v7rr/GHSA-fjcx-qrhr-v7rr.json new file mode 100644 index 00000000000..16c99ecf5f0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fjcx-qrhr-v7rr/GHSA-fjcx-qrhr-v7rr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjcx-qrhr-v7rr", + "modified": "2024-10-31T06:30:45Z", + "published": "2024-10-31T06:30:45Z", + "aliases": [ + "CVE-2024-10392" + ], + "details": "The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10392" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3176122/gpt3-ai-content-generator#file508" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cd8a45c9-ca48-4ea6-b34e-f05206f16155?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fq9m-v26v-2m4f/GHSA-fq9m-v26v-2m4f.json b/advisories/unreviewed/2024/10/GHSA-fq9m-v26v-2m4f/GHSA-fq9m-v26v-2m4f.json new file mode 100644 index 00000000000..780cbed052e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fq9m-v26v-2m4f/GHSA-fq9m-v26v-2m4f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq9m-v26v-2m4f", + "modified": "2024-10-31T06:30:45Z", + "published": "2024-10-31T06:30:45Z", + "aliases": [ + "CVE-2024-21537" + ], + "details": "Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21537" + }, + { + "type": "WEB", + "url": "https://github.com/antonk52/lilconfig/pull/48" + }, + { + "type": "WEB", + "url": "https://github.com/antonk52/lilconfig/commit/2c68a1ab8764fc74acc46771e1ad39ab07a9b0a7" + }, + { + "type": "WEB", + "url": "https://github.com/antonk52/lilconfig/releases/tag/v3.1.1" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-LILCONFIG-6263789" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T05:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json index 280c20d25fe..049c3ee5bb5 100644 --- a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq2p-5pc6-wpgf", - "modified": "2024-10-30T09:30:47Z", + "modified": "2024-10-31T06:30:45Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-9676" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8418" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8428" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8437"