Publish Advisories

GHSA-64mf-xhgv-qwph
GHSA-8w2v-m598-22q3
GHSA-fr4c-ch83-r968
GHSA-gf98-qc2v-6xvh
GHSA-hqhf-c9cf-w4qm
GHSA-hvp9-6mxp-9797
GHSA-p5f2-h5fv-xrrx
GHSA-r69r-g3mg-h539
GHSA-vp6w-3fx2-4f2w
GHSA-w8jp-q8g4-9f42
This commit is contained in:
advisory-database[bot]
2024-10-10 00:33:01 +00:00
parent 82f480253f
commit f556d3aae6
10 changed files with 178 additions and 17 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64mf-xhgv-qwph",
"modified": "2023-03-27T06:30:22Z",
"modified": "2024-10-10T00:31:05Z",
"published": "2023-03-21T21:30:19Z",
"aliases": [
"CVE-2023-1529"
@@ -48,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w2v-m598-22q3",
"modified": "2024-10-09T06:30:23Z",
"modified": "2024-10-10T00:31:06Z",
"published": "2024-10-09T06:30:23Z",
"aliases": [
"CVE-2023-45359"
],
"details": "An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-116"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T06:15:13Z"
@@ -33,6 +33,7 @@
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-78",
"CWE-863"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gf98-qc2v-6xvh",
"modified": "2024-10-09T06:30:23Z",
"modified": "2024-10-10T00:31:05Z",
"published": "2024-10-09T06:30:23Z",
"aliases": [
"CVE-2024-45160"
],
"details": "Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T05:15:13Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqhf-c9cf-w4qm",
"modified": "2024-10-10T00:31:06Z",
"published": "2024-10-10T00:31:06Z",
"aliases": [
"CVE-2024-48942"
],
"details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48942"
},
{
"type": "WEB",
"url": "https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/3236560898/2024-09-16+-+Secure+Login+security+advisory+-+Insecure+default+configuration"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-10T00:15:02Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvp9-6mxp-9797",
"modified": "2024-10-09T06:30:22Z",
"modified": "2024-10-10T00:31:05Z",
"published": "2024-10-09T06:30:22Z",
"aliases": [
"CVE-2024-35288"
],
"details": "Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\\SYSTEM.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T04:15:08Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5f2-h5fv-xrrx",
"modified": "2024-10-10T00:31:06Z",
"published": "2024-10-10T00:31:06Z",
"aliases": [
"CVE-2024-48941"
],
"details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48941"
},
{
"type": "WEB",
"url": "https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/3236560898/2024-09-16+-+Secure+Login+security+advisory+-+Insecure+default+configuration"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-10T00:15:02Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r69r-g3mg-h539",
"modified": "2024-10-10T00:31:06Z",
"published": "2024-10-10T00:31:06Z",
"aliases": [
"CVE-2024-8264"
],
"details": "Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8264"
},
{
"type": "WEB",
"url": "https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm"
},
{
"type": "WEB",
"url": "https://www.fortra.com/security/advisories/product-security/fi-2024-012"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T23:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp6w-3fx2-4f2w",
"modified": "2024-10-10T00:31:06Z",
"published": "2024-10-10T00:31:06Z",
"aliases": [
"CVE-2024-48933"
],
"details": "A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48933"
},
{
"type": "WEB",
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3232"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T23:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8jp-q8g4-9f42",
"modified": "2024-10-09T06:30:23Z",
"modified": "2024-10-10T00:31:05Z",
"published": "2024-10-09T06:30:23Z",
"aliases": [
"CVE-2024-47191"
],
"details": "pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-09T05:15:13Z"