diff --git a/advisories/unreviewed/2023/03/GHSA-64mf-xhgv-qwph/GHSA-64mf-xhgv-qwph.json b/advisories/unreviewed/2023/03/GHSA-64mf-xhgv-qwph/GHSA-64mf-xhgv-qwph.json index ffab3368f2d..9a0b47287b6 100644 --- a/advisories/unreviewed/2023/03/GHSA-64mf-xhgv-qwph/GHSA-64mf-xhgv-qwph.json +++ b/advisories/unreviewed/2023/03/GHSA-64mf-xhgv-qwph/GHSA-64mf-xhgv-qwph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-64mf-xhgv-qwph", - "modified": "2023-03-27T06:30:22Z", + "modified": "2024-10-10T00:31:05Z", "published": "2023-03-21T21:30:19Z", "aliases": [ "CVE-2023-1529" @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8w2v-m598-22q3/GHSA-8w2v-m598-22q3.json b/advisories/unreviewed/2024/10/GHSA-8w2v-m598-22q3/GHSA-8w2v-m598-22q3.json index faa111aaea6..470983eb175 100644 --- a/advisories/unreviewed/2024/10/GHSA-8w2v-m598-22q3/GHSA-8w2v-m598-22q3.json +++ b/advisories/unreviewed/2024/10/GHSA-8w2v-m598-22q3/GHSA-8w2v-m598-22q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w2v-m598-22q3", - "modified": "2024-10-09T06:30:23Z", + "modified": "2024-10-10T00:31:06Z", "published": "2024-10-09T06:30:23Z", "aliases": [ "CVE-2023-45359" ], "details": "An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T06:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json b/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json index abd6d2e2b02..8a7b1c64994 100644 --- a/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json +++ b/advisories/unreviewed/2024/10/GHSA-fr4c-ch83-r968/GHSA-fr4c-ch83-r968.json @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-284", + "CWE-78", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/10/GHSA-gf98-qc2v-6xvh/GHSA-gf98-qc2v-6xvh.json b/advisories/unreviewed/2024/10/GHSA-gf98-qc2v-6xvh/GHSA-gf98-qc2v-6xvh.json index ae9f5dfa65a..ae4a2f20421 100644 --- a/advisories/unreviewed/2024/10/GHSA-gf98-qc2v-6xvh/GHSA-gf98-qc2v-6xvh.json +++ b/advisories/unreviewed/2024/10/GHSA-gf98-qc2v-6xvh/GHSA-gf98-qc2v-6xvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf98-qc2v-6xvh", - "modified": "2024-10-09T06:30:23Z", + "modified": "2024-10-10T00:31:05Z", "published": "2024-10-09T06:30:23Z", "aliases": [ "CVE-2024-45160" ], "details": "Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T05:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json b/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json new file mode 100644 index 00000000000..075c9833f3b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqhf-c9cf-w4qm", + "modified": "2024-10-10T00:31:06Z", + "published": "2024-10-10T00:31:06Z", + "aliases": [ + "CVE-2024-48942" + ], + "details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48942" + }, + { + "type": "WEB", + "url": "https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/3236560898/2024-09-16+-+Secure+Login+security+advisory+-+Insecure+default+configuration" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T00:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hvp9-6mxp-9797/GHSA-hvp9-6mxp-9797.json b/advisories/unreviewed/2024/10/GHSA-hvp9-6mxp-9797/GHSA-hvp9-6mxp-9797.json index 2e62f7b7b4e..05130263c60 100644 --- a/advisories/unreviewed/2024/10/GHSA-hvp9-6mxp-9797/GHSA-hvp9-6mxp-9797.json +++ b/advisories/unreviewed/2024/10/GHSA-hvp9-6mxp-9797/GHSA-hvp9-6mxp-9797.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvp9-6mxp-9797", - "modified": "2024-10-09T06:30:22Z", + "modified": "2024-10-10T00:31:05Z", "published": "2024-10-09T06:30:22Z", "aliases": [ "CVE-2024-35288" ], "details": "Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\\SYSTEM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T04:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json b/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json new file mode 100644 index 00000000000..27ede637473 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5f2-h5fv-xrrx", + "modified": "2024-10-10T00:31:06Z", + "published": "2024-10-10T00:31:06Z", + "aliases": [ + "CVE-2024-48941" + ], + "details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48941" + }, + { + "type": "WEB", + "url": "https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/3236560898/2024-09-16+-+Secure+Login+security+advisory+-+Insecure+default+configuration" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-10T00:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r69r-g3mg-h539/GHSA-r69r-g3mg-h539.json b/advisories/unreviewed/2024/10/GHSA-r69r-g3mg-h539/GHSA-r69r-g3mg-h539.json new file mode 100644 index 00000000000..77b4820a363 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r69r-g3mg-h539/GHSA-r69r-g3mg-h539.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r69r-g3mg-h539", + "modified": "2024-10-10T00:31:06Z", + "published": "2024-10-10T00:31:06Z", + "aliases": [ + "CVE-2024-8264" + ], + "details": "Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8264" + }, + { + "type": "WEB", + "url": "https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm" + }, + { + "type": "WEB", + "url": "https://www.fortra.com/security/advisories/product-security/fi-2024-012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-09T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vp6w-3fx2-4f2w/GHSA-vp6w-3fx2-4f2w.json b/advisories/unreviewed/2024/10/GHSA-vp6w-3fx2-4f2w/GHSA-vp6w-3fx2-4f2w.json new file mode 100644 index 00000000000..4b3f8d57c0e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vp6w-3fx2-4f2w/GHSA-vp6w-3fx2-4f2w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp6w-3fx2-4f2w", + "modified": "2024-10-10T00:31:06Z", + "published": "2024-10-10T00:31:06Z", + "aliases": [ + "CVE-2024-48933" + ], + "details": "A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48933" + }, + { + "type": "WEB", + "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3232" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-09T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8jp-q8g4-9f42/GHSA-w8jp-q8g4-9f42.json b/advisories/unreviewed/2024/10/GHSA-w8jp-q8g4-9f42/GHSA-w8jp-q8g4-9f42.json index 504de0656da..c1968c10210 100644 --- a/advisories/unreviewed/2024/10/GHSA-w8jp-q8g4-9f42/GHSA-w8jp-q8g4-9f42.json +++ b/advisories/unreviewed/2024/10/GHSA-w8jp-q8g4-9f42/GHSA-w8jp-q8g4-9f42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8jp-q8g4-9f42", - "modified": "2024-10-09T06:30:23Z", + "modified": "2024-10-10T00:31:05Z", "published": "2024-10-09T06:30:23Z", "aliases": [ "CVE-2024-47191" ], "details": "pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T05:15:13Z"