From f55b3366f66a0777674d63679b094bce5555e01a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Jul 2024 12:37:15 +0000 Subject: [PATCH] Publish Advisories GHSA-68qf-xhq3-9qj5 GHSA-8vm5-mx6j-hvfc GHSA-92vm-7577-pphj GHSA-99rv-gqrg-p5fc GHSA-cc4r-8r99-3qmp GHSA-g5wh-4vxr-qmjg GHSA-j49j-p46f-pfcv GHSA-phh7-8q4v-gv55 GHSA-q2fj-w5rc-hrq8 GHSA-w9qp-xc8f-8xcq GHSA-x5fg-377f-962v --- .../GHSA-68qf-xhq3-9qj5.json | 35 +++++++++++++++++ .../GHSA-8vm5-mx6j-hvfc.json | 38 +++++++++++++++++++ .../GHSA-92vm-7577-pphj.json | 38 +++++++++++++++++++ .../GHSA-99rv-gqrg-p5fc.json | 38 +++++++++++++++++++ .../GHSA-cc4r-8r99-3qmp.json | 38 +++++++++++++++++++ .../GHSA-g5wh-4vxr-qmjg.json | 38 +++++++++++++++++++ .../GHSA-j49j-p46f-pfcv.json | 35 +++++++++++++++++ .../GHSA-phh7-8q4v-gv55.json | 38 +++++++++++++++++++ .../GHSA-q2fj-w5rc-hrq8.json | 38 +++++++++++++++++++ .../GHSA-w9qp-xc8f-8xcq.json | 38 +++++++++++++++++++ .../GHSA-x5fg-377f-962v.json | 35 +++++++++++++++++ 11 files changed, 409 insertions(+) create mode 100644 advisories/unreviewed/2024/07/GHSA-68qf-xhq3-9qj5/GHSA-68qf-xhq3-9qj5.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-92vm-7577-pphj/GHSA-92vm-7577-pphj.json create mode 100644 advisories/unreviewed/2024/07/GHSA-99rv-gqrg-p5fc/GHSA-99rv-gqrg-p5fc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-cc4r-8r99-3qmp/GHSA-cc4r-8r99-3qmp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-g5wh-4vxr-qmjg/GHSA-g5wh-4vxr-qmjg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-j49j-p46f-pfcv/GHSA-j49j-p46f-pfcv.json create mode 100644 advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json create mode 100644 advisories/unreviewed/2024/07/GHSA-q2fj-w5rc-hrq8/GHSA-q2fj-w5rc-hrq8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json diff --git a/advisories/unreviewed/2024/07/GHSA-68qf-xhq3-9qj5/GHSA-68qf-xhq3-9qj5.json b/advisories/unreviewed/2024/07/GHSA-68qf-xhq3-9qj5/GHSA-68qf-xhq3-9qj5.json new file mode 100644 index 00000000000..5b98339e0b8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-68qf-xhq3-9qj5/GHSA-68qf-xhq3-9qj5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68qf-xhq3-9qj5", + "modified": "2024-07-26T12:35:48Z", + "published": "2024-07-26T12:35:48Z", + "aliases": [ + "CVE-2023-38522" + ], + "details": "Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.\n\nUsers are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38522" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c4mcmpblgl8kkmyt56t23543gp8v56m0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T10:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json b/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json new file mode 100644 index 00000000000..8a096e7fe65 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vm5-mx6j-hvfc", + "modified": "2024-07-26T12:35:48Z", + "published": "2024-07-26T12:35:48Z", + "aliases": [ + "CVE-2024-41684" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to capture cookies and compromise the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41684" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-614" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-92vm-7577-pphj/GHSA-92vm-7577-pphj.json b/advisories/unreviewed/2024/07/GHSA-92vm-7577-pphj/GHSA-92vm-7577-pphj.json new file mode 100644 index 00000000000..548feb60002 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-92vm-7577-pphj/GHSA-92vm-7577-pphj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92vm-7577-pphj", + "modified": "2024-07-26T12:35:49Z", + "published": "2024-07-26T12:35:49Z", + "aliases": [ + "CVE-2024-41689" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/ WPS credentials on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass WPA/ WPS and gain access to the Wi-Fi network of the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41689" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-99rv-gqrg-p5fc/GHSA-99rv-gqrg-p5fc.json b/advisories/unreviewed/2024/07/GHSA-99rv-gqrg-p5fc/GHSA-99rv-gqrg-p5fc.json new file mode 100644 index 00000000000..62065707987 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-99rv-gqrg-p5fc/GHSA-99rv-gqrg-p5fc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rv-gqrg-p5fc", + "modified": "2024-07-26T12:35:49Z", + "published": "2024-07-26T12:35:49Z", + "aliases": [ + "CVE-2024-41688" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext credentials on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41688" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cc4r-8r99-3qmp/GHSA-cc4r-8r99-3qmp.json b/advisories/unreviewed/2024/07/GHSA-cc4r-8r99-3qmp/GHSA-cc4r-8r99-3qmp.json new file mode 100644 index 00000000000..8c5bc219334 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cc4r-8r99-3qmp/GHSA-cc4r-8r99-3qmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc4r-8r99-3qmp", + "modified": "2024-07-26T12:35:50Z", + "published": "2024-07-26T12:35:50Z", + "aliases": [ + "CVE-2024-41691" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext FTP credentials from the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the FTP server associated with the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41691" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g5wh-4vxr-qmjg/GHSA-g5wh-4vxr-qmjg.json b/advisories/unreviewed/2024/07/GHSA-g5wh-4vxr-qmjg/GHSA-g5wh-4vxr-qmjg.json new file mode 100644 index 00000000000..a1e306132b4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g5wh-4vxr-qmjg/GHSA-g5wh-4vxr-qmjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5wh-4vxr-qmjg", + "modified": "2024-07-26T12:35:50Z", + "published": "2024-07-26T12:35:50Z", + "aliases": [ + "CVE-2024-41690" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext default credentials on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41690" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j49j-p46f-pfcv/GHSA-j49j-p46f-pfcv.json b/advisories/unreviewed/2024/07/GHSA-j49j-p46f-pfcv/GHSA-j49j-p46f-pfcv.json new file mode 100644 index 00000000000..b9aa18f9349 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j49j-p46f-pfcv/GHSA-j49j-p46f-pfcv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j49j-p46f-pfcv", + "modified": "2024-07-26T12:35:48Z", + "published": "2024-07-26T12:35:48Z", + "aliases": [ + "CVE-2024-35161" + ], + "details": "Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.\n\nUsers can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.\nUsers are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35161" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c4mcmpblgl8kkmyt56t23543gp8v56m0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json b/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json new file mode 100644 index 00000000000..faf64cc9d38 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phh7-8q4v-gv55", + "modified": "2024-07-26T12:35:49Z", + "published": "2024-07-26T12:35:49Z", + "aliases": [ + "CVE-2024-41686" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41686" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-179" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q2fj-w5rc-hrq8/GHSA-q2fj-w5rc-hrq8.json b/advisories/unreviewed/2024/07/GHSA-q2fj-w5rc-hrq8/GHSA-q2fj-w5rc-hrq8.json new file mode 100644 index 00000000000..5cfd741033d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q2fj-w5rc-hrq8/GHSA-q2fj-w5rc-hrq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2fj-w5rc-hrq8", + "modified": "2024-07-26T12:35:49Z", + "published": "2024-07-26T12:35:49Z", + "aliases": [ + "CVE-2024-41687" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41687" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json b/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json new file mode 100644 index 00000000000..48c2001280f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9qp-xc8f-8xcq", + "modified": "2024-07-26T12:35:49Z", + "published": "2024-07-26T12:35:49Z", + "aliases": [ + "CVE-2024-41685" + ], + "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to capture cookies and obtain sensitive information on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41685" + }, + { + "type": "WEB", + "url": "https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1004" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json b/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json new file mode 100644 index 00000000000..59a5a633f90 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x5fg-377f-962v/GHSA-x5fg-377f-962v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5fg-377f-962v", + "modified": "2024-07-26T12:35:48Z", + "published": "2024-07-26T12:35:48Z", + "aliases": [ + "CVE-2024-35296" + ], + "details": "Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.\n\nUsers are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35296" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c4mcmpblgl8kkmyt56t23543gp8v56m0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T10:15:02Z" + } +} \ No newline at end of file