From f5b859f145c3c7570e64f5813411a7af91039f72 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Sep 2024 15:32:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-chhh-4xrf-42pg.json | 2 +- .../GHSA-g638-3qxw-g3gp.json | 6 ++- .../GHSA-j73p-gc9r-3pf8.json | 12 +++-- .../GHSA-vhqm-6frc-f35m.json | 11 +++-- .../GHSA-x8qr-mh28-f32f.json | 3 +- .../GHSA-23q7-9vq5-jc43.json | 6 ++- .../GHSA-2h5m-ffc8-9ffr.json | 47 +++++++++++++++++++ .../GHSA-3g3x-qrhw-j5jj.json | 39 +++++++++++++++ .../GHSA-4r99-7p57-xjr3.json | 38 +++++++++++++++ .../GHSA-5f48-j349-fj3m.json | 38 +++++++++++++++ .../GHSA-69wq-4pfq-hqxh.json | 9 ++-- .../GHSA-82mg-vc5c-pcm3.json | 39 +++++++++++++++ .../GHSA-8635-cr25-p8xq.json | 43 +++++++++++++++++ .../GHSA-8832-5jj9-833x.json | 38 +++++++++++++++ .../GHSA-8g2h-4x5w-4v4p.json | 38 +++++++++++++++ .../GHSA-8j7x-j8g8-g329.json | 42 +++++++++++++++++ .../GHSA-c4p9-95wg-q39w.json | 11 +++-- .../GHSA-cgp2-rgv5-7hcp.json | 43 +++++++++++++++++ .../GHSA-cqpj-cqf7-q68j.json | 39 +++++++++++++++ .../GHSA-fxwr-6hqv-m4wv.json | 3 +- .../GHSA-g9m4-c8qf-67qw.json | 38 +++++++++++++++ .../GHSA-jr6g-3qr2-xfh3.json | 38 +++++++++++++++ .../GHSA-jvc3-9vpf-mx93.json | 43 +++++++++++++++++ .../GHSA-mgc5-p43f-72pc.json | 42 +++++++++++++++++ .../GHSA-p42p-v9g2-2qc5.json | 38 +++++++++++++++ .../GHSA-p8g3-26x6-6m74.json | 11 +++-- .../GHSA-pmv9-7f92-57xh.json | 38 +++++++++++++++ .../GHSA-pw8j-vg82-pm6c.json | 38 +++++++++++++++ .../GHSA-q6gr-fq83-8hmc.json | 38 +++++++++++++++ .../GHSA-qpx3-c568-35v5.json | 42 +++++++++++++++++ .../GHSA-r657-x7w7-q6j3.json | 38 +++++++++++++++ .../GHSA-rqj4-hg4x-qw45.json | 42 +++++++++++++++++ .../GHSA-x3xw-jp2m-77mv.json | 38 +++++++++++++++ .../GHSA-xhhp-64qq-p9x5.json | 38 +++++++++++++++ 34 files changed, 1005 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5f48-j349-fj3m/GHSA-5f48-j349-fj3m.json create mode 100644 advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8832-5jj9-833x/GHSA-8832-5jj9-833x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8g2h-4x5w-4v4p/GHSA-8g2h-4x5w-4v4p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pmv9-7f92-57xh/GHSA-pmv9-7f92-57xh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q6gr-fq83-8hmc/GHSA-q6gr-fq83-8hmc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qpx3-c568-35v5/GHSA-qpx3-c568-35v5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r657-x7w7-q6j3/GHSA-r657-x7w7-q6j3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rqj4-hg4x-qw45/GHSA-rqj4-hg4x-qw45.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x3xw-jp2m-77mv/GHSA-x3xw-jp2m-77mv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json diff --git a/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json b/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json index b9497315600..db82f4f449c 100644 --- a/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json +++ b/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json b/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json index 6a50a61654d..d4a11815fd9 100644 --- a/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json +++ b/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g638-3qxw-g3gp", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-09-10T15:31:03Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-6089" ], "details": "An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json index 27765c302c3..17b91aeff0c 100644 --- a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json +++ b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j73p-gc9r-3pf8", - "modified": "2024-07-22T15:32:39Z", + "modified": "2024-09-10T15:31:03Z", "published": "2024-07-22T12:30:36Z", "aliases": [ "CVE-2024-34457" ], "details": "On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config.\n\nMitigation:\n\nall users should upgrade to 2.1.4\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-22T10:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vhqm-6frc-f35m/GHSA-vhqm-6frc-f35m.json b/advisories/unreviewed/2024/07/GHSA-vhqm-6frc-f35m/GHSA-vhqm-6frc-f35m.json index 33e9030f3e0..ededc5c5669 100644 --- a/advisories/unreviewed/2024/07/GHSA-vhqm-6frc-f35m/GHSA-vhqm-6frc-f35m.json +++ b/advisories/unreviewed/2024/07/GHSA-vhqm-6frc-f35m/GHSA-vhqm-6frc-f35m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhqm-6frc-f35m", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-09-10T15:31:03Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-40617" ], "details": "Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted request to the affected product, access restricted files containing sensitive information may be accessed. As a result, Administrator Class privileges of the product may be hijacked.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-17T09:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json b/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json index 6145e95b7c5..6ad4584bd25 100644 --- a/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json +++ b/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json index c01f4a42dec..b09e15db00a 100644 --- a/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json +++ b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23q7-9vq5-jc43", - "modified": "2024-09-10T12:30:38Z", + "modified": "2024-09-10T15:31:04Z", "published": "2024-09-10T12:30:38Z", "aliases": [ "CVE-2024-40754" ], "details": "Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json b/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json new file mode 100644 index 00000000000..da786b5d45d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h5m-ffc8-9ffr", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-37728" + ], + "details": "Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the \"Pic/Indexes\" interface", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37728" + }, + { + "type": "WEB", + "url": "https://github.com/wy876/POC/blob/main/OfficeWeb365/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md" + }, + { + "type": "WEB", + "url": "https://github.com/xuetang1125/OfficeWeb365/blob/main/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20.md" + }, + { + "type": "WEB", + "url": "https://ti.qianxin.com/vulnerability/notice-list?value=officeweb365" + }, + { + "type": "WEB", + "url": "https://www.cnnvd.org.cn/home/warn" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json new file mode 100644 index 00000000000..150202421c9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g3x-qrhw-j5jj", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-37230" + ], + "details": "Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37230" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json b/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json new file mode 100644 index 00000000000..7f3bf99cb1c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r99-7p57-xjr3", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-36511" + ], + "details": "An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36511" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-22-256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-358" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5f48-j349-fj3m/GHSA-5f48-j349-fj3m.json b/advisories/unreviewed/2024/09/GHSA-5f48-j349-fj3m/GHSA-5f48-j349-fj3m.json new file mode 100644 index 00000000000..2a7f03de62b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5f48-j349-fj3m/GHSA-5f48-j349-fj3m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f48-j349-fj3m", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-23184" + ], + "details": "Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23184" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2024/oxdc-adv-2024-0002.json" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json b/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json index d6bdffe5875..034c3a9c6fe 100644 --- a/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json +++ b/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69wq-4pfq-hqxh", - "modified": "2024-09-08T06:30:33Z", + "modified": "2024-09-10T15:31:03Z", "published": "2024-09-08T06:30:33Z", "aliases": [ "CVE-2024-6928" ], "details": "The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-08T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json new file mode 100644 index 00000000000..7e0bd104be0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82mg-vc5c-pcm3", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-37229" + ], + "details": "Loftware Spectrum before 5.1 allows SSRF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37229" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json new file mode 100644 index 00000000000..a6e56fe8ce5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8635-cr25-p8xq", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-37226" + ], + "details": "Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37226" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF14.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8832-5jj9-833x/GHSA-8832-5jj9-833x.json b/advisories/unreviewed/2024/09/GHSA-8832-5jj9-833x/GHSA-8832-5jj9-833x.json new file mode 100644 index 00000000000..55dd551f6a9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8832-5jj9-833x/GHSA-8832-5jj9-833x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8832-5jj9-833x", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-21753" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21753" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8g2h-4x5w-4v4p/GHSA-8g2h-4x5w-4v4p.json b/advisories/unreviewed/2024/09/GHSA-8g2h-4x5w-4v4p/GHSA-8g2h-4x5w-4v4p.json new file mode 100644 index 00000000000..16593333efe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8g2h-4x5w-4v4p/GHSA-8g2h-4x5w-4v4p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g2h-4x5w-4v4p", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-42423" + ], + "details": "Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42423" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000225289/dsa-2024-229-security-update-for-dell-thinos-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json b/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json new file mode 100644 index 00000000000..c9200651b1b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j7x-j8g8-g329", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-27257" + ], + "details": "IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27257" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/283966" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167702" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-540" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json index 3a6c70f6d48..ee432a735d1 100644 --- a/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json +++ b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4p9-95wg-q39w", - "modified": "2024-09-09T21:31:23Z", + "modified": "2024-09-10T15:31:04Z", "published": "2024-09-09T21:31:23Z", "aliases": [ "CVE-2024-44411" ], "details": "D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T21:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json new file mode 100644 index 00000000000..d75395f02a2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgp2-rgv5-7hcp", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-37227" + ], + "details": "Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37227" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF13.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json new file mode 100644 index 00000000000..b76826cf383 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqpj-cqf7-q68j", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-44867" + ], + "details": "phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44867" + }, + { + "type": "WEB", + "url": "https://github.com/ChengZyin/CVE-2024-44867/blob/main/CVE-2024-44867.md" + }, + { + "type": "WEB", + "url": "https://github.com/ChengZyin/Exploit/blob/ChengZyin-patch-1/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json index e99d5f6f7fa..94617bb362d 100644 --- a/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json +++ b/advisories/unreviewed/2024/09/GHSA-fxwr-6hqv-m4wv/GHSA-fxwr-6hqv-m4wv.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json b/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json new file mode 100644 index 00000000000..cfb20cf03eb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9m4-c8qf-67qw", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-23185" + ], + "details": "Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up \"full_value\" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general). One can implement restrictions on headers on MTA component preceding Dovecot. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23185" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2024/oxdc-adv-2024-0003.json" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json b/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json new file mode 100644 index 00000000000..bf9c9f692c2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr6g-3qr2-xfh3", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-33508" + ], + "details": "An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33508" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json new file mode 100644 index 00000000000..87e16ef07e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvc3-9vpf-mx93", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-37231" + ], + "details": "Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37231" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF14.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json b/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json new file mode 100644 index 00000000000..8dad73288d3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mgc5-p43f-72pc/GHSA-mgc5-p43f-72pc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgc5-p43f-72pc", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-8443" + ], + "details": "A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8443" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8443" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json b/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json new file mode 100644 index 00000000000..e767c2ba291 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p42p-v9g2-2qc5", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-45323" + ], + "details": "An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45323" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json b/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json index db10372710c..6fe1134fabc 100644 --- a/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json +++ b/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8g3-26x6-6m74", - "modified": "2024-09-10T12:30:38Z", + "modified": "2024-09-10T15:31:04Z", "published": "2024-09-10T12:30:38Z", "aliases": [ "CVE-2024-45845" ], "details": "nix 2.24 through 2.24.5 allows directory traversal via a symlink in a nar file, because of mishandling of a directory containing a symlink and a directory of the same name, aka GHSA-h4vv-h3jq-v493.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T11:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pmv9-7f92-57xh/GHSA-pmv9-7f92-57xh.json b/advisories/unreviewed/2024/09/GHSA-pmv9-7f92-57xh/GHSA-pmv9-7f92-57xh.json new file mode 100644 index 00000000000..e2fb85a6f87 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pmv9-7f92-57xh/GHSA-pmv9-7f92-57xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmv9-7f92-57xh", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2023-44254" + ], + "details": "An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44254" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json b/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json new file mode 100644 index 00000000000..19a7bf41e02 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw8j-vg82-pm6c", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-8654" + ], + "details": "MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8654" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-71477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q6gr-fq83-8hmc/GHSA-q6gr-fq83-8hmc.json b/advisories/unreviewed/2024/09/GHSA-q6gr-fq83-8hmc/GHSA-q6gr-fq83-8hmc.json new file mode 100644 index 00000000000..a182eb55f7e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q6gr-fq83-8hmc/GHSA-q6gr-fq83-8hmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6gr-fq83-8hmc", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-31490" + ], + "details": "An exposure of sensitive information to an unauthorized actor in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.2 through 3.2.4 and 3.1.5 allows attacker to information disclosure via HTTP get requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31490" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-24-051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qpx3-c568-35v5/GHSA-qpx3-c568-35v5.json b/advisories/unreviewed/2024/09/GHSA-qpx3-c568-35v5/GHSA-qpx3-c568-35v5.json new file mode 100644 index 00000000000..8f9a1a282a4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qpx3-c568-35v5/GHSA-qpx3-c568-35v5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpx3-c568-35v5", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-25074" + ], + "details": "An issue was discovered in Samsung Semiconductor Mobile Processor, Automotive Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the SM (Session Management module), which can lead to Denial of Service (Untrusted Pointer Dereference).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25074" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-25074" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r657-x7w7-q6j3/GHSA-r657-x7w7-q6j3.json b/advisories/unreviewed/2024/09/GHSA-r657-x7w7-q6j3/GHSA-r657-x7w7-q6j3.json new file mode 100644 index 00000000000..a0e96fc39fc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r657-x7w7-q6j3/GHSA-r657-x7w7-q6j3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r657-x7w7-q6j3", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2022-45856" + ], + "details": "An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientAndroid 6.4 all versions, 7.0 all versions, 7.2.0 and FortiClientiOS 5.6 all versions, 6.0.0 through 6.0.1, 7.0.0 through 7.0.6 SAML SSO feature may allow an unauthenticated attacker to man-in-the-middle the communication between the FortiClient and  both the service provider and the identity provider.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45856" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-22-230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rqj4-hg4x-qw45/GHSA-rqj4-hg4x-qw45.json b/advisories/unreviewed/2024/09/GHSA-rqj4-hg4x-qw45/GHSA-rqj4-hg4x-qw45.json new file mode 100644 index 00000000000..44c121c00d8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rqj4-hg4x-qw45/GHSA-rqj4-hg4x-qw45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqj4-hg4x-qw45", + "modified": "2024-09-10T15:31:04Z", + "published": "2024-09-10T15:31:04Z", + "aliases": [ + "CVE-2024-25073" + ], + "details": "An issue was discovered in Samsung Semiconductor Mobile Processor, Automotive Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the CC (Call Control module), which can lead to Denial of Service (Untrusted Pointer Dereference).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25073" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-25073" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x3xw-jp2m-77mv/GHSA-x3xw-jp2m-77mv.json b/advisories/unreviewed/2024/09/GHSA-x3xw-jp2m-77mv/GHSA-x3xw-jp2m-77mv.json new file mode 100644 index 00000000000..9c5c47dee77 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x3xw-jp2m-77mv/GHSA-x3xw-jp2m-77mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3xw-jp2m-77mv", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-31489" + ], + "details": "AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31489" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-22-282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json b/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json new file mode 100644 index 00000000000..449d9198c19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhhp-64qq-p9x5", + "modified": "2024-09-10T15:31:05Z", + "published": "2024-09-10T15:31:05Z", + "aliases": [ + "CVE-2024-35282" + ], + "details": "A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken device to obtain cleartext passwords via keychain dump.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35282" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-139" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-316" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T15:15:16Z" + } +} \ No newline at end of file