diff --git a/advisories/unreviewed/2024/02/GHSA-h8r9-fvmc-wrrc/GHSA-h8r9-fvmc-wrrc.json b/advisories/unreviewed/2024/02/GHSA-h8r9-fvmc-wrrc/GHSA-h8r9-fvmc-wrrc.json index 535212d0765..8d78d9e745c 100644 --- a/advisories/unreviewed/2024/02/GHSA-h8r9-fvmc-wrrc/GHSA-h8r9-fvmc-wrrc.json +++ b/advisories/unreviewed/2024/02/GHSA-h8r9-fvmc-wrrc/GHSA-h8r9-fvmc-wrrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8r9-fvmc-wrrc", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-25830" ], "details": "F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:16Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j2mh-mwvc-vm3h/GHSA-j2mh-mwvc-vm3h.json b/advisories/unreviewed/2024/02/GHSA-j2mh-mwvc-vm3h/GHSA-j2mh-mwvc-vm3h.json index 2def25b9c27..7eecd0085ed 100644 --- a/advisories/unreviewed/2024/02/GHSA-j2mh-mwvc-vm3h/GHSA-j2mh-mwvc-vm3h.json +++ b/advisories/unreviewed/2024/02/GHSA-j2mh-mwvc-vm3h/GHSA-j2mh-mwvc-vm3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2mh-mwvc-vm3h", - "modified": "2024-02-28T21:30:20Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-02-28T21:30:20Z", "aliases": [ "CVE-2023-52047" ], "details": "Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T20:15:41Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mrff-v44r-8gc2/GHSA-mrff-v44r-8gc2.json b/advisories/unreviewed/2024/02/GHSA-mrff-v44r-8gc2/GHSA-mrff-v44r-8gc2.json index 3db7006bac6..0219d4392c5 100644 --- a/advisories/unreviewed/2024/02/GHSA-mrff-v44r-8gc2/GHSA-mrff-v44r-8gc2.json +++ b/advisories/unreviewed/2024/02/GHSA-mrff-v44r-8gc2/GHSA-mrff-v44r-8gc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrff-v44r-8gc2", - "modified": "2024-02-29T03:33:14Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-02-29T03:33:14Z", "aliases": [ "CVE-2023-50437" ], "details": "An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:42:00Z" diff --git a/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json b/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json index f7d17f36465..e358f2f9c18 100644 --- a/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json +++ b/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55w9-hrch-c3j9", - "modified": "2024-04-05T21:32:44Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29756" ], "details": "In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x9q6-973q-x3jh/GHSA-x9q6-973q-x3jh.json b/advisories/unreviewed/2024/05/GHSA-x9q6-973q-x3jh/GHSA-x9q6-973q-x3jh.json index 68621d64cf7..4fe4d6c6f5b 100644 --- a/advisories/unreviewed/2024/05/GHSA-x9q6-973q-x3jh/GHSA-x9q6-973q-x3jh.json +++ b/advisories/unreviewed/2024/05/GHSA-x9q6-973q-x3jh/GHSA-x9q6-973q-x3jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9q6-973q-x3jh", - "modified": "2024-05-02T18:30:50Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-05-02T18:30:50Z", "aliases": [ "CVE-2024-29309" ], "details": "An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:07Z" diff --git a/advisories/unreviewed/2024/06/GHSA-577f-9hhg-fc2w/GHSA-577f-9hhg-fc2w.json b/advisories/unreviewed/2024/06/GHSA-577f-9hhg-fc2w/GHSA-577f-9hhg-fc2w.json index 0c02bc37111..daea82ce561 100644 --- a/advisories/unreviewed/2024/06/GHSA-577f-9hhg-fc2w/GHSA-577f-9hhg-fc2w.json +++ b/advisories/unreviewed/2024/06/GHSA-577f-9hhg-fc2w/GHSA-577f-9hhg-fc2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-577f-9hhg-fc2w", - "modified": "2024-06-18T06:30:40Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-06-18T06:30:40Z", "aliases": [ "CVE-2024-33620" ], "details": "Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-36" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T06:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-485q-x8fc-8c94/GHSA-485q-x8fc-8c94.json b/advisories/unreviewed/2024/08/GHSA-485q-x8fc-8c94/GHSA-485q-x8fc-8c94.json new file mode 100644 index 00000000000..1ba73488a86 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-485q-x8fc-8c94/GHSA-485q-x8fc-8c94.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-485q-x8fc-8c94", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7741" + ], + "details": "A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component API Endpoint. The manipulation of the argument file leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7741" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE14-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274361" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274361" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.386433" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json b/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json new file mode 100644 index 00000000000..645ca53c3b8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4r4v-2j2q-ch33/GHSA-4r4v-2j2q-ch33.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r4v-2j2q-ch33", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7738" + ], + "details": "A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7738" + }, + { + "type": "WEB", + "url": "https://github.com/abhi-ingle/Vulnerability-Research/blob/main/POC/Arbitrary%20File%20Read/file_read_report.md" + }, + { + "type": "WEB", + "url": "https://github.com/abhi-ingle/Vulnerability-Research/blob/main/POC/Arbitrary%20File%20Read/poc_arbitrary_file_read.mp4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.385634" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7j43-4jvq-vg4w/GHSA-7j43-4jvq-vg4w.json b/advisories/unreviewed/2024/08/GHSA-7j43-4jvq-vg4w/GHSA-7j43-4jvq-vg4w.json index fa8cab033b1..e9fc3922333 100644 --- a/advisories/unreviewed/2024/08/GHSA-7j43-4jvq-vg4w/GHSA-7j43-4jvq-vg4w.json +++ b/advisories/unreviewed/2024/08/GHSA-7j43-4jvq-vg4w/GHSA-7j43-4jvq-vg4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j43-4jvq-vg4w", - "modified": "2024-08-12T18:30:47Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-08-12T18:30:47Z", "aliases": [ "CVE-2024-36877" ], "details": "Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-123" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8cgw-qh4h-cf58/GHSA-8cgw-qh4h-cf58.json b/advisories/unreviewed/2024/08/GHSA-8cgw-qh4h-cf58/GHSA-8cgw-qh4h-cf58.json new file mode 100644 index 00000000000..6d2e9fc0def --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8cgw-qh4h-cf58/GHSA-8cgw-qh4h-cf58.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cgw-qh4h-cf58", + "modified": "2024-08-13T21:31:55Z", + "published": "2024-08-13T21:31:55Z", + "aliases": [ + "CVE-2024-7570" + ], + "details": "Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7570" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2024-7569-CVE-2024-7570" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8fvc-gf7v-rjqg/GHSA-8fvc-gf7v-rjqg.json b/advisories/unreviewed/2024/08/GHSA-8fvc-gf7v-rjqg/GHSA-8fvc-gf7v-rjqg.json new file mode 100644 index 00000000000..4ee68a93274 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8fvc-gf7v-rjqg/GHSA-8fvc-gf7v-rjqg.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fvc-gf7v-rjqg", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7740" + ], + "details": "A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /api/test/download of the component API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7740" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE14-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274360" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274360" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.386432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8j5m-w2v7-mx38/GHSA-8j5m-w2v7-mx38.json b/advisories/unreviewed/2024/08/GHSA-8j5m-w2v7-mx38/GHSA-8j5m-w2v7-mx38.json new file mode 100644 index 00000000000..afde8dfe414 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8j5m-w2v7-mx38/GHSA-8j5m-w2v7-mx38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j5m-w2v7-mx38", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7593" + ], + "details": "Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7593" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json b/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json index ba9b9ec98a7..8f76abe7c97 100644 --- a/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json +++ b/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frc3-7x76-jwp8", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-37015" ], "details": "An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-297" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T17:15:23Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hp2v-428v-v89g/GHSA-hp2v-428v-v89g.json b/advisories/unreviewed/2024/08/GHSA-hp2v-428v-v89g/GHSA-hp2v-428v-v89g.json new file mode 100644 index 00000000000..86c5404228c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hp2v-428v-v89g/GHSA-hp2v-428v-v89g.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp2v-428v-v89g", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7739" + ], + "details": "A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7739" + }, + { + "type": "WEB", + "url": "https://github.com/abhi-ingle/Vulnerability-Research/blob/main/POC/Script%20Injection/poc_script_inject.mp4" + }, + { + "type": "WEB", + "url": "https://github.com/abhi-ingle/Vulnerability-Research/blob/main/POC/Script%20Injection/script_injection_report.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.385635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qq56-25j2-4m9h/GHSA-qq56-25j2-4m9h.json b/advisories/unreviewed/2024/08/GHSA-qq56-25j2-4m9h/GHSA-qq56-25j2-4m9h.json new file mode 100644 index 00000000000..e6d402c626c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qq56-25j2-4m9h/GHSA-qq56-25j2-4m9h.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq56-25j2-4m9h", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7742" + ], + "details": "A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7742" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE14-3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274362" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274362" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.386434" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rj6p-94v3-4ccp/GHSA-rj6p-94v3-4ccp.json b/advisories/unreviewed/2024/08/GHSA-rj6p-94v3-4ccp/GHSA-rj6p-94v3-4ccp.json new file mode 100644 index 00000000000..54fb101efb6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rj6p-94v3-4ccp/GHSA-rj6p-94v3-4ccp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj6p-94v3-4ccp", + "modified": "2024-08-13T21:31:55Z", + "published": "2024-08-13T21:31:55Z", + "aliases": [ + "CVE-2024-7569" + ], + "details": "An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7569" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2024-7569-CVE-2024-7570" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-215" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w6q8-88ph-g9vq/GHSA-w6q8-88ph-g9vq.json b/advisories/unreviewed/2024/08/GHSA-w6q8-88ph-g9vq/GHSA-w6q8-88ph-g9vq.json new file mode 100644 index 00000000000..d295741afb1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6q8-88ph-g9vq/GHSA-w6q8-88ph-g9vq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6q8-88ph-g9vq", + "modified": "2024-08-13T21:31:56Z", + "published": "2024-08-13T21:31:56Z", + "aliases": [ + "CVE-2024-7743" + ], + "details": "A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of the file /api/file/downloadUrl of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7743" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE14-4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274363" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274363" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.386435" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wpgr-jvp4-g62h/GHSA-wpgr-jvp4-g62h.json b/advisories/unreviewed/2024/08/GHSA-wpgr-jvp4-g62h/GHSA-wpgr-jvp4-g62h.json index ada7a1b4ad3..ea1d2d13995 100644 --- a/advisories/unreviewed/2024/08/GHSA-wpgr-jvp4-g62h/GHSA-wpgr-jvp4-g62h.json +++ b/advisories/unreviewed/2024/08/GHSA-wpgr-jvp4-g62h/GHSA-wpgr-jvp4-g62h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpgr-jvp4-g62h", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T21:31:55Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2023-48171" ], "details": "An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:08Z"