From f625ee34387ad5cff0644a7cbafbdde5cc2bf9a4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 17 Jul 2024 15:32:36 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7wrh-gvmc-wrjp.json | 4 +- .../GHSA-grp4-qf6x-8325.json | 4 +- .../GHSA-m9v7-79rj-pq3w.json | 2 +- .../GHSA-mhjr-7mqj-rp86.json | 4 +- .../GHSA-w495-r927-3gp6.json | 2 +- .../GHSA-x26g-933q-fggm.json | 4 +- .../GHSA-29rm-j4cx-hmc5.json | 2 +- .../GHSA-2rwm-xv5j-777p.json | 38 +++++++++++++++++++ .../GHSA-2wg4-c3jx-83f5.json | 38 +++++++++++++++++++ .../GHSA-2x53-jv7f-c2x5.json | 38 +++++++++++++++++++ .../GHSA-4w6x-hxgr-c3q5.json | 38 +++++++++++++++++++ .../GHSA-4ww9-x3qp-vcwc.json | 38 +++++++++++++++++++ .../GHSA-5v69-92vw-fmjh.json | 6 ++- .../GHSA-7g94-hfqc-q993.json | 6 ++- .../GHSA-7r67-crqq-3693.json | 38 +++++++++++++++++++ .../GHSA-86xc-mwv4-f994.json | 38 +++++++++++++++++++ .../GHSA-8pgq-57fj-h74q.json | 38 +++++++++++++++++++ .../GHSA-99mg-hh47-f9qh.json | 38 +++++++++++++++++++ .../GHSA-9g4r-89hx-hv6j.json | 38 +++++++++++++++++++ .../GHSA-9hmq-8gj3-9hvq.json | 11 ++++-- .../GHSA-gcc2-5vx5-63jr.json | 38 +++++++++++++++++++ .../GHSA-ghgq-x6wc-6jr5.json | 38 +++++++++++++++++++ .../GHSA-h654-r868-pj2q.json | 38 +++++++++++++++++++ .../GHSA-hcf8-5j78-887v.json | 35 +++++++++++++++++ .../GHSA-hg5v-hmf4-qqh9.json | 38 +++++++++++++++++++ .../GHSA-jvf5-642m-hpc3.json | 38 +++++++++++++++++++ .../GHSA-mm2r-gc2g-prj6.json | 31 +++++++++++++++ .../GHSA-p2x2-phjv-4rv6.json | 11 ++++-- .../GHSA-wg42-q7r2-mwrq.json | 11 ++++-- .../GHSA-wjgh-f33q-79fx.json | 11 ++++-- .../GHSA-x95j-7ppj-485m.json | 38 +++++++++++++++++++ .../GHSA-xhc8-4cg9-pfch.json | 11 ++++-- 32 files changed, 730 insertions(+), 33 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-2rwm-xv5j-777p/GHSA-2rwm-xv5j-777p.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json create mode 100644 advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json create mode 100644 advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json create mode 100644 advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json create mode 100644 advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json create mode 100644 advisories/unreviewed/2024/07/GHSA-ghgq-x6wc-6jr5/GHSA-ghgq-x6wc-6jr5.json create mode 100644 advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json create mode 100644 advisories/unreviewed/2024/07/GHSA-jvf5-642m-hpc3/GHSA-jvf5-642m-hpc3.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mm2r-gc2g-prj6/GHSA-mm2r-gc2g-prj6.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x95j-7ppj-485m/GHSA-x95j-7ppj-485m.json diff --git a/advisories/unreviewed/2024/06/GHSA-7wrh-gvmc-wrjp/GHSA-7wrh-gvmc-wrjp.json b/advisories/unreviewed/2024/06/GHSA-7wrh-gvmc-wrjp/GHSA-7wrh-gvmc-wrjp.json index 6100e0df092..d8dcfdf3839 100644 --- a/advisories/unreviewed/2024/06/GHSA-7wrh-gvmc-wrjp/GHSA-7wrh-gvmc-wrjp.json +++ b/advisories/unreviewed/2024/06/GHSA-7wrh-gvmc-wrjp/GHSA-7wrh-gvmc-wrjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wrh-gvmc-wrjp", - "modified": "2024-06-20T06:30:54Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-06-20T06:30:54Z", "aliases": [ "CVE-2024-5686" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-grp4-qf6x-8325/GHSA-grp4-qf6x-8325.json b/advisories/unreviewed/2024/06/GHSA-grp4-qf6x-8325/GHSA-grp4-qf6x-8325.json index 6f5457e10b5..2e30986b484 100644 --- a/advisories/unreviewed/2024/06/GHSA-grp4-qf6x-8325/GHSA-grp4-qf6x-8325.json +++ b/advisories/unreviewed/2024/06/GHSA-grp4-qf6x-8325/GHSA-grp4-qf6x-8325.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grp4-qf6x-8325", - "modified": "2024-06-21T06:31:12Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-06-21T06:31:12Z", "aliases": [ "CVE-2024-5756" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m9v7-79rj-pq3w/GHSA-m9v7-79rj-pq3w.json b/advisories/unreviewed/2024/06/GHSA-m9v7-79rj-pq3w/GHSA-m9v7-79rj-pq3w.json index 19eee055288..084376d1067 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9v7-79rj-pq3w/GHSA-m9v7-79rj-pq3w.json +++ b/advisories/unreviewed/2024/06/GHSA-m9v7-79rj-pq3w/GHSA-m9v7-79rj-pq3w.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-mhjr-7mqj-rp86/GHSA-mhjr-7mqj-rp86.json b/advisories/unreviewed/2024/06/GHSA-mhjr-7mqj-rp86/GHSA-mhjr-7mqj-rp86.json index f1ac6f3f454..8ebc15ff99a 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhjr-7mqj-rp86/GHSA-mhjr-7mqj-rp86.json +++ b/advisories/unreviewed/2024/06/GHSA-mhjr-7mqj-rp86/GHSA-mhjr-7mqj-rp86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhjr-7mqj-rp86", - "modified": "2024-06-20T06:30:54Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-06-20T06:30:54Z", "aliases": [ "CVE-2024-5605" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w495-r927-3gp6/GHSA-w495-r927-3gp6.json b/advisories/unreviewed/2024/06/GHSA-w495-r927-3gp6/GHSA-w495-r927-3gp6.json index fa4d18cde2a..0c7ffa7094b 100644 --- a/advisories/unreviewed/2024/06/GHSA-w495-r927-3gp6/GHSA-w495-r927-3gp6.json +++ b/advisories/unreviewed/2024/06/GHSA-w495-r927-3gp6/GHSA-w495-r927-3gp6.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-x26g-933q-fggm/GHSA-x26g-933q-fggm.json b/advisories/unreviewed/2024/06/GHSA-x26g-933q-fggm/GHSA-x26g-933q-fggm.json index d0c8508a31b..8c2a6657461 100644 --- a/advisories/unreviewed/2024/06/GHSA-x26g-933q-fggm/GHSA-x26g-933q-fggm.json +++ b/advisories/unreviewed/2024/06/GHSA-x26g-933q-fggm/GHSA-x26g-933q-fggm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x26g-933q-fggm", - "modified": "2024-06-21T06:31:12Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-06-21T06:31:12Z", "aliases": [ "CVE-2024-3961" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json b/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json index 072ff98d1cd..e76401b46f8 100644 --- a/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json +++ b/advisories/unreviewed/2024/07/GHSA-29rm-j4cx-hmc5/GHSA-29rm-j4cx-hmc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29rm-j4cx-hmc5", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-17T15:30:49Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-6220" diff --git a/advisories/unreviewed/2024/07/GHSA-2rwm-xv5j-777p/GHSA-2rwm-xv5j-777p.json b/advisories/unreviewed/2024/07/GHSA-2rwm-xv5j-777p/GHSA-2rwm-xv5j-777p.json new file mode 100644 index 00000000000..926c1620508 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2rwm-xv5j-777p/GHSA-2rwm-xv5j-777p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rwm-xv5j-777p", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2023-7272" + ], + "details": "In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7272" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json b/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json new file mode 100644 index 00000000000..99c0eb2d8f3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wg4-c3jx-83f5", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-23474" + ], + "details": "The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23474" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json b/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json new file mode 100644 index 00000000000..8f7a9d6c7fa --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x53-jv7f-c2x5", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-28992" + ], + "details": "The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28992" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json b/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json new file mode 100644 index 00000000000..459c19e903d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w6x-hxgr-c3q5", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23468" + ], + "details": "The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23468" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json b/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json new file mode 100644 index 00000000000..fae92161981 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ww9-x3qp-vcwc", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-23471" + ], + "details": "The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23471" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json b/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json index 1351581a08c..8c3a76022e0 100644 --- a/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json +++ b/advisories/unreviewed/2024/07/GHSA-5v69-92vw-fmjh/GHSA-5v69-92vw-fmjh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v69-92vw-fmjh", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-17T15:30:49Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2024-29737" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/xhx7jt1t24s6d7o435wxng8t0ojfbfh5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/17/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json b/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json index 6353ae38deb..bc9de9cc4c1 100644 --- a/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json +++ b/advisories/unreviewed/2024/07/GHSA-7g94-hfqc-q993/GHSA-7g94-hfqc-q993.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g94-hfqc-q993", - "modified": "2024-07-17T09:30:49Z", + "modified": "2024-07-17T15:30:49Z", "published": "2024-07-17T09:30:49Z", "aliases": [ "CVE-2023-52291" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/pl6xgzoqrl4kcn0nt55zjbsx8dn80mkf" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/17/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json b/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json new file mode 100644 index 00000000000..d6fa8309c3b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r67-crqq-3693", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-28074" + ], + "details": "It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28074" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json new file mode 100644 index 00000000000..39d8d5f5398 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86xc-mwv4-f994", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23465" + ], + "details": "The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.   ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23465" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json b/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json new file mode 100644 index 00000000000..fb7401190ac --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pgq-57fj-h74q", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23469" + ], + "details": "SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23469" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json b/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json new file mode 100644 index 00000000000..122fe770b00 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99mg-hh47-f9qh", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-23475" + ], + "details": "The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23475" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json b/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json new file mode 100644 index 00000000000..802e24aa9e8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g4r-89hx-hv6j", + "modified": "2024-07-17T15:30:51Z", + "published": "2024-07-17T15:30:51Z", + "aliases": [ + "CVE-2024-23472" + ], + "details": "SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23472" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9hmq-8gj3-9hvq/GHSA-9hmq-8gj3-9hvq.json b/advisories/unreviewed/2024/07/GHSA-9hmq-8gj3-9hvq/GHSA-9hmq-8gj3-9hvq.json index d2a49bd9e2b..3a8d20539e9 100644 --- a/advisories/unreviewed/2024/07/GHSA-9hmq-8gj3-9hvq/GHSA-9hmq-8gj3-9hvq.json +++ b/advisories/unreviewed/2024/07/GHSA-9hmq-8gj3-9hvq/GHSA-9hmq-8gj3-9hvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hmq-8gj3-9hvq", - "modified": "2024-07-15T06:30:55Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-07-15T06:30:55Z", "aliases": [ "CVE-2024-6074" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T06:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json b/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json new file mode 100644 index 00000000000..3d3901d2573 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcc2-5vx5-63jr", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23466" + ], + "details": "SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23466" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-ghgq-x6wc-6jr5/GHSA-ghgq-x6wc-6jr5.json b/advisories/unreviewed/2024/07/GHSA-ghgq-x6wc-6jr5/GHSA-ghgq-x6wc-6jr5.json new file mode 100644 index 00000000000..0d4b73b071b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ghgq-x6wc-6jr5/GHSA-ghgq-x6wc-6jr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghgq-x6wc-6jr5", + "modified": "2024-07-17T15:30:52Z", + "published": "2024-07-17T15:30:52Z", + "aliases": [ + "CVE-2024-6833" + ], + "details": "A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6833" + }, + { + "type": "WEB", + "url": "https://github.com/zowe/zowe-cli" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json b/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json new file mode 100644 index 00000000000..eccb00a556f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h654-r868-pj2q", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23467" + ], + "details": "The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23467" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json b/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json new file mode 100644 index 00000000000..c29b2ab427f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcf8-5j78-887v", + "modified": "2024-07-17T15:30:52Z", + "published": "2024-07-17T15:30:52Z", + "aliases": [ + "CVE-2024-29120" + ], + "details": "In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return \"Authorization\" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. \n\nMitigation:\n\nall users should upgrade to 2.1.4\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29120" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/y3oqz7l8vd7jxxx3z2khgl625nvfr60j" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-212" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json b/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json new file mode 100644 index 00000000000..219495b2d8f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg5v-hmf4-qqh9", + "modified": "2024-07-17T15:30:52Z", + "published": "2024-07-17T15:30:52Z", + "aliases": [ + "CVE-2024-28993" + ], + "details": "The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28993" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jvf5-642m-hpc3/GHSA-jvf5-642m-hpc3.json b/advisories/unreviewed/2024/07/GHSA-jvf5-642m-hpc3/GHSA-jvf5-642m-hpc3.json new file mode 100644 index 00000000000..d34ab24c2de --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jvf5-642m-hpc3/GHSA-jvf5-642m-hpc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvf5-642m-hpc3", + "modified": "2024-07-17T15:30:50Z", + "published": "2024-07-17T15:30:50Z", + "aliases": [ + "CVE-2024-23470" + ], + "details": "The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23470" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mm2r-gc2g-prj6/GHSA-mm2r-gc2g-prj6.json b/advisories/unreviewed/2024/07/GHSA-mm2r-gc2g-prj6/GHSA-mm2r-gc2g-prj6.json new file mode 100644 index 00000000000..fa9357b60dc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mm2r-gc2g-prj6/GHSA-mm2r-gc2g-prj6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm2r-gc2g-prj6", + "modified": "2024-07-17T15:30:49Z", + "published": "2024-07-17T15:30:49Z", + "aliases": [ + "CVE-2024-6765" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6765" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p2x2-phjv-4rv6/GHSA-p2x2-phjv-4rv6.json b/advisories/unreviewed/2024/07/GHSA-p2x2-phjv-4rv6/GHSA-p2x2-phjv-4rv6.json index 54811d49032..dda72f147bb 100644 --- a/advisories/unreviewed/2024/07/GHSA-p2x2-phjv-4rv6/GHSA-p2x2-phjv-4rv6.json +++ b/advisories/unreviewed/2024/07/GHSA-p2x2-phjv-4rv6/GHSA-p2x2-phjv-4rv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2x2-phjv-4rv6", - "modified": "2024-07-15T06:30:55Z", + "modified": "2024-07-17T15:30:48Z", "published": "2024-07-15T06:30:55Z", "aliases": [ "CVE-2024-6073" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T06:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wg42-q7r2-mwrq/GHSA-wg42-q7r2-mwrq.json b/advisories/unreviewed/2024/07/GHSA-wg42-q7r2-mwrq/GHSA-wg42-q7r2-mwrq.json index 775c9a17ad1..90473651633 100644 --- a/advisories/unreviewed/2024/07/GHSA-wg42-q7r2-mwrq/GHSA-wg42-q7r2-mwrq.json +++ b/advisories/unreviewed/2024/07/GHSA-wg42-q7r2-mwrq/GHSA-wg42-q7r2-mwrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg42-q7r2-mwrq", - "modified": "2024-07-15T06:30:55Z", + "modified": "2024-07-17T15:30:48Z", "published": "2024-07-15T06:30:55Z", "aliases": [ "CVE-2024-6076" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T06:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wjgh-f33q-79fx/GHSA-wjgh-f33q-79fx.json b/advisories/unreviewed/2024/07/GHSA-wjgh-f33q-79fx/GHSA-wjgh-f33q-79fx.json index 947a46859bc..8f1dddb684c 100644 --- a/advisories/unreviewed/2024/07/GHSA-wjgh-f33q-79fx/GHSA-wjgh-f33q-79fx.json +++ b/advisories/unreviewed/2024/07/GHSA-wjgh-f33q-79fx/GHSA-wjgh-f33q-79fx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjgh-f33q-79fx", - "modified": "2024-07-15T06:30:55Z", + "modified": "2024-07-17T15:30:48Z", "published": "2024-07-15T06:30:55Z", "aliases": [ "CVE-2024-6075" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T06:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x95j-7ppj-485m/GHSA-x95j-7ppj-485m.json b/advisories/unreviewed/2024/07/GHSA-x95j-7ppj-485m/GHSA-x95j-7ppj-485m.json new file mode 100644 index 00000000000..b37689e7926 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x95j-7ppj-485m/GHSA-x95j-7ppj-485m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x95j-7ppj-485m", + "modified": "2024-07-17T15:30:53Z", + "published": "2024-07-17T15:30:52Z", + "aliases": [ + "CVE-2024-6834" + ], + "details": "A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an attacker to handle the whole communication including user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6834" + }, + { + "type": "WEB", + "url": "https://github.com/zowe/api-layer" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-17T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xhc8-4cg9-pfch/GHSA-xhc8-4cg9-pfch.json b/advisories/unreviewed/2024/07/GHSA-xhc8-4cg9-pfch/GHSA-xhc8-4cg9-pfch.json index 64bddce16fc..f0a6e060279 100644 --- a/advisories/unreviewed/2024/07/GHSA-xhc8-4cg9-pfch/GHSA-xhc8-4cg9-pfch.json +++ b/advisories/unreviewed/2024/07/GHSA-xhc8-4cg9-pfch/GHSA-xhc8-4cg9-pfch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhc8-4cg9-pfch", - "modified": "2024-07-15T06:30:53Z", + "modified": "2024-07-17T15:30:47Z", "published": "2024-07-15T06:30:53Z", "aliases": [ "CVE-2024-6072" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T06:15:02Z"