From f7696f41229bd1e04ea67cbe36f891c81699327f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Sep 2024 21:33:07 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7x48-7466-3g33.json | 12 +++++- .../GHSA-gv29-2vcq-f68m.json | 3 +- .../GHSA-5m9f-w8v4-rvgm.json | 2 +- .../GHSA-4c2f-665c-x845.json | 1 + .../GHSA-h66j-qwj8-p6m9.json | 2 +- .../GHSA-pvv9-mc25-j2pr.json | 3 +- .../GHSA-5c89-5mrj-8h62.json | 2 +- .../GHSA-9whp-qh87-g9m8.json | 2 +- .../GHSA-wp3w-g939-hq9w.json | 1 + .../GHSA-2ch6-m8wh-67f2.json | 1 + .../GHSA-wxcf-6q4p-3735.json | 3 +- .../GHSA-84mh-m38q-m9vh.json | 7 +++- .../GHSA-2gmp-x9r7-xp6q.json | 2 +- .../GHSA-2hj6-cwhm-rfg9.json | 35 +++++++++++++++++ .../GHSA-2mj9-cv5h-vqxp.json | 11 ++++-- .../GHSA-2x56-wxfv-qqrm.json | 35 +++++++++++++++++ .../GHSA-3mxv-x893-5542.json | 2 +- .../GHSA-458x-pm5m-qh42.json | 35 +++++++++++++++++ .../GHSA-4pwx-m3xw-8xj9.json | 3 +- .../GHSA-4qrv-8qq4-m334.json | 3 +- .../GHSA-576f-8hqc-j5jv.json | 2 +- .../GHSA-67q9-cxjc-p8vg.json | 2 +- .../GHSA-6cf5-rv3h-c7jx.json | 11 ++++-- .../GHSA-6m86-hgfj-mfmr.json | 2 +- .../GHSA-6q3p-cf37-rf5w.json | 35 +++++++++++++++++ .../GHSA-7486-6g6r-5cxf.json | 11 ++++-- .../GHSA-77f2-r3qh-x5x7.json | 9 +++-- .../GHSA-7h5m-97m9-x6w8.json | 11 ++++-- .../GHSA-7xv2-675g-4wq2.json | 11 ++++-- .../GHSA-84q8-hphj-4r7w.json | 15 ++++++-- .../GHSA-8jvv-vmjw-rvrv.json | 2 +- .../GHSA-9c7x-x2xj-mr98.json | 2 +- .../GHSA-9f35-qf4j-2v26.json | 35 +++++++++++++++++ .../GHSA-9jhx-36qm-567c.json | 11 ++++-- .../GHSA-c83g-2v28-2jp8.json | 35 +++++++++++++++++ .../GHSA-c922-2344-3839.json | 11 ++++-- .../GHSA-cxw7-46xp-6h7x.json | 2 +- .../GHSA-f8cf-9769-43r2.json | 35 +++++++++++++++++ .../GHSA-ff5r-mvxr-r3x8.json | 2 +- .../GHSA-ff8r-g78q-g9wh.json | 2 +- .../GHSA-fqvq-m9ff-5v4w.json | 1 + .../GHSA-frph-pw87-p4w6.json | 2 +- .../GHSA-gvpr-rr23-63gq.json | 38 +++++++++++++++++++ .../GHSA-h642-rg9x-ww4c.json | 11 ++++-- .../GHSA-h9ph-w4hg-9mjw.json | 35 +++++++++++++++++ .../GHSA-j298-ggff-cvm8.json | 1 + .../GHSA-jvw4-8x97-wppq.json | 2 +- .../GHSA-m84f-rjqv-399j.json | 11 ++++-- .../GHSA-m9w6-r7mg-6gqq.json | 3 +- .../GHSA-p22p-4gp5-hqw7.json | 1 + .../GHSA-pcw9-jcmv-xqqq.json | 3 +- .../GHSA-pv49-965m-2m35.json | 2 +- .../GHSA-q2pv-h46f-8gvc.json | 38 +++++++++++++++++++ .../GHSA-q786-f28r-38f4.json | 2 +- .../GHSA-qcmc-q53m-hjr7.json | 11 ++++-- .../GHSA-rjg6-j4q2-2v5v.json | 3 +- .../GHSA-rv5g-p7p6-mpxp.json | 3 +- .../GHSA-vgw3-33x7-h3gh.json | 2 +- .../GHSA-vm47-pw3h-2qgg.json | 2 +- .../GHSA-vvqc-xqxj-mg66.json | 35 +++++++++++++++++ .../GHSA-w44h-95m4-q297.json | 11 ++++-- .../GHSA-w7pj-cjvc-96cx.json | 2 +- .../GHSA-wfgh-48cf-2678.json | 11 ++++-- .../GHSA-xhhp-64qq-p9x5.json | 1 + 64 files changed, 554 insertions(+), 88 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gvpr-rr23-63gq/GHSA-gvpr-rr23-63gq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q2pv-h46f-8gvc/GHSA-q2pv-h46f-8gvc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json diff --git a/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json b/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json index 9ceb86b7c64..43176a0b6f0 100644 --- a/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json +++ b/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x48-7466-3g33", - "modified": "2022-03-24T23:25:23Z", + "modified": "2024-09-20T21:32:41Z", "published": "2022-03-18T00:01:11Z", "aliases": [ "CVE-2021-23556" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ @@ -50,7 +54,7 @@ }, { "type": "WEB", - "url": "https://github.com/Guake/guake/pull/2017/commits/e3d671120bfe7ba28f50e256cc5e8a629781b888" + "url": "https://github.com/Guake/guake/commit/b769b3a5fd71a107c58679d217cccc971b4196b4" }, { "type": "PACKAGE", @@ -60,6 +64,10 @@ "type": "WEB", "url": "https://github.com/Guake/guake/releases" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-7x48-7466-3g33" + }, { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/guake/PYSEC-2022-165.yaml" diff --git a/advisories/unreviewed/2023/08/GHSA-gv29-2vcq-f68m/GHSA-gv29-2vcq-f68m.json b/advisories/unreviewed/2023/08/GHSA-gv29-2vcq-f68m/GHSA-gv29-2vcq-f68m.json index 2a6ea3464a0..7a060e57f01 100644 --- a/advisories/unreviewed/2023/08/GHSA-gv29-2vcq-f68m/GHSA-gv29-2vcq-f68m.json +++ b/advisories/unreviewed/2023/08/GHSA-gv29-2vcq-f68m/GHSA-gv29-2vcq-f68m.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-327" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5m9f-w8v4-rvgm/GHSA-5m9f-w8v4-rvgm.json b/advisories/unreviewed/2024/01/GHSA-5m9f-w8v4-rvgm/GHSA-5m9f-w8v4-rvgm.json index a88b1ab15f9..1eeaecb55d8 100644 --- a/advisories/unreviewed/2024/01/GHSA-5m9f-w8v4-rvgm/GHSA-5m9f-w8v4-rvgm.json +++ b/advisories/unreviewed/2024/01/GHSA-5m9f-w8v4-rvgm/GHSA-5m9f-w8v4-rvgm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4c2f-665c-x845/GHSA-4c2f-665c-x845.json b/advisories/unreviewed/2024/02/GHSA-4c2f-665c-x845/GHSA-4c2f-665c-x845.json index bedfd1102b6..7763581c52e 100644 --- a/advisories/unreviewed/2024/02/GHSA-4c2f-665c-x845/GHSA-4c2f-665c-x845.json +++ b/advisories/unreviewed/2024/02/GHSA-4c2f-665c-x845/GHSA-4c2f-665c-x845.json @@ -41,6 +41,7 @@ "database_specific": { "cwe_ids": [ "CWE-200", + "CWE-327", "CWE-384" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json b/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json index f96fd04acc9..4f15f5ad833 100644 --- a/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json +++ b/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pvv9-mc25-j2pr/GHSA-pvv9-mc25-j2pr.json b/advisories/unreviewed/2024/02/GHSA-pvv9-mc25-j2pr/GHSA-pvv9-mc25-j2pr.json index f3bee92f33a..977b2258ff1 100644 --- a/advisories/unreviewed/2024/02/GHSA-pvv9-mc25-j2pr/GHSA-pvv9-mc25-j2pr.json +++ b/advisories/unreviewed/2024/02/GHSA-pvv9-mc25-j2pr/GHSA-pvv9-mc25-j2pr.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-312" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json b/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json index 5ef526eed4a..95571cd19af 100644 --- a/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json +++ b/advisories/unreviewed/2024/03/GHSA-5c89-5mrj-8h62/GHSA-5c89-5mrj-8h62.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9whp-qh87-g9m8/GHSA-9whp-qh87-g9m8.json b/advisories/unreviewed/2024/03/GHSA-9whp-qh87-g9m8/GHSA-9whp-qh87-g9m8.json index a3f66d2f835..2b0e950c474 100644 --- a/advisories/unreviewed/2024/03/GHSA-9whp-qh87-g9m8/GHSA-9whp-qh87-g9m8.json +++ b/advisories/unreviewed/2024/03/GHSA-9whp-qh87-g9m8/GHSA-9whp-qh87-g9m8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-wp3w-g939-hq9w/GHSA-wp3w-g939-hq9w.json b/advisories/unreviewed/2024/03/GHSA-wp3w-g939-hq9w/GHSA-wp3w-g939-hq9w.json index 25c8fc6b6e0..9414aa6fd7f 100644 --- a/advisories/unreviewed/2024/03/GHSA-wp3w-g939-hq9w/GHSA-wp3w-g939-hq9w.json +++ b/advisories/unreviewed/2024/03/GHSA-wp3w-g939-hq9w/GHSA-wp3w-g939-hq9w.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-300" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json b/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json index 56d34ed6d98..da9284bbc5e 100644 --- a/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json +++ b/advisories/unreviewed/2024/04/GHSA-2ch6-m8wh-67f2/GHSA-2ch6-m8wh-67f2.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-599" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-wxcf-6q4p-3735/GHSA-wxcf-6q4p-3735.json b/advisories/unreviewed/2024/05/GHSA-wxcf-6q4p-3735/GHSA-wxcf-6q4p-3735.json index f3e09de9da9..c303dcf9a02 100644 --- a/advisories/unreviewed/2024/05/GHSA-wxcf-6q4p-3735/GHSA-wxcf-6q4p-3735.json +++ b/advisories/unreviewed/2024/05/GHSA-wxcf-6q4p-3735/GHSA-wxcf-6q4p-3735.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-282" + "CWE-282", + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-84mh-m38q-m9vh/GHSA-84mh-m38q-m9vh.json b/advisories/unreviewed/2024/06/GHSA-84mh-m38q-m9vh/GHSA-84mh-m38q-m9vh.json index 7a1dcb45ba5..c16d178493c 100644 --- a/advisories/unreviewed/2024/06/GHSA-84mh-m38q-m9vh/GHSA-84mh-m38q-m9vh.json +++ b/advisories/unreviewed/2024/06/GHSA-84mh-m38q-m9vh/GHSA-84mh-m38q-m9vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84mh-m38q-m9vh", - "modified": "2024-06-18T21:30:36Z", + "modified": "2024-09-20T21:31:37Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-6129" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -40,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-205" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json b/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json index fc98554cb1c..88df98bca67 100644 --- a/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json +++ b/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gmp-x9r7-xp6q", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-31197" diff --git a/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json b/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json new file mode 100644 index 00000000000..4d4fd154784 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2hj6-cwhm-rfg9/GHSA-2hj6-cwhm-rfg9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hj6-cwhm-rfg9", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46103" + ], + "details": "SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46103" + }, + { + "type": "WEB", + "url": "https://github.com/N0zoM1z0/MY-CVE/blob/main/CVE-2024-46103.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2mj9-cv5h-vqxp/GHSA-2mj9-cv5h-vqxp.json b/advisories/unreviewed/2024/09/GHSA-2mj9-cv5h-vqxp/GHSA-2mj9-cv5h-vqxp.json index d6c829e7ca2..a7b07b355aa 100644 --- a/advisories/unreviewed/2024/09/GHSA-2mj9-cv5h-vqxp/GHSA-2mj9-cv5h-vqxp.json +++ b/advisories/unreviewed/2024/09/GHSA-2mj9-cv5h-vqxp/GHSA-2mj9-cv5h-vqxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mj9-cv5h-vqxp", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46741" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix double free of 'buf' in error path\n\nsmatch warning:\ndrivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf'\n\nIn fastrpc_req_mmap() error path, the fastrpc buffer is freed in\nfastrpc_req_munmap_impl() if unmap is successful.\n\nBut in the end, there is an unconditional call to fastrpc_buf_free().\nSo the above case triggers the double free of fastrpc buf.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json b/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json new file mode 100644 index 00000000000..507ff3ad33b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x56-wxfv-qqrm", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46645" + ], + "details": "eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46645" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json b/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json index 81263c07574..91ac09ce853 100644 --- a/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json +++ b/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mxv-x893-5542", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31174" diff --git a/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json b/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json new file mode 100644 index 00000000000..417fcd64ad7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-458x-pm5m-qh42", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46644" + ], + "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46644" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json b/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json index 580564db021..1bacf64a535 100644 --- a/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json +++ b/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4pwx-m3xw-8xj9", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31175" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json b/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json index a35fe691181..ff82ac7cace 100644 --- a/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json +++ b/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qrv-8qq4-m334", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31185" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json b/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json index 6c1fcc28b62..f4ca657a955 100644 --- a/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json +++ b/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-576f-8hqc-j5jv", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31176" diff --git a/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json b/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json index ea4b6acf149..a4fad359343 100644 --- a/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json +++ b/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67q9-cxjc-p8vg", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31178" diff --git a/advisories/unreviewed/2024/09/GHSA-6cf5-rv3h-c7jx/GHSA-6cf5-rv3h-c7jx.json b/advisories/unreviewed/2024/09/GHSA-6cf5-rv3h-c7jx/GHSA-6cf5-rv3h-c7jx.json index a4dfffcdd76..3d8f601b825 100644 --- a/advisories/unreviewed/2024/09/GHSA-6cf5-rv3h-c7jx/GHSA-6cf5-rv3h-c7jx.json +++ b/advisories/unreviewed/2024/09/GHSA-6cf5-rv3h-c7jx/GHSA-6cf5-rv3h-c7jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cf5-rv3h-c7jx", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush()\n\nThis adds a check before freeing the rx->skb in flush and close\nfunctions to handle the kernel crash seen while removing driver after FW\ndownload fails or before FW download completes.\n\ndmesg log:\n[ 54.634586] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000080\n[ 54.643398] Mem abort info:\n[ 54.646204] ESR = 0x0000000096000004\n[ 54.649964] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 54.655286] SET = 0, FnV = 0\n[ 54.658348] EA = 0, S1PTW = 0\n[ 54.661498] FSC = 0x04: level 0 translation fault\n[ 54.666391] Data abort info:\n[ 54.669273] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 54.674768] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 54.674771] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 54.674775] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000048860000\n[ 54.674780] [0000000000000080] pgd=0000000000000000, p4d=0000000000000000\n[ 54.703880] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 54.710152] Modules linked in: btnxpuart(-) overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_micfil snd_soc_fsl_spdif snd_soc_fsl_sai snd_soc_fsl_utils imx_pcm_dma gpio_ir_recv rc_core sch_fq_codel fuse\n[ 54.744357] CPU: 3 PID: 72 Comm: kworker/u9:0 Not tainted 6.6.3-otbr-g128004619037 #2\n[ 54.744364] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 54.744368] Workqueue: hci0 hci_power_on\n[ 54.757244] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 54.757249] pc : kfree_skb_reason+0x18/0xb0\n[ 54.772299] lr : btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.782921] sp : ffff8000805ebca0\n[ 54.782923] x29: ffff8000805ebca0 x28: ffffa5c6cf1869c0 x27: ffffa5c6cf186000\n[ 54.782931] x26: ffff377b84852400 x25: ffff377b848523c0 x24: ffff377b845e7230\n[ 54.782938] x23: ffffa5c6ce8dbe08 x22: ffffa5c6ceb65410 x21: 00000000ffffff92\n[ 54.782945] x20: ffffa5c6ce8dbe98 x19: ffffffffffffffac x18: ffffffffffffffff\n[ 54.807651] x17: 0000000000000000 x16: ffffa5c6ce2824ec x15: ffff8001005eb857\n[ 54.821917] x14: 0000000000000000 x13: ffffa5c6cf1a02e0 x12: 0000000000000642\n[ 54.821924] x11: 0000000000000040 x10: ffffa5c6cf19d690 x9 : ffffa5c6cf19d688\n[ 54.821931] x8 : ffff377b86000028 x7 : 0000000000000000 x6 : 0000000000000000\n[ 54.821938] x5 : ffff377b86000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 54.843331] x2 : 0000000000000000 x1 : 0000000000000002 x0 : ffffffffffffffac\n[ 54.857599] Call trace:\n[ 54.857601] kfree_skb_reason+0x18/0xb0\n[ 54.863878] btnxpuart_flush+0x40/0x58 [btnxpuart]\n[ 54.863888] hci_dev_open_sync+0x3a8/0xa04\n[ 54.872773] hci_power_on+0x54/0x2e4\n[ 54.881832] process_one_work+0x138/0x260\n[ 54.881842] worker_thread+0x32c/0x438\n[ 54.881847] kthread+0x118/0x11c\n[ 54.881853] ret_from_fork+0x10/0x20\n[ 54.896406] Code: a9be7bfd 910003fd f9000bf3 aa0003f3 (b940d400)\n[ 54.896410] ---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json b/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json index ec20568e656..c344f784c01 100644 --- a/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json +++ b/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m86-hgfj-mfmr", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31171" diff --git a/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json b/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json new file mode 100644 index 00000000000..57ba0e13035 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q3p-cf37-rf5w", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46648" + ], + "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46648" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json b/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json index 4ccb3761d2e..98bdc3488e6 100644 --- a/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json +++ b/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7486-6g6r-5cxf", - "modified": "2024-09-20T18:32:27Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-20T18:32:27Z", "aliases": [ "CVE-2024-42697" ], "details": "Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T18:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-77f2-r3qh-x5x7/GHSA-77f2-r3qh-x5x7.json b/advisories/unreviewed/2024/09/GHSA-77f2-r3qh-x5x7/GHSA-77f2-r3qh-x5x7.json index 2f6fb6c8512..8f5b6116627 100644 --- a/advisories/unreviewed/2024/09/GHSA-77f2-r3qh-x5x7/GHSA-77f2-r3qh-x5x7.json +++ b/advisories/unreviewed/2024/09/GHSA-77f2-r3qh-x5x7/GHSA-77f2-r3qh-x5x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77f2-r3qh-x5x7", - "modified": "2024-09-20T09:30:35Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-20T09:30:35Z", "aliases": [ "CVE-2024-41721" ], "details": "An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T08:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7h5m-97m9-x6w8/GHSA-7h5m-97m9-x6w8.json b/advisories/unreviewed/2024/09/GHSA-7h5m-97m9-x6w8/GHSA-7h5m-97m9-x6w8.json index c348f410852..3cd1695cc78 100644 --- a/advisories/unreviewed/2024/09/GHSA-7h5m-97m9-x6w8/GHSA-7h5m-97m9-x6w8.json +++ b/advisories/unreviewed/2024/09/GHSA-7h5m-97m9-x6w8/GHSA-7h5m-97m9-x6w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h5m-97m9-x6w8", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46738" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Fix use-after-free when removing resource in vmci_resource_remove()\n\nWhen removing a resource from vmci_resource_table in\nvmci_resource_remove(), the search is performed using the resource\nhandle by comparing context and resource fields.\n\nIt is possible though to create two resources with different types\nbut same handle (same context and resource fields).\n\nWhen trying to remove one of the resources, vmci_resource_remove()\nmay not remove the intended one, but the object will still be freed\nas in the case of the datagram type in vmci_datagram_destroy_handle().\nvmci_resource_table will still hold a pointer to this freed resource\nleading to a use-after-free vulnerability.\n\nBUG: KASAN: use-after-free in vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\nBUG: KASAN: use-after-free in vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\nRead of size 4 at addr ffff88801c16d800 by task syz-executor197/1592\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x82/0xa9 lib/dump_stack.c:106\n print_address_description.constprop.0+0x21/0x366 mm/kasan/report.c:239\n __kasan_report.cold+0x7f/0x132 mm/kasan/report.c:425\n kasan_report+0x38/0x51 mm/kasan/report.c:442\n vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]\n vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147\n vmci_qp_broker_detach+0x89a/0x11b9 drivers/misc/vmw_vmci/vmci_queue_pair.c:2182\n ctx_free_ctx+0x473/0xbe1 drivers/misc/vmw_vmci/vmci_context.c:444\n kref_put include/linux/kref.h:65 [inline]\n vmci_ctx_put drivers/misc/vmw_vmci/vmci_context.c:497 [inline]\n vmci_ctx_destroy+0x170/0x1d6 drivers/misc/vmw_vmci/vmci_context.c:195\n vmci_host_close+0x125/0x1ac drivers/misc/vmw_vmci/vmci_host.c:143\n __fput+0x261/0xa34 fs/file_table.c:282\n task_work_run+0xf0/0x194 kernel/task_work.c:164\n tracehook_notify_resume include/linux/tracehook.h:189 [inline]\n exit_to_user_mode_loop+0x184/0x189 kernel/entry/common.c:187\n exit_to_user_mode_prepare+0x11b/0x123 kernel/entry/common.c:220\n __syscall_exit_to_user_mode_work kernel/entry/common.c:302 [inline]\n syscall_exit_to_user_mode+0x18/0x42 kernel/entry/common.c:313\n do_syscall_64+0x41/0x85 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x6e/0x0\n\nThis change ensures the type is also checked when removing\nthe resource from vmci_resource_table in vmci_resource_remove().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json b/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json index e1fef22fa5f..facdea10b05 100644 --- a/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json +++ b/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xv2-675g-4wq2", - "modified": "2024-09-20T18:32:26Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-20T18:32:26Z", "aliases": [ "CVE-2023-47480" ], "details": "An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T17:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json b/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json index 2194cc1353a..d4ca6086c83 100644 --- a/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json +++ b/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84q8-hphj-4r7w", - "modified": "2024-09-20T18:32:27Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-20T18:32:27Z", "aliases": [ "CVE-2024-45489" ], "details": "Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however, it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45489" }, + { + "type": "WEB", + "url": "https://arc.net/blog/CVE-2024-45489-incident-response" + }, { "type": "WEB", "url": "https://kibty.town/blog/arc" @@ -29,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T17:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json b/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json index 34f1024bb8a..c711921d494 100644 --- a/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json +++ b/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jvv-vmjw-rvrv", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31170" diff --git a/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json b/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json index 018f7863905..f70d2de518d 100644 --- a/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json +++ b/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c7x-x2xj-mr98", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31184" diff --git a/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json b/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json new file mode 100644 index 00000000000..471e8af3d10 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f35-qf4j-2v26", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46647" + ], + "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46647" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9jhx-36qm-567c/GHSA-9jhx-36qm-567c.json b/advisories/unreviewed/2024/09/GHSA-9jhx-36qm-567c/GHSA-9jhx-36qm-567c.json index 760286a788d..3717905b22c 100644 --- a/advisories/unreviewed/2024/09/GHSA-9jhx-36qm-567c/GHSA-9jhx-36qm-567c.json +++ b/advisories/unreviewed/2024/09/GHSA-9jhx-36qm-567c/GHSA-9jhx-36qm-567c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jhx-36qm-567c", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46726" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure index calculation will not overflow\n\n[WHY & HOW]\nMake sure vmid0p72_idx, vnom0p8_idx and vmax0p9_idx calculation will\nnever overflow and exceess array size.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json b/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json new file mode 100644 index 00000000000..91bc7162ef8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c83g-2v28-2jp8/GHSA-c83g-2v28-2jp8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c83g-2v28-2jp8", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46640" + ], + "details": "SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46640" + }, + { + "type": "WEB", + "url": "https://gitee.com/zheng_botong/CVE-2024-46640" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c922-2344-3839/GHSA-c922-2344-3839.json b/advisories/unreviewed/2024/09/GHSA-c922-2344-3839/GHSA-c922-2344-3839.json index 107a9da5369..8377390f27e 100644 --- a/advisories/unreviewed/2024/09/GHSA-c922-2344-3839/GHSA-c922-2344-3839.json +++ b/advisories/unreviewed/2024/09/GHSA-c922-2344-3839/GHSA-c922-2344-3839.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c922-2344-3839", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46742" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open()\n\nnull-ptr-deref will occur when (req_op_level == SMB2_OPLOCK_LEVEL_LEASE)\nand parse_lease_state() return NULL.\n\nFix this by check if 'lease_ctx_info' is NULL.\n\nAdditionally, remove the redundant parentheses in\nparse_durable_handle_context().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json b/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json index 3dc8d474a0d..1d5f90f3bc5 100644 --- a/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json +++ b/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxw7-46xp-6h7x", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-31198" diff --git a/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json b/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json new file mode 100644 index 00000000000..71aa3724b9a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8cf-9769-43r2", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46646" + ], + "details": "eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46646" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json b/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json index 90b564652e5..bcb26978e22 100644 --- a/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json +++ b/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ff5r-mvxr-r3x8", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31183" diff --git a/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json b/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json index 08491141363..dc2dc23c478 100644 --- a/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json +++ b/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ff8r-g78q-g9wh", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31172" diff --git a/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json b/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json index 2ccd0fc417d..a194804da47 100644 --- a/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json +++ b/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json b/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json index 64cbc156b34..6913b321a03 100644 --- a/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json +++ b/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frph-pw87-p4w6", - "modified": "2024-09-18T15:30:50Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:50Z", "aliases": [ "CVE-2024-31168" diff --git a/advisories/unreviewed/2024/09/GHSA-gvpr-rr23-63gq/GHSA-gvpr-rr23-63gq.json b/advisories/unreviewed/2024/09/GHSA-gvpr-rr23-63gq/GHSA-gvpr-rr23-63gq.json new file mode 100644 index 00000000000..f06027322e2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gvpr-rr23-63gq/GHSA-gvpr-rr23-63gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvpr-rr23-63gq", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46654" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46654" + }, + { + "type": "WEB", + "url": "https://github.com/magicblack/maccms10/issues/1183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h642-rg9x-ww4c/GHSA-h642-rg9x-ww4c.json b/advisories/unreviewed/2024/09/GHSA-h642-rg9x-ww4c/GHSA-h642-rg9x-ww4c.json index efb71ef9116..07e96afdded 100644 --- a/advisories/unreviewed/2024/09/GHSA-h642-rg9x-ww4c/GHSA-h642-rg9x-ww4c.json +++ b/advisories/unreviewed/2024/09/GHSA-h642-rg9x-ww4c/GHSA-h642-rg9x-ww4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h642-rg9x-ww4c", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46735" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery()\n\nWhen two UBLK_CMD_START_USER_RECOVERY commands are submitted, the\nfirst one sets 'ubq->ubq_daemon' to NULL, and the second one triggers\nWARN in ublk_queue_reinit() and subsequently a NULL pointer dereference\nissue.\n\nFix it by adding the check in ublk_ctrl_start_recovery() and return\nimmediately in case of zero 'ub->nr_queues_ready'.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n RIP: 0010:ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x75/0x170\n ? exc_page_fault+0x64/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? ublk_ctrl_start_recovery.constprop.0+0x82/0x180\n ublk_ctrl_uring_cmd+0x4f7/0x6c0\n ? pick_next_task_idle+0x26/0x40\n io_uring_cmd+0x9a/0x1b0\n io_issue_sqe+0x193/0x3f0\n io_wq_submit_work+0x9b/0x390\n io_worker_handle_work+0x165/0x360\n io_wq_worker+0xcb/0x2f0\n ? finish_task_switch.isra.0+0x203/0x290\n ? finish_task_switch.isra.0+0x203/0x290\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_io_wq_worker+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json b/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json new file mode 100644 index 00000000000..2c8a8bce893 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h9ph-w4hg-9mjw/GHSA-h9ph-w4hg-9mjw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9ph-w4hg-9mjw", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46101" + ], + "details": "GDidees CMS <= v3.9.1 has a file upload vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46101" + }, + { + "type": "WEB", + "url": "https://github.com/N0zoM1z0/MY-CVE/blob/main/CVE-2024-46101.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json b/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json index 09d77308643..7671618ab38 100644 --- a/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json +++ b/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json b/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json index a0a858c4673..575a75e9077 100644 --- a/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json +++ b/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvw4-8x97-wppq", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31179" diff --git a/advisories/unreviewed/2024/09/GHSA-m84f-rjqv-399j/GHSA-m84f-rjqv-399j.json b/advisories/unreviewed/2024/09/GHSA-m84f-rjqv-399j/GHSA-m84f-rjqv-399j.json index cfb0a6f26ba..68ab6aea83a 100644 --- a/advisories/unreviewed/2024/09/GHSA-m84f-rjqv-399j/GHSA-m84f-rjqv-399j.json +++ b/advisories/unreviewed/2024/09/GHSA-m84f-rjqv-399j/GHSA-m84f-rjqv-399j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m84f-rjqv-399j", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46725" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds write warning\n\nCheck the ring type value to fix the out-of-bounds\nwrite warning", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json b/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json index 6437717b69f..e993e607a05 100644 --- a/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json +++ b/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9w6-r7mg-6gqq", - "modified": "2024-09-18T15:30:50Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:50Z", "aliases": [ "CVE-2024-31167" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json b/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json index 87e2302e1a7..978bb99f139 100644 --- a/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json +++ b/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json b/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json index e16b95e9519..b454c59c831 100644 --- a/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json +++ b/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcw9-jcmv-xqqq", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31182" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json b/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json index 868202f53ac..e51b72f9f43 100644 --- a/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json +++ b/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv49-965m-2m35", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31181" diff --git a/advisories/unreviewed/2024/09/GHSA-q2pv-h46f-8gvc/GHSA-q2pv-h46f-8gvc.json b/advisories/unreviewed/2024/09/GHSA-q2pv-h46f-8gvc/GHSA-q2pv-h46f-8gvc.json new file mode 100644 index 00000000000..f34983ab3f8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q2pv-h46f-8gvc/GHSA-q2pv-h46f-8gvc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2pv-h46f-8gvc", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-45229" + ], + "details": "The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by injecting invalid arguments into a GET request, potentially exposing the authentication tokens of other currently logged-in users. These tokens can then be used to invoke additional APIs on port 9183. This exploit does not disclose any username or password information. \n\nCurrently, there are no workarounds in Versa Director. However, if there is Web Application Firewall (WAF) or API Gateway fronting the Versa Director, it can be used to block access to the URLs of vulnerable API. /vnms/devicereg/device/* (on ports 9182 & 9183) and /versa/vnms/devicereg/device/* (on port 443). Versa recommends that Directors be upgraded to one of the remediated software versions. This vulnerability is not exploitable on Versa Directors not exposed to the Internet.We have validated that no Versa-hosted head ends have been affected by this vulnerability. Please contact Versa Technical Support or Versa account team for any further assistance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45229" + }, + { + "type": "WEB", + "url": "https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json b/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json index a320b4e78a0..fe8d6dc0e30 100644 --- a/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json +++ b/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q786-f28r-38f4", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31173" diff --git a/advisories/unreviewed/2024/09/GHSA-qcmc-q53m-hjr7/GHSA-qcmc-q53m-hjr7.json b/advisories/unreviewed/2024/09/GHSA-qcmc-q53m-hjr7/GHSA-qcmc-q53m-hjr7.json index 9bdcc669580..001db092b92 100644 --- a/advisories/unreviewed/2024/09/GHSA-qcmc-q53m-hjr7/GHSA-qcmc-q53m-hjr7.json +++ b/advisories/unreviewed/2024/09/GHSA-qcmc-q53m-hjr7/GHSA-qcmc-q53m-hjr7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcmc-q53m-hjr7", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46740" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF caused by offsets overwrite\n\nBinder objects are processed and copied individually into the target\nbuffer during transactions. Any raw data in-between these objects is\ncopied as well. However, this raw data copy lacks an out-of-bounds\ncheck. If the raw data exceeds the data section size then the copy\noverwrites the offsets section. This eventually triggers an error that\nattempts to unwind the processed objects. However, at this point the\noffsets used to index these objects are now corrupted.\n\nUnwinding with corrupted offsets can result in decrements of arbitrary\nnodes and lead to their premature release. Other users of such nodes are\nleft with a dangling pointer triggering a use-after-free. This issue is\nmade evident by the following KASAN report (trimmed):\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c\n Write of size 4 at addr ffff47fc91598f04 by task binder-util/743\n\n CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n _raw_spin_lock+0xe4/0x19c\n binder_free_buf+0x128/0x434\n binder_thread_write+0x8a4/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Allocated by task 743:\n __kmalloc_cache_noprof+0x110/0x270\n binder_new_node+0x50/0x700\n binder_transaction+0x413c/0x6da8\n binder_thread_write+0x978/0x3260\n binder_ioctl+0x18f0/0x258c\n [...]\n\n Freed by task 745:\n kfree+0xbc/0x208\n binder_thread_read+0x1c5c/0x37d4\n binder_ioctl+0x16d8/0x258c\n [...]\n ==================================================================\n\nTo avoid this issue, let's check that the raw data copy is within the\nboundaries of the data section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json b/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json index 557efaad70a..5daec7946d1 100644 --- a/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json +++ b/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjg6-j4q2-2v5v", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-31196" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json b/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json index 64359e00655..fbb71e7b6f9 100644 --- a/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json +++ b/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv5g-p7p6-mpxp", - "modified": "2024-09-18T15:30:50Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:50Z", "aliases": [ "CVE-2024-31165" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-690" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json b/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json index 62bb117413e..27427d0947e 100644 --- a/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json +++ b/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgw3-33x7-h3gh", - "modified": "2024-09-18T15:30:50Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:50Z", "aliases": [ "CVE-2024-31166" diff --git a/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json b/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json index f0f5d014ff0..0a0e2fef4e0 100644 --- a/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json +++ b/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vm47-pw3h-2qgg", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:39Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31180" diff --git a/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json b/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json new file mode 100644 index 00000000000..9412e310c47 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqc-xqxj-mg66", + "modified": "2024-09-20T21:31:39Z", + "published": "2024-09-20T21:31:39Z", + "aliases": [ + "CVE-2024-46649" + ], + "details": "eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46649" + }, + { + "type": "WEB", + "url": "https://github.com/skit-cyber-security/eNMS_vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w44h-95m4-q297/GHSA-w44h-95m4-q297.json b/advisories/unreviewed/2024/09/GHSA-w44h-95m4-q297/GHSA-w44h-95m4-q297.json index 0140318526f..b83008647c1 100644 --- a/advisories/unreviewed/2024/09/GHSA-w44h-95m4-q297/GHSA-w44h-95m4-q297.json +++ b/advisories/unreviewed/2024/09/GHSA-w44h-95m4-q297/GHSA-w44h-95m4-q297.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w44h-95m4-q297", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46739" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind\n\nFor primary VM Bus channels, primary_channel pointer is always NULL. This\npointer is valid only for the secondary channels. Also, rescind callback\nis meant for primary channels only.\n\nFix NULL pointer dereference by retrieving the device_obj from the parent\nfor the primary channel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json b/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json index 8f6b7bdc369..da47b72e13c 100644 --- a/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json +++ b/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7pj-cjvc-96cx", - "modified": "2024-09-18T15:30:51Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T15:30:51Z", "aliases": [ "CVE-2024-31169" diff --git a/advisories/unreviewed/2024/09/GHSA-wfgh-48cf-2678/GHSA-wfgh-48cf-2678.json b/advisories/unreviewed/2024/09/GHSA-wfgh-48cf-2678/GHSA-wfgh-48cf-2678.json index a7acf833bad..7f2bcae6c7c 100644 --- a/advisories/unreviewed/2024/09/GHSA-wfgh-48cf-2678/GHSA-wfgh-48cf-2678.json +++ b/advisories/unreviewed/2024/09/GHSA-wfgh-48cf-2678/GHSA-wfgh-48cf-2678.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfgh-48cf-2678", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T21:31:38Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46737" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix kernel crash if commands allocation fails\n\nIf the commands allocation fails in nvmet_tcp_alloc_cmds()\nthe kernel crashes in nvmet_tcp_release_queue_work() because of\na NULL pointer dereference.\n\n nvmet: failed to install queue 0 cntlid 1 ret 6\n Unable to handle kernel NULL pointer dereference at\n virtual address 0000000000000008\n\nFix the bug by setting queue->nr_cmds to zero in case\nnvmet_tcp_alloc_cmd() fails.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json b/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json index 449d9198c19..3eedddbf26f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json +++ b/advisories/unreviewed/2024/09/GHSA-xhhp-64qq-p9x5/GHSA-xhhp-64qq-p9x5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-316" ], "severity": "MODERATE",