From f7af90b94287232f6d3e57baf0458a1fb9c62bd3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Sep 2024 12:32:02 +0000 Subject: [PATCH] Publish Advisories GHSA-8pxv-x6jq-5vw9 GHSA-f67c-8m2w-79hm GHSA-9h7v-6cr6-hcpx GHSA-j73p-gc9r-3pf8 GHSA-6mh6-642h-83x7 GHSA-852g-3f6p-43mm GHSA-8hhj-q97q-8vh4 GHSA-gf35-p27p-qqwm GHSA-gv3v-x3f3-7fxm GHSA-vggf-h36f-57fp GHSA-vp33-g4hg-rcwq GHSA-wmq4-q8rm-8vp5 --- .../GHSA-8pxv-x6jq-5vw9.json | 6 +- .../GHSA-f67c-8m2w-79hm.json | 6 +- .../GHSA-9h7v-6cr6-hcpx.json | 6 +- .../GHSA-j73p-gc9r-3pf8.json | 6 +- .../GHSA-6mh6-642h-83x7.json | 38 ++++++++++++ .../GHSA-852g-3f6p-43mm.json | 38 ++++++++++++ .../GHSA-8hhj-q97q-8vh4.json | 62 +++++++++++++++++++ .../GHSA-gf35-p27p-qqwm.json | 38 ++++++++++++ .../GHSA-gv3v-x3f3-7fxm.json | 43 +++++++++++++ .../GHSA-vggf-h36f-57fp.json | 38 ++++++++++++ .../GHSA-vp33-g4hg-rcwq.json | 38 ++++++++++++ .../GHSA-wmq4-q8rm-8vp5.json | 38 ++++++++++++ 12 files changed, 353 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8hhj-q97q-8vh4/GHSA-8hhj-q97q-8vh4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vp33-g4hg-rcwq/GHSA-vp33-g4hg-rcwq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json diff --git a/advisories/github-reviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json b/advisories/github-reviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json index bd2efd89d60..a49135ab2a0 100644 --- a/advisories/github-reviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json +++ b/advisories/github-reviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pxv-x6jq-5vw9", - "modified": "2024-09-10T18:18:25Z", + "modified": "2024-09-11T12:30:51Z", "published": "2024-07-22T12:30:37Z", "aliases": [ "CVE-2024-38503" @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/22/3" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/22/3" diff --git a/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json index abcbbb17868..775b9bbd1ee 100644 --- a/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json +++ b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f67c-8m2w-79hm", - "modified": "2024-07-08T06:31:33Z", + "modified": "2024-09-11T12:30:51Z", "published": "2023-11-06T12:30:24Z", "aliases": [ "CVE-2023-5090" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5090" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2758" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3854" diff --git a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json index 35e7ca97a20..8fd0d7f388a 100644 --- a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json +++ b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7v-6cr6-hcpx", - "modified": "2024-09-11T06:30:38Z", + "modified": "2024-09-11T12:30:51Z", "published": "2024-06-18T12:30:41Z", "aliases": [ "CVE-2024-5953" @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6569" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6576" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5953" diff --git a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json index 17b91aeff0c..0573f3fc9d0 100644 --- a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json +++ b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j73p-gc9r-3pf8", - "modified": "2024-09-10T15:31:03Z", + "modified": "2024-09-11T12:30:51Z", "published": "2024-07-22T12:30:36Z", "aliases": [ "CVE-2024-34457" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/brlfrmvw9dcv38zoofmhxg7qookmwn7j" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/22/2" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/22/2" diff --git a/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json b/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json new file mode 100644 index 00000000000..7da7d8a7f09 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mh6-642h-83x7", + "modified": "2024-09-11T12:30:52Z", + "published": "2024-09-11T12:30:52Z", + "aliases": [ + "CVE-2024-7609" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before 12.34.8.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7609" + }, + { + "type": "WEB", + "url": "https://https://www.usom.gov.tr/bildirim/tr-24-1447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json b/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json new file mode 100644 index 00000000000..0cb6abca380 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-852g-3f6p-43mm", + "modified": "2024-09-11T12:30:52Z", + "published": "2024-09-11T12:30:52Z", + "aliases": [ + "CVE-2024-45788" + ], + "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45788" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8hhj-q97q-8vh4/GHSA-8hhj-q97q-8vh4.json b/advisories/unreviewed/2024/09/GHSA-8hhj-q97q-8vh4/GHSA-8hhj-q97q-8vh4.json new file mode 100644 index 00000000000..df849127af2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8hhj-q97q-8vh4/GHSA-8hhj-q97q-8vh4.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hhj-q97q-8vh4", + "modified": "2024-09-11T12:30:52Z", + "published": "2024-09-11T12:30:52Z", + "aliases": [ + "CVE-2024-5416" + ], + "details": "The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5416" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.21.8/includes/widgets/image.php#L820" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.21.8/includes/widgets/social-icons.php#L659" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.21.8/includes/widgets/testimonial.php#L608" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.21.8/includes/widgets/traits/button-trait.php#L523" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3123936" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3149264" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a99a64f7-1ea8-4de6-b24f-1f69bf25c1f5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json b/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json new file mode 100644 index 00000000000..c64bf3efe87 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf35-p27p-qqwm", + "modified": "2024-09-11T12:30:51Z", + "published": "2024-09-11T12:30:51Z", + "aliases": [ + "CVE-2024-45786" + ], + "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to gain unauthorized access to sensitive information belonging to other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45786" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json b/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json new file mode 100644 index 00000000000..6cf3b13e574 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv3v-x3f3-7fxm", + "modified": "2024-09-11T12:30:51Z", + "published": "2024-09-11T12:30:51Z", + "aliases": [ + "CVE-2024-8096" + ], + "details": "When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8096" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2669852" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2024-8096.html" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2024-8096.json" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json b/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json new file mode 100644 index 00000000000..e6a5871f1fe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vggf-h36f-57fp", + "modified": "2024-09-11T12:30:52Z", + "published": "2024-09-11T12:30:52Z", + "aliases": [ + "CVE-2024-45787" + ], + "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting response of the API request leading to exposure of sensitive information belonging to other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45787" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vp33-g4hg-rcwq/GHSA-vp33-g4hg-rcwq.json b/advisories/unreviewed/2024/09/GHSA-vp33-g4hg-rcwq/GHSA-vp33-g4hg-rcwq.json new file mode 100644 index 00000000000..3556c368233 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vp33-g4hg-rcwq/GHSA-vp33-g4hg-rcwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp33-g4hg-rcwq", + "modified": "2024-09-11T12:30:51Z", + "published": "2024-09-11T12:30:51Z", + "aliases": [ + "CVE-2024-45327" + ], + "details": "An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45327" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json b/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json new file mode 100644 index 00000000000..9221565560e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmq4-q8rm-8vp5", + "modified": "2024-09-11T12:30:52Z", + "published": "2024-09-11T12:30:52Z", + "aliases": [ + "CVE-2024-45789" + ], + "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application.\n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass certain constraints in the registration process leading to creation of multiple accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45789" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-354" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T12:15:02Z" + } +} \ No newline at end of file