From f8d39d7ab2f5f4314acd72e2c18858d629b24a0b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 4 Dec 2024 06:32:49 +0000 Subject: [PATCH] Publish Advisories GHSA-2gj6-9934-w9r6 GHSA-2jgc-wx9f-vpp5 GHSA-9rm8-2h7m-56ch GHSA-fc7c-2fxx-pgq7 GHSA-v5rj-qw4c-6pc2 GHSA-x9w4-r3mh-39fw --- .../GHSA-2gj6-9934-w9r6.json | 40 +++++++++++++++++ .../GHSA-2jgc-wx9f-vpp5.json | 36 +++++++++++++++ .../GHSA-9rm8-2h7m-56ch.json | 40 +++++++++++++++++ .../GHSA-fc7c-2fxx-pgq7.json | 34 ++++++++++++++ .../GHSA-v5rj-qw4c-6pc2.json | 44 +++++++++++++++++++ .../GHSA-x9w4-r3mh-39fw.json | 29 ++++++++++++ 6 files changed, 223 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-2gj6-9934-w9r6/GHSA-2gj6-9934-w9r6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2jgc-wx9f-vpp5/GHSA-2jgc-wx9f-vpp5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9rm8-2h7m-56ch/GHSA-9rm8-2h7m-56ch.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fc7c-2fxx-pgq7/GHSA-fc7c-2fxx-pgq7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x9w4-r3mh-39fw/GHSA-x9w4-r3mh-39fw.json diff --git a/advisories/unreviewed/2024/12/GHSA-2gj6-9934-w9r6/GHSA-2gj6-9934-w9r6.json b/advisories/unreviewed/2024/12/GHSA-2gj6-9934-w9r6/GHSA-2gj6-9934-w9r6.json new file mode 100644 index 00000000000..3ddea7514db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2gj6-9934-w9r6/GHSA-2gj6-9934-w9r6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gj6-9934-w9r6", + "modified": "2024-12-04T06:31:02Z", + "published": "2024-12-04T06:31:02Z", + "aliases": [ + "CVE-2024-9404" + ], + "details": "Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service.\n\n\n\n\nThis vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9404" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240930-cve-2024-9404-denial-of-service-vulnerability-identified-in-the-vport-07-3-series" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2jgc-wx9f-vpp5/GHSA-2jgc-wx9f-vpp5.json b/advisories/unreviewed/2024/12/GHSA-2jgc-wx9f-vpp5/GHSA-2jgc-wx9f-vpp5.json new file mode 100644 index 00000000000..0c6839c38a2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2jgc-wx9f-vpp5/GHSA-2jgc-wx9f-vpp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jgc-wx9f-vpp5", + "modified": "2024-12-04T06:31:02Z", + "published": "2024-12-04T06:31:02Z", + "aliases": [ + "CVE-2024-12123" + ], + "details": "A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. \n\nWhen an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, \nwhich the application then accepts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12123" + }, + { + "type": "WEB", + "url": "https://helpcenter.issuetrak.com/home/2340-issuetrak-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-472" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9rm8-2h7m-56ch/GHSA-9rm8-2h7m-56ch.json b/advisories/unreviewed/2024/12/GHSA-9rm8-2h7m-56ch/GHSA-9rm8-2h7m-56ch.json new file mode 100644 index 00000000000..fcf426ee9e9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9rm8-2h7m-56ch/GHSA-9rm8-2h7m-56ch.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rm8-2h7m-56ch", + "modified": "2024-12-04T06:31:02Z", + "published": "2024-12-04T06:31:02Z", + "aliases": [ + "CVE-2024-12099" + ], + "details": "The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.2.0 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12099" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3201770%40dollie&new=3201770%40dollie&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f29514d0-20a5-43f2-bf36-660579103220?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fc7c-2fxx-pgq7/GHSA-fc7c-2fxx-pgq7.json b/advisories/unreviewed/2024/12/GHSA-fc7c-2fxx-pgq7/GHSA-fc7c-2fxx-pgq7.json new file mode 100644 index 00000000000..676d07215f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fc7c-2fxx-pgq7/GHSA-fc7c-2fxx-pgq7.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc7c-2fxx-pgq7", + "modified": "2024-12-04T06:31:02Z", + "published": "2024-12-04T06:31:02Z", + "aliases": [ + "CVE-2024-54664" + ], + "details": "An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context, a different vulnerability than CVE-2024-52945.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54664" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS24-012" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json b/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json new file mode 100644 index 00000000000..0017a8aedc8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5rj-qw4c-6pc2", + "modified": "2024-12-04T06:31:01Z", + "published": "2024-12-04T06:31:01Z", + "aliases": [ + "CVE-2024-10885" + ], + "details": "The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10885" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/searchiq/tags/4.6/library/shortcode.php#L66" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3198694/searchiq/trunk/library/shortcode.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86e8e16f-9d93-457a-9093-2fd236e51682?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x9w4-r3mh-39fw/GHSA-x9w4-r3mh-39fw.json b/advisories/unreviewed/2024/12/GHSA-x9w4-r3mh-39fw/GHSA-x9w4-r3mh-39fw.json new file mode 100644 index 00000000000..c317ec9e70f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x9w4-r3mh-39fw/GHSA-x9w4-r3mh-39fw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9w4-r3mh-39fw", + "modified": "2024-12-04T06:31:02Z", + "published": "2024-12-04T06:31:02Z", + "aliases": [ + "CVE-2024-54661" + ], + "details": "readline.sh in socat through 1.8.0.1 relies on the /tmp/$USER/stderr2 file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54661" + }, + { + "type": "WEB", + "url": "https://repo.or.cz/socat.git/blob/6ff391324d2d3b9f6bfb58e7d16a20be43b47af7:/readline.sh#l29" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T05:15:07Z" + } +} \ No newline at end of file