Publish Advisories

GHSA-7w82-8h79-m4wp
GHSA-844m-hq7r-wxc8
GHSA-9q42-j26w-29g5
GHSA-c39h-g3mf-r3mh
GHSA-c9q3-f5v3-g7hw
GHSA-frw3-949h-qqfj
GHSA-fv5f-crch-5hqw
GHSA-fxvf-jcp9-ch47
GHSA-h3p7-vxpm-g349
GHSA-hc77-8v8p-w9rp
GHSA-hph6-492h-2m77
GHSA-hvrf-34fw-qpr2
GHSA-j8px-pjmp-325f
GHSA-jj58-488v-4rgf
GHSA-jqf5-g644-hc6w
GHSA-mh6q-v4mp-2cc7
GHSA-mj4p-gmhr-92g3
GHSA-pqqr-79q5-9qwg
GHSA-qj86-v6m7-4qv2
GHSA-v2j3-f5j8-8jrp
GHSA-xhf3-pp4q-gxh5
GHSA-xjjc-xf36-3jp9
GHSA-xqgq-669f-hf3x
GHSA-xvcq-gm57-37c5
This commit is contained in:
advisory-database[bot]
2024-06-17 18:33:07 +00:00
parent 5a90e0fd01
commit fa19c1c046
24 changed files with 724 additions and 7 deletions
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w82-8h79-m4wp",
"modified": "2024-06-17T18:31:35Z",
"published": "2024-06-17T18:31:35Z",
"aliases": [
"CVE-2024-6056"
],
"details": "A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to observable response discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268784. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6056"
},
{
"type": "WEB",
"url": "https://powerful-bulb-c36.notion.site/idor-c6eb58e8fc40416ba53c7915ca0174c4?pvs=4"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.268784"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.268784"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.352978"
}
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:18Z"
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-844m-hq7r-wxc8",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2018-25103"
],
"details": "There exists a use-after-free-vulnerability in lighttpd <= 1.4.50 that can allow access to do a case-insensitive comparison against the reused pointer.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25103"
},
{
"type": "WEB",
"url": "https://github.com/lighttpd/lighttpd1.4/commit/df8e4f95614e476276a55e34da2aa8b00b1148e9"
},
{
"type": "WEB",
"url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024002.pdf"
},
{
"type": "WEB",
"url": "https://blogvdoo.wordpress.com/2018/11/06/giving-back-securing-open-source-iot-projects/#more-736"
},
{
"type": "WEB",
"url": "https://www.binarly.io/blog/lighttpd-gains-new-life"
},
{
"type": "WEB",
"url": "https://www.runzero.com/blog/lighttpd"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:12Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q42-j26w-29g5",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-36527"
],
"details": "puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36527"
},
{
"type": "WEB",
"url": "https://gist.github.com/7a6163/25fef08f75eed219c8ca21e332d6e911"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:16Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c39h-g3mf-r3mh",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-17T18:31:33Z",
"aliases": [
"CVE-2024-36575"
],
"details": "A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36575"
},
{
"type": "WEB",
"url": "https://gist.github.com/mestrtee/0d830798f20839d634278d7af0155f9e"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T16:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9q3-f5v3-g7hw",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-37662"
],
"details": "TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37662"
},
{
"type": "WEB",
"url": "https://github.com/ouuan/router-vuln-report/blob/master/nat-rst/tl-7dr5130-nat-rst.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frw3-949h-qqfj",
"modified": "2024-06-17T18:31:35Z",
"published": "2024-06-17T18:31:35Z",
"aliases": [
"CVE-2024-37794"
],
"details": "Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37794"
},
{
"type": "WEB",
"url": "https://github.com/cvc5/cvc5/issues/10813"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv5f-crch-5hqw",
"modified": "2024-06-17T18:31:35Z",
"published": "2024-06-17T18:31:35Z",
"aliases": [
"CVE-2024-6058"
],
"details": "A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. The manipulation of the argument height/width leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6058"
},
{
"type": "WEB",
"url": "https://gentle-khaan-c53.notion.site/Reflected-XSS-in-Labvantage-LIMS-cc960e84650a4df58ecabe82338e0272"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.268785"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.268785"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.353198"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:18Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxvf-jcp9-ch47",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-37661"
],
"details": "TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37661"
},
{
"type": "WEB",
"url": "https://github.com/ouuan/router-vuln-report/blob/master/icmp-redirect/tl-7dr5130-redirect.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3p7-vxpm-g349",
"modified": "2024-06-14T18:31:43Z",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-14T18:31:43Z",
"aliases": [
"CVE-2024-33373"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33373"
},
{
"type": "WEB",
"url": "https://github.com/ShravanSinghRathore/Security-Advisory-Multiple-Vulnerabilities-in-LB-link-BL-W1210M-Router/wiki/Password-Policy-Bypass--%7C--Inconsistent-Password-Policy-%28CVE%E2%80%902024%E2%80%9033373%29"
},
{
"type": "WEB",
"url": "https://redfoxsec.com/blog/security-advisory-multiple-vulnerabilities-in-lb-link-bl-w1210m-router"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc77-8v8p-w9rp",
"modified": "2024-06-17T18:31:35Z",
"published": "2024-06-17T18:31:35Z",
"aliases": [
"CVE-2024-37664"
],
"details": "Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37664"
},
{
"type": "WEB",
"url": "https://github.com/ouuan/router-vuln-report/blob/master/nat-rst/redmi-rb03-nat-rst.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hph6-492h-2m77",
"modified": "2024-06-13T09:30:59Z",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-13T09:30:59Z",
"aliases": [
"CVE-2024-36187"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvrf-34fw-qpr2",
"modified": "2024-06-17T18:31:35Z",
"published": "2024-06-17T18:31:35Z",
"aliases": [
"CVE-2024-37795"
],
"details": "A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` command with specific formatting errors.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37795"
},
{
"type": "WEB",
"url": "https://github.com/cvc5/cvc5/issues/10813"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8px-pjmp-325f",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-17T18:31:33Z",
"aliases": [
"CVE-2024-36574"
],
"details": "A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36574"
},
{
"type": "WEB",
"url": "https://gist.github.com/mestrtee/d5a0c93459599f77557b5bbe78b57325"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T16:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj58-488v-4rgf",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-17T18:31:33Z",
"aliases": [
"CVE-2024-36573"
],
"details": "almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36573"
},
{
"type": "WEB",
"url": "https://gist.github.com/mestrtee/fd8181bbc180d775f8367a2b9e0ffcd1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T16:15:14Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqf5-g644-hc6w",
"modified": "2024-06-13T09:30:59Z",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-13T09:30:59Z",
"aliases": [
"CVE-2024-36185"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh6q-v4mp-2cc7",
"modified": "2024-06-17T15:30:54Z",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-17T15:30:54Z",
"aliases": [
"CVE-2024-4032"
@@ -26,6 +26,30 @@
"type": "WEB",
"url": "https://github.com/python/cpython/pull/113179"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/22adf29da8d99933ffed8647d3e0726edd16f7f8"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/40d75c2b7f5c67e254d0a025e0f2e2c7ada7f69f"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/895f7e2ac23eff4743143beef0f0c5ac71ea27d3"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/ba431579efdcbaed7a96f2ac4ea0775879a332fb"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/c62c9e518b784fe44432a3f4fc265fb95b651906"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/commit/f86b17ac511e68192ba71f27e752321a3252cee3"
},
{
"type": "WEB",
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/NRUHDUS2IV2USIZM2CVMSFL6SCKU3RZA"
@@ -37,6 +61,10 @@
{
"type": "WEB",
"url": "https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/17/3"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj4p-gmhr-92g3",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-36578"
],
"details": "akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36578"
},
{
"type": "WEB",
"url": "https://gist.github.com/mestrtee/8bc749ec2b5453d887b2f4a362a65897"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T16:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqqr-79q5-9qwg",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-36973"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe()\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function\ngp_auxiliary_device_release() calls ida_free() and\nkfree(aux_device_wrapper) to free memory. We should't\ncall them again in the error handling path.\n\nFix this by skipping the redundant cleanup functions.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36973"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/086c6cbcc563c81d55257f9b27e14faf1d0963d3"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qj86-v6m7-4qv2",
"modified": "2024-06-17T18:31:33Z",
"published": "2024-06-17T18:31:33Z",
"aliases": [
"CVE-2024-36577"
],
"details": "apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36577"
},
{
"type": "WEB",
"url": "https://gist.github.com/mestrtee/c90189f3d8480a5f267395ec40701373"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T16:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v2j3-f5j8-8jrp",
"modified": "2024-06-17T18:31:34Z",
"published": "2024-06-17T18:31:34Z",
"aliases": [
"CVE-2024-37663"
],
"details": "Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37663"
},
{
"type": "WEB",
"url": "https://github.com/ouuan/router-vuln-report/blob/master/icmp-redirect/redmi-rb03-redirect.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-17T18:15:17Z"
}
}

Some files were not shown because too many files have changed in this diff Show More