Publish Advisories

GHSA-94rv-4qh8-r994
GHSA-29p8-776w-hr3v
GHSA-gqhx-wxjr-rphx
GHSA-8m6h-6qw7-f6cg
GHSA-8q58-8vm2-mf3q
GHSA-qvvr-wcmf-4v5h
GHSA-v6cc-j2v5-w3jj
GHSA-gj98-p2xm-q3hc
GHSA-5777-rcjj-9p22
GHSA-gc2c-r5jf-whf8
GHSA-hg4p-55w9-888w
GHSA-rh54-7qq9-x5v8
GHSA-w784-6hh8-995v
GHSA-xgq9-7gw6-jr5r
This commit is contained in:
advisory-database[bot]
2024-09-16 15:34:07 +00:00
parent cf3642eaf4
commit fcac682434
14 changed files with 253 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94rv-4qh8-r994",
"modified": "2023-04-21T06:30:17Z",
"modified": "2024-09-16T15:32:44Z",
"published": "2023-04-14T12:30:23Z",
"aliases": [
"CVE-2023-2042"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -32,6 +36,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.225920"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.109292"
}
],
"database_specific": {
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqhx-wxjr-rphx",
"modified": "2024-04-04T05:10:46Z",
"modified": "2024-09-16T15:32:44Z",
"published": "2023-06-26T21:30:59Z",
"aliases": [
"CVE-2023-2992"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-405"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8m6h-6qw7-f6cg",
"modified": "2023-11-03T15:33:55Z",
"modified": "2024-09-16T15:32:45Z",
"published": "2023-11-03T15:33:55Z",
"aliases": [
"CVE-2023-3961"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q58-8vm2-mf3q",
"modified": "2023-11-06T09:30:14Z",
"modified": "2024-09-16T15:32:45Z",
"published": "2023-11-06T09:30:14Z",
"aliases": [
"CVE-2023-42669"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-266",
"CWE-269"
],
"severity": "MODERATE",
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-497"
],
"severity": "LOW",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5777-rcjj-9p22",
"modified": "2024-09-16T15:32:46Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-39772"
],
"details": "Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39772"
},
{
"type": "WEB",
"url": "https://mattermost.com/security-updates"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:16Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc2c-r5jf-whf8",
"modified": "2024-09-16T15:32:46Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-38315"
],
"details": "IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38315"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/294742"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7168379"
}
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:16Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg4p-55w9-888w",
"modified": "2024-09-16T15:32:46Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-6401"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: before 4.6.2.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6401"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1475"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:17Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh54-7qq9-x5v8",
"modified": "2024-09-16T15:32:47Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-7098"
],
"details": "Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7098"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1475"
}
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:17Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w784-6hh8-995v",
"modified": "2024-09-16T15:32:47Z",
"published": "2024-09-16T15:32:47Z",
"aliases": [
"CVE-2024-7104"
],
"details": "Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.This issue affects ww.Winsure: before 4.6.2.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7104"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1475"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:17Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgq9-7gw6-jr5r",
"modified": "2024-09-16T15:32:46Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-45835"
],
"details": "Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45835"
},
{
"type": "WEB",
"url": "https://mattermost.com/security-updates"
}
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T15:15:16Z"
}
}