diff --git a/advisories/unreviewed/2023/04/GHSA-94rv-4qh8-r994/GHSA-94rv-4qh8-r994.json b/advisories/unreviewed/2023/04/GHSA-94rv-4qh8-r994/GHSA-94rv-4qh8-r994.json index d5746962cc6..e6976d1abd7 100644 --- a/advisories/unreviewed/2023/04/GHSA-94rv-4qh8-r994/GHSA-94rv-4qh8-r994.json +++ b/advisories/unreviewed/2023/04/GHSA-94rv-4qh8-r994/GHSA-94rv-4qh8-r994.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94rv-4qh8-r994", - "modified": "2023-04-21T06:30:17Z", + "modified": "2024-09-16T15:32:44Z", "published": "2023-04-14T12:30:23Z", "aliases": [ "CVE-2023-2042" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -32,6 +36,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.225920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.109292" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-29p8-776w-hr3v/GHSA-29p8-776w-hr3v.json b/advisories/unreviewed/2023/06/GHSA-29p8-776w-hr3v/GHSA-29p8-776w-hr3v.json index 91aafb4658d..0171f709515 100644 --- a/advisories/unreviewed/2023/06/GHSA-29p8-776w-hr3v/GHSA-29p8-776w-hr3v.json +++ b/advisories/unreviewed/2023/06/GHSA-29p8-776w-hr3v/GHSA-29p8-776w-hr3v.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-gqhx-wxjr-rphx/GHSA-gqhx-wxjr-rphx.json b/advisories/unreviewed/2023/06/GHSA-gqhx-wxjr-rphx/GHSA-gqhx-wxjr-rphx.json index 8941aa3d257..3f021ec6b04 100644 --- a/advisories/unreviewed/2023/06/GHSA-gqhx-wxjr-rphx/GHSA-gqhx-wxjr-rphx.json +++ b/advisories/unreviewed/2023/06/GHSA-gqhx-wxjr-rphx/GHSA-gqhx-wxjr-rphx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqhx-wxjr-rphx", - "modified": "2024-04-04T05:10:46Z", + "modified": "2024-09-16T15:32:44Z", "published": "2023-06-26T21:30:59Z", "aliases": [ "CVE-2023-2992" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-405" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-8m6h-6qw7-f6cg/GHSA-8m6h-6qw7-f6cg.json b/advisories/unreviewed/2023/11/GHSA-8m6h-6qw7-f6cg/GHSA-8m6h-6qw7-f6cg.json index fb73cc92c46..ee693f57f78 100644 --- a/advisories/unreviewed/2023/11/GHSA-8m6h-6qw7-f6cg/GHSA-8m6h-6qw7-f6cg.json +++ b/advisories/unreviewed/2023/11/GHSA-8m6h-6qw7-f6cg/GHSA-8m6h-6qw7-f6cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8m6h-6qw7-f6cg", - "modified": "2023-11-03T15:33:55Z", + "modified": "2024-09-16T15:32:45Z", "published": "2023-11-03T15:33:55Z", "aliases": [ "CVE-2023-3961" diff --git a/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json b/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json index ec53ff3c9d8..7a2a51c45bc 100644 --- a/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json +++ b/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8q58-8vm2-mf3q", - "modified": "2023-11-06T09:30:14Z", + "modified": "2024-09-16T15:32:45Z", "published": "2023-11-06T09:30:14Z", "aliases": [ "CVE-2023-42669" diff --git a/advisories/unreviewed/2024/01/GHSA-qvvr-wcmf-4v5h/GHSA-qvvr-wcmf-4v5h.json b/advisories/unreviewed/2024/01/GHSA-qvvr-wcmf-4v5h/GHSA-qvvr-wcmf-4v5h.json index 9135ce3356a..2dca04df191 100644 --- a/advisories/unreviewed/2024/01/GHSA-qvvr-wcmf-4v5h/GHSA-qvvr-wcmf-4v5h.json +++ b/advisories/unreviewed/2024/01/GHSA-qvvr-wcmf-4v5h/GHSA-qvvr-wcmf-4v5h.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-266", "CWE-269" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-v6cc-j2v5-w3jj/GHSA-v6cc-j2v5-w3jj.json b/advisories/unreviewed/2024/01/GHSA-v6cc-j2v5-w3jj/GHSA-v6cc-j2v5-w3jj.json index ea1b620a635..6b38493959f 100644 --- a/advisories/unreviewed/2024/01/GHSA-v6cc-j2v5-w3jj/GHSA-v6cc-j2v5-w3jj.json +++ b/advisories/unreviewed/2024/01/GHSA-v6cc-j2v5-w3jj/GHSA-v6cc-j2v5-w3jj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-497" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json index f4f5b38a794..365b16f4c19 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json +++ b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5777-rcjj-9p22/GHSA-5777-rcjj-9p22.json b/advisories/unreviewed/2024/09/GHSA-5777-rcjj-9p22/GHSA-5777-rcjj-9p22.json new file mode 100644 index 00000000000..05eb2eb9e5d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5777-rcjj-9p22/GHSA-5777-rcjj-9p22.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5777-rcjj-9p22", + "modified": "2024-09-16T15:32:46Z", + "published": "2024-09-16T15:32:46Z", + "aliases": [ + "CVE-2024-39772" + ], + "details": "Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39772" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gc2c-r5jf-whf8/GHSA-gc2c-r5jf-whf8.json b/advisories/unreviewed/2024/09/GHSA-gc2c-r5jf-whf8/GHSA-gc2c-r5jf-whf8.json new file mode 100644 index 00000000000..ed3f72dbed1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gc2c-r5jf-whf8/GHSA-gc2c-r5jf-whf8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc2c-r5jf-whf8", + "modified": "2024-09-16T15:32:46Z", + "published": "2024-09-16T15:32:46Z", + "aliases": [ + "CVE-2024-38315" + ], + "details": "IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38315" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/294742" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7168379" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json b/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json new file mode 100644 index 00000000000..9249268f592 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg4p-55w9-888w", + "modified": "2024-09-16T15:32:46Z", + "published": "2024-09-16T15:32:46Z", + "aliases": [ + "CVE-2024-6401" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: before 4.6.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6401" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json b/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json new file mode 100644 index 00000000000..9d8d6d6fcb9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh54-7qq9-x5v8", + "modified": "2024-09-16T15:32:47Z", + "published": "2024-09-16T15:32:46Z", + "aliases": [ + "CVE-2024-7098" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7098" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json b/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json new file mode 100644 index 00000000000..6bccad01146 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w784-6hh8-995v/GHSA-w784-6hh8-995v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w784-6hh8-995v", + "modified": "2024-09-16T15:32:47Z", + "published": "2024-09-16T15:32:47Z", + "aliases": [ + "CVE-2024-7104" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.This issue affects ww.Winsure: before 4.6.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7104" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xgq9-7gw6-jr5r/GHSA-xgq9-7gw6-jr5r.json b/advisories/unreviewed/2024/09/GHSA-xgq9-7gw6-jr5r/GHSA-xgq9-7gw6-jr5r.json new file mode 100644 index 00000000000..190adc63683 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xgq9-7gw6-jr5r/GHSA-xgq9-7gw6-jr5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgq9-7gw6-jr5r", + "modified": "2024-09-16T15:32:46Z", + "published": "2024-09-16T15:32:46Z", + "aliases": [ + "CVE-2024-45835" + ], + "details": "Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45835" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T15:15:16Z" + } +} \ No newline at end of file