Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-11 15:32:36 +00:00
parent f7af90b942
commit fce4a0d2d5
35 changed files with 653 additions and 32 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h69v-wwmx-68xj",
"modified": "2024-05-21T18:31:23Z",
"modified": "2024-09-11T15:31:10Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2024-27127"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5pr4-6wfv-6xhj",
"modified": "2024-07-25T21:31:20Z",
"modified": "2024-09-11T15:31:10Z",
"published": "2024-07-25T21:31:20Z",
"aliases": [
"CVE-2024-7105"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2hrx-xx6v-c3v2",
"modified": "2024-08-08T18:31:20Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-08T18:31:20Z",
"aliases": [
"CVE-2024-7480"
@@ -44,6 +44,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-639",
"CWE-99"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fwc-22ch-m5hj",
"modified": "2024-08-05T00:30:51Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-05T00:30:51Z",
"aliases": [
"CVE-2024-7461"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-898x-8mpw-mjf8",
"modified": "2024-08-08T18:31:20Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-08T18:31:20Z",
"aliases": [
"CVE-2024-7477"
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-36"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5hg-xwhp-3gj9",
"modified": "2024-08-16T18:30:57Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-16T18:30:57Z",
"aliases": [
"CVE-2024-42638"
],
"details": "H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-16T18:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3r8-2pw7-fhc3",
"modified": "2024-08-16T00:32:04Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-16T00:32:04Z",
"aliases": [
"CVE-2024-34727"
],
"details": "In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T22:15:06Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhrv-84gm-4q6x",
"modified": "2024-08-15T18:31:52Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-15T18:31:52Z",
"aliases": [
"CVE-2024-22217"
],
"details": "A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T18:15:19Z"
@@ -44,6 +44,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-639",
"CWE-99"
],
"severity": "MODERATE",
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x6qm-4c7w-8wm7",
"modified": "2024-08-15T21:31:20Z",
"modified": "2024-09-11T15:31:11Z",
"published": "2024-08-15T21:31:20Z",
"aliases": [
"CVE-2024-7868"
],
"details": "In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gwr-wc4w-j445",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-7805"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7805"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jgh-5fp7-98p9",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8637"
],
"details": "Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8637"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/361784548"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75jr-77wp-rpvh",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-27114"
],
"details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27114"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2024-27114"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gq2-vwq9-w8vw",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8646"
],
"details": "In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.\nThis vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.\nThis vulnerability only affects applications that are explicitly deployed to the root context ('/').",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8646"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-ee4j/glassfish/pull/24655"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/34"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/163"
},
{
"type": "WEB",
"url": "https://glassfish.org/download"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:14Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x9g-pvv2-c542",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-45790"
],
"details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45790"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291"
}
],
"database_specific": {
"cwe_ids": [
"CWE-307"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T13:15:03Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8259-2x72-2gvc",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-8642"
],
"details": "In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module \"transfer-data-plane\". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Green"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8642"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-edc/Connector/commit/04899e91dcdb4a407db4eb7af3e7b6ff9a9e9ad6"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-edc/Connector/releases/tag/v0.9.0"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/28"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/234"
}
],
"database_specific": {
"cwe_ids": [
"CWE-303"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:14Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84h3-pfxq-r99h",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-27112"
],
"details": "A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27112"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2024-27112"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:12Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97v4-fg36-6rc2",
"modified": "2024-09-11T15:31:12Z",
"published": "2024-09-11T15:31:12Z",
"aliases": [
"CVE-2024-27115"
],
"details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27115"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2024-27115"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-11T14:15:13Z"
}
}

Some files were not shown because too many files have changed in this diff Show More