From fce4a0d2d55fe3f991a41dcc8de38144cd3318e1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Sep 2024 15:32:36 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-h69v-wwmx-68xj.json | 2 +- .../GHSA-5pr4-6wfv-6xhj.json | 2 +- .../GHSA-2hrx-xx6v-c3v2.json | 2 +- .../GHSA-4r4m-v89p-5c69.json | 1 + .../GHSA-7fwc-22ch-m5hj.json | 2 +- .../GHSA-898x-8mpw-mjf8.json | 2 +- .../GHSA-9mv8-jqq2-5m57.json | 1 + .../GHSA-f5hg-xwhp-3gj9.json | 11 ++-- .../GHSA-h3r8-2pw7-fhc3.json | 11 ++-- .../GHSA-hhrv-84gm-4q6x.json | 11 ++-- .../GHSA-x2qm-672h-5482.json | 1 + .../GHSA-x6qm-4c7w-8wm7.json | 6 ++- .../GHSA-5gwr-wc4w-j445.json | 31 ++++++++++++ .../GHSA-5jgh-5fp7-98p9.json | 39 +++++++++++++++ .../GHSA-75jr-77wp-rpvh.json | 38 ++++++++++++++ .../GHSA-7gq2-vwq9-w8vw.json | 50 +++++++++++++++++++ .../GHSA-7x9g-pvv2-c542.json | 38 ++++++++++++++ .../GHSA-8259-2x72-2gvc.json | 50 +++++++++++++++++++ .../GHSA-84h3-pfxq-r99h.json | 38 ++++++++++++++ .../GHSA-97v4-fg36-6rc2.json | 38 ++++++++++++++ .../GHSA-fj8w-h44c-988h.json | 2 +- .../GHSA-fpv4-p5w2-xgfg.json | 2 +- .../GHSA-g84q-54hf-36rg.json | 42 ++++++++++++++++ .../GHSA-gv3v-x3f3-7fxm.json | 11 ++-- .../GHSA-gxw8-fmh9-2w53.json | 38 ++++++++++++++ .../GHSA-h2g3-9wm9-c3jc.json | 2 +- .../GHSA-jhg9-gwwm-6qw2.json | 39 +++++++++++++++ .../GHSA-jw76-x8jc-r725.json | 39 +++++++++++++++ .../GHSA-mmr8-xr7x-rrxw.json | 2 +- .../GHSA-mxf9-pg49-g3hg.json | 2 +- .../GHSA-q9c5-cgr2-rx6v.json | 38 ++++++++++++++ .../GHSA-r6cg-gw4p-5gmj.json | 39 +++++++++++++++ .../GHSA-vj44-f7fj-3gf2.json | 11 ++-- .../GHSA-vr5r-frmj-8fwp.json | 42 ++++++++++++++++ .../GHSA-x6fj-x43r-fcg6.json | 2 +- 35 files changed, 653 insertions(+), 32 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-5gwr-wc4w-j445/GHSA-5gwr-wc4w-j445.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7gq2-vwq9-w8vw/GHSA-7gq2-vwq9-w8vw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8259-2x72-2gvc/GHSA-8259-2x72-2gvc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g84q-54hf-36rg/GHSA-g84q-54hf-36rg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q9c5-cgr2-rx6v/GHSA-q9c5-cgr2-rx6v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vr5r-frmj-8fwp/GHSA-vr5r-frmj-8fwp.json diff --git a/advisories/unreviewed/2024/05/GHSA-h69v-wwmx-68xj/GHSA-h69v-wwmx-68xj.json b/advisories/unreviewed/2024/05/GHSA-h69v-wwmx-68xj/GHSA-h69v-wwmx-68xj.json index ab803f2a2fc..b2717d71bb5 100644 --- a/advisories/unreviewed/2024/05/GHSA-h69v-wwmx-68xj/GHSA-h69v-wwmx-68xj.json +++ b/advisories/unreviewed/2024/05/GHSA-h69v-wwmx-68xj/GHSA-h69v-wwmx-68xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h69v-wwmx-68xj", - "modified": "2024-05-21T18:31:23Z", + "modified": "2024-09-11T15:31:10Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2024-27127" diff --git a/advisories/unreviewed/2024/07/GHSA-5pr4-6wfv-6xhj/GHSA-5pr4-6wfv-6xhj.json b/advisories/unreviewed/2024/07/GHSA-5pr4-6wfv-6xhj/GHSA-5pr4-6wfv-6xhj.json index e9791fa2c6f..f024f791f50 100644 --- a/advisories/unreviewed/2024/07/GHSA-5pr4-6wfv-6xhj/GHSA-5pr4-6wfv-6xhj.json +++ b/advisories/unreviewed/2024/07/GHSA-5pr4-6wfv-6xhj/GHSA-5pr4-6wfv-6xhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pr4-6wfv-6xhj", - "modified": "2024-07-25T21:31:20Z", + "modified": "2024-09-11T15:31:10Z", "published": "2024-07-25T21:31:20Z", "aliases": [ "CVE-2024-7105" diff --git a/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json b/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json index c0e7be22d27..169c20f9949 100644 --- a/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json +++ b/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hrx-xx6v-c3v2", - "modified": "2024-08-08T18:31:20Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-08T18:31:20Z", "aliases": [ "CVE-2024-7480" diff --git a/advisories/unreviewed/2024/08/GHSA-4r4m-v89p-5c69/GHSA-4r4m-v89p-5c69.json b/advisories/unreviewed/2024/08/GHSA-4r4m-v89p-5c69/GHSA-4r4m-v89p-5c69.json index 7cd800dc50a..82d16d4b8fd 100644 --- a/advisories/unreviewed/2024/08/GHSA-4r4m-v89p-5c69/GHSA-4r4m-v89p-5c69.json +++ b/advisories/unreviewed/2024/08/GHSA-4r4m-v89p-5c69/GHSA-4r4m-v89p-5c69.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-99" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-7fwc-22ch-m5hj/GHSA-7fwc-22ch-m5hj.json b/advisories/unreviewed/2024/08/GHSA-7fwc-22ch-m5hj/GHSA-7fwc-22ch-m5hj.json index 6f4fa74e01d..3a97bc25ce5 100644 --- a/advisories/unreviewed/2024/08/GHSA-7fwc-22ch-m5hj/GHSA-7fwc-22ch-m5hj.json +++ b/advisories/unreviewed/2024/08/GHSA-7fwc-22ch-m5hj/GHSA-7fwc-22ch-m5hj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fwc-22ch-m5hj", - "modified": "2024-08-05T00:30:51Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-05T00:30:51Z", "aliases": [ "CVE-2024-7461" diff --git a/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json b/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json index 47f0b805a85..f31b76d8759 100644 --- a/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json +++ b/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-898x-8mpw-mjf8", - "modified": "2024-08-08T18:31:20Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-08T18:31:20Z", "aliases": [ "CVE-2024-7477" diff --git a/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json b/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json index 582cf4604ad..e90ef9ea0cc 100644 --- a/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json +++ b/advisories/unreviewed/2024/08/GHSA-9mv8-jqq2-5m57/GHSA-9mv8-jqq2-5m57.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json b/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json index f7219913a99..65b28e69667 100644 --- a/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json +++ b/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5hg-xwhp-3gj9", - "modified": "2024-08-16T18:30:57Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-16T18:30:57Z", "aliases": [ "CVE-2024-42638" ], "details": "H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T18:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json b/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json index 0a37a527e82..7755606c123 100644 --- a/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json +++ b/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3r8-2pw7-fhc3", - "modified": "2024-08-16T00:32:04Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-16T00:32:04Z", "aliases": [ "CVE-2024-34727" ], "details": "In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json b/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json index f496f52e101..126cd4d65ff 100644 --- a/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json +++ b/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hhrv-84gm-4q6x", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-22217" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T18:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x2qm-672h-5482/GHSA-x2qm-672h-5482.json b/advisories/unreviewed/2024/08/GHSA-x2qm-672h-5482/GHSA-x2qm-672h-5482.json index da5b00669f6..736bef8b41e 100644 --- a/advisories/unreviewed/2024/08/GHSA-x2qm-672h-5482/GHSA-x2qm-672h-5482.json +++ b/advisories/unreviewed/2024/08/GHSA-x2qm-672h-5482/GHSA-x2qm-672h-5482.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-99" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json b/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json index f9ecca01393..57a4918127d 100644 --- a/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json +++ b/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6qm-4c7w-8wm7", - "modified": "2024-08-15T21:31:20Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-08-15T21:31:20Z", "aliases": [ "CVE-2024-7868" ], "details": "In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-5gwr-wc4w-j445/GHSA-5gwr-wc4w-j445.json b/advisories/unreviewed/2024/09/GHSA-5gwr-wc4w-j445/GHSA-5gwr-wc4w-j445.json new file mode 100644 index 00000000000..b5fa9a6d23f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5gwr-wc4w-j445/GHSA-5gwr-wc4w-j445.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gwr-wc4w-j445", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-7805" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7805" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json b/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json new file mode 100644 index 00000000000..ca7e61c9b61 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5jgh-5fp7-98p9/GHSA-5jgh-5fp7-98p9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jgh-5fp7-98p9", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8637" + ], + "details": "Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8637" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/361784548" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json b/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json new file mode 100644 index 00000000000..60958a4f96b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-75jr-77wp-rpvh/GHSA-75jr-77wp-rpvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jr-77wp-rpvh", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-27114" + ], + "details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27114" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2024-27114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7gq2-vwq9-w8vw/GHSA-7gq2-vwq9-w8vw.json b/advisories/unreviewed/2024/09/GHSA-7gq2-vwq9-w8vw/GHSA-7gq2-vwq9-w8vw.json new file mode 100644 index 00000000000..2e8e082869d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7gq2-vwq9-w8vw/GHSA-7gq2-vwq9-w8vw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gq2-vwq9-w8vw", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8646" + ], + "details": "In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.\nThis vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.\nThis vulnerability only affects applications that are explicitly deployed to the root context ('/').", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8646" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-ee4j/glassfish/pull/24655" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/34" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/163" + }, + { + "type": "WEB", + "url": "https://glassfish.org/download" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json b/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json new file mode 100644 index 00000000000..ea5a0d3468d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x9g-pvv2-c542", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-45790" + ], + "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45790" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8259-2x72-2gvc/GHSA-8259-2x72-2gvc.json b/advisories/unreviewed/2024/09/GHSA-8259-2x72-2gvc/GHSA-8259-2x72-2gvc.json new file mode 100644 index 00000000000..82b1ffa1bcc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8259-2x72-2gvc/GHSA-8259-2x72-2gvc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8259-2x72-2gvc", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8642" + ], + "details": "In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module \"transfer-data-plane\". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8642" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-edc/Connector/commit/04899e91dcdb4a407db4eb7af3e7b6ff9a9e9ad6" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-edc/Connector/releases/tag/v0.9.0" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/28" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/234" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json b/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json new file mode 100644 index 00000000000..ba91baa54bd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84h3-pfxq-r99h", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-27112" + ], + "details": "A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27112" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2024-27112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json b/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json new file mode 100644 index 00000000000..b12832cd3f5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97v4-fg36-6rc2", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-27115" + ], + "details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27115" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2024-27115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json b/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json index 02b05a4a344..e09dc5dbca3 100644 --- a/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json +++ b/advisories/unreviewed/2024/09/GHSA-fj8w-h44c-988h/GHSA-fj8w-h44c-988h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json b/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json index 18dc08b1cc0..6b0c7297a28 100644 --- a/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json +++ b/advisories/unreviewed/2024/09/GHSA-fpv4-p5w2-xgfg/GHSA-fpv4-p5w2-xgfg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g84q-54hf-36rg/GHSA-g84q-54hf-36rg.json b/advisories/unreviewed/2024/09/GHSA-g84q-54hf-36rg/GHSA-g84q-54hf-36rg.json new file mode 100644 index 00000000000..141c8ef6fae --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g84q-54hf-36rg/GHSA-g84q-54hf-36rg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g84q-54hf-36rg", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-6091" + ], + "details": "A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this restriction by executing commands with a modified path, such as '/bin/./whoami', which is not recognized by the denylist.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6091" + }, + { + "type": "WEB", + "url": "https://github.com/significant-gravitas/autogpt/commit/ef691359b774a1f9f80cf4f5ace9821967b718ed" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8a742c13-bb5e-4bc9-8b86-049d8a386050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json b/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json index 6cf3b13e574..3dad77bcb2c 100644 --- a/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json +++ b/advisories/unreviewed/2024/09/GHSA-gv3v-x3f3-7fxm/GHSA-gv3v-x3f3-7fxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv3v-x3f3-7fxm", - "modified": "2024-09-11T12:30:51Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-09-11T12:30:51Z", "aliases": [ "CVE-2024-8096" ], "details": "When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T10:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json b/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json new file mode 100644 index 00000000000..8b750564df1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxw8-fmh9-2w53", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-27113" + ], + "details": "An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27113" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2024-27113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json b/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json index bd915e2fca8..b99d7445b61 100644 --- a/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json +++ b/advisories/unreviewed/2024/09/GHSA-h2g3-9wm9-c3jc/GHSA-h2g3-9wm9-c3jc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json b/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json new file mode 100644 index 00000000000..78096c52fd2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jhg9-gwwm-6qw2/GHSA-jhg9-gwwm-6qw2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhg9-gwwm-6qw2", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8639" + ], + "details": "Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8639" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/362658609" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json b/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json new file mode 100644 index 00000000000..b114901e530 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jw76-x8jc-r725/GHSA-jw76-x8jc-r725.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw76-x8jc-r725", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8638" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8638" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/362539773" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json b/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json index dd05fe1a7be..8c74bd00c75 100644 --- a/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json +++ b/advisories/unreviewed/2024/09/GHSA-mmr8-xr7x-rrxw/GHSA-mmr8-xr7x-rrxw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json b/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json index 2ae8429e228..37bd7a36273 100644 --- a/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json +++ b/advisories/unreviewed/2024/09/GHSA-mxf9-pg49-g3hg/GHSA-mxf9-pg49-g3hg.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-q9c5-cgr2-rx6v/GHSA-q9c5-cgr2-rx6v.json b/advisories/unreviewed/2024/09/GHSA-q9c5-cgr2-rx6v/GHSA-q9c5-cgr2-rx6v.json new file mode 100644 index 00000000000..71a351f4b52 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q9c5-cgr2-rx6v/GHSA-q9c5-cgr2-rx6v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9c5-cgr2-rx6v", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8306" + ], + "details": "CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized\naccess, loss of confidentiality, integrity and availability of the workstation when non-admin\nauthenticated user tries to perform privilege escalation by tampering with the binaries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8306" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-254-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-254-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json b/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json new file mode 100644 index 00000000000..af13b91d708 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r6cg-gw4p-5gmj/GHSA-r6cg-gw4p-5gmj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6cg-gw4p-5gmj", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-8636" + ], + "details": "Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8636" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/361461526" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vj44-f7fj-3gf2/GHSA-vj44-f7fj-3gf2.json b/advisories/unreviewed/2024/09/GHSA-vj44-f7fj-3gf2/GHSA-vj44-f7fj-3gf2.json index e49cf053321..306641c17e6 100644 --- a/advisories/unreviewed/2024/09/GHSA-vj44-f7fj-3gf2/GHSA-vj44-f7fj-3gf2.json +++ b/advisories/unreviewed/2024/09/GHSA-vj44-f7fj-3gf2/GHSA-vj44-f7fj-3gf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj44-f7fj-3gf2", - "modified": "2024-09-11T00:30:51Z", + "modified": "2024-09-11T15:31:11Z", "published": "2024-09-11T00:30:51Z", "aliases": [ "CVE-2024-40662" ], "details": "In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T00:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vr5r-frmj-8fwp/GHSA-vr5r-frmj-8fwp.json b/advisories/unreviewed/2024/09/GHSA-vr5r-frmj-8fwp/GHSA-vr5r-frmj-8fwp.json new file mode 100644 index 00000000000..5a421c3020a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vr5r-frmj-8fwp/GHSA-vr5r-frmj-8fwp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr5r-frmj-8fwp", + "modified": "2024-09-11T15:31:12Z", + "published": "2024-09-11T15:31:12Z", + "aliases": [ + "CVE-2024-4465" + ], + "details": "An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges.\n\n\n\nIf a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the reporting configuration. This could result in a partial loss of data integrity. In Guardian/CMC instances with a reporting configuration, there could be limited Denial of Service (DoS) impacts, as the reports may not reach their intended destination, and there could also be limited information disclosure impacts. Furthermore, modifying the destination SMTP server for the reports could lead to the compromise of external credentials, as they might be sent to an unauthorized server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4465" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2024:2-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-11T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json b/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json index f2a57564a2a..5f86edbd562 100644 --- a/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json +++ b/advisories/unreviewed/2024/09/GHSA-x6fj-x43r-fcg6/GHSA-x6fj-x43r-fcg6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false,