Publish Advisories

GHSA-372x-c6rw-v8f9
GHSA-62vc-2f72-vcj3
GHSA-8q5j-74vg-j4hr
GHSA-9m3j-vpcw-4f37
GHSA-cq85-4f5h-qqc4
GHSA-hmqj-rccj-3q53
GHSA-mf2m-vhfh-2qjv
GHSA-w267-2gcr-ggcp
GHSA-c5x4-rjx4-c2hr
GHSA-fc9r-q9rh-hrg7
GHSA-g3px-cpxh-v7xc
GHSA-hmvg-cx6j-hfj7
GHSA-hxq4-v53v-rh4h
GHSA-r32c-fmcr-34r3
GHSA-vjr2-5xwq-8c35
This commit is contained in:
advisory-database[bot]
2024-03-04 09:31:50 +00:00
parent 370ee5a156
commit ff0efb862e
15 changed files with 335 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-372x-c6rw-v8f9",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-1552"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874502"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62vc-2f72-vcj3",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-1553"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1855686%2C1867982%2C1871498%2C1872296%2C1873521%2C1873577%2C1873597%2C1873866%2C1874080%2C1874740%2C1875795%2C1875906%2C1876425%2C1878211%2C1878286"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q5j-74vg-j4hr",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-1550"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1860065"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9m3j-vpcw-4f37",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:04Z",
"aliases": [
"CVE-2024-1548"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1832627"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cq85-4f5h-qqc4",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-1551"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1864385"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmqj-rccj-3q53",
"modified": "2024-02-20T21:30:23Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:04Z",
"aliases": [
"CVE-2024-1547"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1877879"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf2m-vhfh-2qjv",
"modified": "2024-02-20T21:30:24Z",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-1549"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1833814"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w267-2gcr-ggcp",
"modified": "2024-02-20T21:30:23Z",
"modified": "2024-03-04T09:30:28Z",
"published": "2024-02-20T15:31:04Z",
"aliases": [
"CVE-2024-1546"
@@ -22,6 +22,14 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1843752"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-05"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c5x4-rjx4-c2hr",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2023-49602"
],
"details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49602"
},
{
"type": "WEB",
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc9r-q9rh-hrg7",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2023-25176"
],
"details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25176"
},
{
"type": "WEB",
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3px-cpxh-v7xc",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2023-46708"
],
"details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46708"
},
{
"type": "WEB",
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmvg-cx6j-hfj7",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2024-26622"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntomoyo: fix UAF write bug in tomoyo_write_control()\n\nSince tomoyo_write_control() updates head->write_buf when write()\nof long lines is requested, we need to fetch head->write_buf after\nhead->io_sem is held. Otherwise, concurrent write() requests can\ncause use-after-free-write and double-free problems.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26622"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2f03fc340cac9ea1dc63cbf8c93dd2eb0f227815"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxq4-v53v-rh4h",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2024-21816"
],
"details": "in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21816"
},
{
"type": "WEB",
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-281"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r32c-fmcr-34r3",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2023-4479"
],
"details": "Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4479"
},
{
"type": "WEB",
"url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-4479"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T08:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjr2-5xwq-8c35",
"modified": "2024-03-04T09:30:29Z",
"published": "2024-03-04T09:30:29Z",
"aliases": [
"CVE-2024-21826"
],
"details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21826"
},
{
"type": "WEB",
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-922"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T07:15:10Z"
}
}