From ff0efb862e624bbeb50ef60d5add8dcdf8785737 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 4 Mar 2024 09:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-372x-c6rw-v8f9 GHSA-62vc-2f72-vcj3 GHSA-8q5j-74vg-j4hr GHSA-9m3j-vpcw-4f37 GHSA-cq85-4f5h-qqc4 GHSA-hmqj-rccj-3q53 GHSA-mf2m-vhfh-2qjv GHSA-w267-2gcr-ggcp GHSA-c5x4-rjx4-c2hr GHSA-fc9r-q9rh-hrg7 GHSA-g3px-cpxh-v7xc GHSA-hmvg-cx6j-hfj7 GHSA-hxq4-v53v-rh4h GHSA-r32c-fmcr-34r3 GHSA-vjr2-5xwq-8c35 --- .../GHSA-372x-c6rw-v8f9.json | 10 ++++- .../GHSA-62vc-2f72-vcj3.json | 10 ++++- .../GHSA-8q5j-74vg-j4hr.json | 10 ++++- .../GHSA-9m3j-vpcw-4f37.json | 10 ++++- .../GHSA-cq85-4f5h-qqc4.json | 10 ++++- .../GHSA-hmqj-rccj-3q53.json | 10 ++++- .../GHSA-mf2m-vhfh-2qjv.json | 10 ++++- .../GHSA-w267-2gcr-ggcp.json | 10 ++++- .../GHSA-c5x4-rjx4-c2hr.json | 38 +++++++++++++++++++ .../GHSA-fc9r-q9rh-hrg7.json | 38 +++++++++++++++++++ .../GHSA-g3px-cpxh-v7xc.json | 38 +++++++++++++++++++ .../GHSA-hmvg-cx6j-hfj7.json | 35 +++++++++++++++++ .../GHSA-hxq4-v53v-rh4h.json | 38 +++++++++++++++++++ .../GHSA-r32c-fmcr-34r3.json | 38 +++++++++++++++++++ .../GHSA-vjr2-5xwq-8c35.json | 38 +++++++++++++++++++ 15 files changed, 335 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-c5x4-rjx4-c2hr/GHSA-c5x4-rjx4-c2hr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fc9r-q9rh-hrg7/GHSA-fc9r-q9rh-hrg7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g3px-cpxh-v7xc/GHSA-g3px-cpxh-v7xc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hxq4-v53v-rh4h/GHSA-hxq4-v53v-rh4h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r32c-fmcr-34r3/GHSA-r32c-fmcr-34r3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vjr2-5xwq-8c35/GHSA-vjr2-5xwq-8c35.json diff --git a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json index 28b7cf7118e..54f23453143 100644 --- a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json +++ b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-372x-c6rw-v8f9", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1552" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874502" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json index a58ebbb09de..d317c369dfc 100644 --- a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json +++ b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62vc-2f72-vcj3", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1553" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1855686%2C1867982%2C1871498%2C1872296%2C1873521%2C1873577%2C1873597%2C1873866%2C1874080%2C1874740%2C1875795%2C1875906%2C1876425%2C1878211%2C1878286" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json index 437112f0aec..fe1457f87c3 100644 --- a/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json +++ b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8q5j-74vg-j4hr", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1550" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1860065" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json index 1b19fe0f9c7..790ddd9536c 100644 --- a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json +++ b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m3j-vpcw-4f37", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1548" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1832627" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json index 1f45d3a354b..e28e16bf649 100644 --- a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json +++ b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq85-4f5h-qqc4", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1551" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1864385" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json index a2a58607c7e..f665735e577 100644 --- a/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json +++ b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hmqj-rccj-3q53", - "modified": "2024-02-20T21:30:23Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1547" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1877879" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json index 0e567017a68..707552b0b4d 100644 --- a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json +++ b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf2m-vhfh-2qjv", - "modified": "2024-02-20T21:30:24Z", + "modified": "2024-03-04T09:30:29Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1549" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1833814" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json index d9128f93ac2..970f1a4e7d8 100644 --- a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json +++ b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w267-2gcr-ggcp", - "modified": "2024-02-20T21:30:23Z", + "modified": "2024-03-04T09:30:28Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1546" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1843752" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-05" diff --git a/advisories/unreviewed/2024/03/GHSA-c5x4-rjx4-c2hr/GHSA-c5x4-rjx4-c2hr.json b/advisories/unreviewed/2024/03/GHSA-c5x4-rjx4-c2hr/GHSA-c5x4-rjx4-c2hr.json new file mode 100644 index 00000000000..4fb00ff7621 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c5x4-rjx4-c2hr/GHSA-c5x4-rjx4-c2hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5x4-rjx4-c2hr", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2023-49602" + ], + "details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49602" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fc9r-q9rh-hrg7/GHSA-fc9r-q9rh-hrg7.json b/advisories/unreviewed/2024/03/GHSA-fc9r-q9rh-hrg7/GHSA-fc9r-q9rh-hrg7.json new file mode 100644 index 00000000000..9a6efbcd4a7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fc9r-q9rh-hrg7/GHSA-fc9r-q9rh-hrg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9r-q9rh-hrg7", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2023-25176" + ], + "details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25176" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g3px-cpxh-v7xc/GHSA-g3px-cpxh-v7xc.json b/advisories/unreviewed/2024/03/GHSA-g3px-cpxh-v7xc/GHSA-g3px-cpxh-v7xc.json new file mode 100644 index 00000000000..4923a002cde --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g3px-cpxh-v7xc/GHSA-g3px-cpxh-v7xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3px-cpxh-v7xc", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2023-46708" + ], + "details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46708" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json new file mode 100644 index 00000000000..8dec6f3d6fb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hmvg-cx6j-hfj7/GHSA-hmvg-cx6j-hfj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmvg-cx6j-hfj7", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2024-26622" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntomoyo: fix UAF write bug in tomoyo_write_control()\n\nSince tomoyo_write_control() updates head->write_buf when write()\nof long lines is requested, we need to fetch head->write_buf after\nhead->io_sem is held. Otherwise, concurrent write() requests can\ncause use-after-free-write and double-free problems.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26622" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f03fc340cac9ea1dc63cbf8c93dd2eb0f227815" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hxq4-v53v-rh4h/GHSA-hxq4-v53v-rh4h.json b/advisories/unreviewed/2024/03/GHSA-hxq4-v53v-rh4h/GHSA-hxq4-v53v-rh4h.json new file mode 100644 index 00000000000..bd5015b8254 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hxq4-v53v-rh4h/GHSA-hxq4-v53v-rh4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxq4-v53v-rh4h", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2024-21816" + ], + "details": "in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21816" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r32c-fmcr-34r3/GHSA-r32c-fmcr-34r3.json b/advisories/unreviewed/2024/03/GHSA-r32c-fmcr-34r3/GHSA-r32c-fmcr-34r3.json new file mode 100644 index 00000000000..a8bf4a17f6f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r32c-fmcr-34r3/GHSA-r32c-fmcr-34r3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r32c-fmcr-34r3", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2023-4479" + ], + "details": "Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4479" + }, + { + "type": "WEB", + "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-4479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vjr2-5xwq-8c35/GHSA-vjr2-5xwq-8c35.json b/advisories/unreviewed/2024/03/GHSA-vjr2-5xwq-8c35/GHSA-vjr2-5xwq-8c35.json new file mode 100644 index 00000000000..481a72c1dc7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vjr2-5xwq-8c35/GHSA-vjr2-5xwq-8c35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjr2-5xwq-8c35", + "modified": "2024-03-04T09:30:29Z", + "published": "2024-03-04T09:30:29Z", + "aliases": [ + "CVE-2024-21826" + ], + "details": "in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21826" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-03.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T07:15:10Z" + } +} \ No newline at end of file