From ffadee44cb31f8ac1f383be379e4391dcd8d345e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 21 May 2024 21:32:01 +0000 Subject: [PATCH] Publish Advisories GHSA-29gq-rw72-mrqg GHSA-32mg-q3wg-529p GHSA-45q4-h8rr-hgx2 GHSA-58c4-h2gx-8qfv GHSA-cjjw-5q77-9xc9 GHSA-jqff-8g2v-642h GHSA-qv6x-53jj-vw59 GHSA-rw3m-9ff4-qmp2 GHSA-vq53-2g5p-3wf9 GHSA-vvf7-q7rc-3m2m --- .../GHSA-29gq-rw72-mrqg.json | 38 ++++++++++++++++ .../GHSA-32mg-q3wg-529p.json | 35 +++++++++++++++ .../GHSA-45q4-h8rr-hgx2.json | 35 +++++++++++++++ .../GHSA-58c4-h2gx-8qfv.json | 38 ++++++++++++++++ .../GHSA-cjjw-5q77-9xc9.json | 35 +++++++++++++++ .../GHSA-jqff-8g2v-642h.json | 35 +++++++++++++++ .../GHSA-qv6x-53jj-vw59.json | 35 +++++++++++++++ .../GHSA-rw3m-9ff4-qmp2.json | 6 ++- .../GHSA-vq53-2g5p-3wf9.json | 43 +++++++++++++++++++ .../GHSA-vvf7-q7rc-3m2m.json | 6 ++- 10 files changed, 304 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jqff-8g2v-642h/GHSA-jqff-8g2v-642h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qv6x-53jj-vw59/GHSA-qv6x-53jj-vw59.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json diff --git a/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json b/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json new file mode 100644 index 00000000000..e8d72b87350 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29gq-rw72-mrqg", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-25724" + ], + "details": "In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25724" + }, + { + "type": "WEB", + "url": "https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/index.html#cve-2024-25724" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json b/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json new file mode 100644 index 00000000000..2718aa82251 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32mg-q3wg-529p", + "modified": "2024-05-21T21:30:28Z", + "published": "2024-05-21T21:30:28Z", + "aliases": [ + "CVE-2024-34274" + ], + "details": "OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34274" + }, + { + "type": "WEB", + "url": "https://github.com/OpenBD/openbd-core/issues/89" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json new file mode 100644 index 00000000000..d4305a749c2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45q4-h8rr-hgx2", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-35060" + ], + "details": "An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35060" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json b/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json new file mode 100644 index 00000000000..f6450591b0f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-58c4-h2gx-8qfv/GHSA-58c4-h2gx-8qfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58c4-h2gx-8qfv", + "modified": "2024-05-21T21:30:28Z", + "published": "2024-05-21T21:30:28Z", + "aliases": [ + "CVE-2024-5040" + ], + "details": "There are multiple ways in \nLCDS LAquis SCADA for an attacker to access locations outside of their own directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5040" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-142-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json b/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json new file mode 100644 index 00000000000..673e99578e6 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cjjw-5q77-9xc9/GHSA-cjjw-5q77-9xc9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjjw-5q77-9xc9", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-31756" + ], + "details": "An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attacker to escalate privileges via the Hw65.sys component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31756" + }, + { + "type": "WEB", + "url": "https://northwave-cybersecurity.com/vulnerability-notice-hardware-access-driver-marvintest-solutions" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jqff-8g2v-642h/GHSA-jqff-8g2v-642h.json b/advisories/unreviewed/2024/05/GHSA-jqff-8g2v-642h/GHSA-jqff-8g2v-642h.json new file mode 100644 index 00000000000..7528b5a3c1c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jqff-8g2v-642h/GHSA-jqff-8g2v-642h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqff-8g2v-642h", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-35059" + ], + "details": "An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35059" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qv6x-53jj-vw59/GHSA-qv6x-53jj-vw59.json b/advisories/unreviewed/2024/05/GHSA-qv6x-53jj-vw59/GHSA-qv6x-53jj-vw59.json new file mode 100644 index 00000000000..7b6b324f28a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qv6x-53jj-vw59/GHSA-qv6x-53jj-vw59.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv6x-53jj-vw59", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-35061" + ], + "details": "NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35061" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/remote-code-execution-via-man-in-the-middle-more-ujkze" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json b/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json index 61007347f5f..81538ab2f1c 100644 --- a/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json +++ b/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rw3m-9ff4-qmp2", - "modified": "2024-05-19T21:30:23Z", + "modified": "2024-05-21T21:30:27Z", "published": "2024-05-19T21:30:23Z", "aliases": [ "CVE-2024-36076" @@ -14,6 +14,10 @@ ], "references": [ + { + "type": "WEB", + "url": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-2vfc-3h43-vghh" + }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36076" diff --git a/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json b/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json new file mode 100644 index 00000000000..8c6e6c86101 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq53-2g5p-3wf9", + "modified": "2024-05-21T21:30:27Z", + "published": "2024-05-21T21:30:27Z", + "aliases": [ + "CVE-2024-33525" + ], + "details": "A Stored Cross-site Scripting (XSS) vulnerability in the \"Import of organizational units and title of organizational unit\" feature in ILIAS 7.20 to 7.30 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33525" + }, + { + "type": "WEB", + "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&cmd=layout&ref_id=1719&obj_id=159938" + }, + { + "type": "WEB", + "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&cmd=layout&ref_id=1719&obj_id=170029" + }, + { + "type": "WEB", + "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&cmd=layout&ref_id=1719&obj_id=170040" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-21T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json b/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json index 9daa615d075..14a5992af80 100644 --- a/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json +++ b/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vvf7-q7rc-3m2m", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-05-21T21:30:27Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-34257" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34257" }, + { + "type": "WEB", + "url": "https://github.com/ZackSecurity/VulnerReport/blob/cve/totolink/EX1800T/1.md" + }, { "type": "WEB", "url": "https://immense-mirror-b42.notion.site/TOTOLINK-EX1800T-has-an-unauthorized-arbitrary-command-execution-vulnerability-2f3e308f5e1d45a2b8a64f198cacc350"