Skip to content

Commit cc27e78

Browse files
author
cvelistV5 Github Action
committed
3 changes (2 new | 1 updated):
- 2 new CVEs: CVE-2024-51175, CVE-2024-52792 - 1 updated CVEs: CVE-2024-1394
1 parent 3460ae4 commit cc27e78

File tree

5 files changed

+228
-46
lines changed

5 files changed

+228
-46
lines changed

cves/2024/1xxx/CVE-2024-1394.json

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
"assignerShortName": "redhat",
99
"dateReserved": "2024-02-09T06:02:35.056Z",
1010
"datePublished": "2024-03-21T12:16:38.790Z",
11-
"dateUpdated": "2024-12-17T15:03:37.294Z"
11+
"dateUpdated": "2024-12-17T21:47:17.516Z"
1212
},
1313
"containers": {
1414
"cna": {
@@ -516,7 +516,7 @@
516516
"defaultStatus": "affected",
517517
"versions": [
518518
{
519-
"version": "1:1.23.4-5.2.rhaos4.12.el9",
519+
"version": "1:1.23.4-5.2.rhaos4.12.el8",
520520
"lessThan": "*",
521521
"versionType": "rpm",
522522
"status": "unaffected"
@@ -573,7 +573,7 @@
573573
"defaultStatus": "affected",
574574
"versions": [
575575
{
576-
"version": "0:1.25.5-13.1.rhaos4.12.git76343da.el8",
576+
"version": "0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9",
577577
"lessThan": "*",
578578
"versionType": "rpm",
579579
"status": "unaffected"
@@ -611,7 +611,7 @@
611611
"defaultStatus": "affected",
612612
"versions": [
613613
{
614-
"version": "0:2.14.0-7.1.rhaos4.12.el8",
614+
"version": "0:2.14.0-5.2.rhaos4.12.el9",
615615
"lessThan": "*",
616616
"versionType": "rpm",
617617
"status": "unaffected"
@@ -630,7 +630,7 @@
630630
"defaultStatus": "affected",
631631
"versions": [
632632
{
633-
"version": "0:4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el9",
633+
"version": "0:4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el8",
634634
"lessThan": "*",
635635
"versionType": "rpm",
636636
"status": "unaffected"
@@ -687,7 +687,7 @@
687687
"defaultStatus": "affected",
688688
"versions": [
689689
{
690-
"version": "2:1.9.4-3.2.rhaos4.12.el8",
690+
"version": "2:1.9.4-3.2.rhaos4.12.el9",
691691
"lessThan": "*",
692692
"versionType": "rpm",
693693
"status": "unaffected"
@@ -763,7 +763,7 @@
763763
"defaultStatus": "affected",
764764
"versions": [
765765
{
766-
"version": "0:1.26.0-4.2.el9",
766+
"version": "0:1.26.0-4.1.el8",
767767
"lessThan": "*",
768768
"versionType": "rpm",
769769
"status": "unaffected"
@@ -801,7 +801,7 @@
801801
"defaultStatus": "affected",
802802
"versions": [
803803
{
804-
"version": "0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el9",
804+
"version": "0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el8",
805805
"lessThan": "*",
806806
"versionType": "rpm",
807807
"status": "unaffected"
@@ -839,7 +839,7 @@
839839
"defaultStatus": "affected",
840840
"versions": [
841841
{
842-
"version": "4:1.1.12-1.1.rhaos4.13.el8",
842+
"version": "4:1.1.12-1.1.rhaos4.13.el9",
843843
"lessThan": "*",
844844
"versionType": "rpm",
845845
"status": "unaffected"
@@ -858,7 +858,7 @@
858858
"defaultStatus": "affected",
859859
"versions": [
860860
{
861-
"version": "2:1.11.2-2.2.rhaos4.13.el9",
861+
"version": "2:1.11.2-2.2.rhaos4.13.el8",
862862
"lessThan": "*",
863863
"versionType": "rpm",
864864
"status": "unaffected"
@@ -934,7 +934,7 @@
934934
"defaultStatus": "affected",
935935
"versions": [
936936
{
937-
"version": "0:1.27.0-3.1.el9",
937+
"version": "0:1.27.0-3.1.el8",
938938
"lessThan": "*",
939939
"versionType": "rpm",
940940
"status": "unaffected"
@@ -972,7 +972,7 @@
972972
"defaultStatus": "affected",
973973
"versions": [
974974
{
975-
"version": "0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el9",
975+
"version": "0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8",
976976
"lessThan": "*",
977977
"versionType": "rpm",
978978
"status": "unaffected"
@@ -1010,7 +1010,7 @@
10101010
"defaultStatus": "affected",
10111011
"versions": [
10121012
{
1013-
"version": "3:4.4.1-11.3.rhaos4.14.el8",
1013+
"version": "3:4.4.1-11.3.rhaos4.14.el9",
10141014
"lessThan": "*",
10151015
"versionType": "rpm",
10161016
"status": "unaffected"
@@ -1048,7 +1048,7 @@
10481048
"defaultStatus": "affected",
10491049
"versions": [
10501050
{
1051-
"version": "1:1.29.1-10.4.rhaos4.14.el9",
1051+
"version": "1:1.29.1-10.4.rhaos4.14.el8",
10521052
"lessThan": "*",
10531053
"versionType": "rpm",
10541054
"status": "unaffected"
@@ -1086,7 +1086,7 @@
10861086
"defaultStatus": "affected",
10871087
"versions": [
10881088
{
1089-
"version": "3:2.1.7-3.4.rhaos4.14.el9",
1089+
"version": "3:2.1.7-3.4.rhaos4.14.el8",
10901090
"lessThan": "*",
10911091
"versionType": "rpm",
10921092
"status": "unaffected"
@@ -1124,7 +1124,7 @@
11241124
"defaultStatus": "affected",
11251125
"versions": [
11261126
{
1127-
"version": "0:1.27.4-7.2.rhaos4.14.git082c52f.el8",
1127+
"version": "0:1.27.4-7.2.rhaos4.14.git082c52f.el9",
11281128
"lessThan": "*",
11291129
"versionType": "rpm",
11301130
"status": "unaffected"
@@ -1181,7 +1181,7 @@
11811181
"defaultStatus": "affected",
11821182
"versions": [
11831183
{
1184-
"version": "0:4.14.0-202404160939.p0.g7bee54d.assembly.stream.el9",
1184+
"version": "0:4.14.0-202404160939.p0.g7bee54d.assembly.stream.el8",
11851185
"lessThan": "*",
11861186
"versionType": "rpm",
11871187
"status": "unaffected"
@@ -1219,7 +1219,7 @@
12191219
"defaultStatus": "affected",
12201220
"versions": [
12211221
{
1222-
"version": "0:4.14.0-202404151639.p0.g81558cc.assembly.stream.el9",
1222+
"version": "0:4.14.0-202404151639.p0.g81558cc.assembly.stream.el8",
12231223
"lessThan": "*",
12241224
"versionType": "rpm",
12251225
"status": "unaffected"
@@ -1276,7 +1276,7 @@
12761276
"defaultStatus": "affected",
12771277
"versions": [
12781278
{
1279-
"version": "0:4.14.0-202404151639.p0.g607e2dd.assembly.stream.el8",
1279+
"version": "0:4.14.0-202404151639.p0.g607e2dd.assembly.stream.el9",
12801280
"lessThan": "*",
12811281
"versionType": "rpm",
12821282
"status": "unaffected"
@@ -1295,7 +1295,7 @@
12951295
"defaultStatus": "affected",
12961296
"versions": [
12971297
{
1298-
"version": "3:4.4.1-11.4.rhaos4.14.el8",
1298+
"version": "3:4.4.1-11.4.rhaos4.14.el9",
12991299
"lessThan": "*",
13001300
"versionType": "rpm",
13011301
"status": "unaffected"
@@ -1333,7 +1333,7 @@
13331333
"defaultStatus": "affected",
13341334
"versions": [
13351335
{
1336-
"version": "2:1.11.2-10.4.rhaos4.14.el9",
1336+
"version": "2:1.11.2-10.4.rhaos4.14.el8",
13371337
"lessThan": "*",
13381338
"versionType": "rpm",
13391339
"status": "unaffected"
@@ -1503,7 +1503,7 @@
15031503
"defaultStatus": "affected",
15041504
"versions": [
15051505
{
1506-
"version": "0:4.15.0-202403211240.p0.g62c4d45.assembly.stream.el8",
1506+
"version": "0:4.15.0-202403211240.p0.g62c4d45.assembly.stream.el9",
15071507
"lessThan": "*",
15081508
"versionType": "rpm",
15091509
"status": "unaffected"
@@ -1522,7 +1522,7 @@
15221522
"defaultStatus": "affected",
15231523
"versions": [
15241524
{
1525-
"version": "0:4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el9",
1525+
"version": "0:4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el8",
15261526
"lessThan": "*",
15271527
"versionType": "rpm",
15281528
"status": "unaffected"
@@ -1560,7 +1560,7 @@
15601560
"defaultStatus": "affected",
15611561
"versions": [
15621562
{
1563-
"version": "4:1.1.12-1.1.rhaos4.15.el9",
1563+
"version": "4:1.1.12-1.1.rhaos4.15.el8",
15641564
"lessThan": "*",
15651565
"versionType": "rpm",
15661566
"status": "unaffected"
@@ -1579,7 +1579,7 @@
15791579
"defaultStatus": "affected",
15801580
"versions": [
15811581
{
1582-
"version": "2:1.11.2-21.2.rhaos4.15.el8",
1582+
"version": "2:1.11.2-21.2.rhaos4.15.el9",
15831583
"lessThan": "*",
15841584
"versionType": "rpm",
15851585
"status": "unaffected"
@@ -2713,7 +2713,7 @@
27132713
"providerMetadata": {
27142714
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
27152715
"shortName": "redhat",
2716-
"dateUpdated": "2024-12-17T15:03:37.294Z"
2716+
"dateUpdated": "2024-12-17T21:47:17.516Z"
27172717
}
27182718
},
27192719
"adp": [
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"dataType": "CVE_RECORD",
3+
"cveMetadata": {
4+
"state": "PUBLISHED",
5+
"cveId": "CVE-2024-51175",
6+
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
7+
"assignerShortName": "mitre",
8+
"dateUpdated": "2024-12-17T21:47:59.815355",
9+
"dateReserved": "2024-10-28T00:00:00",
10+
"datePublished": "2024-12-17T00:00:00"
11+
},
12+
"containers": {
13+
"cna": {
14+
"providerMetadata": {
15+
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
16+
"shortName": "mitre",
17+
"dateUpdated": "2024-12-17T21:47:59.815355"
18+
},
19+
"descriptions": [
20+
{
21+
"lang": "en",
22+
"value": "An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component."
23+
}
24+
],
25+
"affected": [
26+
{
27+
"vendor": "n/a",
28+
"product": "n/a",
29+
"versions": [
30+
{
31+
"version": "n/a",
32+
"status": "affected"
33+
}
34+
]
35+
}
36+
],
37+
"references": [
38+
{
39+
"url": "https://github.com/a1drewlong/h3c-S1526/blob/main/Vulnerability%20Cases.md"
40+
}
41+
],
42+
"problemTypes": [
43+
{
44+
"descriptions": [
45+
{
46+
"type": "text",
47+
"lang": "en",
48+
"description": "n/a"
49+
}
50+
]
51+
}
52+
]
53+
}
54+
},
55+
"dataVersion": "5.1"
56+
}
Lines changed: 105 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,105 @@
1+
{
2+
"dataType": "CVE_RECORD",
3+
"dataVersion": "5.1",
4+
"cveMetadata": {
5+
"cveId": "CVE-2024-52792",
6+
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
7+
"state": "PUBLISHED",
8+
"assignerShortName": "GitHub_M",
9+
"dateReserved": "2024-11-15T17:11:13.439Z",
10+
"datePublished": "2024-12-17T21:46:27.319Z",
11+
"dateUpdated": "2024-12-17T21:46:27.319Z"
12+
},
13+
"containers": {
14+
"cna": {
15+
"title": "Arbitrary config values override in lam",
16+
"problemTypes": [
17+
{
18+
"descriptions": [
19+
{
20+
"cweId": "CWE-610",
21+
"lang": "en",
22+
"description": "CWE-610: Externally Controlled Reference to a Resource in Another Sphere",
23+
"type": "CWE"
24+
}
25+
]
26+
}
27+
],
28+
"metrics": [
29+
{
30+
"cvssV3_1": {
31+
"attackComplexity": "LOW",
32+
"attackVector": "NETWORK",
33+
"availabilityImpact": "HIGH",
34+
"baseScore": 6.5,
35+
"baseSeverity": "MEDIUM",
36+
"confidentialityImpact": "NONE",
37+
"integrityImpact": "HIGH",
38+
"privilegesRequired": "HIGH",
39+
"scope": "UNCHANGED",
40+
"userInteraction": "NONE",
41+
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
42+
"version": "3.1"
43+
}
44+
}
45+
],
46+
"references": [
47+
{
48+
"name": "https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-6cp9-j5r7-xhcc",
49+
"tags": [
50+
"x_refsource_CONFIRM"
51+
],
52+
"url": "https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-6cp9-j5r7-xhcc"
53+
},
54+
{
55+
"name": "https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-fm9w-7m7v-wxqv",
56+
"tags": [
57+
"x_refsource_MISC"
58+
],
59+
"url": "https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-fm9w-7m7v-wxqv"
60+
},
61+
{
62+
"name": "https://github.com/LDAPAccountManager/lam/blob/fd665fef3b222bf8205154b14f676815d2d6ae20/lam/templates/config/mainmanage.php#L263",
63+
"tags": [
64+
"x_refsource_MISC"
65+
],
66+
"url": "https://github.com/LDAPAccountManager/lam/blob/fd665fef3b222bf8205154b14f676815d2d6ae20/lam/templates/config/mainmanage.php#L263"
67+
},
68+
{
69+
"name": "https://github.com/LDAPAccountManager/lam/releases/tag/9.0",
70+
"tags": [
71+
"x_refsource_MISC"
72+
],
73+
"url": "https://github.com/LDAPAccountManager/lam/releases/tag/9.0"
74+
}
75+
],
76+
"affected": [
77+
{
78+
"vendor": "LDAPAccountManager",
79+
"product": "lam",
80+
"versions": [
81+
{
82+
"version": "< 9.0",
83+
"status": "affected"
84+
}
85+
]
86+
}
87+
],
88+
"providerMetadata": {
89+
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
90+
"shortName": "GitHub_M",
91+
"dateUpdated": "2024-12-17T21:46:27.319Z"
92+
},
93+
"descriptions": [
94+
{
95+
"lang": "en",
96+
"value": "LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration values, that are set via `mainmanage.php` and `confmain.php`. This allows setting arbitrary config values and thus effectively bypassing `mitigation` of CVE-2024-23333/GHSA-fm9w-7m7v-wxqv. Configuration values for the main config or server profiles are set via `mainmanage.php` and `confmain.php`.\nThe values are written to `config.cfg` or `serverprofile.conf` in the format of `settingsName: settingsValue` line-by-line.\nAn attacker can smuggle arbitrary config values in a config file, by inserting a newline into certain config fields, followed by the value. This vulnerability has been addressed in version 9.0. All users are advised to upgrade. There are no known workarounds for this vulnerability."
97+
}
98+
],
99+
"source": {
100+
"advisory": "GHSA-6cp9-j5r7-xhcc",
101+
"discovery": "UNKNOWN"
102+
}
103+
}
104+
}
105+
}

0 commit comments

Comments
 (0)