mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-05-06 18:53:08 +00:00
"-Synchronized-Data."
This commit is contained in:
parent
82e3661fbe
commit
2d33e20ae2
@ -149,16 +149,6 @@
|
|||||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2218944",
|
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2218944",
|
||||||
"refsource": "MISC",
|
"refsource": "MISC",
|
||||||
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=2218944"
|
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=2218944"
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://www.debian.org/security/2023/dsa-5492",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://www.debian.org/security/2023/dsa-5492"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -154,36 +154,6 @@
|
|||||||
"url": "https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/",
|
"url": "https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/",
|
||||||
"refsource": "MISC",
|
"refsource": "MISC",
|
||||||
"name": "https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/"
|
"name": "https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/344H6HO6SSC4KT7PDFXSDIXKMKHISSGF/",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/344H6HO6SSC4KT7PDFXSDIXKMKHISSGF/"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://security.netapp.com/advisory/ntap-20231027-0002/"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://www.debian.org/security/2023/dsa-5480",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://www.debian.org/security/2023/dsa-5480"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"url": "https://www.debian.org/security/2023/dsa-5492",
|
|
||||||
"refsource": "MISC",
|
|
||||||
"name": "https://www.debian.org/security/2023/dsa-5492"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -1,18 +1,81 @@
|
|||||||
{
|
{
|
||||||
|
"data_version": "4.0",
|
||||||
"data_type": "CVE",
|
"data_type": "CVE",
|
||||||
"data_format": "MITRE",
|
"data_format": "MITRE",
|
||||||
"data_version": "4.0",
|
|
||||||
"CVE_data_meta": {
|
"CVE_data_meta": {
|
||||||
"ID": "CVE-2024-22399",
|
"ID": "CVE-2024-22399",
|
||||||
"ASSIGNER": "cve@mitre.org",
|
"ASSIGNER": "security@apache.org",
|
||||||
"STATE": "RESERVED"
|
"STATE": "PUBLIC"
|
||||||
},
|
},
|
||||||
"description": {
|
"description": {
|
||||||
"description_data": [
|
"description_data": [
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"lang": "eng",
|
||||||
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
|
"value": "Deserialization of Untrusted Data vulnerability in Apache Seata.\u00a0\n\nWhen developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol.\n\nThis issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0.\n\nUsers are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue."
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
},
|
||||||
|
"problemtype": {
|
||||||
|
"problemtype_data": [
|
||||||
|
{
|
||||||
|
"description": [
|
||||||
|
{
|
||||||
|
"lang": "eng",
|
||||||
|
"value": "CWE-502 Deserialization of Untrusted Data",
|
||||||
|
"cweId": "CWE-502"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"affects": {
|
||||||
|
"vendor": {
|
||||||
|
"vendor_data": [
|
||||||
|
{
|
||||||
|
"vendor_name": "Apache Software Foundation",
|
||||||
|
"product": {
|
||||||
|
"product_data": [
|
||||||
|
{
|
||||||
|
"product_name": "Apache Seata",
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_affected": "=",
|
||||||
|
"version_value": "2.0.0"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"version_affected": "<=",
|
||||||
|
"version_name": "1.0.0",
|
||||||
|
"version_value": "1.8.0"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"references": {
|
||||||
|
"reference_data": [
|
||||||
|
{
|
||||||
|
"url": "https://lists.apache.org/thread/91nzzlxyj4nmks85gbzwkkjtbmnmlkc4",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "https://lists.apache.org/thread/91nzzlxyj4nmks85gbzwkkjtbmnmlkc4"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"generator": {
|
||||||
|
"engine": "Vulnogram 0.1.0-dev"
|
||||||
|
},
|
||||||
|
"source": {
|
||||||
|
"discovery": "EXTERNAL"
|
||||||
|
},
|
||||||
|
"credits": [
|
||||||
|
{
|
||||||
|
"lang": "en",
|
||||||
|
"value": "X1r0z(exp10it666123@gmail.com)"
|
||||||
|
}
|
||||||
|
]
|
||||||
}
|
}
|
@ -79,33 +79,33 @@
|
|||||||
{
|
{
|
||||||
"attackComplexity": "LOW",
|
"attackComplexity": "LOW",
|
||||||
"attackVector": "LOCAL",
|
"attackVector": "LOCAL",
|
||||||
"availabilityImpact": "LOW",
|
"availabilityImpact": "NONE",
|
||||||
"availabilityRequirement": "NOT_DEFINED",
|
"availabilityRequirement": "NOT_DEFINED",
|
||||||
"baseScore": 6.1,
|
"baseScore": 5.5,
|
||||||
"baseSeverity": "MEDIUM",
|
"baseSeverity": "MEDIUM",
|
||||||
"confidentialityImpact": "HIGH",
|
"confidentialityImpact": "HIGH",
|
||||||
"confidentialityRequirement": "NOT_DEFINED",
|
"confidentialityRequirement": "NOT_DEFINED",
|
||||||
"environmentalScore": 6.1,
|
"environmentalScore": 5.5,
|
||||||
"environmentalSeverity": "MEDIUM",
|
"environmentalSeverity": "MEDIUM",
|
||||||
"exploitCodeMaturity": "NOT_DEFINED",
|
"exploitCodeMaturity": "NOT_DEFINED",
|
||||||
"integrityImpact": "NONE",
|
"integrityImpact": "NONE",
|
||||||
"integrityRequirement": "NOT_DEFINED",
|
"integrityRequirement": "NOT_DEFINED",
|
||||||
"modifiedAttackComplexity": "LOW",
|
"modifiedAttackComplexity": "LOW",
|
||||||
"modifiedAttackVector": "LOCAL",
|
"modifiedAttackVector": "LOCAL",
|
||||||
"modifiedAvailabilityImpact": "LOW",
|
"modifiedAvailabilityImpact": "NONE",
|
||||||
"modifiedConfidentialityImpact": "HIGH",
|
"modifiedConfidentialityImpact": "HIGH",
|
||||||
"modifiedIntegrityImpact": "NONE",
|
"modifiedIntegrityImpact": "NONE",
|
||||||
"modifiedPrivilegesRequired": "NONE",
|
"modifiedPrivilegesRequired": "NONE",
|
||||||
"modifiedScope": "NOT_DEFINED",
|
"modifiedScope": "UNCHANGED",
|
||||||
"modifiedUserInteraction": "REQUIRED",
|
"modifiedUserInteraction": "REQUIRED",
|
||||||
"privilegesRequired": "NONE",
|
"privilegesRequired": "NONE",
|
||||||
"remediationLevel": "NOT_DEFINED",
|
"remediationLevel": "NOT_DEFINED",
|
||||||
"reportConfidence": "NOT_DEFINED",
|
"reportConfidence": "NOT_DEFINED",
|
||||||
"scope": "UNCHANGED",
|
"scope": "UNCHANGED",
|
||||||
"temporalScore": 6.1,
|
"temporalScore": 5.5,
|
||||||
"temporalSeverity": "MEDIUM",
|
"temporalSeverity": "MEDIUM",
|
||||||
"userInteraction": "REQUIRED",
|
"userInteraction": "REQUIRED",
|
||||||
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L",
|
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
|
||||||
"version": "3.1"
|
"version": "3.1"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
Loading…
x
Reference in New Issue
Block a user