Auto-Update: 2024-05-07T02:00:29.790723+00:00

This commit is contained in:
cad-safe-bot 2024-05-07 02:03:21 +00:00
parent bcd2015170
commit 34ecdd3d90
8 changed files with 109 additions and 33 deletions

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-23186",
"sourceIdentifier": "security@open-xchange.com",
"published": "2024-05-06T07:15:06.450",
"lastModified": "2024-05-06T12:44:56.377",
"lastModified": "2024-05-07T01:15:06.237",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
@ -47,6 +47,10 @@
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/May/3",
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/releases/8.22/",
"source": "security@open-xchange.com"

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-23187",
"sourceIdentifier": "security@open-xchange.com",
"published": "2024-05-06T07:15:06.850",
"lastModified": "2024-05-06T12:44:56.377",
"lastModified": "2024-05-07T01:15:06.333",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
@ -47,6 +47,10 @@
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/May/3",
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/releases/8.22/",
"source": "security@open-xchange.com"

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-23188",
"sourceIdentifier": "security@open-xchange.com",
"published": "2024-05-06T07:15:07.137",
"lastModified": "2024-05-06T12:44:56.377",
"lastModified": "2024-05-07T01:15:06.413",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
@ -47,6 +47,10 @@
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/May/3",
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/releases/8.22/",
"source": "security@open-xchange.com"

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-23193",
"sourceIdentifier": "security@open-xchange.com",
"published": "2024-05-06T07:15:07.533",
"lastModified": "2024-05-06T12:44:56.377",
"lastModified": "2024-05-07T01:15:06.497",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
@ -47,6 +47,10 @@
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/May/3",
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/releases/8.22/",
"source": "security@open-xchange.com"

View File

@ -0,0 +1,55 @@
{
"id": "CVE-2024-2913",
"sourceIdentifier": "security@huntr.dev",
"published": "2024-05-07T00:15:08.590",
"lastModified": "2024-05-07T00:15:08.590",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "security@huntr.dev",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 2.5
}
]
},
"weaknesses": [
{
"source": "security@huntr.dev",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-367"
}
]
}
],
"references": [
{
"url": "https://huntr.com/bounties/a3c69faf-cca0-4c10-8739-57e5bef7a95f",
"source": "security@huntr.dev"
}
]
}

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-3661",
"sourceIdentifier": "9119a7d8-5eab-497f-8521-727c672e3725",
"published": "2024-05-06T19:15:11.027",
"lastModified": "2024-05-06T19:53:38.797",
"lastModified": "2024-05-07T01:15:06.570",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
@ -17,20 +17,20 @@
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 8.8,
"baseScore": 7.6,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.3
"impactScore": 4.7
}
]
},
@ -60,7 +60,11 @@
"source": "9119a7d8-5eab-497f-8521-727c672e3725"
},
{
"url": "https://www.leviathansecurity.com/blog/tunnelvision",
"url": "https://tunnelvisionbug.com/",
"source": "9119a7d8-5eab-497f-8521-727c672e3725"
},
{
"url": "https://www.leviathansecurity.com/research/tunnelvision",
"source": "9119a7d8-5eab-497f-8521-727c672e3725"
}
]

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-05-06T23:55:20.194436+00:00
2024-05-07T02:00:29.790723+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-05-06T23:15:06.527000+00:00
2024-05-07T01:15:06.570000+00:00
```
### Last Data Feed Release
@ -27,31 +27,31 @@ Repository synchronizes with the NVD every 2 hours.
Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/releases/latest)
```plain
2024-05-06T00:00:20.275707+00:00
2024-05-07T00:00:20.268181+00:00
```
### Total Number of included CVEs
```plain
248794
248795
```
### CVEs added in the last Commit
Recently added CVEs: `2`
Recently added CVEs: `1`
- [CVE-2024-29941](CVE-2024/CVE-2024-299xx/CVE-2024-29941.json) (`2024-05-06T23:15:06.527`)
- [CVE-2024-30973](CVE-2024/CVE-2024-309xx/CVE-2024-30973.json) (`2024-05-06T22:15:08.687`)
- [CVE-2024-2913](CVE-2024/CVE-2024-29xx/CVE-2024-2913.json) (`2024-05-07T00:15:08.590`)
### CVEs modified in the last Commit
Recently modified CVEs: `4`
Recently modified CVEs: `5`
- [CVE-2021-33235](CVE-2021/CVE-2021-332xx/CVE-2021-33235.json) (`2024-05-06T22:15:08.107`)
- [CVE-2021-33236](CVE-2021/CVE-2021-332xx/CVE-2021-33236.json) (`2024-05-06T22:15:08.323`)
- [CVE-2022-35604](CVE-2022/CVE-2022-356xx/CVE-2022-35604.json) (`2024-05-06T22:15:08.420`)
- [CVE-2022-39196](CVE-2022/CVE-2022-391xx/CVE-2022-39196.json) (`2024-05-06T22:15:08.537`)
- [CVE-2024-23186](CVE-2024/CVE-2024-231xx/CVE-2024-23186.json) (`2024-05-07T01:15:06.237`)
- [CVE-2024-23187](CVE-2024/CVE-2024-231xx/CVE-2024-23187.json) (`2024-05-07T01:15:06.333`)
- [CVE-2024-23188](CVE-2024/CVE-2024-231xx/CVE-2024-23188.json) (`2024-05-07T01:15:06.413`)
- [CVE-2024-23193](CVE-2024/CVE-2024-231xx/CVE-2024-23193.json) (`2024-05-07T01:15:06.497`)
- [CVE-2024-3661](CVE-2024/CVE-2024-36xx/CVE-2024-3661.json) (`2024-05-07T01:15:06.570`)
## Download and Usage

View File

@ -176751,8 +176751,8 @@ CVE-2021-33224,0,0,460f29f33c7b2ef0f88d615846aa9cbc10705726651d3c4176055e2486d5d
CVE-2021-33226,0,0,23ae55da8127bc08e50c68693d8570ff88c626dd2d2e522370d8aa1aa67d5656,2024-04-11T01:11:50.980000
CVE-2021-3323,0,0,c7da0d65021fe774e54067b5beaac7234b51f705e7cbedf2cd5f9026a600874d,2021-10-18T18:05:18.787000
CVE-2021-33231,0,0,2486ca29e522167650eeaa2d4ccde4ff977f650ac0959a39188dc788e468be6b,2022-10-22T02:00:30.903000
CVE-2021-33235,0,1,63778c744133d889144d963edfe7d547bdabf6492531df001fccb2632da5086b,2024-05-06T22:15:08.107000
CVE-2021-33236,0,1,36fbf1aa0f94f37d2686699048b54a34b09df249d8bcfe109c228433a38290f8,2024-05-06T22:15:08.323000
CVE-2021-33235,0,0,63778c744133d889144d963edfe7d547bdabf6492531df001fccb2632da5086b,2024-05-06T22:15:08.107000
CVE-2021-33236,0,0,36fbf1aa0f94f37d2686699048b54a34b09df249d8bcfe109c228433a38290f8,2024-05-06T22:15:08.323000
CVE-2021-33237,0,0,6922179c76258265567505deb1ab98f4726f94e30d68a942e90c2d3ebe5a37bf,2023-11-07T03:35:49.617000
CVE-2021-3325,0,0,ae776f53b68e3c4f4bf6c10d6ca0c26accf1bcc36ab5d1c45e941873936fab96,2023-11-07T03:37:58.210000
CVE-2021-33254,0,0,60440fe09b3e82e1540b92ecf6e6f7fda731e94151867be57ea85863ba48d97e,2022-06-09T12:17:19.760000
@ -201972,7 +201972,7 @@ CVE-2022-3560,0,0,229f1fa29077a4bd405e76e0bd504309e1e1b57ca51efaf76f6b8af10bf44e
CVE-2022-35601,0,0,26a472552b68b0be09bf184b55be29e6935a5b8e67e89da0e941ffb820dc6f9d,2022-08-18T19:54:21.767000
CVE-2022-35602,0,0,89fe26f695b4808425dd9df648af4c70e9432cb0ac999cb03dabb3cadaff7d9c,2022-08-18T19:54:04.040000
CVE-2022-35603,0,0,8022ab1924cb780bb93fa69943eee08969e54d24671f151d214f07064cebb656,2022-08-18T19:31:05.760000
CVE-2022-35604,0,1,171dcd644a77cf0eaa2e1c000d45138242a0774075d99abc38a7581ee9db09fe,2024-05-06T22:15:08.420000
CVE-2022-35604,0,0,171dcd644a77cf0eaa2e1c000d45138242a0774075d99abc38a7581ee9db09fe,2024-05-06T22:15:08.420000
CVE-2022-35605,0,0,9540f99c2678487ba8d27ed1658096eb8c9ab40f82bb560848c9498986bce7c3,2022-08-18T19:38:17.890000
CVE-2022-35606,0,0,fd4a8cd54ad3168dc34d5382fd69ad6d6354584995be15b9e66702771fc5979a,2022-08-18T19:39:31.837000
CVE-2022-3561,0,0,e6d5b9edb6d1a2702aaec547c7915f068713789c96beb153a83af862e3221fdd,2022-11-21T13:10:16.283000
@ -204825,7 +204825,7 @@ CVE-2022-39190,0,0,fc53cb9f50915a691cdc9413601718280a065136805f267a09f8b8f0030ba
CVE-2022-39193,0,0,954c84cf04881007868978b7ce54873e679f3fc34fcd7db1feb1651b49d698e8,2023-08-08T14:22:24.967000
CVE-2022-39194,0,0,5fc4ab6d0d883d9ef536bef11493395756ceed83ec16e51bdb9ac2a6fee27874,2022-09-07T20:33:50.900000
CVE-2022-39195,0,0,cd60c7f5a55a6854b6b2ac00ee584275e07224643731a18e1a5776a07a4dceb4,2023-01-24T19:46:10.467000
CVE-2022-39196,0,1,1d27f8e12ef47600bfaf17f73272ce9a4461f61bacf1a3a150a5eaae3ea3a479,2024-05-06T22:15:08.537000
CVE-2022-39196,0,0,1d27f8e12ef47600bfaf17f73272ce9a4461f61bacf1a3a150a5eaae3ea3a479,2024-05-06T22:15:08.537000
CVE-2022-39197,0,0,1c2c1fc4cd3ad8c69e7214d4532cd1be69b584b50966673dbb8d74f3f7450ccd,2022-09-22T19:57:02.237000
CVE-2022-39198,0,0,b79fa0b1dc3b29865c444bc19dba722a93f5515a69b601f082c4ecf4ba81a825,2022-10-20T15:42:04.160000
CVE-2022-39199,0,0,c249171d3f6493fc79acecf944fce9b6fffd025711ebcdb5622455e964b4f7c8,2022-11-26T03:32:59.630000
@ -242541,15 +242541,15 @@ CVE-2024-23180,0,0,e1d7dd545ba9f64a187a87150c5e0980c64760319d7ec16ab7d59d98e268c
CVE-2024-23181,0,0,1670ba0f025ea5af6bb232b7859412796f7e598981dee961828ca2057439dfe0,2024-01-29T22:55:15.377000
CVE-2024-23182,0,0,f1264713bd57ef4128de6f3045f4c61bebd1bad343f929e4484b785773092265,2024-01-29T22:55:36.183000
CVE-2024-23183,0,0,93cf9ba468f15615134365f0103ab70e70069d42361d31f584c40ec201d8a9a2,2024-01-29T22:55:48.787000
CVE-2024-23186,0,0,7a282615543ec95b6d26df0cc7c1bade99e682889ba4c77ea986efbcaf3c6fcf,2024-05-06T12:44:56.377000
CVE-2024-23187,0,0,a7bc339e59279930b912dbd38ba2928687b718719fdf246e6482b300892a7eaf,2024-05-06T12:44:56.377000
CVE-2024-23188,0,0,7ddf908d55b86df0ec44ec8f1b1830b429d7629aac45aac28f7d7e751d64a988,2024-05-06T12:44:56.377000
CVE-2024-23186,0,1,e3bdfd5bd678ced4b2fd895b3721253cc2c923176c2928b6b0bb555eb2d808c5,2024-05-07T01:15:06.237000
CVE-2024-23187,0,1,e6d13051072eb4406fb0c2e34cc3b2a6ee4557f926084a50df7879030f66acda,2024-05-07T01:15:06.333000
CVE-2024-23188,0,1,614284cb774dfe75bf033c05e6b89bb66664729f86f8af14c1f5844c96195c22,2024-05-07T01:15:06.413000
CVE-2024-23189,0,0,38105a286e29ba4aeb2b7f55c2818d00acb37082743b2ce1bce1b1cce9e3180d,2024-04-11T11:15:48.320000
CVE-2024-2319,0,0,7c418d002244d51b00ca2fafa0c8e14c5cc40641054fa1d4dc85ce7d77674499,2024-03-08T21:19:43.127000
CVE-2024-23190,0,0,add17161c7c8505b6ba715b4898e70540bf15ecced41ee84c2b2e0388a683985,2024-04-11T11:15:48.423000
CVE-2024-23191,0,0,459948535d54516570f8d837aea6f84683ce700a59124af1293fdc8518256e81,2024-04-11T11:15:48.497000
CVE-2024-23192,0,0,ddfbef4409196a7a3eeb03bbc2422d0e54ca57b797a5b47e231d14cc76bbe3c5,2024-04-11T11:15:48.570000
CVE-2024-23193,0,0,9aa4766fa42b62c30a0a8899c496bc2d18216f3ef000654037c8f9dcbad1b7b5,2024-05-06T12:44:56.377000
CVE-2024-23193,0,1,64be9353dc56d57632e40547144a950f83a6701fb3fef7f2846c7142df079d6b,2024-05-07T01:15:06.497000
CVE-2024-23196,0,0,916695e8de6ad88a7eb739e09a11651ad9458fb3044e054e85a4e9fe2ce054c9,2024-02-10T04:06:14.577000
CVE-2024-23201,0,0,0f8fb4c7d86a834d8d9bd84c59d7ac097591ba1ab57e91c147b21ce025d3951c,2024-03-13T23:15:45.840000
CVE-2024-23203,0,0,a7d3b9c842d401a26cd60b5363d9fd931ec7b6ace08dfe359efc5de9e4d5324f,2024-03-13T22:15:09.117000
@ -245987,6 +245987,7 @@ CVE-2024-29126,0,0,0b79b403693aaf9c7e5913e80ff094ac46679e95aebf4152f34d3ef9f7148
CVE-2024-29127,0,0,e9f78e19445942ea45feb1efb6740d368decd0d9fd92fbb7f6217ca73bcee889,2024-03-19T14:31:27.883000
CVE-2024-29128,0,0,d04b46dfc40328b876fdc916a43fa7604fa03f240de5b2e8b86271d20186b1ca,2024-03-19T14:31:27.883000
CVE-2024-29129,0,0,a7c8734a1d99d99da881b37063436fc7d70f1e96d6183e82074470bef23a602e,2024-03-19T14:31:27.883000
CVE-2024-2913,1,1,a6143b804752a82e467f715ff0a6d714e9265e73f056d4a715d61e651bd64917,2024-05-07T00:15:08.590000
CVE-2024-29130,0,0,ce58c0744ffcb2d9cf875af96e8272ed1e3181995922f97c96a8939275c844b7,2024-03-19T14:31:27.883000
CVE-2024-29131,0,0,6dbc951f2aa0a9755b2bbdaa4d19905af93dd93bd4d25c017134d25c3898b424,2024-05-01T18:15:18.090000
CVE-2024-29133,0,0,6d247a2a3b8929a01a554821f00c7bbb378a28b457c9c68818a91f35f629cc39,2024-05-01T17:15:31.283000
@ -246360,7 +246361,7 @@ CVE-2024-29935,0,0,be0415ab39e2424d7707b3e026043937bddf40f9f881b75f312fe4db29a75
CVE-2024-29936,0,0,a0aa951ea6a61ca1da8503010b43db132d71646708e0e57d95e11fe2a44ec10b,2024-03-27T12:29:30.307000
CVE-2024-29937,0,0,cdd1fd1a57199ebd6cafb76fa77d6bf4c6b90236c50377042f461f6ac9babff6,2024-04-11T12:47:44.137000
CVE-2024-2994,0,0,de6c04df0e9f8de4e560093b2cf89202918172d57c506b82e636ef6cb9957d81,2024-04-11T01:25:44.640000
CVE-2024-29941,1,1,cd124a898b60f4b61110b252c2a53c119d2558e7ba223f4ac9cefc518f83f10e,2024-05-06T23:15:06.527000
CVE-2024-29941,0,0,cd124a898b60f4b61110b252c2a53c119d2558e7ba223f4ac9cefc518f83f10e,2024-05-06T23:15:06.527000
CVE-2024-29943,0,0,7068f3aaca8e1e080468ea07f9763f838e8d9ceb1f502d8b2bb56d270ef56f2f,2024-05-01T18:15:18.933000
CVE-2024-29944,0,0,59ef64fc7119589746b7ad82f7cc667d1e8ed3ea80b24b438153f375cffbb5e9,2024-05-01T18:15:18.987000
CVE-2024-29945,0,0,216b7153a77839bedb4bb1c536945361a5963d79dfd22094fc46f227d0975c54,2024-04-10T01:15:18.693000
@ -246919,7 +246920,7 @@ CVE-2024-30953,0,0,b6048a3223dd71969afb665512f3c96be52d96e721358fb67ff9cf9a8128e
CVE-2024-3096,0,0,13c78a6e73aead16232dc164a15de56938b00baab3c6940a2000c803dd2e4bee,2024-05-01T17:15:37.723000
CVE-2024-30965,0,0,0e44dd5d951a25ac3e8873a32678a3145da47d1060cb5312576a9c0471b643ad,2024-04-02T18:12:16.283000
CVE-2024-3097,0,0,34b222095b4c58e8686826c73c47f391fd247710053df9aaf322e019da7a6c42,2024-04-26T15:56:40.820000
CVE-2024-30973,1,1,df027f07491416bd1cc297061197f3db11587134f5dbeee53707411d90b551c9,2024-05-06T22:15:08.687000
CVE-2024-30973,0,0,df027f07491416bd1cc297061197f3db11587134f5dbeee53707411d90b551c9,2024-05-06T22:15:08.687000
CVE-2024-30974,0,0,fad1ff421513e997a755a646f437b1cf2946e8e72ed4701dccf29e92d3c1baae,2024-04-22T13:28:50.310000
CVE-2024-30977,0,0,0a99023cc49f8723c27525ea3fd6d09c0a18e0536fb7ad1e37e70ef0654b9714,2024-04-08T18:49:25.863000
CVE-2024-30979,0,0,80ab36bca498e33975593d086ceeeedf107c2c6f87bef059b959bbe8c3731bf4,2024-04-17T16:51:07.347000
@ -248439,7 +248440,7 @@ CVE-2024-3650,0,0,e078ac649d7d0d133fe9598e10336739bc9d365236ed72d408805e3868c3d4
CVE-2024-3652,0,0,455dabb71414a7592172807b25da69c5818ecc78456d9f87c63904d4c0988a33,2024-05-01T17:15:37.793000
CVE-2024-3654,0,0,954800a828ed246c147def14a6599156bd18a3e2cc72072dd62b0ab02b4bbf53,2024-04-19T16:19:49.043000
CVE-2024-3660,0,0,27de83d41a96740d974951cfc0f4ab32e626a768053ae4e7908802eefe823936,2024-04-17T12:48:31.863000
CVE-2024-3661,0,0,d922da9e63dddfd0bcf752dff7bff19eac0165dd6c57a0256fc2b919221c7f05,2024-05-06T19:53:38.797000
CVE-2024-3661,0,1,c6febbadd34c61ff9ce9fd477e2289fbf09f49b42a8f843ca0c46218957c8d07,2024-05-07T01:15:06.570000
CVE-2024-3662,0,0,aac492e0cb08799a7f888c46af5bedb595fa2e9ad6dc15c21be50e9dae70066e,2024-04-15T13:15:31.997000
CVE-2024-3664,0,0,afb9452532a9b46276f3e123567931f2d9b14afd62c66b887c9d751f65c725bc,2024-04-23T12:52:09.397000
CVE-2024-3665,0,0,22dbbd6c0bec2b9f433688ae97b549cd541e7f2d387c3796dd32246c851476cf,2024-04-23T12:52:09.397000

Can't render this file because it is too large.