Auto-Update: 2024-03-17T15:00:38.042037+00:00

This commit is contained in:
cad-safe-bot 2024-03-17 15:03:27 +00:00
parent 94bafe0365
commit 4ceb69dd67
3 changed files with 100 additions and 15 deletions

View File

@ -0,0 +1,88 @@
{
"id": "CVE-2024-2564",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-03-17T14:15:06.973",
"lastModified": "2024-03-17T14:15:06.973",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in PandaXGO PandaX up to 20240310 and classified as critical. This issue affects the function ExportUser of the file /apps/system/api/user.go. The manipulation of the argument filename leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257063."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.5
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-24"
}
]
}
],
"references": [
{
"url": "https://github.com/PandaXGO/PandaX/issues/6",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.257063",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.257063",
"source": "cna@vuldb.com"
}
]
}

View File

@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-03-17T13:00:38.305363+00:00
2024-03-17T15:00:38.042037+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-03-17T12:15:07.617000+00:00
2024-03-17T14:15:06.973000+00:00
```
### Last Data Feed Release
@ -29,24 +29,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
241730
241731
```
### CVEs added in the last Commit
Recently added CVEs: `4`
Recently added CVEs: `1`
* [CVE-2024-2560](CVE-2024/CVE-2024-25xx/CVE-2024-2560.json) (`2024-03-17T11:15:06.297`)
* [CVE-2024-2561](CVE-2024/CVE-2024-25xx/CVE-2024-2561.json) (`2024-03-17T11:15:06.540`)
* [CVE-2024-2562](CVE-2024/CVE-2024-25xx/CVE-2024-2562.json) (`2024-03-17T12:15:07.343`)
* [CVE-2024-2563](CVE-2024/CVE-2024-25xx/CVE-2024-2563.json) (`2024-03-17T12:15:07.617`)
* [CVE-2024-2564](CVE-2024/CVE-2024-25xx/CVE-2024-2564.json) (`2024-03-17T14:15:06.973`)
### CVEs modified in the last Commit
Recently modified CVEs: `1`
Recently modified CVEs: `0`
* [CVE-2023-27534](CVE-2023/CVE-2023-275xx/CVE-2023-27534.json) (`2024-03-17T12:15:07.023`)
## Download and Usage

View File

@ -219336,7 +219336,7 @@ CVE-2023-2753,0,0,4ecf5398bff210b49fa24c4de40f831d5fe62d4e27f885c305b06210dc7395
CVE-2023-27530,0,0,bbdbd6bd09e5403444301a316c014367de950b68297f3c5c5163341a6899a17f,2023-12-08T22:15:07.603000
CVE-2023-27532,0,0,6e558ef4c9db36b1e54f4e743272a386ec3944cb0cd1f1ee52412a3f882d8662,2023-03-16T17:23:23.517000
CVE-2023-27533,0,0,8efc2d3b0d613e079e2ff08782daf5d279bd3c39cc2493d8662942722001c292,2023-11-07T04:09:58.970000
CVE-2023-27534,0,1,aae8ee275589144f846d2a1300226fddeee79fb032dfd4b8bfac5d0cf836e6aa,2024-03-17T12:15:07.023000
CVE-2023-27534,0,0,aae8ee275589144f846d2a1300226fddeee79fb032dfd4b8bfac5d0cf836e6aa,2024-03-17T12:15:07.023000
CVE-2023-27535,0,0,9dd9adc2eef50b049de0adb22bb47f77301b46425035a140d7678322628887a0,2023-11-07T04:09:59.127000
CVE-2023-27536,0,0,4e21d8aa8217d2d2a6dea9322c843207d3839bd7f7d74aa22c6fcfbbcd573a34,2023-11-07T04:09:59.200000
CVE-2023-27537,0,0,7c58ae2df903a95939ca9660d65f06d149e776b6a57035215f459abd5b18eb8f,2023-10-20T18:44:28.253000
@ -241065,7 +241065,7 @@ CVE-2024-25594,0,0,041a8f1098ea8eb68537c88dc97c5b5bc81f29a13cfba102c394bd754ead0
CVE-2024-25596,0,0,13114d7ee8f79cd717d046d21908c5184e1a5e393e712bad1e319d6228d0994e,2024-03-15T16:26:49.320000
CVE-2024-25597,0,0,e1e937a2ce2376e555303951d31b92ae54df886e8583dbc9427f46a5c7a19dfc,2024-03-15T16:26:49.320000
CVE-2024-25598,0,0,fb13eab656ab973b3987c473d0c30d3886e191cae180bf92b8f730aaf3f724ee,2024-03-15T16:26:49.320000
CVE-2024-2560,1,1,a7cc379c94422e2afce41b3b6bf6bbbf323812b8496844ae4c1dcf67681d09d4,2024-03-17T11:15:06.297000
CVE-2024-2560,0,0,a7cc379c94422e2afce41b3b6bf6bbbf323812b8496844ae4c1dcf67681d09d4,2024-03-17T11:15:06.297000
CVE-2024-25601,0,0,81f4fdae91c2e2979380ffdf7201132bd42db70ea50ec659a221655da6bb1b91,2024-02-22T19:07:37.840000
CVE-2024-25602,0,0,6a0412f9e3d86cacfb35a934a8fd793128a0f85212ec26797b187230b94df26a,2024-02-22T19:07:37.840000
CVE-2024-25603,0,0,863f490c7ea22d0d3c701bfeb2e8a36747268d73fdd29bb24261158009a35432,2024-02-22T19:07:37.840000
@ -241075,7 +241075,7 @@ CVE-2024-25606,0,0,f4127f65859da9e4eafb304ab5f5357c338dbc6a805533edaf8b3a431051a
CVE-2024-25607,0,0,b1bdbb091cda1b1a0832d5c938cadf7ef73e9fe8fb0a2223ee265a0dd4bacd84,2024-02-20T19:50:53.960000
CVE-2024-25608,0,0,777906eeb0a5b0a9c86f59255c54f56d84853d1b7a72669bef6a4f4e08ea2a75,2024-02-20T19:50:53.960000
CVE-2024-25609,0,0,70b2abe4f6b07d14dd1eaed8f77b182b189fc3d24fbd2fcce03d566544ebecbb,2024-02-20T19:50:53.960000
CVE-2024-2561,1,1,bd018974413114451f5b439e6a0f8391d5f00b5dd172b0eaa3902e1b875f2acd,2024-03-17T11:15:06.540000
CVE-2024-2561,0,0,bd018974413114451f5b439e6a0f8391d5f00b5dd172b0eaa3902e1b875f2acd,2024-03-17T11:15:06.540000
CVE-2024-25610,0,0,b35a6722f35ec1b5b38b71e712f8a9e94e1a8cc00e1ca63d3d3fefe1476d192a,2024-02-20T19:50:53.960000
CVE-2024-25611,0,0,b8aad29ecd8dafe739aa6a39e6e9b9c4b39c67e14764ad44399a3e75bbf7bb9a,2024-03-06T15:18:08.093000
CVE-2024-25612,0,0,a837136520aeaa34f4b70e7dd03ddbfd53112c6e4bd6fadaa68c3f07ddc2bf40,2024-03-06T15:18:08.093000
@ -241086,7 +241086,7 @@ CVE-2024-25616,0,0,08e7e92a31b8175954afe7fe6329cd6c1ab805b72ac96ece1d0fb03d1064f
CVE-2024-25617,0,0,d737d9ee2715258f911ebb3f89a3dffbc47a4a22baf4554c7d4e9230aee01721,2024-02-15T06:23:39.303000
CVE-2024-25618,0,0,6ed8249b3ca4bef56b61ecd19434b2c991b2098ab9bdaaf5d9d685277d557b66,2024-02-15T06:23:39.303000
CVE-2024-25619,0,0,39abdc988e4d73d7f7229c43ce3f985993a99ce60ee39e82390d8dd27310f40d,2024-02-15T06:23:39.303000
CVE-2024-2562,1,1,70f9debb76f5aee871bef259609492bc248526475d2b24841c8e51944840bb15,2024-03-17T12:15:07.343000
CVE-2024-2562,0,0,70f9debb76f5aee871bef259609492bc248526475d2b24841c8e51944840bb15,2024-03-17T12:15:07.343000
CVE-2024-25620,0,0,103fa94e29e01d07bc8fc6806aebaa5600b7a8dea376343a1f804f899bde136f,2024-02-15T06:23:39.303000
CVE-2024-25623,0,0,d7097ca06a605433eb8efcfef9343f15725de6d8ed69964da29f4e86bee1b907,2024-02-20T19:50:53.960000
CVE-2024-25625,0,0,aa9fbe54dd7bd2282f80b78321777ab8fac3f81631cae43246d091ee25cf0360,2024-02-20T19:50:53.960000
@ -241094,12 +241094,13 @@ CVE-2024-25626,0,0,d9f83485f5fb6b4cc55a1d4f971342f8155aa2e72270d86c4d53f59fca85d
CVE-2024-25627,0,0,335cf8e2ea0e82de853c22c4501c52460485e1ff41aacc65c72ac02bb7c794f4,2024-02-16T21:39:50.223000
CVE-2024-25628,0,0,a1db75d4a91c0decb510706632a7a99db70da095e2ef543a17e18a8ebf5faf6e,2024-02-16T21:39:50.223000
CVE-2024-25629,0,0,e8492adb2680f110ac06a58986c9b019034accc223969f879ac2af270156ad78,2024-02-23T16:14:43.447000
CVE-2024-2563,1,1,c69203a23c6a79e1918a4ddad25e19618a314dc6a28d3feb5308bf93d7a93818,2024-03-17T12:15:07.617000
CVE-2024-2563,0,0,c69203a23c6a79e1918a4ddad25e19618a314dc6a28d3feb5308bf93d7a93818,2024-03-17T12:15:07.617000
CVE-2024-25630,0,0,e8dd8461a6c439d380ff2cfaa26bd120d833e99bc88eaeb33a16736643fcf67c,2024-02-20T19:50:53.960000
CVE-2024-25631,0,0,c8bdaced4c0d5563bd57b345057b4e4f59369a45b7c12f5563c1a08a0da6b5d9,2024-02-20T19:50:53.960000
CVE-2024-25634,0,0,c1510e3ab0b733f2989d621c241e546f656e3e790b7a0232e637470ddb569500,2024-02-20T19:50:53.960000
CVE-2024-25635,0,0,02f92a5a9bdf152263c68c7161477865d30fa40fbd763157286667e134fdd120,2024-02-20T19:50:53.960000
CVE-2024-25636,0,0,25ca08d2d7942010a89cee168f33ec13089ab5d688be0f620a303dd1bdaf78e7,2024-02-20T19:50:53.960000
CVE-2024-2564,1,1,20c5f4f1c2679e3f384ad4559d078395b49d5e5aee769ccefe30e3301a8d3204,2024-03-17T14:15:06.973000
CVE-2024-25640,0,0,e7a5a66e06481c463ef3267e2ad9b6391b00223315aeb71281eb8d63b041ce79,2024-02-20T19:50:53.960000
CVE-2024-25642,0,0,bf91eeb1502dedca60fe6c035b93d7dfc5a440bc6932322c6ae4d128b4c7c145,2024-02-13T14:01:40.577000
CVE-2024-25643,0,0,08f3e6c0d454841d4e4dc84aae81812246ffbd96bb71cc2e9e4566cd4077e910,2024-02-13T14:01:07.747000

Can't render this file because it is too large.