mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-07-09 16:05:11 +00:00
Auto-Update: 2024-03-31T06:00:37.488737+00:00
This commit is contained in:
parent
7f28a586ef
commit
bbaca4d840
92
CVE-2024/CVE-2024-31xx/CVE-2024-3118.json
Normal file
92
CVE-2024/CVE-2024-31xx/CVE-2024-3118.json
Normal file
@ -0,0 +1,92 @@
|
||||
{
|
||||
"id": "CVE-2024-3118",
|
||||
"sourceIdentifier": "cna@vuldb.com",
|
||||
"published": "2024-03-31T05:15:07.427",
|
||||
"lastModified": "2024-03-31T05:15:07.427",
|
||||
"vulnStatus": "Received",
|
||||
"descriptions": [
|
||||
{
|
||||
"lang": "en",
|
||||
"value": "A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown processing of the component Attachment Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258779. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."
|
||||
}
|
||||
],
|
||||
"metrics": {
|
||||
"cvssMetricV31": [
|
||||
{
|
||||
"source": "cna@vuldb.com",
|
||||
"type": "Secondary",
|
||||
"cvssData": {
|
||||
"version": "3.1",
|
||||
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
|
||||
"attackVector": "NETWORK",
|
||||
"attackComplexity": "LOW",
|
||||
"privilegesRequired": "LOW",
|
||||
"userInteraction": "NONE",
|
||||
"scope": "UNCHANGED",
|
||||
"confidentialityImpact": "LOW",
|
||||
"integrityImpact": "LOW",
|
||||
"availabilityImpact": "LOW",
|
||||
"baseScore": 6.3,
|
||||
"baseSeverity": "MEDIUM"
|
||||
},
|
||||
"exploitabilityScore": 2.8,
|
||||
"impactScore": 3.4
|
||||
}
|
||||
],
|
||||
"cvssMetricV2": [
|
||||
{
|
||||
"source": "cna@vuldb.com",
|
||||
"type": "Secondary",
|
||||
"cvssData": {
|
||||
"version": "2.0",
|
||||
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
|
||||
"accessVector": "NETWORK",
|
||||
"accessComplexity": "LOW",
|
||||
"authentication": "SINGLE",
|
||||
"confidentialityImpact": "PARTIAL",
|
||||
"integrityImpact": "PARTIAL",
|
||||
"availabilityImpact": "PARTIAL",
|
||||
"baseScore": 6.5
|
||||
},
|
||||
"baseSeverity": "MEDIUM",
|
||||
"exploitabilityScore": 8.0,
|
||||
"impactScore": 6.4,
|
||||
"acInsufInfo": false,
|
||||
"obtainAllPrivilege": false,
|
||||
"obtainUserPrivilege": false,
|
||||
"obtainOtherPrivilege": false,
|
||||
"userInteractionRequired": false
|
||||
}
|
||||
]
|
||||
},
|
||||
"weaknesses": [
|
||||
{
|
||||
"source": "cna@vuldb.com",
|
||||
"type": "Primary",
|
||||
"description": [
|
||||
{
|
||||
"lang": "en",
|
||||
"value": "CWE-275"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"url": "https://github.com/sweatxi/BugHub/blob/main/dreamer_Excessive_authority.pdf",
|
||||
"source": "cna@vuldb.com"
|
||||
},
|
||||
{
|
||||
"url": "https://vuldb.com/?ctiid.258779",
|
||||
"source": "cna@vuldb.com"
|
||||
},
|
||||
{
|
||||
"url": "https://vuldb.com/?id.258779",
|
||||
"source": "cna@vuldb.com"
|
||||
},
|
||||
{
|
||||
"url": "https://vuldb.com/?submit.303196",
|
||||
"source": "cna@vuldb.com"
|
||||
}
|
||||
]
|
||||
}
|
18
README.md
18
README.md
@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
|
||||
### Last Repository Update
|
||||
|
||||
```plain
|
||||
2024-03-31T04:00:37.816603+00:00
|
||||
2024-03-31T06:00:37.488737+00:00
|
||||
```
|
||||
|
||||
### Most recent CVE Modification Timestamp synchronized with NVD
|
||||
|
||||
```plain
|
||||
2024-03-31T03:15:07.680000+00:00
|
||||
2024-03-31T05:15:07.427000+00:00
|
||||
```
|
||||
|
||||
### Last Data Feed Release
|
||||
@ -33,26 +33,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
|
||||
### Total Number of included CVEs
|
||||
|
||||
```plain
|
||||
243446
|
||||
243447
|
||||
```
|
||||
|
||||
### CVEs added in the last Commit
|
||||
|
||||
Recently added CVEs: `3`
|
||||
Recently added CVEs: `1`
|
||||
|
||||
- [CVE-2023-41724](CVE-2023/CVE-2023-417xx/CVE-2023-41724.json) (`2024-03-31T02:15:07.660`)
|
||||
- [CVE-2023-46808](CVE-2023/CVE-2023-468xx/CVE-2023-46808.json) (`2024-03-31T02:15:08.757`)
|
||||
- [CVE-2024-3117](CVE-2024/CVE-2024-31xx/CVE-2024-3117.json) (`2024-03-31T02:15:09.253`)
|
||||
- [CVE-2024-3118](CVE-2024/CVE-2024-31xx/CVE-2024-3118.json) (`2024-03-31T05:15:07.427`)
|
||||
|
||||
|
||||
### CVEs modified in the last Commit
|
||||
|
||||
Recently modified CVEs: `4`
|
||||
Recently modified CVEs: `0`
|
||||
|
||||
- [CVE-2023-35936](CVE-2023/CVE-2023-359xx/CVE-2023-35936.json) (`2024-03-31T03:15:07.323`)
|
||||
- [CVE-2023-38745](CVE-2023/CVE-2023-387xx/CVE-2023-38745.json) (`2024-03-31T03:15:07.507`)
|
||||
- [CVE-2024-28180](CVE-2024/CVE-2024-281xx/CVE-2024-28180.json) (`2024-03-31T03:15:07.680`)
|
||||
- [CVE-2024-2947](CVE-2024/CVE-2024-29xx/CVE-2024-2947.json) (`2024-03-31T02:15:09.150`)
|
||||
|
||||
|
||||
## Download and Usage
|
||||
|
15
_state.csv
15
_state.csv
@ -225503,7 +225503,7 @@ CVE-2023-35932,0,0,9aa62afd9c04ed737450b22ad4e5f34a1b572e47ec96f3cef758efb6e2667
|
||||
CVE-2023-35933,0,0,848c8ef509b8a6fbfb131cb1cce7e5f66a38335587cd7935744630a5fea4b16b,2023-07-06T18:13:47.323000
|
||||
CVE-2023-35934,0,0,d85d797aab1a37ae63c75c6f14b1e074ab53a4c73273488f8049bf54a940ecc7,2023-08-25T03:15:08.643000
|
||||
CVE-2023-35935,0,0,26abc60921b70a7fe361d6ee286d2c04394d57791ce8034d43fd9a2755964fc2,2023-11-07T04:16:06.170000
|
||||
CVE-2023-35936,0,1,695e9a121f2ed313ad07ca355c7a4d6694975c1ab711bd2c2a8c884ba3bcf7e0,2024-03-31T03:15:07.323000
|
||||
CVE-2023-35936,0,0,695e9a121f2ed313ad07ca355c7a4d6694975c1ab711bd2c2a8c884ba3bcf7e0,2024-03-31T03:15:07.323000
|
||||
CVE-2023-35937,0,0,7aced41f3666d57cf9ebbf7c2aa97136200234a3ea21a0a19f38d39b2e0062ac,2023-07-12T18:34:05.977000
|
||||
CVE-2023-35938,0,0,94ce0d110604560822ba467e70a8484a415daf7ec6d3efb9f38612ff27939f00,2023-07-10T13:26:11.097000
|
||||
CVE-2023-35939,0,0,0b21171bcfb0e354583c033f7dbb4fa7df44432c1d3eb445c3b2fec82d3d51c4,2023-07-11T00:03:34.423000
|
||||
@ -227571,7 +227571,7 @@ CVE-2023-38740,0,0,019101b99ffb836cd33190068bf0b533f41ed028ff9485d1b46b9d0c7dd54
|
||||
CVE-2023-38741,0,0,ce0a0c9eb7be728ea17a39c33952b39571a317dd12a11331f9d85dddf38f759f,2023-08-23T19:15:21.507000
|
||||
CVE-2023-38743,0,0,db78b369153f3b3788448490d76734d5843fcf48c2a8e9ac9a4fe83a8ba4ac0e,2023-09-13T03:53:23.610000
|
||||
CVE-2023-38744,0,0,e1fe6470e7d978a03eb71de05a501dd2afd3793d87802411bf5fd7592eae2549,2023-08-11T21:01:37.107000
|
||||
CVE-2023-38745,0,1,0b27f3afacaa6c4f4042850ee4c054928098c0ac0ea49a5a89d14594266455f8,2024-03-31T03:15:07.507000
|
||||
CVE-2023-38745,0,0,0b27f3afacaa6c4f4042850ee4c054928098c0ac0ea49a5a89d14594266455f8,2024-03-31T03:15:07.507000
|
||||
CVE-2023-38746,0,0,4209563afeb3ad1dda9125ee94ddb685efbf9fd550683bd1d9c4a6bec2c17401,2023-08-08T17:40:50.963000
|
||||
CVE-2023-38747,0,0,787dc83d063c2ba477fe02c74f183c6f9164483330a313dc42b4617dd570f85b,2023-08-08T17:41:41.393000
|
||||
CVE-2023-38748,0,0,47cafa1721abe3f389f7568c2025cc99ae081adf45b91f4ad86daeaa1465bd51,2023-08-08T17:41:51.407000
|
||||
@ -229611,7 +229611,7 @@ CVE-2023-4172,0,0,7d864af5899760e5fd916de8d5b7cb4c836384b557d17d8798fea9491ff22d
|
||||
CVE-2023-41720,0,0,8e9fc1420effd6ecd9db2851fddc14d3419717893d5acef5b2ea72a58b50524c,2024-03-26T19:27:41.727000
|
||||
CVE-2023-41721,0,0,b8fe1a9595e9621301ef0bca4addee7da64b2a00520a510a37f29d2e79188e54,2023-10-31T20:02:00.777000
|
||||
CVE-2023-41723,0,0,2c6f443b87b008a8a9e627848e133dd59ab18ee4f518502f55e24551d97a1e0a,2023-11-14T20:30:54.470000
|
||||
CVE-2023-41724,1,1,732f63fe2a13f213c4b44a8f22c219603f1cbdc0eb12b8ec8612056a026c1d80,2024-03-31T02:15:07.660000
|
||||
CVE-2023-41724,0,0,732f63fe2a13f213c4b44a8f22c219603f1cbdc0eb12b8ec8612056a026c1d80,2024-03-31T02:15:07.660000
|
||||
CVE-2023-41725,0,0,ef65a845340b2e5995978b7ff227127be0d8e07ed7a8d62bd421fd7106110973,2023-11-09T20:48:01.590000
|
||||
CVE-2023-41726,0,0,fb669107c42200a4419d1537040429448894a928afcfa430fdee2f48dca99d87,2023-11-09T20:47:03.140000
|
||||
CVE-2023-41727,0,0,1aea9ec78204883dbfc26cfb24b18446bca80c0abe98ce4d6d9d69448220db2e,2023-12-21T04:48:25.067000
|
||||
@ -232790,7 +232790,7 @@ CVE-2023-46802,0,0,81ab742ef444b7c62f7f45fae874a3923600da74bccd6c05821cc0f3c3485
|
||||
CVE-2023-46803,0,0,6d9acf7fa697eba714f52e6c2563d15daaa62001c85a491829c55db066eb5d2d,2023-12-21T04:49:22.117000
|
||||
CVE-2023-46804,0,0,303fee7e8ddf7f125b651ea337e3f6426140c80ed6928e8d77bc4dfdbfc39c28,2023-12-21T04:49:19.073000
|
||||
CVE-2023-46805,0,0,b3750b1134c367aa26eee38c16dcc83cd379c521a8dbf852dda3b3c6b98f8cb7,2024-01-22T17:15:09.080000
|
||||
CVE-2023-46808,1,1,ceda4042b63040c43b7056228cda340fdfff07ed9fced727105df39fb3a34e82,2024-03-31T02:15:08.757000
|
||||
CVE-2023-46808,0,0,ceda4042b63040c43b7056228cda340fdfff07ed9fced727105df39fb3a34e82,2024-03-31T02:15:08.757000
|
||||
CVE-2023-4681,0,0,d4b1d47c3f1f541f581a94f5a50c79c85882e6afa6d0d58510fdf4b0129b96ab,2023-09-05T16:22:15.077000
|
||||
CVE-2023-46813,0,0,0af53a0caece30dfcd1819ea3bb4e83013593f443624938126da8e4e939c317d,2024-01-11T21:15:10.350000
|
||||
CVE-2023-46814,0,0,01aab49816e0f8e94032f262e78c516846a1785150c21f030465f67639b72521,2023-11-29T18:54:35.827000
|
||||
@ -242658,7 +242658,7 @@ CVE-2024-28175,0,0,c8f25bff8e97476e2963865ef2e9cf777aae8f2ef724b2ba6f372c990cea8
|
||||
CVE-2024-28176,0,0,e24a2fcdc9349247e2e43b9922e7672e3c86bf046f747c2c25c63256b0d3ac9e,2024-03-30T04:15:08.393000
|
||||
CVE-2024-28179,0,0,1d7f36e4d02ee4bbf452e665bf14e1c56ee9929edf7bcaabe5b5ce5f4d7fb342,2024-03-21T12:58:51.093000
|
||||
CVE-2024-2818,0,0,1d77c7f149be6ba43356caff5e9da48b4aa8873ad07ab7a1a109734c26f7f24b,2024-03-28T12:42:56.150000
|
||||
CVE-2024-28180,0,1,70b7e15bae54b0026dbd7121b8d49cac4933c8976161f82f27967c15e8313bd2,2024-03-31T03:15:07.680000
|
||||
CVE-2024-28180,0,0,70b7e15bae54b0026dbd7121b8d49cac4933c8976161f82f27967c15e8313bd2,2024-03-31T03:15:07.680000
|
||||
CVE-2024-28181,0,0,43f0a809bba9c8c0eb02896e0986a3f9ccb9b3e30fc3eda1da963f37d0308dd8,2024-03-14T20:11:36.180000
|
||||
CVE-2024-28183,0,0,cf458d02a70f845821c561c029cb5e0bad9a91e6728031a2f307f44764bb9819,2024-03-25T16:43:06.137000
|
||||
CVE-2024-28184,0,0,477afbf0dc7ee8d9429045c75878ff2a88abaa5598b6ce7fba2a5f1850b6b613,2024-03-23T03:15:11.827000
|
||||
@ -243045,7 +243045,7 @@ CVE-2024-29440,0,0,b41dbba691936eb263a6e48ee2f4c3b0c65bf928cbb922caedd1e0f5f03ba
|
||||
CVE-2024-29442,0,0,7905121fe561461f75c739d09685b7ffc46a6e6f08464603a503f7d567bf4eab,2024-03-26T12:55:05.010000
|
||||
CVE-2024-2945,0,0,309a513aec715a57b9d74929d2379e417477e6045825bb68d9c761cada7aab5c,2024-03-27T12:29:30.307000
|
||||
CVE-2024-29469,0,0,acf93e04574e9669a29498319a75720c9b5a03ff4de2c06070b1f52ac9f365b7,2024-03-21T12:58:51.093000
|
||||
CVE-2024-2947,0,1,a0974f989c938567e0766b86e9d78f9601d99582b08f603d90b723c9ac89cc71,2024-03-31T02:15:09.150000
|
||||
CVE-2024-2947,0,0,a0974f989c938567e0766b86e9d78f9601d99582b08f603d90b723c9ac89cc71,2024-03-31T02:15:09.150000
|
||||
CVE-2024-29470,0,0,ec8cc83a60b9ef7edaa49e0605acc097203825f31a2e1ca35494b606ac2473df,2024-03-21T12:58:51.093000
|
||||
CVE-2024-29471,0,0,82d45a5ffd79414ce139218b143945b76a967fb1502a8005b616153a32c452ff,2024-03-21T12:58:51.093000
|
||||
CVE-2024-29472,0,0,8914457096a81cfec257e1932986907f8b2f25a966f10c0d7629905ec24b0f86,2024-03-21T12:58:51.093000
|
||||
@ -243444,4 +243444,5 @@ CVE-2024-31137,0,0,449ac74d89f8a92f177d1d77ee28ed4c10488cbb05e1f09ccbde9d94a1737
|
||||
CVE-2024-31138,0,0,7951d56a99dbfcb87972373932c19c3399e083ef12fc541bc18f929442b04b18,2024-03-28T16:07:30.893000
|
||||
CVE-2024-31139,0,0,cf8c25425780f1d36f604f7c3d037b16544eea3ab0908ce694956183986a8d87,2024-03-28T16:07:30.893000
|
||||
CVE-2024-31140,0,0,a7e2204480cd3644823842970dd746ee5c020bc95b54375f7cfa679b79796cd1,2024-03-28T16:07:30.893000
|
||||
CVE-2024-3117,1,1,2b5896fa9e31a7f382e3333b82dc6c56151d9b065cefc13b8e230bd36f1a358b,2024-03-31T02:15:09.253000
|
||||
CVE-2024-3117,0,0,2b5896fa9e31a7f382e3333b82dc6c56151d9b065cefc13b8e230bd36f1a358b,2024-03-31T02:15:09.253000
|
||||
CVE-2024-3118,1,1,4948c3a8db390364f937067f9f3ddbaf706a2ee5ae7ec8f1c3c08ee3107a421a,2024-03-31T05:15:07.427000
|
||||
|
Can't render this file because it is too large.
|
Loading…
x
Reference in New Issue
Block a user