diff --git a/CVE-2024/CVE-2024-77xx/CVE-2024-7701.json b/CVE-2024/CVE-2024-77xx/CVE-2024-7701.json new file mode 100644 index 00000000000..4882c59012d --- /dev/null +++ b/CVE-2024/CVE-2024-77xx/CVE-2024-7701.json @@ -0,0 +1,78 @@ +{ + "id": "CVE-2024-7701", + "sourceIdentifier": "96148269-fe82-4198-b1bf-3a73ce8bc92e", + "published": "2024-12-15T11:15:05.387", + "lastModified": "2024-12-15T11:15:05.387", + "vulnStatus": "Received", + "cveTags": [], + "descriptions": [ + { + "lang": "en", + "value": "Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0." + } + ], + "metrics": { + "cvssMetricV40": [ + { + "source": "96148269-fe82-4198-b1bf-3a73ce8bc92e", + "type": "Secondary", + "cvssData": { + "version": "4.0", + "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", + "baseScore": 5.1, + "baseSeverity": "MEDIUM", + "attackVector": "PHYSICAL", + "attackComplexity": "LOW", + "attackRequirements": "NONE", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "vulnerableSystemConfidentiality": "HIGH", + "vulnerableSystemIntegrity": "NONE", + "vulnerableSystemAvailability": "NONE", + "subsequentSystemConfidentiality": "NONE", + "subsequentSystemIntegrity": "NONE", + "subsequentSystemAvailability": "NONE", + "exploitMaturity": "NOT_DEFINED", + "confidentialityRequirements": "NOT_DEFINED", + "integrityRequirements": "NOT_DEFINED", + "availabilityRequirements": "NOT_DEFINED", + "modifiedAttackVector": "NOT_DEFINED", + "modifiedAttackComplexity": "NOT_DEFINED", + "modifiedAttackRequirements": "NOT_DEFINED", + "modifiedPrivilegesRequired": "NOT_DEFINED", + "modifiedUserInteraction": "NOT_DEFINED", + "modifiedVulnerableSystemConfidentiality": "NOT_DEFINED", + "modifiedVulnerableSystemIntegrity": "NOT_DEFINED", + "modifiedVulnerableSystemAvailability": "NOT_DEFINED", + "modifiedSubsequentSystemConfidentiality": "NOT_DEFINED", + "modifiedSubsequentSystemIntegrity": "NOT_DEFINED", + "modifiedSubsequentSystemAvailability": "NOT_DEFINED", + "safety": "NOT_DEFINED", + "automatable": "NOT_DEFINED", + "recovery": "NOT_DEFINED", + "valueDensity": "NOT_DEFINED", + "vulnerabilityResponseEffort": "NOT_DEFINED", + "providerUrgency": "NOT_DEFINED" + } + } + ] + }, + "weaknesses": [ + { + "source": "96148269-fe82-4198-b1bf-3a73ce8bc92e", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-916" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/percona/percona-toolkit/blob/aa1ac0e6889168fddf73c3a72d447e9ea0c0c63b/src/go/pt-secure-collect/encrypt.go#L17", + "source": "96148269-fe82-4198-b1bf-3a73ce8bc92e" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index d8825bce5c7..2690eefebfd 100644 --- a/README.md +++ b/README.md @@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2024-12-15T07:00:19.599984+00:00 +2024-12-15T13:00:20.043223+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2024-12-15T05:15:05.803000+00:00 +2024-12-15T11:15:05.387000+00:00 ``` ### Last Data Feed Release @@ -33,14 +33,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -273884 +273885 ``` ### CVEs added in the last Commit Recently added CVEs: `1` -- [CVE-2024-56082](CVE-2024/CVE-2024-560xx/CVE-2024-56082.json) (`2024-12-15T05:15:05.803`) +- [CVE-2024-7701](CVE-2024/CVE-2024-77xx/CVE-2024-7701.json) (`2024-12-15T11:15:05.387`) ### CVEs modified in the last Commit diff --git a/_state.csv b/_state.csv index 85e9cb9cc09..5c0dbaf26ec 100644 --- a/_state.csv +++ b/_state.csv @@ -270192,7 +270192,7 @@ CVE-2024-56072,0,0,bd6e4433d11f02012078ec78b3d640c7b5f2f1fd75efb6e332973e1bbc623 CVE-2024-56073,0,0,01824a247f09195beb347683faab76db49c5c6281fc26b7356c5505b6ae504c1,2024-12-15T03:15:16.433000 CVE-2024-56074,0,0,0642cc60954135db9d21e04c2f8a3494d7d5e43e5456627fcfb7a5451c970b77,2024-12-15T04:15:05.360000 CVE-2024-5608,0,0,ced92374bfec9f9526a30572e667eb2d7d2eee08d2b8c010b292f0924bebbe2c,2024-11-26T01:42:21.587000 -CVE-2024-56082,1,1,57d547b5a105acb2d3e1ac52bd9fee3095823a449148e9ae5f97a8b20acffe15,2024-12-15T05:15:05.803000 +CVE-2024-56082,0,0,57d547b5a105acb2d3e1ac52bd9fee3095823a449148e9ae5f97a8b20acffe15,2024-12-15T05:15:05.803000 CVE-2024-5609,0,0,4c03a855f07c8ea18d8e7a70e1e2d3467f32254daea5abf62f130fb919fa93d1,2024-06-06T19:16:09.920000 CVE-2024-5611,0,0,52c51c7a288f3c0ab122ffc809ef2624c3045fff37cac024f8608d70739aac41,2024-11-21T09:48:00.920000 CVE-2024-5612,0,0,fa9f2c267dc0651754a7af098fdc2eb62147cefb9c269a544f85a4928011ea0a,2024-11-21T09:48:01.037000 @@ -272046,6 +272046,7 @@ CVE-2024-7697,0,0,122b8f72aeda3c5b2d61460f1dce24bd382a6f877b1c3f9efb3e322459b58e CVE-2024-7698,0,0,28382cbcfd0fa7ea6a7d15c9ccdd01abba2e948df9ed5ab95948fe232327814d,2024-09-27T19:39:43.350000 CVE-2024-7699,0,0,69660c01a9078b1bb8b8ba16d42135a8912e2caf5b6ecd54d7bddf6785b1e596,2024-09-27T18:59:31.277000 CVE-2024-7700,0,0,b57636a6ff7952071612c6f1892a1333ca0104c06c954b5d5e21b60cfc424ebb,2024-09-16T14:20:21.087000 +CVE-2024-7701,1,1,c21e98ebb5a36700320113e8cc5b090af992f4d8c6eea98accd19a173ea9a44d,2024-12-15T11:15:05.387000 CVE-2024-7702,0,0,1098975bd71f66b03b30c93d5413d8a5ef0d8cda516b0c70a1252211ba8e5726,2024-08-26T18:15:46.870000 CVE-2024-7703,0,0,7f76e29a5ed460fd6ac72a2955499c5bf4953d8afc86b29ced015fa447c06880,2024-08-19T12:59:59.177000 CVE-2024-7704,0,0,bd3f518e669136b0eab54f268d3d0c8d3f377c12c71cbb007eb510f9a54f561d,2024-08-13T12:58:25.437000