diff --git a/advisories/unreviewed/2023/08/GHSA-ccmh-37rx-6pp5/GHSA-ccmh-37rx-6pp5.json b/advisories/unreviewed/2023/08/GHSA-ccmh-37rx-6pp5/GHSA-ccmh-37rx-6pp5.json index 6398fd76e6e..159a8e28526 100644 --- a/advisories/unreviewed/2023/08/GHSA-ccmh-37rx-6pp5/GHSA-ccmh-37rx-6pp5.json +++ b/advisories/unreviewed/2023/08/GHSA-ccmh-37rx-6pp5/GHSA-ccmh-37rx-6pp5.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4456" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:4933" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4456" diff --git a/advisories/unreviewed/2023/08/GHSA-f3rm-cm42-4w4f/GHSA-f3rm-cm42-4w4f.json b/advisories/unreviewed/2023/08/GHSA-f3rm-cm42-4w4f/GHSA-f3rm-cm42-4w4f.json index d2c8d45bc7b..e3abc739ccc 100644 --- a/advisories/unreviewed/2023/08/GHSA-f3rm-cm42-4w4f/GHSA-f3rm-cm42-4w4f.json +++ b/advisories/unreviewed/2023/08/GHSA-f3rm-cm42-4w4f/GHSA-f3rm-cm42-4w4f.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/174643/Ivanti-Sentry-Authentication-Bypass-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-2pgp-5w4w-9255/GHSA-2pgp-5w4w-9255.json b/advisories/unreviewed/2023/09/GHSA-2pgp-5w4w-9255/GHSA-2pgp-5w4w-9255.json index 9c3560c6097..b92f63ff04e 100644 --- a/advisories/unreviewed/2023/09/GHSA-2pgp-5w4w-9255/GHSA-2pgp-5w4w-9255.json +++ b/advisories/unreviewed/2023/09/GHSA-2pgp-5w4w-9255/GHSA-2pgp-5w4w-9255.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pgp-5w4w-9255", - "modified": "2023-09-11T12:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T12:30:17Z", "aliases": [ "CVE-2023-3612" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.sk-cert.sk/sk/threat/sk-cert-bezpecnostne-varovanie-v20230811-10" + }, + { + "type": "WEB", + "url": "https://www.sk-cert.sk/threat/sk-cert-bezpecnostne-varovanie-v20230811-10" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-2qp5-3jc8-pprj/GHSA-2qp5-3jc8-pprj.json b/advisories/unreviewed/2023/09/GHSA-2qp5-3jc8-pprj/GHSA-2qp5-3jc8-pprj.json new file mode 100644 index 00000000000..6037d1bf27c --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-2qp5-3jc8-pprj/GHSA-2qp5-3jc8-pprj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qp5-3jc8-pprj", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4828" + ], + "details": "An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4828" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-346q-rm44-2j2v/GHSA-346q-rm44-2j2v.json b/advisories/unreviewed/2023/09/GHSA-346q-rm44-2j2v/GHSA-346q-rm44-2j2v.json new file mode 100644 index 00000000000..bf5803ccb7a --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-346q-rm44-2j2v/GHSA-346q-rm44-2j2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-346q-rm44-2j2v", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-20233" + ], + "details": "A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by sending crafted CCMs to an affected device. A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20233" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-3fqx-hqc3-q3wf/GHSA-3fqx-hqc3-q3wf.json b/advisories/unreviewed/2023/09/GHSA-3fqx-hqc3-q3wf/GHSA-3fqx-hqc3-q3wf.json index 089786ebd1a..194caa395d3 100644 --- a/advisories/unreviewed/2023/09/GHSA-3fqx-hqc3-q3wf/GHSA-3fqx-hqc3-q3wf.json +++ b/advisories/unreviewed/2023/09/GHSA-3fqx-hqc3-q3wf/GHSA-3fqx-hqc3-q3wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fqx-hqc3-q3wf", - "modified": "2023-09-11T21:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T21:30:17Z", "aliases": [ "CVE-2023-35679" ], "details": "In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json index 80f03a65d52..00d997a92ad 100644 --- a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json +++ b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3r84-hhrv-2935", - "modified": "2023-09-11T21:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T21:30:17Z", "aliases": [ "CVE-2023-35676" ], "details": "In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-5hxg-4c73-j4wf/GHSA-5hxg-4c73-j4wf.json b/advisories/unreviewed/2023/09/GHSA-5hxg-4c73-j4wf/GHSA-5hxg-4c73-j4wf.json new file mode 100644 index 00000000000..43bf1362a71 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-5hxg-4c73-j4wf/GHSA-5hxg-4c73-j4wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hxg-4c73-j4wf", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-20191" + ], + "details": "A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL.\n\n This vulnerability is due to incomplete support for this feature. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.\n\n There are workarounds that address this vulnerability.\n\n \n\n \n This advisory is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2023 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20191" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnx-acl-PyzDkeYF" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-6677-fgc8-98h4/GHSA-6677-fgc8-98h4.json b/advisories/unreviewed/2023/09/GHSA-6677-fgc8-98h4/GHSA-6677-fgc8-98h4.json new file mode 100644 index 00000000000..e51bcb3c82b --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-6677-fgc8-98h4/GHSA-6677-fgc8-98h4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6677-fgc8-98h4", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-3280" + ], + "details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3280" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2023-3280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json b/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json new file mode 100644 index 00000000000..e51d2f607fa --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-69cm-qhp7-ch23/GHSA-69cm-qhp7-ch23.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69cm-qhp7-ch23", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-2680" + ], + "details": "This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2680" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-2680" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2203387" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-6mqc-xv9m-7m85/GHSA-6mqc-xv9m-7m85.json b/advisories/unreviewed/2023/09/GHSA-6mqc-xv9m-7m85/GHSA-6mqc-xv9m-7m85.json index 87ceda75b3c..ead43df45b2 100644 --- a/advisories/unreviewed/2023/09/GHSA-6mqc-xv9m-7m85/GHSA-6mqc-xv9m-7m85.json +++ b/advisories/unreviewed/2023/09/GHSA-6mqc-xv9m-7m85/GHSA-6mqc-xv9m-7m85.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mqc-xv9m-7m85", - "modified": "2023-09-11T21:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T21:30:17Z", "aliases": [ "CVE-2023-35677" ], "details": "In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-6v48-qpg5-fj4m/GHSA-6v48-qpg5-fj4m.json b/advisories/unreviewed/2023/09/GHSA-6v48-qpg5-fj4m/GHSA-6v48-qpg5-fj4m.json new file mode 100644 index 00000000000..81ebdaff450 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-6v48-qpg5-fj4m/GHSA-6v48-qpg5-fj4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v48-qpg5-fj4m", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-20135" + ], + "details": "A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.\n\n This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. An attacker could exploit this vulnerability by modifying an ISO image and then carrying out install requests in parallel. A successful exploit could allow the attacker to execute arbitrary code on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20135" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-L9zOkBz5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-7f5q-x8vx-pfrp/GHSA-7f5q-x8vx-pfrp.json b/advisories/unreviewed/2023/09/GHSA-7f5q-x8vx-pfrp/GHSA-7f5q-x8vx-pfrp.json new file mode 100644 index 00000000000..88d5d5fe9ff --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-7f5q-x8vx-pfrp/GHSA-7f5q-x8vx-pfrp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f5q-x8vx-pfrp", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4155" + ], + "details": "A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a denial of service or potentially guest-to-host escape in kernel configurations without stack guard pages (`CONFIG_VMAP_STACK`).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4155" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-4155" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2213802" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-8h46-vgr3-9j7m/GHSA-8h46-vgr3-9j7m.json b/advisories/unreviewed/2023/09/GHSA-8h46-vgr3-9j7m/GHSA-8h46-vgr3-9j7m.json new file mode 100644 index 00000000000..285b3ac2166 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-8h46-vgr3-9j7m/GHSA-8h46-vgr3-9j7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h46-vgr3-9j7m", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4803" + ], + "details": "A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4803" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-922c-wmf5-rmhj/GHSA-922c-wmf5-rmhj.json b/advisories/unreviewed/2023/09/GHSA-922c-wmf5-rmhj/GHSA-922c-wmf5-rmhj.json index 4317c88f4ff..e55b311f473 100644 --- a/advisories/unreviewed/2023/09/GHSA-922c-wmf5-rmhj/GHSA-922c-wmf5-rmhj.json +++ b/advisories/unreviewed/2023/09/GHSA-922c-wmf5-rmhj/GHSA-922c-wmf5-rmhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-922c-wmf5-rmhj", - "modified": "2023-09-11T15:31:01Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T15:31:01Z", "aliases": [ "CVE-2023-41000" ], "details": "GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-93fj-26p2-qqgh/GHSA-93fj-26p2-qqgh.json b/advisories/unreviewed/2023/09/GHSA-93fj-26p2-qqgh/GHSA-93fj-26p2-qqgh.json index 36cc002e95c..d48268c3ea9 100644 --- a/advisories/unreviewed/2023/09/GHSA-93fj-26p2-qqgh/GHSA-93fj-26p2-qqgh.json +++ b/advisories/unreviewed/2023/09/GHSA-93fj-26p2-qqgh/GHSA-93fj-26p2-qqgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93fj-26p2-qqgh", - "modified": "2023-09-12T15:30:20Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-12T15:30:20Z", "aliases": [ "CVE-2023-39637" ], "details": "D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-cp42-9j6q-v649/GHSA-cp42-9j6q-v649.json b/advisories/unreviewed/2023/09/GHSA-cp42-9j6q-v649/GHSA-cp42-9j6q-v649.json new file mode 100644 index 00000000000..87f7fe4e5ea --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-cp42-9j6q-v649/GHSA-cp42-9j6q-v649.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp42-9j6q-v649", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-3301" + ], + "details": "A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3301" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-3301" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215784" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-f2fh-jcp2-h8mp/GHSA-f2fh-jcp2-h8mp.json b/advisories/unreviewed/2023/09/GHSA-f2fh-jcp2-h8mp/GHSA-f2fh-jcp2-h8mp.json index dc4abf38afa..edb3bfed8bc 100644 --- a/advisories/unreviewed/2023/09/GHSA-f2fh-jcp2-h8mp/GHSA-f2fh-jcp2-h8mp.json +++ b/advisories/unreviewed/2023/09/GHSA-f2fh-jcp2-h8mp/GHSA-f2fh-jcp2-h8mp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2fh-jcp2-h8mp", - "modified": "2023-09-11T09:31:44Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T09:31:44Z", "aliases": [ "CVE-2023-4104" ], "details": "An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.\n*This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN client for Linux < v2.16.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-fj9m-2hq3-2ghm/GHSA-fj9m-2hq3-2ghm.json b/advisories/unreviewed/2023/09/GHSA-fj9m-2hq3-2ghm/GHSA-fj9m-2hq3-2ghm.json new file mode 100644 index 00000000000..23986bd9114 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-fj9m-2hq3-2ghm/GHSA-fj9m-2hq3-2ghm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj9m-2hq3-2ghm", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4801" + ], + "details": "An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4801" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-grh3-7c9c-hj98/GHSA-grh3-7c9c-hj98.json b/advisories/unreviewed/2023/09/GHSA-grh3-7c9c-hj98/GHSA-grh3-7c9c-hj98.json index 50976f42e03..2c47c64770d 100644 --- a/advisories/unreviewed/2023/09/GHSA-grh3-7c9c-hj98/GHSA-grh3-7c9c-hj98.json +++ b/advisories/unreviewed/2023/09/GHSA-grh3-7c9c-hj98/GHSA-grh3-7c9c-hj98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grh3-7c9c-hj98", - "modified": "2023-09-11T21:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T21:30:17Z", "aliases": [ "CVE-2023-35675" ], "details": "In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-h3r4-4c9w-25g8/GHSA-h3r4-4c9w-25g8.json b/advisories/unreviewed/2023/09/GHSA-h3r4-4c9w-25g8/GHSA-h3r4-4c9w-25g8.json index e063c0c4efd..36693d83f1e 100644 --- a/advisories/unreviewed/2023/09/GHSA-h3r4-4c9w-25g8/GHSA-h3r4-4c9w-25g8.json +++ b/advisories/unreviewed/2023/09/GHSA-h3r4-4c9w-25g8/GHSA-h3r4-4c9w-25g8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3r4-4c9w-25g8", - "modified": "2023-09-12T00:30:26Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-12T00:30:26Z", "aliases": [ "CVE-2023-38878" ], "details": "A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaScript in the web browser of a victim by injecting a malicious payload into the 'error' and 'error_description' parameters of 'oauth2.php'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-h9pj-ph75-37pg/GHSA-h9pj-ph75-37pg.json b/advisories/unreviewed/2023/09/GHSA-h9pj-ph75-37pg/GHSA-h9pj-ph75-37pg.json index 072890d1f4b..bd69e6eb5e8 100644 --- a/advisories/unreviewed/2023/09/GHSA-h9pj-ph75-37pg/GHSA-h9pj-ph75-37pg.json +++ b/advisories/unreviewed/2023/09/GHSA-h9pj-ph75-37pg/GHSA-h9pj-ph75-37pg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9pj-ph75-37pg", - "modified": "2023-09-12T15:30:20Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-12T15:30:20Z", "aliases": [ "CVE-2023-41013" ], "details": "Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the \"p4\" field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-j2wp-f4r8-6834/GHSA-j2wp-f4r8-6834.json b/advisories/unreviewed/2023/09/GHSA-j2wp-f4r8-6834/GHSA-j2wp-f4r8-6834.json new file mode 100644 index 00000000000..9f8a5871216 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-j2wp-f4r8-6834/GHSA-j2wp-f4r8-6834.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2wp-f4r8-6834", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-20236" + ], + "details": "A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device.\n\n This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20236" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-j3jp-5cvm-4wvf/GHSA-j3jp-5cvm-4wvf.json b/advisories/unreviewed/2023/09/GHSA-j3jp-5cvm-4wvf/GHSA-j3jp-5cvm-4wvf.json new file mode 100644 index 00000000000..aa55434b7e8 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-j3jp-5cvm-4wvf/GHSA-j3jp-5cvm-4wvf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jp-5cvm-4wvf", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-20190" + ], + "details": "A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device.\n\n This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is applied to an interface of an affected device. An attacker could exploit this vulnerability by sending traffic through the affected device that should be denied by the configured ACL. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device, allowing the attacker to access trusted networks that the device might be protecting.\n\n There are workarounds that address this vulnerability.\n\n \n\n \n This advisory is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2023 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20190" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-comp3acl-vGmp6BQ3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-mw88-4c77-3c33/GHSA-mw88-4c77-3c33.json b/advisories/unreviewed/2023/09/GHSA-mw88-4c77-3c33/GHSA-mw88-4c77-3c33.json new file mode 100644 index 00000000000..a2e54af36df --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-mw88-4c77-3c33/GHSA-mw88-4c77-3c33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw88-4c77-3c33", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4802" + ], + "details": "A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4802" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-p25m-jpj4-qcrr/GHSA-p25m-jpj4-qcrr.json b/advisories/unreviewed/2023/09/GHSA-p25m-jpj4-qcrr/GHSA-p25m-jpj4-qcrr.json new file mode 100644 index 00000000000..bf109d31a57 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-p25m-jpj4-qcrr/GHSA-p25m-jpj4-qcrr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p25m-jpj4-qcrr", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-4785" + ], + "details": "Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4785" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/pull/33656" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/pull/33667" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/pull/33669" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/pull/33670" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/pull/33672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-p5xv-5g6h-qw33/GHSA-p5xv-5g6h-qw33.json b/advisories/unreviewed/2023/09/GHSA-p5xv-5g6h-qw33/GHSA-p5xv-5g6h-qw33.json new file mode 100644 index 00000000000..3fa89d493e6 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-p5xv-5g6h-qw33/GHSA-p5xv-5g6h-qw33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5xv-5g6h-qw33", + "modified": "2023-09-13T18:31:26Z", + "published": "2023-09-13T18:31:26Z", + "aliases": [ + "CVE-2023-3255" + ], + "details": "A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3255" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-3255" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2218486" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-pq9p-wffw-c523/GHSA-pq9p-wffw-c523.json b/advisories/unreviewed/2023/09/GHSA-pq9p-wffw-c523/GHSA-pq9p-wffw-c523.json index c595f61a74a..aac90a6108f 100644 --- a/advisories/unreviewed/2023/09/GHSA-pq9p-wffw-c523/GHSA-pq9p-wffw-c523.json +++ b/advisories/unreviewed/2023/09/GHSA-pq9p-wffw-c523/GHSA-pq9p-wffw-c523.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq9p-wffw-c523", - "modified": "2023-09-11T21:30:17Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-11T21:30:17Z", "aliases": [ "CVE-2023-35680" ], "details": "In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-v2gw-42rh-8v5g/GHSA-v2gw-42rh-8v5g.json b/advisories/unreviewed/2023/09/GHSA-v2gw-42rh-8v5g/GHSA-v2gw-42rh-8v5g.json index 29162932827..fba9d385c68 100644 --- a/advisories/unreviewed/2023/09/GHSA-v2gw-42rh-8v5g/GHSA-v2gw-42rh-8v5g.json +++ b/advisories/unreviewed/2023/09/GHSA-v2gw-42rh-8v5g/GHSA-v2gw-42rh-8v5g.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4630" }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2023/08/31/security-release-gitlab-16-3-1-released/" + }, { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/415117" diff --git a/advisories/unreviewed/2023/09/GHSA-w324-97v9-pxqg/GHSA-w324-97v9-pxqg.json b/advisories/unreviewed/2023/09/GHSA-w324-97v9-pxqg/GHSA-w324-97v9-pxqg.json index 5483a763160..357cc1d268b 100644 --- a/advisories/unreviewed/2023/09/GHSA-w324-97v9-pxqg/GHSA-w324-97v9-pxqg.json +++ b/advisories/unreviewed/2023/09/GHSA-w324-97v9-pxqg/GHSA-w324-97v9-pxqg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w324-97v9-pxqg", - "modified": "2023-09-08T03:30:20Z", + "modified": "2023-09-13T18:31:25Z", "published": "2023-09-08T03:30:20Z", "aliases": [ "CVE-2023-36184" ], "details": "CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-xp6g-r6xf-wr5c/GHSA-xp6g-r6xf-wr5c.json b/advisories/unreviewed/2023/09/GHSA-xp6g-r6xf-wr5c/GHSA-xp6g-r6xf-wr5c.json index 631feef3076..93041a5cfba 100644 --- a/advisories/unreviewed/2023/09/GHSA-xp6g-r6xf-wr5c/GHSA-xp6g-r6xf-wr5c.json +++ b/advisories/unreviewed/2023/09/GHSA-xp6g-r6xf-wr5c/GHSA-xp6g-r6xf-wr5c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp6g-r6xf-wr5c", - "modified": "2023-09-12T15:30:20Z", + "modified": "2023-09-13T18:31:26Z", "published": "2023-09-12T15:30:20Z", "aliases": [ "CVE-2023-27169" ], "details": "Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": null, "github_reviewed": false,