Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-11-15 15:31:43 +00:00
parent 4004bbae30
commit 031a3f50cb
31 changed files with 793 additions and 41 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27pw-7wxg-pvx9",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-42544"
],
"details": "Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42544"
},
{
"type": "WEB",
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T08:15:20Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3248-f5xr-jwg7",
"modified": "2023-11-08T03:30:32Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-08T03:30:32Z",
"aliases": [
"CVE-2023-46770"
],
"details": "Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T03:15:08Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3w8r-3jh9-89v9",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-15T15:30:21Z",
"aliases": [
"CVE-2023-48087"
],
"details": "xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48087"
},
{
"type": "WEB",
"url": "https://github.com/xuxueli/xxl-job/issues/3330"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-15T15:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x38-82cr-g8gh",
"modified": "2023-11-09T18:34:55Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-09T18:34:55Z",
"aliases": [
"CVE-2023-36688"
],
"details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T16:15:34Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g88-4hgm-m99x",
"modified": "2023-11-09T18:34:55Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-09T18:34:55Z",
"aliases": [
"CVE-2023-45884"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T17:15:08Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5ch2-qvr7-76ch",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-15T15:30:21Z",
"aliases": [
"CVE-2023-5676"
],
"details": "In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5676"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-openj9/openj9/pull/18085"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/13"
}
],
"database_specific": {
"cwe_ids": [
"CWE-364"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-15T14:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65wf-2455-72cw",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-42545"
],
"details": "Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42545"
},
{
"type": "WEB",
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T08:15:21Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6733-7rp7-vf3m",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-15T15:30:21Z",
"aliases": [
"CVE-2023-48088"
],
"details": "xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48088"
},
{
"type": "WEB",
"url": "https://github.com/xuxueli/xxl-job/issues/3329"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-15T15:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f2c-c54p-7m36",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-46851"
],
"details": "Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing internal files then can lead to other exploits, like session hijacking, or remote code execution.\n\nThis issue affects Apache Allura from 1.0.1 through 1.15.0.\n\nUsers are recommended to upgrade to version 1.16.0, which fixes the issue.  If you are unable to upgrade, set \"disable_entry_points.allura.importers = forge-tracker, forge-discussion\" in your .ini config file.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46851"
},
{
"type": "WEB",
"url": "https://allura.apache.org/posts/2023-allura-1.16.0.html"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/hqk0vltl7qgrq215zgwjfoj0khbov0gx"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T09:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vf8-rmp2-v23x",
"modified": "2023-11-09T03:30:19Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47007"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_391B8 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-897x-xvj8-42rq",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-15T15:30:21Z",
"aliases": [
"CVE-2023-5245"
],
"details": "FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory.\n\nWhen creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract().\n\nArbitrary file creation can directly lead to code execution\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5245"
},
{
"type": "WEB",
"url": "https://github.com/combust/mleap/pull/866#issuecomment-1738032225"
},
{
"type": "WEB",
"url": "https://research.jfrog.com/vulnerabilities/mleap-path-traversal-rce-xray-532656/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-15T13:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96x6-ppmq-j9wc",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-42553"
],
"details": "Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42553"
},
{
"type": "WEB",
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T08:15:23Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jpw-fc84-wc8p",
"modified": "2023-11-08T18:30:31Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-08T18:30:31Z",
"aliases": [
"CVE-2023-46621"
],
"details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T16:15:10Z"
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp9w-gp2m-qfm3",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-46845"
],
"details": "EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46845"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN29195731/"
},
{
"type": "WEB",
"url": "https://www.ec-cube.net/info/weakness/20231026/index.php"
},
{
"type": "WEB",
"url": "https://www.ec-cube.net/info/weakness/20231026/index_3.php"
},
{
"type": "WEB",
"url": "https://www.ec-cube.net/info/weakness/20231026/index_40.php"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T08:15:24Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5gr-7qpp-2p9m",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2022-45350"
],
"details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History user activity log, audit tool.This issue affects Simple History user activity log, audit tool: from n/a through 3.3.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45350"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/simple-history/wordpress-simple-history-plugin-3-3-1-csv-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1236"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T15:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3c6-r6p2-gr6c",
"modified": "2023-11-08T03:30:32Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-08T03:30:32Z",
"aliases": [
"CVE-2023-46769"
],
"details": "Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T03:15:07Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4p3-9fc9-2447",
"modified": "2023-11-15T15:30:20Z",
"published": "2023-11-15T15:30:20Z",
"aliases": [
"CVE-2023-5076"
],
"details": "The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5076"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/2988896/ziteboard-online-whiteboard"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5608f50-e17a-471f-b644-dceb64d82f0c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-07T08:15:24Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h974-rh4p-qm47",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-15T15:30:21Z",
"aliases": [
"CVE-2023-4602"
],
"details": "The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4602"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1wliD7YvLqL2xWnR6jLEnWgoWRKsv9dCI/view?usp=sharing"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/2966178/"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d014f512-9030-49ce-945d-4900594fb373?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-15T13:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgg2-x3jc-9xcr",
"modified": "2023-11-09T18:34:55Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-09T18:34:55Z",
"aliases": [
"CVE-2023-25994"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T16:15:34Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3mr-93pv-j56f",
"modified": "2023-11-09T03:30:19Z",
"modified": "2023-11-15T15:30:21Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47006"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ipaddr field in the sub_6FC74 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"

Some files were not shown because too many files have changed in this diff Show More