Publish Advisories

GHSA-j34q-xv9p-mp65
GHSA-r2p2-33c5-88q4
GHSA-vq44-qfg4-mfgg
GHSA-wmf9-7mph-r64c
GHSA-wx33-jrf7-q6rw
GHSA-mfpj-f925-v5gx
GHSA-2rw7-4xg9-x3cw
GHSA-m8r8-3226-6wp8
GHSA-r2mj-49jv-4jq7
GHSA-phw4-gv7f-mc27
GHSA-236w-6xxf-5g8v
GHSA-32m5-wrmj-7cr6
GHSA-65xh-f2p9-7f43
GHSA-7fr4-pq6g-x238
GHSA-8vch-3v7f-hvqj
GHSA-9whp-qh87-g9m8
GHSA-f2qw-c8r7-cf3j
GHSA-mpvx-g3x3-756v
GHSA-rq76-jq4v-wrmq
GHSA-x85q-fq3m-83jc
This commit is contained in:
advisory-database[bot]
2024-03-01 03:31:58 +00:00
parent b3133ef07b
commit 04d34503f1
20 changed files with 491 additions and 14 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j34q-xv9p-mp65",
"modified": "2022-05-24T17:41:40Z",
"modified": "2024-03-01T03:30:33Z",
"published": "2022-05-24T17:41:40Z",
"aliases": [
"CVE-2020-13574"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13574"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2p2-33c5-88q4",
"modified": "2022-05-24T17:41:40Z",
"modified": "2024-03-01T03:30:33Z",
"published": "2022-05-24T17:41:40Z",
"aliases": [
"CVE-2020-13575"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13575"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq44-qfg4-mfgg",
"modified": "2022-05-24T17:41:41Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2022-05-24T17:41:41Z",
"aliases": [
"CVE-2020-13578"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13578"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmf9-7mph-r64c",
"modified": "2022-05-24T17:41:41Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2022-05-24T17:41:41Z",
"aliases": [
"CVE-2020-13577"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13577"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx33-jrf7-q6rw",
"modified": "2022-05-24T17:41:40Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2022-05-24T17:41:40Z",
"aliases": [
"CVE-2020-13576"
@@ -21,6 +21,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13576"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JINMAJB4WQASTKTNSPQL3V7YMSYPKIA2"
@@ -36,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-190"
"CWE-190",
"CWE-680"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfpj-f925-v5gx",
"modified": "2023-06-14T00:30:39Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2023-06-14T00:30:39Z",
"aliases": [
"CVE-2023-29360"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-14T00:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rw7-4xg9-x3cw",
"modified": "2023-08-24T09:30:26Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2023-08-24T09:30:26Z",
"aliases": [
"CVE-2023-4511"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/issues/19258"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HCUPLDY7HLPO46PHMGIJSUBJFTT237C"
@@ -46,7 +50,7 @@
"cwe_ids": [
"CWE-835"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-24T07:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8r8-3226-6wp8",
"modified": "2023-08-24T09:30:27Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2023-08-24T09:30:27Z",
"aliases": [
"CVE-2023-4513"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/issues/19259"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HCUPLDY7HLPO46PHMGIJSUBJFTT237C"
@@ -46,7 +50,7 @@
"cwe_ids": [
"CWE-401"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-24T07:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2mj-49jv-4jq7",
"modified": "2023-12-15T00:31:02Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2023-10-03T15:30:34Z",
"aliases": [
"CVE-2023-4886"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7851"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1061"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-4886"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phw4-gv7f-mc27",
"modified": "2024-02-11T06:30:27Z",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-01-03T09:30:30Z",
"aliases": [
"CVE-2024-0208"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/issues/19496"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00016.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/34DBP5P2RHQ7XUABPANYYMOGV5KS6VEP"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-236w-6xxf-5g8v",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2024-22100"
],
"details": "\n\n\n\n\nMicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. A user must open a malicious DCM file in order to exploit the vulnerability.\n\n\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22100"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-060-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T01:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32m5-wrmj-7cr6",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-50305"
],
"details": "IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50305"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/273336"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7124058"
}
],
"database_specific": {
"cwe_ids": [
"CWE-521"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T02:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65xh-f2p9-7f43",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-50312"
],
"details": "IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50312"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/274711"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7125527"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T03:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fr4-pq6g-x238",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-28949"
],
"details": "IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28949"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/251216"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7124058"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T02:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vch-3v7f-hvqj",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-28525"
],
"details": "IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251052.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28525"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/251052"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7124058"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T02:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9whp-qh87-g9m8",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-47716"
],
"details": "IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47716"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/271656"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7078780"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T03:15:06Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2qw-c8r7-cf3j",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-38366"
],
"details": "IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 261115.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38366"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/261115"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7039783"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T03:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpvx-g3x3-756v",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2024-1941"
],
"details": "\nDelta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1941"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-060-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T01:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq76-jq4v-wrmq",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2024-25578"
],
"details": "\n\n\nMicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within the application.\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25578"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-060-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T01:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x85q-fq3m-83jc",
"modified": "2024-03-01T03:30:34Z",
"published": "2024-03-01T03:30:34Z",
"aliases": [
"CVE-2023-50324"
],
"details": "IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50324"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275038"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7112504"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T02:15:07Z"
}
}