diff --git a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json new file mode 100644 index 00000000000..c0bc4560a06 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63f3-2rgp-79qx", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2024-26585" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix race between tx work scheduling and socket close\n\nSimilarly to previous commit, the submitting thread (recvmsg/sendmsg)\nmay exit as soon as the async crypto handler calls complete().\nReorder scheduling the work before calling complete().\nThis seems more logical in the first place, as it's\nthe inverse order of what the submitting thread will do.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26585" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json index f6b81a348c5..df6b98f9d08 100644 --- a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json +++ b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8459-gg55-8qjj", - "modified": "2024-02-20T18:30:33Z", + "modified": "2024-02-21T15:30:45Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50387" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50387" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" diff --git a/advisories/unreviewed/2024/02/GHSA-97xg-49m6-fvcr/GHSA-97xg-49m6-fvcr.json b/advisories/unreviewed/2024/02/GHSA-97xg-49m6-fvcr/GHSA-97xg-49m6-fvcr.json new file mode 100644 index 00000000000..559c2bf1ed2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-97xg-49m6-fvcr/GHSA-97xg-49m6-fvcr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97xg-49m6-fvcr", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2023-33843" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256544.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33843" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/256544" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7116607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cq4r-v726-cpj4/GHSA-cq4r-v726-cpj4.json b/advisories/unreviewed/2024/02/GHSA-cq4r-v726-cpj4/GHSA-cq4r-v726-cpj4.json index 52d9275ef1b..17240b0ba56 100644 --- a/advisories/unreviewed/2024/02/GHSA-cq4r-v726-cpj4/GHSA-cq4r-v726-cpj4.json +++ b/advisories/unreviewed/2024/02/GHSA-cq4r-v726-cpj4/GHSA-cq4r-v726-cpj4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq4r-v726-cpj4", - "modified": "2024-02-20T00:30:34Z", + "modified": "2024-02-21T15:30:44Z", "published": "2024-02-20T00:30:34Z", "aliases": [ "CVE-2023-6260" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://sra.io/advisories" + }, + { + "type": "WEB", + "url": "https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-g6x9-362c-53pf/GHSA-g6x9-362c-53pf.json b/advisories/unreviewed/2024/02/GHSA-g6x9-362c-53pf/GHSA-g6x9-362c-53pf.json new file mode 100644 index 00000000000..07d4bf0a62e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g6x9-362c-53pf/GHSA-g6x9-362c-53pf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6x9-362c-53pf", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2023-50955" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50955" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275777" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7116610" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json b/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json new file mode 100644 index 00000000000..76c9531ac1d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hpjc-53pc-jh5v/GHSA-hpjc-53pc-jh5v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpjc-53pc-jh5v", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2024-22778" + ], + "details": "HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22778" + }, + { + "type": "WEB", + "url": "https://github.com/hackmdio/codimd/issues/1846" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json b/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json new file mode 100644 index 00000000000..5d2c280dcdc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j66f-jc3v-93vp", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2024-26582" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: fix use-after-free with partial reads and async decrypt\n\ntls_decrypt_sg doesn't take a reference on the pages from clear_skb,\nso the put_page() in tls_decrypt_done releases them, and we trigger\na use-after-free in process_rx_list when we try to read from the\npartially-read skb.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26582" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32b55c5ff9103b8508c1e04bfa5a08c64e7a925f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json b/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json new file mode 100644 index 00000000000..4529e6e0be9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j737-8h5g-42g9", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2024-26583" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix race between async notify and socket close\n\nThe submitting thread (one which called recvmsg/sendmsg)\nmay exit as soon as the async crypto handler calls complete()\nso any code past that point risks touching already freed data.\n\nTry to avoid the locking and extra flags altogether.\nHave the main thread hold an extra reference, this way\nwe can depend solely on the atomic ref counter for\nsynchronization.\n\nDon't futz with reiniting the completion, either, we are now\ntightly controlling when completion fires.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26583" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json b/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json index 704a83ab865..b9df261d091 100644 --- a/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json +++ b/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p56p-x426-8q87", - "modified": "2024-02-20T00:30:34Z", + "modified": "2024-02-21T15:30:44Z", "published": "2024-02-20T00:30:34Z", "aliases": [ "CVE-2023-6259" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://sra.io/advisories" + }, + { + "type": "WEB", + "url": "https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json index 0b1fef3955a..3f79f8c3d08 100644 --- a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json +++ b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv4h-p8jr-6cv2", - "modified": "2024-02-19T03:30:24Z", + "modified": "2024-02-21T15:30:45Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50868" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50868" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" diff --git a/advisories/unreviewed/2024/02/GHSA-q2cv-7j58-rfmj/GHSA-q2cv-7j58-rfmj.json b/advisories/unreviewed/2024/02/GHSA-q2cv-7j58-rfmj/GHSA-q2cv-7j58-rfmj.json new file mode 100644 index 00000000000..260bcae291d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q2cv-7j58-rfmj/GHSA-q2cv-7j58-rfmj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2cv-7j58-rfmj", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2023-47795" + ], + "details": "Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47795" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-47795" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json new file mode 100644 index 00000000000..fbea130dd94 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjjw-vjj8-q96x", + "modified": "2024-02-21T15:30:45Z", + "published": "2024-02-21T15:30:45Z", + "aliases": [ + "CVE-2024-26584" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: handle backlogging of crypto requests\n\nSince we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our\nrequests to the crypto API, crypto_aead_{encrypt,decrypt} can return\n -EBUSY instead of -EINPROGRESS in valid situations. For example, when\nthe cryptd queue for AESNI is full (easy to trigger with an\nartificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued\nto the backlog but still processed. In that case, the async callback\nwill also be called twice: first with err == -EINPROGRESS, which it\nseems we can just ignore, then with err == 0.\n\nCompared to Sabrina's original patch this version uses the new\ntls_*crypt_async_wait() helpers and converts the EBUSY to\nEINPROGRESS to avoid having to modify all the error handling\npaths. The handling is identical.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26584" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8590541473188741055d27b955db0777569438e3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T15:15:09Z" + } +} \ No newline at end of file