From 0b50e62ea740a9c4dd4f7305abef8eb201a43c79 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 15 Feb 2024 09:31:49 +0000 Subject: [PATCH] Publish Advisories GHSA-p5vr-h433-qhqr GHSA-p6rw-gvvh-q8v4 GHSA-46w2-vp86-hhwc GHSA-4g2f-j53w-6jfc GHSA-4ghr-47h5-v2hf GHSA-58qw-vfcj-x2hg GHSA-62cw-wj7m-9hmq GHSA-75qr-hmmv-f5vx GHSA-8m6h-q36w-xvg7 GHSA-p74r-mvhv-7jx7 GHSA-pgq6-4q3w-7pvf GHSA-q767-p668-fq97 GHSA-qxwj-fm5r-rhx8 --- .../GHSA-p5vr-h433-qhqr.json | 10 +++-- .../GHSA-p6rw-gvvh-q8v4.json | 6 ++- .../GHSA-46w2-vp86-hhwc.json | 35 ++++++++++++++++ .../GHSA-4g2f-j53w-6jfc.json | 42 +++++++++++++++++++ .../GHSA-4ghr-47h5-v2hf.json | 6 ++- .../GHSA-58qw-vfcj-x2hg.json | 42 +++++++++++++++++++ .../GHSA-62cw-wj7m-9hmq.json | 35 ++++++++++++++++ .../GHSA-75qr-hmmv-f5vx.json | 39 +++++++++++++++++ .../GHSA-8m6h-q36w-xvg7.json | 38 +++++++++++++++++ .../GHSA-p74r-mvhv-7jx7.json | 42 +++++++++++++++++++ .../GHSA-pgq6-4q3w-7pvf.json | 6 ++- .../GHSA-q767-p668-fq97.json | 42 +++++++++++++++++++ .../GHSA-qxwj-fm5r-rhx8.json | 2 +- 13 files changed, 338 insertions(+), 7 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4g2f-j53w-6jfc/GHSA-4g2f-j53w-6jfc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-58qw-vfcj-x2hg/GHSA-58qw-vfcj-x2hg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-62cw-wj7m-9hmq/GHSA-62cw-wj7m-9hmq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-75qr-hmmv-f5vx/GHSA-75qr-hmmv-f5vx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p74r-mvhv-7jx7/GHSA-p74r-mvhv-7jx7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q767-p668-fq97/GHSA-q767-p668-fq97.json diff --git a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json index e220ce6cf85..1b9ac3de720 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json +++ b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5vr-h433-qhqr", - "modified": "2024-01-31T15:30:20Z", + "modified": "2024-02-15T09:30:35Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-6779" @@ -31,11 +31,11 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ" }, { "type": "WEB", @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" diff --git a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json index 746d1c13b47..8b37b52d5d9 100644 --- a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json +++ b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6rw-gvvh-q8v4", - "modified": "2024-01-31T15:30:20Z", + "modified": "2024-02-15T09:30:35Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-6246" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176931/glibc-qsort-Out-Of-Bounds-Read-Write.html" diff --git a/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json b/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json new file mode 100644 index 00000000000..4ba404947a0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46w2-vp86-hhwc", + "modified": "2024-02-15T09:30:36Z", + "published": "2024-02-15T09:30:35Z", + "aliases": [ + "CVE-2024-24256" + ], + "details": "SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24256" + }, + { + "type": "WEB", + "url": "https://github.com/l8l1/killl.github.io/blob/main/3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T08:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4g2f-j53w-6jfc/GHSA-4g2f-j53w-6jfc.json b/advisories/unreviewed/2024/02/GHSA-4g2f-j53w-6jfc/GHSA-4g2f-j53w-6jfc.json new file mode 100644 index 00000000000..0261166912d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4g2f-j53w-6jfc/GHSA-4g2f-j53w-6jfc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g2f-j53w-6jfc", + "modified": "2024-02-15T09:30:36Z", + "published": "2024-02-15T09:30:36Z", + "aliases": [ + "CVE-2023-4538" + ], + "details": "The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords.\n\nThis issue affects ERP XL: from 2020.2.2 through 2023.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4538" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/02/CVE-2023-4537" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/02/CVE-2023-4537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T09:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json b/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json index e9afe0e66f8..a52ebe2ad6e 100644 --- a/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json +++ b/advisories/unreviewed/2024/02/GHSA-4ghr-47h5-v2hf/GHSA-4ghr-47h5-v2hf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4ghr-47h5-v2hf", - "modified": "2024-02-07T15:30:47Z", + "modified": "2024-02-15T09:30:35Z", "published": "2024-02-02T00:31:25Z", "aliases": [ "CVE-2023-47257" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47257" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20240208140218/https://gotham-security.com/screenconnect-cve-2023-47256" + }, { "type": "WEB", "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fix" diff --git a/advisories/unreviewed/2024/02/GHSA-58qw-vfcj-x2hg/GHSA-58qw-vfcj-x2hg.json b/advisories/unreviewed/2024/02/GHSA-58qw-vfcj-x2hg/GHSA-58qw-vfcj-x2hg.json new file mode 100644 index 00000000000..cab2fa869f7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-58qw-vfcj-x2hg/GHSA-58qw-vfcj-x2hg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58qw-vfcj-x2hg", + "modified": "2024-02-15T09:30:36Z", + "published": "2024-02-15T09:30:36Z", + "aliases": [ + "CVE-2023-4537" + ], + "details": "Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.\n\nThis issue affects ERP XL: from 2020.2.2 through 2023.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4537" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/02/CVE-2023-4537" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2023/02/CVE-2023-4537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T09:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-62cw-wj7m-9hmq/GHSA-62cw-wj7m-9hmq.json b/advisories/unreviewed/2024/02/GHSA-62cw-wj7m-9hmq/GHSA-62cw-wj7m-9hmq.json new file mode 100644 index 00000000000..15b186d09dc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-62cw-wj7m-9hmq/GHSA-62cw-wj7m-9hmq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62cw-wj7m-9hmq", + "modified": "2024-02-15T09:30:35Z", + "published": "2024-02-15T09:30:35Z", + "aliases": [ + "CVE-2024-21727" + ], + "details": "XSS vulnerability in DP Calendar component for Joomla.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21727" + }, + { + "type": "WEB", + "url": "https://extensions.joomla.org/extension/dpcalendar" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-75qr-hmmv-f5vx/GHSA-75qr-hmmv-f5vx.json b/advisories/unreviewed/2024/02/GHSA-75qr-hmmv-f5vx/GHSA-75qr-hmmv-f5vx.json new file mode 100644 index 00000000000..30d980c62ff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-75qr-hmmv-f5vx/GHSA-75qr-hmmv-f5vx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75qr-hmmv-f5vx", + "modified": "2024-02-15T09:30:36Z", + "published": "2024-02-15T09:30:36Z", + "aliases": [ + "CVE-2024-24386" + ], + "details": "An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24386" + }, + { + "type": "WEB", + "url": "https://erickduarte.notion.site/VitalPBX-3-2-4-5-ee402173241c493687aa22ec60160c67?pvs=4" + }, + { + "type": "WEB", + "url": "https://github.com/erick-duarte/CVE-2024-24386" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T08:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json b/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json new file mode 100644 index 00000000000..7900f8f4802 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8m6h-q36w-xvg7/GHSA-8m6h-q36w-xvg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m6h-q36w-xvg7", + "modified": "2024-02-15T09:30:35Z", + "published": "2024-02-15T09:30:35Z", + "aliases": [ + "CVE-2024-0353" + ], + "details": "Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0353" + }, + { + "type": "WEB", + "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T08:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p74r-mvhv-7jx7/GHSA-p74r-mvhv-7jx7.json b/advisories/unreviewed/2024/02/GHSA-p74r-mvhv-7jx7/GHSA-p74r-mvhv-7jx7.json new file mode 100644 index 00000000000..e79b044e194 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p74r-mvhv-7jx7/GHSA-p74r-mvhv-7jx7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p74r-mvhv-7jx7", + "modified": "2024-02-15T09:30:36Z", + "published": "2024-02-15T09:30:36Z", + "aliases": [ + "CVE-2023-4539" + ], + "details": "Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. \n\nThis issue affects ERP XL: from 2020.2.2 through 2023.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4539" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/02/CVE-2023-4537" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/02/CVE-2023-4537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T09:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pgq6-4q3w-7pvf/GHSA-pgq6-4q3w-7pvf.json b/advisories/unreviewed/2024/02/GHSA-pgq6-4q3w-7pvf/GHSA-pgq6-4q3w-7pvf.json index e45f697592d..61a49733537 100644 --- a/advisories/unreviewed/2024/02/GHSA-pgq6-4q3w-7pvf/GHSA-pgq6-4q3w-7pvf.json +++ b/advisories/unreviewed/2024/02/GHSA-pgq6-4q3w-7pvf/GHSA-pgq6-4q3w-7pvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgq6-4q3w-7pvf", - "modified": "2024-02-07T18:30:26Z", + "modified": "2024-02-15T09:30:35Z", "published": "2024-02-02T00:31:25Z", "aliases": [ "CVE-2023-47256" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47256" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20240208140218/https://gotham-security.com/screenconnect-cve-2023-47256" + }, { "type": "WEB", "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fix" diff --git a/advisories/unreviewed/2024/02/GHSA-q767-p668-fq97/GHSA-q767-p668-fq97.json b/advisories/unreviewed/2024/02/GHSA-q767-p668-fq97/GHSA-q767-p668-fq97.json new file mode 100644 index 00000000000..ee7eed0cd09 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q767-p668-fq97/GHSA-q767-p668-fq97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q767-p668-fq97", + "modified": "2024-02-15T09:30:35Z", + "published": "2024-02-15T09:30:35Z", + "aliases": [ + "CVE-2024-0708" + ], + "details": "The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not be public.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0708" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3034324/landing-page-cat/trunk/includes/landing/landing.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7b34f50a-4d2d-49b8-86e4-0416c8be202b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json b/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json index e46e2110dc7..30692cd7f85 100644 --- a/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json +++ b/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxwj-fm5r-rhx8", - "modified": "2024-02-15T06:31:36Z", + "modified": "2024-02-15T09:30:35Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2023-46596"