Publish Advisories

GHSA-g7cg-jg33-rrhv
GHSA-5rc2-qffv-3c8p
GHSA-xf5h-8pqw-mggq
GHSA-962v-m5vf-4cv6
GHSA-w5h3-rmvr-mgm6
GHSA-vqxw-rw4p-r6vh
GHSA-4vg6-rrvh-fpmr
GHSA-548x-pj87-qv7f
GHSA-76q5-rvjr-8vhj
GHSA-7x8g-jfhh-pqhm
GHSA-h6hc-84g9-qq4q
GHSA-qmjp-x43g-wwmh
GHSA-vx2f-5c28-4wg3
GHSA-wgpq-p2hm-56v9
This commit is contained in:
advisory-database[bot]
2024-02-01 15:31:47 +00:00
parent 5cae6a9f1e
commit 0f47fd0b9a
14 changed files with 314 additions and 14 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7cg-jg33-rrhv",
"modified": "2023-04-26T21:30:37Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2023-04-26T21:30:37Z",
"aliases": [
"CVE-2023-27559"
@@ -28,13 +28,21 @@
{
"type": "WEB",
"url": "https://https://www.ibm.com/support/pages/node/6985667"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230511-0010/"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6985667"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-26T20:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rc2-qffv-3c8p",
"modified": "2023-06-30T03:30:17Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2023-06-14T09:30:42Z",
"aliases": [
"CVE-2023-30631"
@@ -46,7 +46,7 @@
"cwe_ids": [
"CWE-20"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-14T08:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf5h-8pqw-mggq",
"modified": "2023-07-06T21:14:55Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2023-07-06T21:14:55Z",
"aliases": [
"CVE-2023-25832"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-09T21:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-962v-m5vf-4cv6",
"modified": "2023-10-25T18:32:22Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39219"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:28Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5h3-rmvr-mgm6",
"modified": "2023-10-25T18:32:21Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-37283"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-287"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:28Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqxw-rw4p-r6vh",
"modified": "2024-01-25T15:31:53Z",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-01-25T15:31:53Z",
"aliases": [
"CVE-2024-22729"
],
"details": "NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-25T15:15:08Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vg6-rrvh-fpmr",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-24059"
],
"details": "springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24059"
},
{
"type": "WEB",
"url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#2-file-upload-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:56Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-548x-pj87-qv7f",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-0935"
],
"details": "An insertion of Sensitive Information into Log File vulnerability is affecting DELMIA Apriso Release 2019 through Release 2024",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0935"
},
{
"type": "WEB",
"url": "https://www.3ds.com/vulnerability/advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:56Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76q5-rvjr-8vhj",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-24062"
],
"details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24062"
},
{
"type": "WEB",
"url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#12-stored-cross-site-scripting-sysrole"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:56Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x8g-jfhh-pqhm",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-0704"
],
"details": "Rejected reason: very low impact - impractical to correct",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0704"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T15:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6hc-84g9-qq4q",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2023-6078"
],
"details": "An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6078"
},
{
"type": "WEB",
"url": "https://www.3ds.com/vulnerability/advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:55Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmjp-x43g-wwmh",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-24060"
],
"details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24060"
},
{
"type": "WEB",
"url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#11-stored-cross-site-scripting-sysuser"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:56Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx2f-5c28-4wg3",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-24061"
],
"details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24061"
},
{
"type": "WEB",
"url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#13-stored-cross-site-scripting-syscontentadd"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T14:15:56Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgpq-p2hm-56v9",
"modified": "2024-02-01T15:30:24Z",
"published": "2024-02-01T15:30:24Z",
"aliases": [
"CVE-2024-1141"
],
"details": "A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1141"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1141"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258836"
}
],
"database_specific": {
"cwe_ids": [
"CWE-779"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T15:15:08Z"
}
}