From 0f47fd0b9ac59b408bbb98470c05f443d7727f61 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Feb 2024 15:31:47 +0000 Subject: [PATCH] Publish Advisories GHSA-g7cg-jg33-rrhv GHSA-5rc2-qffv-3c8p GHSA-xf5h-8pqw-mggq GHSA-962v-m5vf-4cv6 GHSA-w5h3-rmvr-mgm6 GHSA-vqxw-rw4p-r6vh GHSA-4vg6-rrvh-fpmr GHSA-548x-pj87-qv7f GHSA-76q5-rvjr-8vhj GHSA-7x8g-jfhh-pqhm GHSA-h6hc-84g9-qq4q GHSA-qmjp-x43g-wwmh GHSA-vx2f-5c28-4wg3 GHSA-wgpq-p2hm-56v9 --- .../GHSA-g7cg-jg33-rrhv.json | 12 +++++- .../GHSA-5rc2-qffv-3c8p.json | 4 +- .../GHSA-xf5h-8pqw-mggq.json | 4 +- .../GHSA-962v-m5vf-4cv6.json | 4 +- .../GHSA-w5h3-rmvr-mgm6.json | 4 +- .../GHSA-vqxw-rw4p-r6vh.json | 11 +++-- .../GHSA-4vg6-rrvh-fpmr.json | 35 ++++++++++++++++ .../GHSA-548x-pj87-qv7f.json | 38 +++++++++++++++++ .../GHSA-76q5-rvjr-8vhj.json | 35 ++++++++++++++++ .../GHSA-7x8g-jfhh-pqhm.json | 31 ++++++++++++++ .../GHSA-h6hc-84g9-qq4q.json | 38 +++++++++++++++++ .../GHSA-qmjp-x43g-wwmh.json | 35 ++++++++++++++++ .../GHSA-vx2f-5c28-4wg3.json | 35 ++++++++++++++++ .../GHSA-wgpq-p2hm-56v9.json | 42 +++++++++++++++++++ 14 files changed, 314 insertions(+), 14 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-4vg6-rrvh-fpmr/GHSA-4vg6-rrvh-fpmr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-548x-pj87-qv7f/GHSA-548x-pj87-qv7f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-76q5-rvjr-8vhj/GHSA-76q5-rvjr-8vhj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7x8g-jfhh-pqhm/GHSA-7x8g-jfhh-pqhm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h6hc-84g9-qq4q/GHSA-h6hc-84g9-qq4q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qmjp-x43g-wwmh/GHSA-qmjp-x43g-wwmh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vx2f-5c28-4wg3/GHSA-vx2f-5c28-4wg3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wgpq-p2hm-56v9/GHSA-wgpq-p2hm-56v9.json diff --git a/advisories/unreviewed/2023/04/GHSA-g7cg-jg33-rrhv/GHSA-g7cg-jg33-rrhv.json b/advisories/unreviewed/2023/04/GHSA-g7cg-jg33-rrhv/GHSA-g7cg-jg33-rrhv.json index d1aece98ab2..c6d59d09c57 100644 --- a/advisories/unreviewed/2023/04/GHSA-g7cg-jg33-rrhv/GHSA-g7cg-jg33-rrhv.json +++ b/advisories/unreviewed/2023/04/GHSA-g7cg-jg33-rrhv/GHSA-g7cg-jg33-rrhv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7cg-jg33-rrhv", - "modified": "2023-04-26T21:30:37Z", + "modified": "2024-02-01T15:30:24Z", "published": "2023-04-26T21:30:37Z", "aliases": [ "CVE-2023-27559" @@ -28,13 +28,21 @@ { "type": "WEB", "url": "https://https://www.ibm.com/support/pages/node/6985667" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230511-0010/" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6985667" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-26T20:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json index 487dda08cfe..47b9eeb50d9 100644 --- a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json +++ b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rc2-qffv-3c8p", - "modified": "2023-06-30T03:30:17Z", + "modified": "2024-02-01T15:30:24Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-30631" @@ -46,7 +46,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-14T08:15:09Z" diff --git a/advisories/unreviewed/2023/07/GHSA-xf5h-8pqw-mggq/GHSA-xf5h-8pqw-mggq.json b/advisories/unreviewed/2023/07/GHSA-xf5h-8pqw-mggq/GHSA-xf5h-8pqw-mggq.json index 25fee44c18d..a69a1c13c28 100644 --- a/advisories/unreviewed/2023/07/GHSA-xf5h-8pqw-mggq/GHSA-xf5h-8pqw-mggq.json +++ b/advisories/unreviewed/2023/07/GHSA-xf5h-8pqw-mggq/GHSA-xf5h-8pqw-mggq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xf5h-8pqw-mggq", - "modified": "2023-07-06T21:14:55Z", + "modified": "2024-02-01T15:30:24Z", "published": "2023-07-06T21:14:55Z", "aliases": [ "CVE-2023-25832" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-09T21:15:11Z" diff --git a/advisories/unreviewed/2023/10/GHSA-962v-m5vf-4cv6/GHSA-962v-m5vf-4cv6.json b/advisories/unreviewed/2023/10/GHSA-962v-m5vf-4cv6/GHSA-962v-m5vf-4cv6.json index da2f0857872..29db411563a 100644 --- a/advisories/unreviewed/2023/10/GHSA-962v-m5vf-4cv6/GHSA-962v-m5vf-4cv6.json +++ b/advisories/unreviewed/2023/10/GHSA-962v-m5vf-4cv6/GHSA-962v-m5vf-4cv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-962v-m5vf-4cv6", - "modified": "2023-10-25T18:32:22Z", + "modified": "2024-02-01T15:30:24Z", "published": "2023-10-25T18:32:22Z", "aliases": [ "CVE-2023-39219" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-25T18:17:28Z" diff --git a/advisories/unreviewed/2023/10/GHSA-w5h3-rmvr-mgm6/GHSA-w5h3-rmvr-mgm6.json b/advisories/unreviewed/2023/10/GHSA-w5h3-rmvr-mgm6/GHSA-w5h3-rmvr-mgm6.json index 74f102243bd..ca6d51d6d3b 100644 --- a/advisories/unreviewed/2023/10/GHSA-w5h3-rmvr-mgm6/GHSA-w5h3-rmvr-mgm6.json +++ b/advisories/unreviewed/2023/10/GHSA-w5h3-rmvr-mgm6/GHSA-w5h3-rmvr-mgm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5h3-rmvr-mgm6", - "modified": "2023-10-25T18:32:21Z", + "modified": "2024-02-01T15:30:24Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-37283" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-25T18:17:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-vqxw-rw4p-r6vh/GHSA-vqxw-rw4p-r6vh.json b/advisories/unreviewed/2024/01/GHSA-vqxw-rw4p-r6vh/GHSA-vqxw-rw4p-r6vh.json index f8efe772ecf..e3e61e8bb52 100644 --- a/advisories/unreviewed/2024/01/GHSA-vqxw-rw4p-r6vh/GHSA-vqxw-rw4p-r6vh.json +++ b/advisories/unreviewed/2024/01/GHSA-vqxw-rw4p-r6vh/GHSA-vqxw-rw4p-r6vh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqxw-rw4p-r6vh", - "modified": "2024-01-25T15:31:53Z", + "modified": "2024-02-01T15:30:24Z", "published": "2024-01-25T15:31:53Z", "aliases": [ "CVE-2024-22729" ], "details": "NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T15:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4vg6-rrvh-fpmr/GHSA-4vg6-rrvh-fpmr.json b/advisories/unreviewed/2024/02/GHSA-4vg6-rrvh-fpmr/GHSA-4vg6-rrvh-fpmr.json new file mode 100644 index 00000000000..fa465d8c5b1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4vg6-rrvh-fpmr/GHSA-4vg6-rrvh-fpmr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vg6-rrvh-fpmr", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-24059" + ], + "details": "springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24059" + }, + { + "type": "WEB", + "url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#2-file-upload-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-548x-pj87-qv7f/GHSA-548x-pj87-qv7f.json b/advisories/unreviewed/2024/02/GHSA-548x-pj87-qv7f/GHSA-548x-pj87-qv7f.json new file mode 100644 index 00000000000..2f975024bd2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-548x-pj87-qv7f/GHSA-548x-pj87-qv7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-548x-pj87-qv7f", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-0935" + ], + "details": "An insertion of Sensitive Information into Log File vulnerability is affecting DELMIA Apriso Release 2019 through Release 2024", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0935" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-76q5-rvjr-8vhj/GHSA-76q5-rvjr-8vhj.json b/advisories/unreviewed/2024/02/GHSA-76q5-rvjr-8vhj/GHSA-76q5-rvjr-8vhj.json new file mode 100644 index 00000000000..bc56e26bcc6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-76q5-rvjr-8vhj/GHSA-76q5-rvjr-8vhj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76q5-rvjr-8vhj", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-24062" + ], + "details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24062" + }, + { + "type": "WEB", + "url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#12-stored-cross-site-scripting-sysrole" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7x8g-jfhh-pqhm/GHSA-7x8g-jfhh-pqhm.json b/advisories/unreviewed/2024/02/GHSA-7x8g-jfhh-pqhm/GHSA-7x8g-jfhh-pqhm.json new file mode 100644 index 00000000000..1e476c8d3b8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7x8g-jfhh-pqhm/GHSA-7x8g-jfhh-pqhm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x8g-jfhh-pqhm", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-0704" + ], + "details": "Rejected reason: very low impact - impractical to correct", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0704" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h6hc-84g9-qq4q/GHSA-h6hc-84g9-qq4q.json b/advisories/unreviewed/2024/02/GHSA-h6hc-84g9-qq4q/GHSA-h6hc-84g9-qq4q.json new file mode 100644 index 00000000000..2201288f34d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h6hc-84g9-qq4q/GHSA-h6hc-84g9-qq4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6hc-84g9-qq4q", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2023-6078" + ], + "details": "An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6078" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qmjp-x43g-wwmh/GHSA-qmjp-x43g-wwmh.json b/advisories/unreviewed/2024/02/GHSA-qmjp-x43g-wwmh/GHSA-qmjp-x43g-wwmh.json new file mode 100644 index 00000000000..1f1fa1fda7f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qmjp-x43g-wwmh/GHSA-qmjp-x43g-wwmh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmjp-x43g-wwmh", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-24060" + ], + "details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24060" + }, + { + "type": "WEB", + "url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#11-stored-cross-site-scripting-sysuser" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vx2f-5c28-4wg3/GHSA-vx2f-5c28-4wg3.json b/advisories/unreviewed/2024/02/GHSA-vx2f-5c28-4wg3/GHSA-vx2f-5c28-4wg3.json new file mode 100644 index 00000000000..d3da0bb2f22 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vx2f-5c28-4wg3/GHSA-vx2f-5c28-4wg3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx2f-5c28-4wg3", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-24061" + ], + "details": "springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24061" + }, + { + "type": "WEB", + "url": "https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/springboot-manager.md#13-stored-cross-site-scripting-syscontentadd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wgpq-p2hm-56v9/GHSA-wgpq-p2hm-56v9.json b/advisories/unreviewed/2024/02/GHSA-wgpq-p2hm-56v9/GHSA-wgpq-p2hm-56v9.json new file mode 100644 index 00000000000..a24d48dc927 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wgpq-p2hm-56v9/GHSA-wgpq-p2hm-56v9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgpq-p2hm-56v9", + "modified": "2024-02-01T15:30:24Z", + "published": "2024-02-01T15:30:24Z", + "aliases": [ + "CVE-2024-1141" + ], + "details": "A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1141" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-1141" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-779" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T15:15:08Z" + } +} \ No newline at end of file