diff --git a/advisories/unreviewed/2024/01/GHSA-39rp-fmqv-8wr2/GHSA-39rp-fmqv-8wr2.json b/advisories/unreviewed/2024/01/GHSA-39rp-fmqv-8wr2/GHSA-39rp-fmqv-8wr2.json new file mode 100644 index 00000000000..6652b824177 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-39rp-fmqv-8wr2/GHSA-39rp-fmqv-8wr2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39rp-fmqv-8wr2", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2024-1012" + ], + "details": "A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1012" + }, + { + "type": "WEB", + "url": "https://github.com/4nNns/cveAdd/blob/b73e94ff089ae2201d9836b4d61b8175ff21618a/sqli/%E4%B8%87%E6%88%B7EZOFFICE%20%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252281" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252281" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T08:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8g5q-mp2w-j766/GHSA-8g5q-mp2w-j766.json b/advisories/unreviewed/2024/01/GHSA-8g5q-mp2w-j766/GHSA-8g5q-mp2w-j766.json index 73c2b190be5..48371604dbb 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g5q-mp2w-j766/GHSA-8g5q-mp2w-j766.json +++ b/advisories/unreviewed/2024/01/GHSA-8g5q-mp2w-j766/GHSA-8g5q-mp2w-j766.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://jvn.jp/vu/JVNVU95103362" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-02" + }, { "type": "WEB", "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-020_en.pdf" diff --git a/advisories/unreviewed/2024/01/GHSA-9xc9-xq7w-vpcr/GHSA-9xc9-xq7w-vpcr.json b/advisories/unreviewed/2024/01/GHSA-9xc9-xq7w-vpcr/GHSA-9xc9-xq7w-vpcr.json new file mode 100644 index 00000000000..d60efd19d45 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9xc9-xq7w-vpcr/GHSA-9xc9-xq7w-vpcr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xc9-xq7w-vpcr", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2023-44313" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include).\n\nUsers are recommended to upgrade to version 2.2.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44313" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5r" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T09:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fgff-579x-65fj/GHSA-fgff-579x-65fj.json b/advisories/unreviewed/2024/01/GHSA-fgff-579x-65fj/GHSA-fgff-579x-65fj.json new file mode 100644 index 00000000000..df24d9dec17 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fgff-579x-65fj/GHSA-fgff-579x-65fj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgff-579x-65fj", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2024-23775" + ], + "details": "Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23775" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T08:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fjv8-rf2g-h37h/GHSA-fjv8-rf2g-h37h.json b/advisories/unreviewed/2024/01/GHSA-fjv8-rf2g-h37h/GHSA-fjv8-rf2g-h37h.json new file mode 100644 index 00000000000..56d3918f3c4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fjv8-rf2g-h37h/GHSA-fjv8-rf2g-h37h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjv8-rf2g-h37h", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2024-0836" + ], + "details": "The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary reviews.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0836" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3028627/review-schema/trunk/app/Controllers/Ajax/Review.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b7039206-a25a-4aa0-87e2-be11dd1f12eb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T08:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p6rp-mx85-m459/GHSA-p6rp-mx85-m459.json b/advisories/unreviewed/2024/01/GHSA-p6rp-mx85-m459/GHSA-p6rp-mx85-m459.json new file mode 100644 index 00000000000..2043e891591 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p6rp-mx85-m459/GHSA-p6rp-mx85-m459.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rp-mx85-m459", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2024-22236" + ], + "details": "In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22236" + }, + { + "type": "WEB", + "url": "https://spring.io/security/cve-2024-22236" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r8xp-52mq-rmm8/GHSA-r8xp-52mq-rmm8.json b/advisories/unreviewed/2024/01/GHSA-r8xp-52mq-rmm8/GHSA-r8xp-52mq-rmm8.json new file mode 100644 index 00000000000..06d8ffd879d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r8xp-52mq-rmm8/GHSA-r8xp-52mq-rmm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8xp-52mq-rmm8", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2023-44312" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects \n\nApache ServiceComb Service-Center\n\n before 2.1.0 (include).\n\nUsers are recommended to upgrade to version 2.2.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44312" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/dkvlgnrmc17qzjdy9k0cr60wpzcssk1s" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T09:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v334-55hv-wvc6/GHSA-v334-55hv-wvc6.json b/advisories/unreviewed/2024/01/GHSA-v334-55hv-wvc6/GHSA-v334-55hv-wvc6.json index 15694a0fdd1..523f83add08 100644 --- a/advisories/unreviewed/2024/01/GHSA-v334-55hv-wvc6/GHSA-v334-55hv-wvc6.json +++ b/advisories/unreviewed/2024/01/GHSA-v334-55hv-wvc6/GHSA-v334-55hv-wvc6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://jvn.jp/vu/JVNVU99497477" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-03" + }, { "type": "WEB", "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-019_en.pdf" diff --git a/advisories/unreviewed/2024/01/GHSA-w2fw-qqqw-v63m/GHSA-w2fw-qqqw-v63m.json b/advisories/unreviewed/2024/01/GHSA-w2fw-qqqw-v63m/GHSA-w2fw-qqqw-v63m.json new file mode 100644 index 00000000000..e9be4ea4ffc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w2fw-qqqw-v63m/GHSA-w2fw-qqqw-v63m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2fw-qqqw-v63m", + "modified": "2024-01-31T09:30:18Z", + "published": "2024-01-31T09:30:18Z", + "aliases": [ + "CVE-2024-23170" + ], + "details": "An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in \"Everlasting ROBOT: the Marvin Attack\" by Hubert Kario.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23170" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T08:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w7vr-jmcf-cx4m/GHSA-w7vr-jmcf-cx4m.json b/advisories/unreviewed/2024/01/GHSA-w7vr-jmcf-cx4m/GHSA-w7vr-jmcf-cx4m.json index 0ff08e52123..46460411f73 100644 --- a/advisories/unreviewed/2024/01/GHSA-w7vr-jmcf-cx4m/GHSA-w7vr-jmcf-cx4m.json +++ b/advisories/unreviewed/2024/01/GHSA-w7vr-jmcf-cx4m/GHSA-w7vr-jmcf-cx4m.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://jvn.jp/vu/JVNVU95103362" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-02" + }, { "type": "WEB", "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-020_en.pdf"