From 1ca93f91a5917ded731dedaba7e813f632f65938 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 29 Jan 2024 21:31:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3f63-hfp8-52jq.json | 4 ++ .../GHSA-fcqj-x222-4c7r.json | 19 +++++-- .../GHSA-qr34-fv3w-3x4j.json | 8 ++- .../GHSA-phrf-fj83-fcfv.json | 4 ++ .../GHSA-2x33-pfvq-675c.json | 35 +++++++++++++ .../GHSA-39g9-xc8h-ffgp.json | 35 +++++++++++++ .../GHSA-3crw-hq66-3456.json | 11 ++-- .../GHSA-555g-cg2q-wmc3.json | 43 ++++++++++++++++ .../GHSA-6m95-c675-56r5.json | 46 +++++++++++++++++ .../GHSA-6xwv-xr2m-rj2h.json | 9 ++-- .../GHSA-7258-xmq8-x5x7.json | 9 ++-- .../GHSA-7m9h-xc4x-cg98.json | 38 ++++++++++++++ .../GHSA-7xm8-wjq7-88r5.json | 43 ++++++++++++++++ .../GHSA-89ph-wr9x-hcfc.json | 4 ++ .../GHSA-8c2v-657f-h9r7.json | 35 +++++++++++++ .../GHSA-8mxm-prp8-gc3w.json | 35 +++++++++++++ .../GHSA-8p2h-w6cv-wr2w.json | 38 ++++++++++++++ .../GHSA-969g-frgv-hccv.json | 4 ++ .../GHSA-9933-5g23-6jq2.json | 11 ++-- .../GHSA-9fpx-vc83-vhpf.json | 43 ++++++++++++++++ .../GHSA-c7jw-pgmq-gj8x.json | 38 ++++++++++++++ .../GHSA-cmqr-cw5f-xffm.json | 11 ++-- .../GHSA-crgw-m82j-jv5c.json | 38 ++++++++++++++ .../GHSA-f3p3-3pq5-xp8x.json | 35 +++++++++++++ .../GHSA-f9w7-q39f-hcvh.json | 50 +++++++++++++++++++ .../GHSA-gccg-f527-63v3.json | 35 +++++++++++++ .../GHSA-gqqw-gq22-ww82.json | 9 ++-- .../GHSA-h994-99h2-49qc.json | 38 ++++++++++++++ .../GHSA-hcpx-fjcv-rp6j.json | 9 ++-- .../GHSA-hf79-3hfm-mgmr.json | 11 ++-- .../GHSA-pwgf-w5vm-vm95.json | 38 ++++++++++++++ .../GHSA-q6vx-6v63-ffqp.json | 35 +++++++++++++ .../GHSA-rc4g-22pj-c822.json | 35 +++++++++++++ .../GHSA-rcv3-6pgv-6p72.json | 9 ++-- .../GHSA-vr6g-w83m-c9vg.json | 11 ++-- .../GHSA-wgfc-hm58-hx63.json | 38 ++++++++++++++ .../GHSA-wpxw-5xfm-x22v.json | 43 ++++++++++++++++ .../GHSA-x22g-h3w3-4m5v.json | 11 ++-- .../GHSA-x8jc-9x8v-27f5.json | 9 ++-- 39 files changed, 929 insertions(+), 48 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-2x33-pfvq-675c/GHSA-2x33-pfvq-675c.json create mode 100644 advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-555g-cg2q-wmc3/GHSA-555g-cg2q-wmc3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6m95-c675-56r5/GHSA-6m95-c675-56r5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7m9h-xc4x-cg98/GHSA-7m9h-xc4x-cg98.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8mxm-prp8-gc3w/GHSA-8mxm-prp8-gc3w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8p2h-w6cv-wr2w/GHSA-8p2h-w6cv-wr2w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9fpx-vc83-vhpf/GHSA-9fpx-vc83-vhpf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-c7jw-pgmq-gj8x/GHSA-c7jw-pgmq-gj8x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f9w7-q39f-hcvh/GHSA-f9w7-q39f-hcvh.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-h994-99h2-49qc/GHSA-h994-99h2-49qc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pwgf-w5vm-vm95/GHSA-pwgf-w5vm-vm95.json create mode 100644 advisories/unreviewed/2024/01/GHSA-q6vx-6v63-ffqp/GHSA-q6vx-6v63-ffqp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rc4g-22pj-c822/GHSA-rc4g-22pj-c822.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wgfc-hm58-hx63/GHSA-wgfc-hm58-hx63.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wpxw-5xfm-x22v/GHSA-wpxw-5xfm-x22v.json diff --git a/advisories/github-reviewed/2024/01/GHSA-3f63-hfp8-52jq/GHSA-3f63-hfp8-52jq.json b/advisories/github-reviewed/2024/01/GHSA-3f63-hfp8-52jq/GHSA-3f63-hfp8-52jq.json index 161d348457f..465b07e1971 100644 --- a/advisories/github-reviewed/2024/01/GHSA-3f63-hfp8-52jq/GHSA-3f63-hfp8-52jq.json +++ b/advisories/github-reviewed/2024/01/GHSA-3f63-hfp8-52jq/GHSA-3f63-hfp8-52jq.json @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/releases" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html" + }, { "type": "WEB", "url": "https://pillow.readthedocs.io/en/stable/releasenotes/10.2.0.html#security" diff --git a/advisories/unreviewed/2023/05/GHSA-fcqj-x222-4c7r/GHSA-fcqj-x222-4c7r.json b/advisories/unreviewed/2023/05/GHSA-fcqj-x222-4c7r/GHSA-fcqj-x222-4c7r.json index 60685794b63..ba03cff6e74 100644 --- a/advisories/unreviewed/2023/05/GHSA-fcqj-x222-4c7r/GHSA-fcqj-x222-4c7r.json +++ b/advisories/unreviewed/2023/05/GHSA-fcqj-x222-4c7r/GHSA-fcqj-x222-4c7r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fcqj-x222-4c7r", - "modified": "2023-05-11T12:30:14Z", + "modified": "2024-01-29T21:30:25Z", "published": "2023-05-11T12:30:14Z", "aliases": [ "CVE-2023-31445" ], "details": "Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31445" }, + { + "type": "WEB", + "url": "https://blog.kscsc.online/cves/202331445/md.html" + }, { "type": "WEB", "url": "https://github.com/Dodge-MPTC/CVE-2023-31445-Unprivileged-Information-Disclosure" @@ -25,13 +32,17 @@ { "type": "WEB", "url": "https://www.cassianetworks.com" + }, + { + "type": "WEB", + "url": "https://www.swiruhack.online/cves/202331445/md.html" } ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-11T12:15:09Z" diff --git a/advisories/unreviewed/2023/09/GHSA-qr34-fv3w-3x4j/GHSA-qr34-fv3w-3x4j.json b/advisories/unreviewed/2023/09/GHSA-qr34-fv3w-3x4j/GHSA-qr34-fv3w-3x4j.json index fff4c7c6a87..5ab16413af0 100644 --- a/advisories/unreviewed/2023/09/GHSA-qr34-fv3w-3x4j/GHSA-qr34-fv3w-3x4j.json +++ b/advisories/unreviewed/2023/09/GHSA-qr34-fv3w-3x4j/GHSA-qr34-fv3w-3x4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr34-fv3w-3x4j", - "modified": "2023-09-29T00:30:15Z", + "modified": "2024-01-29T21:30:25Z", "published": "2023-09-27T15:30:34Z", "aliases": [ "CVE-2023-35793" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35793" }, + { + "type": "WEB", + "url": "https://blog.kscsc.online/cves/202335793/md.html" + }, { "type": "WEB", "url": "https://github.com/Dodge-MPTC/CVE-2023-35793-CSRF-On-Web-SSH" @@ -34,7 +38,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-27T15:18:52Z" diff --git a/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json b/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json index 8f4d4953567..ca581dd815b 100644 --- a/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json +++ b/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35794" }, + { + "type": "WEB", + "url": "https://blog.kscsc.online/cves/202335794/md.html" + }, { "type": "WEB", "url": "https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking" diff --git a/advisories/unreviewed/2024/01/GHSA-2x33-pfvq-675c/GHSA-2x33-pfvq-675c.json b/advisories/unreviewed/2024/01/GHSA-2x33-pfvq-675c/GHSA-2x33-pfvq-675c.json new file mode 100644 index 00000000000..308b31e2c55 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2x33-pfvq-675c/GHSA-2x33-pfvq-675c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x33-pfvq-675c", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24136" + ], + "details": "The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24136" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/2024_Math_Game_XSS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json b/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json new file mode 100644 index 00000000000..75b408bd80b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39g9-xc8h-ffgp", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24134" + ], + "details": "Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24134" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/2024_Online_Food_Menu_XSS/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3crw-hq66-3456/GHSA-3crw-hq66-3456.json b/advisories/unreviewed/2024/01/GHSA-3crw-hq66-3456/GHSA-3crw-hq66-3456.json index af7b19708bb..ef52e5fcf29 100644 --- a/advisories/unreviewed/2024/01/GHSA-3crw-hq66-3456/GHSA-3crw-hq66-3456.json +++ b/advisories/unreviewed/2024/01/GHSA-3crw-hq66-3456/GHSA-3crw-hq66-3456.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3crw-hq66-3456", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-51210" ], "details": "SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-555g-cg2q-wmc3/GHSA-555g-cg2q-wmc3.json b/advisories/unreviewed/2024/01/GHSA-555g-cg2q-wmc3/GHSA-555g-cg2q-wmc3.json new file mode 100644 index 00000000000..1e21df73706 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-555g-cg2q-wmc3/GHSA-555g-cg2q-wmc3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-555g-cg2q-wmc3", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-51840" + ], + "details": "DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51840" + }, + { + "type": "WEB", + "url": "https://github.com/doramart/DoraCMS/issues/262" + }, + { + "type": "WEB", + "url": "https://github.com/doramart/DoraCMS" + }, + { + "type": "WEB", + "url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-51840.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6m95-c675-56r5/GHSA-6m95-c675-56r5.json b/advisories/unreviewed/2024/01/GHSA-6m95-c675-56r5/GHSA-6m95-c675-56r5.json new file mode 100644 index 00000000000..a65add11526 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6m95-c675-56r5/GHSA-6m95-c675-56r5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m95-c675-56r5", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-1018" + ], + "details": "A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252288.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1018" + }, + { + "type": "WEB", + "url": "https://github.com/1MurasaKi/PboostCMS_XSS/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252288" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252288" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6xwv-xr2m-rj2h/GHSA-6xwv-xr2m-rj2h.json b/advisories/unreviewed/2024/01/GHSA-6xwv-xr2m-rj2h/GHSA-6xwv-xr2m-rj2h.json index 373b6bc0ec9..ec46b433252 100644 --- a/advisories/unreviewed/2024/01/GHSA-6xwv-xr2m-rj2h/GHSA-6xwv-xr2m-rj2h.json +++ b/advisories/unreviewed/2024/01/GHSA-6xwv-xr2m-rj2h/GHSA-6xwv-xr2m-rj2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xwv-xr2m-rj2h", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-47201" ], "details": "A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47200.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json b/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json index faad40537e8..97d5f947fb9 100644 --- a/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json +++ b/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7258-xmq8-x5x7", - "modified": "2024-01-23T03:31:07Z", + "modified": "2024-01-29T21:30:26Z", "published": "2024-01-23T03:31:07Z", "aliases": [ "CVE-2023-42915" ], "details": "Multiple issues were addressed by updating to curl version 8.4.0. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 16.7.5 and iPadOS 16.7.5. Multiple issues in curl.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7m9h-xc4x-cg98/GHSA-7m9h-xc4x-cg98.json b/advisories/unreviewed/2024/01/GHSA-7m9h-xc4x-cg98/GHSA-7m9h-xc4x-cg98.json new file mode 100644 index 00000000000..d2d8baf004d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7m9h-xc4x-cg98/GHSA-7m9h-xc4x-cg98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m9h-xc4x-cg98", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-4551" + ], + "details": "Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection.\n\nThe AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the executing process.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4551" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json b/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json new file mode 100644 index 00000000000..365b50722c6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xm8-wjq7-88r5", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-51839" + ], + "details": "DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51839" + }, + { + "type": "WEB", + "url": "https://github.com/DeviceFarmer/stf/issues/736" + }, + { + "type": "WEB", + "url": "https://github.com/DeviceFarmer/stf" + }, + { + "type": "WEB", + "url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-51839.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-89ph-wr9x-hcfc/GHSA-89ph-wr9x-hcfc.json b/advisories/unreviewed/2024/01/GHSA-89ph-wr9x-hcfc/GHSA-89ph-wr9x-hcfc.json index c674ac2e1fa..f2559fba0e5 100644 --- a/advisories/unreviewed/2024/01/GHSA-89ph-wr9x-hcfc/GHSA-89ph-wr9x-hcfc.json +++ b/advisories/unreviewed/2024/01/GHSA-89ph-wr9x-hcfc/GHSA-89ph-wr9x-hcfc.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31446" }, + { + "type": "WEB", + "url": "https://blog.kscsc.online/cves/202331446/md.html" + }, { "type": "WEB", "url": "https://github.com/Dodge-MPTC/CVE-2023-31446-Remote-Code-Execution" diff --git a/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json b/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json new file mode 100644 index 00000000000..9b401a18b2f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8c2v-657f-h9r7/GHSA-8c2v-657f-h9r7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c2v-657f-h9r7", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24139" + ], + "details": "Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24139" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/Login_System_with_Email_Verification_SQL_Injection/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8mxm-prp8-gc3w/GHSA-8mxm-prp8-gc3w.json b/advisories/unreviewed/2024/01/GHSA-8mxm-prp8-gc3w/GHSA-8mxm-prp8-gc3w.json new file mode 100644 index 00000000000..8f6d5bba6a3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8mxm-prp8-gc3w/GHSA-8mxm-prp8-gc3w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mxm-prp8-gc3w", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24141" + ], + "details": "Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24141" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/School-Task-Manager-System-SQLi-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8p2h-w6cv-wr2w/GHSA-8p2h-w6cv-wr2w.json b/advisories/unreviewed/2024/01/GHSA-8p2h-w6cv-wr2w/GHSA-8p2h-w6cv-wr2w.json new file mode 100644 index 00000000000..5078979d6c8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8p2h-w6cv-wr2w/GHSA-8p2h-w6cv-wr2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p2h-w6cv-wr2w", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-4553" + ], + "details": "Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files.\n\n\nAppBuilder configuration files are viewable by unauthenticated users.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4553" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-969g-frgv-hccv/GHSA-969g-frgv-hccv.json b/advisories/unreviewed/2024/01/GHSA-969g-frgv-hccv/GHSA-969g-frgv-hccv.json index 555a0cf4b91..a2549f220db 100644 --- a/advisories/unreviewed/2024/01/GHSA-969g-frgv-hccv/GHSA-969g-frgv-hccv.json +++ b/advisories/unreviewed/2024/01/GHSA-969g-frgv-hccv/GHSA-969g-frgv-hccv.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://advisory.abay.sh/cve-2023-6524" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3015598%40mappress-google-maps-for-wordpress%2Ftrunk&old=3001436%40mappress-google-maps-for-wordpress%2Ftrunk&sfp_email=&sfph_mail=" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3001436%40mappress-google-maps-for-wordpress%2Ftags%2F2.88.13&new=3015598%40mappress-google-maps-for-wordpress%2Ftags%2F2.88.14#file31" diff --git a/advisories/unreviewed/2024/01/GHSA-9933-5g23-6jq2/GHSA-9933-5g23-6jq2.json b/advisories/unreviewed/2024/01/GHSA-9933-5g23-6jq2/GHSA-9933-5g23-6jq2.json index 77655a56760..995363e34c5 100644 --- a/advisories/unreviewed/2024/01/GHSA-9933-5g23-6jq2/GHSA-9933-5g23-6jq2.json +++ b/advisories/unreviewed/2024/01/GHSA-9933-5g23-6jq2/GHSA-9933-5g23-6jq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9933-5g23-6jq2", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52092" ], "details": "A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9fpx-vc83-vhpf/GHSA-9fpx-vc83-vhpf.json b/advisories/unreviewed/2024/01/GHSA-9fpx-vc83-vhpf/GHSA-9fpx-vc83-vhpf.json new file mode 100644 index 00000000000..42dbc1ddce1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9fpx-vc83-vhpf/GHSA-9fpx-vc83-vhpf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fpx-vc83-vhpf", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-23940" + ], + "details": "Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23940" + }, + { + "type": "WEB", + "url": "https://helpcenter.trendmicro.com/en-us/article/tmka-12134" + }, + { + "type": "WEB", + "url": "https://helpcenter.trendmicro.com/ja-jp/article/tmka-12132" + }, + { + "type": "WEB", + "url": "https://medium.com/@s1kr10s/av-when-a-friend-becomes-an-enemy-55f41aba42b1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c7jw-pgmq-gj8x/GHSA-c7jw-pgmq-gj8x.json b/advisories/unreviewed/2024/01/GHSA-c7jw-pgmq-gj8x/GHSA-c7jw-pgmq-gj8x.json new file mode 100644 index 00000000000..aa04d28f82e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c7jw-pgmq-gj8x/GHSA-c7jw-pgmq-gj8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7jw-pgmq-gj8x", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-22836" + ], + "details": "In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22836" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=f9bf67ef-be15-4f87-a526-bf6064e8f682" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cmqr-cw5f-xffm/GHSA-cmqr-cw5f-xffm.json b/advisories/unreviewed/2024/01/GHSA-cmqr-cw5f-xffm/GHSA-cmqr-cw5f-xffm.json index 0a03a4cdf6b..4805f28af68 100644 --- a/advisories/unreviewed/2024/01/GHSA-cmqr-cw5f-xffm/GHSA-cmqr-cw5f-xffm.json +++ b/advisories/unreviewed/2024/01/GHSA-cmqr-cw5f-xffm/GHSA-cmqr-cw5f-xffm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmqr-cw5f-xffm", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52091" ], "details": "An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json b/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json new file mode 100644 index 00000000000..8b816cb6283 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crgw-m82j-jv5c", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-4550" + ], + "details": "Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files.\n\nAn unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. \n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4550" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json new file mode 100644 index 00000000000..02ca1f17920 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3p3-3pq5-xp8x", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24135" + ], + "details": "Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24135" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/2024_Product_Inventory_with_Export_to_Excel_XSS/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f9w7-q39f-hcvh/GHSA-f9w7-q39f-hcvh.json b/advisories/unreviewed/2024/01/GHSA-f9w7-q39f-hcvh/GHSA-f9w7-q39f-hcvh.json new file mode 100644 index 00000000000..4618311c7fb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f9w7-q39f-hcvh/GHSA-f9w7-q39f-hcvh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9w7-q39f-hcvh", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-1017" + ], + "details": "A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument USERNAME leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-252287.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1017" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176714/Gabriels-FTP-Server-1.2-Denial-Of-Service.html" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252287" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252287" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=wwHuXfYS8yQ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json b/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json new file mode 100644 index 00000000000..30829431aa9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gccg-f527-63v3", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-49038" + ], + "details": "Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49038" + }, + { + "type": "WEB", + "url": "https://github.com/christopher-pace/CVE-2023-49038" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json b/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json index a1ea006f760..e6c6629f642 100644 --- a/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json +++ b/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqqw-gq22-ww82", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2023-42937" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-h994-99h2-49qc/GHSA-h994-99h2-49qc.json b/advisories/unreviewed/2024/01/GHSA-h994-99h2-49qc/GHSA-h994-99h2-49qc.json new file mode 100644 index 00000000000..72eb54e88d2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h994-99h2-49qc/GHSA-h994-99h2-49qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h994-99h2-49qc", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-30970" + ], + "details": "Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30970" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=69be99ef-ad24-4339-9017-c8bf70789c72" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hcpx-fjcv-rp6j/GHSA-hcpx-fjcv-rp6j.json b/advisories/unreviewed/2024/01/GHSA-hcpx-fjcv-rp6j/GHSA-hcpx-fjcv-rp6j.json index 5516d239157..70353e104d8 100644 --- a/advisories/unreviewed/2024/01/GHSA-hcpx-fjcv-rp6j/GHSA-hcpx-fjcv-rp6j.json +++ b/advisories/unreviewed/2024/01/GHSA-hcpx-fjcv-rp6j/GHSA-hcpx-fjcv-rp6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hcpx-fjcv-rp6j", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52093" ], "details": "An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-hf79-3hfm-mgmr/GHSA-hf79-3hfm-mgmr.json b/advisories/unreviewed/2024/01/GHSA-hf79-3hfm-mgmr/GHSA-hf79-3hfm-mgmr.json index d0563b98c8a..fde8dbc5a56 100644 --- a/advisories/unreviewed/2024/01/GHSA-hf79-3hfm-mgmr/GHSA-hf79-3hfm-mgmr.json +++ b/advisories/unreviewed/2024/01/GHSA-hf79-3hfm-mgmr/GHSA-hf79-3hfm-mgmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf79-3hfm-mgmr", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-46892" ], "details": "The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-294" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pwgf-w5vm-vm95/GHSA-pwgf-w5vm-vm95.json b/advisories/unreviewed/2024/01/GHSA-pwgf-w5vm-vm95/GHSA-pwgf-w5vm-vm95.json new file mode 100644 index 00000000000..8e0e4f5cf75 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pwgf-w5vm-vm95/GHSA-pwgf-w5vm-vm95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwgf-w5vm-vm95", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-4552" + ], + "details": "Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files.\n\nAn authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4552" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q6vx-6v63-ffqp/GHSA-q6vx-6v63-ffqp.json b/advisories/unreviewed/2024/01/GHSA-q6vx-6v63-ffqp/GHSA-q6vx-6v63-ffqp.json new file mode 100644 index 00000000000..4ad94e8a8d5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q6vx-6v63-ffqp/GHSA-q6vx-6v63-ffqp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6vx-6v63-ffqp", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-24140" + ], + "details": "Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24140" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/Daily_Habit_Tracker_App_SQL_Injection" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rc4g-22pj-c822/GHSA-rc4g-22pj-c822.json b/advisories/unreviewed/2024/01/GHSA-rc4g-22pj-c822/GHSA-rc4g-22pj-c822.json new file mode 100644 index 00000000000..377e3d22956 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rc4g-22pj-c822/GHSA-rc4g-22pj-c822.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc4g-22pj-c822", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2024-22570" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22570" + }, + { + "type": "WEB", + "url": "https://github.com/Num-Nine/CVE/issues/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rcv3-6pgv-6p72/GHSA-rcv3-6pgv-6p72.json b/advisories/unreviewed/2024/01/GHSA-rcv3-6pgv-6p72/GHSA-rcv3-6pgv-6p72.json index a2d967caafa..af8e8b5ce65 100644 --- a/advisories/unreviewed/2024/01/GHSA-rcv3-6pgv-6p72/GHSA-rcv3-6pgv-6p72.json +++ b/advisories/unreviewed/2024/01/GHSA-rcv3-6pgv-6p72/GHSA-rcv3-6pgv-6p72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcv3-6pgv-6p72", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-47202" ], "details": "A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-vr6g-w83m-c9vg/GHSA-vr6g-w83m-c9vg.json b/advisories/unreviewed/2024/01/GHSA-vr6g-w83m-c9vg/GHSA-vr6g-w83m-c9vg.json index d32e3b14237..f517b142d4b 100644 --- a/advisories/unreviewed/2024/01/GHSA-vr6g-w83m-c9vg/GHSA-vr6g-w83m-c9vg.json +++ b/advisories/unreviewed/2024/01/GHSA-vr6g-w83m-c9vg/GHSA-vr6g-w83m-c9vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr6g-w83m-c9vg", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52090" ], "details": "A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-wgfc-hm58-hx63/GHSA-wgfc-hm58-hx63.json b/advisories/unreviewed/2024/01/GHSA-wgfc-hm58-hx63/GHSA-wgfc-hm58-hx63.json new file mode 100644 index 00000000000..00c52530334 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wgfc-hm58-hx63/GHSA-wgfc-hm58-hx63.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgfc-hm58-hx63", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-4554" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files.\n\nAppBuilder's XML processor is vulnerable to XML External Entity Processing (XXE), allowing an authenticated user to upload specially crafted XML files to induce server-side request forgery, disclose files local to the server that processes them.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4554" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wpxw-5xfm-x22v/GHSA-wpxw-5xfm-x22v.json b/advisories/unreviewed/2024/01/GHSA-wpxw-5xfm-x22v/GHSA-wpxw-5xfm-x22v.json new file mode 100644 index 00000000000..a680c0f1026 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wpxw-5xfm-x22v/GHSA-wpxw-5xfm-x22v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpxw-5xfm-x22v", + "modified": "2024-01-29T21:30:27Z", + "published": "2024-01-29T21:30:27Z", + "aliases": [ + "CVE-2023-51842" + ], + "details": "An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51842" + }, + { + "type": "WEB", + "url": "https://github.com/Ylianst/MeshCentral/tree/master" + }, + { + "type": "WEB", + "url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/Bug_MeshCentral.md" + }, + { + "type": "WEB", + "url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-51842.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x22g-h3w3-4m5v/GHSA-x22g-h3w3-4m5v.json b/advisories/unreviewed/2024/01/GHSA-x22g-h3w3-4m5v/GHSA-x22g-h3w3-4m5v.json index 0aa97f537d3..c5139686392 100644 --- a/advisories/unreviewed/2024/01/GHSA-x22g-h3w3-4m5v/GHSA-x22g-h3w3-4m5v.json +++ b/advisories/unreviewed/2024/01/GHSA-x22g-h3w3-4m5v/GHSA-x22g-h3w3-4m5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x22g-h3w3-4m5v", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-01-29T21:30:26Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2023-48118" ], "details": "SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json b/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json index ce10beb68d9..c42946aec17 100644 --- a/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json +++ b/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8jc-9x8v-27f5", - "modified": "2024-01-26T18:30:34Z", + "modified": "2024-01-29T21:30:27Z", "published": "2024-01-23T03:31:07Z", "aliases": [ "CVE-2023-42935" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:10Z"