From 1dd0c223d733149f379b30d55f61136b4abfc90e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 3 Apr 2023 21:33:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-c547-2659-q37g.json | 4 ++ .../GHSA-w774-7g7w-83fx.json | 11 +++- .../GHSA-mjcr-h6w7-xcx6.json | 4 ++ .../GHSA-cjp4-p28m-9gvx.json | 4 ++ .../GHSA-6hgw-f77h-gx4f.json | 4 ++ .../GHSA-pr8p-6jwr-v79h.json | 4 ++ .../GHSA-3vwp-294x-6v9c.json | 4 ++ .../GHSA-gwr4-pj6r-2576.json | 4 ++ .../GHSA-pppw-hpjp-v2p9.json | 4 ++ .../GHSA-v833-mfjc-7qr5.json | 4 ++ .../GHSA-5fc7-wjrw-2jh4.json | 4 ++ .../GHSA-8p6c-rh83-4gp7.json | 4 ++ .../GHSA-pp2p-5ghw-9ccc.json | 4 ++ .../GHSA-2v4g-w3qw-prh4.json | 9 ++- .../GHSA-472h-pprq-pg3p.json | 11 ++-- .../GHSA-6738-85h4-qhxj.json | 9 ++- .../GHSA-6f7j-jmxj-m9g3.json | 11 ++-- .../GHSA-f289-g9w2-9j5h.json | 11 ++-- .../GHSA-g874-7753-4g62.json | 9 ++- .../GHSA-gqqh-295f-w7wc.json | 11 ++-- .../GHSA-h55g-mm6m-gw37.json | 11 ++-- .../GHSA-hq4v-9j7v-jcvr.json | 12 ++-- .../GHSA-p365-9mq8-7r2q.json | 12 ++-- .../GHSA-q3c4-7524-h583.json | 9 ++- .../GHSA-r255-vm29-9xg5.json | 11 ++-- .../GHSA-r26p-gh73-qgq9.json | 11 ++-- .../GHSA-w85v-q239-vpx6.json | 12 ++-- .../GHSA-xf7f-g3ff-jjc9.json | 9 ++- .../GHSA-4rmp-wcvv-c8xm.json | 35 ++++++++++++ .../GHSA-84x2-qv2c-9cvx.json | 35 ++++++++++++ .../GHSA-88w6-3m63-r5j7.json | 35 ++++++++++++ .../GHSA-8r7j-pj39-v7xh.json | 35 ++++++++++++ .../GHSA-ch7j-864f-m7r5.json | 35 ++++++++++++ .../GHSA-h639-737x-65xp.json | 35 ++++++++++++ .../GHSA-m6x9-6mp2-f49x.json | 35 ++++++++++++ .../GHSA-q552-8jxx-pwh8.json | 35 ++++++++++++ .../GHSA-r7cq-76xj-2g24.json | 35 ++++++++++++ .../GHSA-rfh2-62gc-x7hw.json | 55 +++++++++++++++++++ .../GHSA-x57h-h95f-93cr.json | 35 ++++++++++++ 39 files changed, 565 insertions(+), 57 deletions(-) create mode 100644 advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json create mode 100644 advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json create mode 100644 advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json create mode 100644 advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json create mode 100644 advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json create mode 100644 advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json create mode 100644 advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json create mode 100644 advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json create mode 100644 advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json create mode 100644 advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json create mode 100644 advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json diff --git a/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json b/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json index 99a32193ddd..c0f41a5bdd0 100644 --- a/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json +++ b/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json @@ -81,6 +81,10 @@ "type": "WEB", "url": "http://httpd.apache.org/security/vulnerabilities_24.html" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/May/33" diff --git a/advisories/unreviewed/2022/05/GHSA-w774-7g7w-83fx/GHSA-w774-7g7w-83fx.json b/advisories/unreviewed/2022/05/GHSA-w774-7g7w-83fx/GHSA-w774-7g7w-83fx.json index e722bd101f6..e0c84e5d636 100644 --- a/advisories/unreviewed/2022/05/GHSA-w774-7g7w-83fx/GHSA-w774-7g7w-83fx.json +++ b/advisories/unreviewed/2022/05/GHSA-w774-7g7w-83fx/GHSA-w774-7g7w-83fx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w774-7g7w-83fx", - "modified": "2022-05-24T17:27:41Z", + "modified": "2023-04-03T21:32:47Z", "published": "2022-05-24T17:27:41Z", "aliases": [ "CVE-2020-25213" ], "details": "The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,6 +52,10 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/160003/WordPress-File-Manager-6.8-Remote-Code-Execution.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171650/WordPress-File-Manager-6.9-Shell-Upload.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-mjcr-h6w7-xcx6/GHSA-mjcr-h6w7-xcx6.json b/advisories/unreviewed/2022/10/GHSA-mjcr-h6w7-xcx6/GHSA-mjcr-h6w7-xcx6.json index 2daed4a9515..cbcd9c25c08 100644 --- a/advisories/unreviewed/2022/10/GHSA-mjcr-h6w7-xcx6/GHSA-mjcr-h6w7-xcx6.json +++ b/advisories/unreviewed/2022/10/GHSA-mjcr-h6w7-xcx6/GHSA-mjcr-h6w7-xcx6.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/371098" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json b/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json index a5b5f4fe6fd..96479771eb4 100644 --- a/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json +++ b/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/170070/perfSONAR-4.4.5-Cross-Site-Request-Forgery.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171629/perfSONAR-4.4.5-Cross-Site-Request-Forgery.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-6hgw-f77h-gx4f/GHSA-6hgw-f77h-gx4f.json b/advisories/unreviewed/2022/12/GHSA-6hgw-f77h-gx4f/GHSA-6hgw-f77h-gx4f.json index 03c3f1eb893..45b8b189d02 100644 --- a/advisories/unreviewed/2022/12/GHSA-6hgw-f77h-gx4f/GHSA-6hgw-f77h-gx4f.json +++ b/advisories/unreviewed/2022/12/GHSA-6hgw-f77h-gx4f/GHSA-6hgw-f77h-gx4f.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/earth2sky/Disclosed/blob/main/CVE-2022-30519" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171627/Reprise-Software-RLM-14.2BL4-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-pr8p-6jwr-v79h/GHSA-pr8p-6jwr-v79h.json b/advisories/unreviewed/2022/12/GHSA-pr8p-6jwr-v79h/GHSA-pr8p-6jwr-v79h.json index 01c60ff1346..0eda41c7f50 100644 --- a/advisories/unreviewed/2022/12/GHSA-pr8p-6jwr-v79h/GHSA-pr8p-6jwr-v79h.json +++ b/advisories/unreviewed/2022/12/GHSA-pr8p-6jwr-v79h/GHSA-pr8p-6jwr-v79h.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/otsmr/internet-of-vulnerable-things/tree/main/exploits" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171623/TP-Link-TL-WR902AC-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json b/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json index 9cb65691431..2c28e4474b2 100644 --- a/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json +++ b/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171644/sudo-1.9.12p1-Privilege-Escalation.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/01/19/1" diff --git a/advisories/unreviewed/2023/01/GHSA-gwr4-pj6r-2576/GHSA-gwr4-pj6r-2576.json b/advisories/unreviewed/2023/01/GHSA-gwr4-pj6r-2576/GHSA-gwr4-pj6r-2576.json index 9380edb3ed4..c0a7b3da4f8 100644 --- a/advisories/unreviewed/2023/01/GHSA-gwr4-pj6r-2576/GHSA-gwr4-pj6r-2576.json +++ b/advisories/unreviewed/2023/01/GHSA-gwr4-pj6r-2576/GHSA-gwr4-pj6r-2576.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/yui/yui2/tags" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171633/Yahoo-User-Interface-TreeView-2.8.2-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-pppw-hpjp-v2p9/GHSA-pppw-hpjp-v2p9.json b/advisories/unreviewed/2023/01/GHSA-pppw-hpjp-v2p9/GHSA-pppw-hpjp-v2p9.json index be4d0998cb6..d410d44291a 100644 --- a/advisories/unreviewed/2023/01/GHSA-pppw-hpjp-v2p9/GHSA-pppw-hpjp-v2p9.json +++ b/advisories/unreviewed/2023/01/GHSA-pppw-hpjp-v2p9/GHSA-pppw-hpjp-v2p9.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.tenable.com/security/research/tra-2023-2" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171661/WordPress-Paid-Memberships-Pro-2.9.8-SQL-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json b/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json index 54d43e74842..9088e80f341 100644 --- a/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json +++ b/advisories/unreviewed/2023/01/GHSA-v833-mfjc-7qr5/GHSA-v833-mfjc-7qr5.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html" + }, { "type": "WEB", "url": "http://www.binaryworld.it/" diff --git a/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json b/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json index 965ce86dc9c..5572c65ce6c 100644 --- a/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json +++ b/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://phpgurukul.com/projects/Art-Gallery-MS-PHP.zip" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171642/Art-Gallery-Management-System-Project-1.0-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json b/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json index ef592d1150c..d09e972e5ef 100644 --- a/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json +++ b/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://phpgurukul.com/projects/Art-Gallery-MS-PHP.zip" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171643/Art-Gallery-Management-System-Project-1.0-SQL-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json b/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json index ce506afb165..bbb6cf63436 100644 --- a/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json +++ b/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://phpgurukul.com/projects/Art-Gallery-MS-PHP.zip" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171643/Art-Gallery-Management-System-Project-1.0-SQL-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json b/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json index 61c8e843b5e..8495b528bc2 100644 --- a/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json +++ b/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2v4g-w3qw-prh4", - "modified": "2023-03-29T21:30:17Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-29T21:30:17Z", "aliases": [ "CVE-2022-47607" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-472h-pprq-pg3p/GHSA-472h-pprq-pg3p.json b/advisories/unreviewed/2023/03/GHSA-472h-pprq-pg3p/GHSA-472h-pprq-pg3p.json index b3d974cdcbc..429bdaa0493 100644 --- a/advisories/unreviewed/2023/03/GHSA-472h-pprq-pg3p/GHSA-472h-pprq-pg3p.json +++ b/advisories/unreviewed/2023/03/GHSA-472h-pprq-pg3p/GHSA-472h-pprq-pg3p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-472h-pprq-pg3p", - "modified": "2023-03-28T00:34:28Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2023-26924" ], "details": "LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-6738-85h4-qhxj/GHSA-6738-85h4-qhxj.json b/advisories/unreviewed/2023/03/GHSA-6738-85h4-qhxj/GHSA-6738-85h4-qhxj.json index b4fa86894a3..c747a10dd63 100644 --- a/advisories/unreviewed/2023/03/GHSA-6738-85h4-qhxj/GHSA-6738-85h4-qhxj.json +++ b/advisories/unreviewed/2023/03/GHSA-6738-85h4-qhxj/GHSA-6738-85h4-qhxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6738-85h4-qhxj", - "modified": "2023-03-28T00:34:28Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2023-26549" ], "details": "The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json b/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json index 715b372e63a..ad3c5ac2bf3 100644 --- a/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json +++ b/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f7j-jmxj-m9g3", - "modified": "2023-03-27T21:30:26Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-27T21:30:26Z", "aliases": [ "CVE-2023-1074" ], "details": "A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a user starts a malicious networking service and someone connects to this service. This could allow a local user to starve resources, causing a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f289-g9w2-9j5h/GHSA-f289-g9w2-9j5h.json b/advisories/unreviewed/2023/03/GHSA-f289-g9w2-9j5h/GHSA-f289-g9w2-9j5h.json index 630faab58fd..7f4bf99142d 100644 --- a/advisories/unreviewed/2023/03/GHSA-f289-g9w2-9j5h/GHSA-f289-g9w2-9j5h.json +++ b/advisories/unreviewed/2023/03/GHSA-f289-g9w2-9j5h/GHSA-f289-g9w2-9j5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f289-g9w2-9j5h", - "modified": "2023-03-28T03:30:18Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T03:30:18Z", "aliases": [ "CVE-2023-25262" ], "details": "Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-28T01:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json b/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json index 551716a2916..5c8efea9b46 100644 --- a/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json +++ b/advisories/unreviewed/2023/03/GHSA-g874-7753-4g62/GHSA-g874-7753-4g62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g874-7753-4g62", - "modified": "2023-03-31T12:30:16Z", + "modified": "2023-04-03T21:32:48Z", "published": "2023-03-31T12:30:16Z", "aliases": [ "CVE-2023-1769" ], "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page with the input php://filter/read=convert.base64-encode/resource=grade_table leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-224670 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-31T11:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-gqqh-295f-w7wc/GHSA-gqqh-295f-w7wc.json b/advisories/unreviewed/2023/03/GHSA-gqqh-295f-w7wc/GHSA-gqqh-295f-w7wc.json index e3fec013e0c..67e20737553 100644 --- a/advisories/unreviewed/2023/03/GHSA-gqqh-295f-w7wc/GHSA-gqqh-295f-w7wc.json +++ b/advisories/unreviewed/2023/03/GHSA-gqqh-295f-w7wc/GHSA-gqqh-295f-w7wc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqqh-295f-w7wc", - "modified": "2023-03-27T21:30:25Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-27T21:30:25Z", "aliases": [ "CVE-2023-1077" ], "details": "In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing memory corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-h55g-mm6m-gw37/GHSA-h55g-mm6m-gw37.json b/advisories/unreviewed/2023/03/GHSA-h55g-mm6m-gw37/GHSA-h55g-mm6m-gw37.json index fd0b08f9ee7..d3fe7d1c51e 100644 --- a/advisories/unreviewed/2023/03/GHSA-h55g-mm6m-gw37/GHSA-h55g-mm6m-gw37.json +++ b/advisories/unreviewed/2023/03/GHSA-h55g-mm6m-gw37/GHSA-h55g-mm6m-gw37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h55g-mm6m-gw37", - "modified": "2023-03-30T21:30:20Z", + "modified": "2023-04-03T21:32:48Z", "published": "2023-03-30T21:30:20Z", "aliases": [ "CVE-2023-1739" ], "details": "A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224627.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json b/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json index bd174697e12..07fb81db4e6 100644 --- a/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json +++ b/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq4v-9j7v-jcvr", - "modified": "2023-03-28T21:30:20Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T21:30:20Z", "aliases": [ "CVE-2022-24674" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-28T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json b/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json index 494e7dd8a9b..c9512dc7927 100644 --- a/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json +++ b/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p365-9mq8-7r2q", - "modified": "2023-03-28T21:30:20Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T21:30:20Z", "aliases": [ "CVE-2022-24672" ], "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15802.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-28T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json b/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json index 4c59237168e..23e92f66de9 100644 --- a/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json +++ b/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3c4-7524-h583", - "modified": "2023-03-29T21:30:17Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-29T21:30:17Z", "aliases": [ "CVE-2022-47610" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-r255-vm29-9xg5/GHSA-r255-vm29-9xg5.json b/advisories/unreviewed/2023/03/GHSA-r255-vm29-9xg5/GHSA-r255-vm29-9xg5.json index 9fca37689a8..2e1a6d6dc39 100644 --- a/advisories/unreviewed/2023/03/GHSA-r255-vm29-9xg5/GHSA-r255-vm29-9xg5.json +++ b/advisories/unreviewed/2023/03/GHSA-r255-vm29-9xg5/GHSA-r255-vm29-9xg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r255-vm29-9xg5", - "modified": "2023-03-27T21:30:25Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-27T21:30:25Z", "aliases": [ "CVE-2023-1380" ], "details": "A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json b/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json index 08350364497..7e6565af3e5 100644 --- a/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json +++ b/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r26p-gh73-qgq9", - "modified": "2023-03-27T21:30:25Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-27T21:30:25Z", "aliases": [ "CVE-2023-1078" ], "details": "A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json b/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json index af3e68a5f7d..14b7d14b435 100644 --- a/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json +++ b/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w85v-q239-vpx6", - "modified": "2023-03-28T21:30:20Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-28T21:30:20Z", "aliases": [ "CVE-2022-24673" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15845.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-28T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json b/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json index d5401ff7cb0..97944229572 100644 --- a/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json +++ b/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf7f-g3ff-jjc9", - "modified": "2023-03-29T21:30:17Z", + "modified": "2023-04-03T21:32:47Z", "published": "2023-03-29T21:30:17Z", "aliases": [ "CVE-2022-47613" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json new file mode 100644 index 00000000000..c88c7d66007 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rmp-wcvv-c8xm", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43772" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43772" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14454594588045--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Insertion-of-Sensitive-Information-into-Log-File-Versions-before-9-4-0-0-and-9-3-0-1-including-8-3-x-Impacted-CVE-2022-43772-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json new file mode 100644 index 00000000000..2b4d0e72d04 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84x2-qv2c-9cvx", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43771" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43771" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14455007818509--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Limitation-of-a-Pathname-to-a-Restricted-Directory-Path-Traversal-Versions-before-9-4-0-0-and-9-3-0-1-including-8-3-x-Impacted-CVE-2022-43771-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json new file mode 100644 index 00000000000..65dd255d473 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88w6-3m63-r5j7", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43938" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43938" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14454630725645--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Directives-in-Statically-Saved-Code-Static-Code-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43938-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json new file mode 100644 index 00000000000..31ab0f4497c --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r7j-pj39-v7xh", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-4769" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4769" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14452244712589--Resolved-Pentaho-BA-Server-Generation-of-Error-Message-Containing-Sensitive-Information-Versions-before-9-4-0-0-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4769-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json new file mode 100644 index 00000000000..a998941b06e --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch7j-864f-m7r5", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43941" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43941" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14456719346957--Resolved-Pentaho-BA-Server-Improper-Restriction-of-XML-External-Entity-Reference-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-CVE-2022-43941-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json new file mode 100644 index 00000000000..e731c4e28c5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h639-737x-65xp", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-4770" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4770" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14455209015949--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Generation-of-Error-Message-Containing-Sensitive-Information-Versions-before-9-4-0-0-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4770-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json new file mode 100644 index 00000000000..159845695fe --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6x9-6mp2-f49x", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-4771" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4771" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14455436088717--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4771-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json new file mode 100644 index 00000000000..0ed367e6875 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q552-8jxx-pwh8", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-3960" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3960" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14456813547917--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Directives-in-Statically-Saved-Code-Static-Code-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-CVE-2022-3960-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json b/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json new file mode 100644 index 00000000000..9a338f2d04b --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7cq-76xj-2g24", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43939" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43939" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json new file mode 100644 index 00000000000..a21582a18d0 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfh2-62gc-x7hw", + "modified": "2023-04-03T21:32:44Z", + "published": "2023-04-03T21:32:44Z", + "aliases": [ + "CVE-2023-29218" + ], + "details": "The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29218" + }, + { + "type": "WEB", + "url": "https://github.com/twitter/the-algorithm/issues/1386" + }, + { + "type": "WEB", + "url": "https://github.com/twitter/the-algorithm/tree/ec83d01dcaebf369444d75ed04b3625a0a645eb9" + }, + { + "type": "WEB", + "url": "https://steventey.com/blog/twitter-algorithm" + }, + { + "type": "WEB", + "url": "https://twitter.com/Kaptain_Kobold/status/1642379706925477888" + }, + { + "type": "WEB", + "url": "https://twitter.com/aakashg0/status/1641976913165180929" + }, + { + "type": "WEB", + "url": "https://twitter.com/elonmusk/status/1642324821324230657" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json new file mode 100644 index 00000000000..7294233385b --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x57h-h95f-93cr", + "modified": "2023-04-03T21:32:47Z", + "published": "2023-04-03T21:32:47Z", + "aliases": [ + "CVE-2022-43940" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43940" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14456609400973--Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T19:15:00Z" + } +} \ No newline at end of file