From 20c152e681178ad04909ee4c3d8c465d310c36a2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 16 Mar 2024 03:32:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gw9q-c7gh-j9vm.json | 10 +++- .../GHSA-f89w-2cg8-8h78.json | 6 ++- .../GHSA-554m-v42f-hcq9.json | 10 +++- .../GHSA-22f2-7248-9pxp.json | 6 ++- .../GHSA-6q4q-mhg5-v6xh.json | 10 +++- .../GHSA-r9cj-pfgj-jc26.json | 6 ++- .../GHSA-24pv-3jc8-2432.json | 38 ++++++++++++++ .../GHSA-25v7-q3wp-pg2v.json | 38 ++++++++++++++ .../GHSA-2c5c-7h32-vwfp.json | 38 ++++++++++++++ .../GHSA-45hm-gg77-pjg9.json | 46 +++++++++++++++++ .../GHSA-49x6-w2c9-99x9.json | 38 ++++++++++++++ .../GHSA-557p-6hf2-6q66.json | 38 ++++++++++++++ .../GHSA-58qv-qvf3-f8mp.json | 6 ++- .../GHSA-5f4p-5jw7-7w7q.json | 38 ++++++++++++++ .../GHSA-649c-gmmm-5xfj.json | 42 ++++++++++++++++ .../GHSA-6qx4-rgm3-9ghw.json | 38 ++++++++++++++ .../GHSA-9742-f8rf-87v4.json | 42 ++++++++++++++++ .../GHSA-9886-cqjq-qrvc.json | 6 ++- .../GHSA-9gmf-mg2v-j8r6.json | 38 ++++++++++++++ .../GHSA-gwh7-h623-wx42.json | 38 ++++++++++++++ .../GHSA-h47f-gx76-rcqj.json | 38 ++++++++++++++ .../GHSA-hq26-fq88-3f4h.json | 50 +++++++++++++++++++ .../GHSA-jvmw-753q-r77g.json | 46 +++++++++++++++++ .../GHSA-pjqg-r9g3-49qj.json | 38 ++++++++++++++ .../GHSA-rh76-8g69-p8g8.json | 38 ++++++++++++++ 25 files changed, 734 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-24pv-3jc8-2432/GHSA-24pv-3jc8-2432.json create mode 100644 advisories/unreviewed/2024/03/GHSA-25v7-q3wp-pg2v/GHSA-25v7-q3wp-pg2v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2c5c-7h32-vwfp/GHSA-2c5c-7h32-vwfp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-49x6-w2c9-99x9/GHSA-49x6-w2c9-99x9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-557p-6hf2-6q66/GHSA-557p-6hf2-6q66.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5f4p-5jw7-7w7q/GHSA-5f4p-5jw7-7w7q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-649c-gmmm-5xfj/GHSA-649c-gmmm-5xfj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6qx4-rgm3-9ghw/GHSA-6qx4-rgm3-9ghw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9gmf-mg2v-j8r6/GHSA-9gmf-mg2v-j8r6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gwh7-h623-wx42/GHSA-gwh7-h623-wx42.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h47f-gx76-rcqj/GHSA-h47f-gx76-rcqj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hq26-fq88-3f4h/GHSA-hq26-fq88-3f4h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pjqg-r9g3-49qj/GHSA-pjqg-r9g3-49qj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rh76-8g69-p8g8/GHSA-rh76-8g69-p8g8.json diff --git a/advisories/unreviewed/2022/05/GHSA-gw9q-c7gh-j9vm/GHSA-gw9q-c7gh-j9vm.json b/advisories/unreviewed/2022/05/GHSA-gw9q-c7gh-j9vm/GHSA-gw9q-c7gh-j9vm.json index aabc35110fe..62717e12c5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw9q-c7gh-j9vm/GHSA-gw9q-c7gh-j9vm.json +++ b/advisories/unreviewed/2022/05/GHSA-gw9q-c7gh-j9vm/GHSA-gw9q-c7gh-j9vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw9q-c7gh-j9vm", - "modified": "2022-05-01T18:24:47Z", + "modified": "2024-03-16T03:30:57Z", "published": "2022-05-01T18:24:47Z", "aliases": [ "CVE-2007-4559" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=263261" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH" + }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202309-06" diff --git a/advisories/unreviewed/2023/10/GHSA-f89w-2cg8-8h78/GHSA-f89w-2cg8-8h78.json b/advisories/unreviewed/2023/10/GHSA-f89w-2cg8-8h78/GHSA-f89w-2cg8-8h78.json index a9e60f6f84d..ffc6d9f93c7 100644 --- a/advisories/unreviewed/2023/10/GHSA-f89w-2cg8-8h78/GHSA-f89w-2cg8-8h78.json +++ b/advisories/unreviewed/2023/10/GHSA-f89w-2cg8-8h78/GHSA-f89w-2cg8-8h78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f89w-2cg8-8h78", - "modified": "2024-02-18T12:30:31Z", + "modified": "2024-03-16T03:30:58Z", "published": "2023-10-06T18:30:32Z", "aliases": [ "CVE-2023-5366" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00004.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VYYUBF6OW2JG7VOFEOROHXGSJCTES3QO" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/08/4" diff --git a/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json index 889b9c8bdba..b2adede1cba 100644 --- a/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json +++ b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-554m-v42f-hcq9", - "modified": "2024-02-26T18:30:27Z", + "modified": "2024-03-16T03:30:58Z", "published": "2024-01-31T15:30:20Z", "aliases": [ "CVE-2023-5992" @@ -40,6 +40,14 @@ { "type": "WEB", "url": "https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-22f2-7248-9pxp/GHSA-22f2-7248-9pxp.json b/advisories/unreviewed/2024/02/GHSA-22f2-7248-9pxp/GHSA-22f2-7248-9pxp.json index e6d76c204e8..5a583331dbd 100644 --- a/advisories/unreviewed/2024/02/GHSA-22f2-7248-9pxp/GHSA-22f2-7248-9pxp.json +++ b/advisories/unreviewed/2024/02/GHSA-22f2-7248-9pxp/GHSA-22f2-7248-9pxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22f2-7248-9pxp", - "modified": "2024-03-08T03:31:23Z", + "modified": "2024-03-16T03:30:59Z", "published": "2024-02-22T18:30:28Z", "aliases": [ "CVE-2023-52161" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://iwd.wiki.kernel.org" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KSGT4IZ23CJBOQA3AFYEMBJ5OHFZBMK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TL2CFNWBL2E6AT2SIY2PR3IAWVCDYJZQ" diff --git a/advisories/unreviewed/2024/02/GHSA-6q4q-mhg5-v6xh/GHSA-6q4q-mhg5-v6xh.json b/advisories/unreviewed/2024/02/GHSA-6q4q-mhg5-v6xh/GHSA-6q4q-mhg5-v6xh.json index 148372e38cc..eb629839781 100644 --- a/advisories/unreviewed/2024/02/GHSA-6q4q-mhg5-v6xh/GHSA-6q4q-mhg5-v6xh.json +++ b/advisories/unreviewed/2024/02/GHSA-6q4q-mhg5-v6xh/GHSA-6q4q-mhg5-v6xh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q4q-mhg5-v6xh", - "modified": "2024-02-13T00:30:27Z", + "modified": "2024-03-16T03:30:58Z", "published": "2024-02-13T00:30:27Z", "aliases": [ "CVE-2024-1454" @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2263929" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-r9cj-pfgj-jc26/GHSA-r9cj-pfgj-jc26.json b/advisories/unreviewed/2024/02/GHSA-r9cj-pfgj-jc26/GHSA-r9cj-pfgj-jc26.json index 23d9c3fdaaf..51286af4d98 100644 --- a/advisories/unreviewed/2024/02/GHSA-r9cj-pfgj-jc26/GHSA-r9cj-pfgj-jc26.json +++ b/advisories/unreviewed/2024/02/GHSA-r9cj-pfgj-jc26/GHSA-r9cj-pfgj-jc26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9cj-pfgj-jc26", - "modified": "2024-02-22T15:30:38Z", + "modified": "2024-03-16T03:30:58Z", "published": "2024-02-22T15:30:38Z", "aliases": [ "CVE-2023-3966" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2178363" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VYYUBF6OW2JG7VOFEOROHXGSJCTES3QO" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-24pv-3jc8-2432/GHSA-24pv-3jc8-2432.json b/advisories/unreviewed/2024/03/GHSA-24pv-3jc8-2432/GHSA-24pv-3jc8-2432.json new file mode 100644 index 00000000000..59436fd6efe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-24pv-3jc8-2432/GHSA-24pv-3jc8-2432.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24pv-3jc8-2432", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51407" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51407" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/split-test-for-elementor/wordpress-split-test-for-elementor-plugin-1-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-25v7-q3wp-pg2v/GHSA-25v7-q3wp-pg2v.json b/advisories/unreviewed/2024/03/GHSA-25v7-q3wp-pg2v/GHSA-25v7-q3wp-pg2v.json new file mode 100644 index 00000000000..70f6a53aa74 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-25v7-q3wp-pg2v/GHSA-25v7-q3wp-pg2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25v7-q3wp-pg2v", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-27194" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andrei Ivasiuc Fontific | Google Fonts allows Stored XSS.This issue affects Fontific | Google Fonts: from n/a through 0.1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27194" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fontific/wordpress-fontific-plugin-0-1-6-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2c5c-7h32-vwfp/GHSA-2c5c-7h32-vwfp.json b/advisories/unreviewed/2024/03/GHSA-2c5c-7h32-vwfp/GHSA-2c5c-7h32-vwfp.json new file mode 100644 index 00000000000..f9ed941dba2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2c5c-7h32-vwfp/GHSA-2c5c-7h32-vwfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c5c-7h32-vwfp", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51486" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/a through 1.2.101.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-pdf-invoice-builder/wordpress-woocommerce-pdf-invoice-builder-create-invoices-packing-slips-and-more-plugin-1-2-101-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json b/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json new file mode 100644 index 00000000000..1839c00253a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45hm-gg77-pjg9", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-6525" + ], + "details": "The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6525" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementskit-lite/tags/3.0.3/widgets/progressbar/progressbar.php#L535" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3011323/elementskit-lite/trunk/widgets/progressbar/progressbar.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e724394d-97aa-42e4-b36e-6e49bfefa2f6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-49x6-w2c9-99x9/GHSA-49x6-w2c9-99x9.json b/advisories/unreviewed/2024/03/GHSA-49x6-w2c9-99x9/GHSA-49x6-w2c9-99x9.json new file mode 100644 index 00000000000..da1a883cbb8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-49x6-w2c9-99x9/GHSA-49x6-w2c9-99x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49x6-w2c9-99x9", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-27195" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sandi Verdev Watermark RELOADED allows Stored XSS.This issue affects Watermark RELOADED: from n/a through 1.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27195" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/watermark-reloaded/wordpress-watermark-reloaded-plugin-1-3-5-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-557p-6hf2-6q66/GHSA-557p-6hf2-6q66.json b/advisories/unreviewed/2024/03/GHSA-557p-6hf2-6q66/GHSA-557p-6hf2-6q66.json new file mode 100644 index 00000000000..56b43d5fcbe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-557p-6hf2-6q66/GHSA-557p-6hf2-6q66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-557p-6hf2-6q66", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51474" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51474" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/terraclassifieds/wordpress-terraclassifieds-plugin-2-0-3-cross-site-request-forgery-csrf-to-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json b/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json index 34496e492d6..5e729c2ccd2 100644 --- a/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json +++ b/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58qv-qvf3-f8mp", - "modified": "2024-03-03T21:31:25Z", + "modified": "2024-03-16T03:30:58Z", "published": "2024-03-03T21:31:25Z", "aliases": [ "CVE-2024-28084" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://git.kernel.org/pub/scm/network/wireless/iwd.git/commit/?id=d34b4e16e045142590ed7cb653e01ed0ae5362eb" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KSGT4IZ23CJBOQA3AFYEMBJ5OHFZBMK" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-5f4p-5jw7-7w7q/GHSA-5f4p-5jw7-7w7q.json b/advisories/unreviewed/2024/03/GHSA-5f4p-5jw7-7w7q/GHSA-5f4p-5jw7-7w7q.json new file mode 100644 index 00000000000..474346b7ea3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5f4p-5jw7-7w7q/GHSA-5f4p-5jw7-7w7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f4p-5jw7-7w7q", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51510" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51510" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/export-media-urls/wordpress-export-media-urls-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-649c-gmmm-5xfj/GHSA-649c-gmmm-5xfj.json b/advisories/unreviewed/2024/03/GHSA-649c-gmmm-5xfj/GHSA-649c-gmmm-5xfj.json new file mode 100644 index 00000000000..9967cc16575 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-649c-gmmm-5xfj/GHSA-649c-gmmm-5xfj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-649c-gmmm-5xfj", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-2308" + ], + "details": "The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2308" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050556%40elementinvader-addons-for-elementor&new=3050556%40elementinvader-addons-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/40a272dc-cb2a-472f-be42-733efcb2fa61?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6qx4-rgm3-9ghw/GHSA-6qx4-rgm3-9ghw.json b/advisories/unreviewed/2024/03/GHSA-6qx4-rgm3-9ghw/GHSA-6qx4-rgm3-9ghw.json new file mode 100644 index 00000000000..ecb175b8a3b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6qx4-rgm3-9ghw/GHSA-6qx4-rgm3-9ghw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qx4-rgm3-9ghw", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-27197" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bee BeePress allows Stored XSS.This issue affects BeePress: from n/a through 6.9.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27197" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/beepress/wordpress-beepress-plugin-6-9-8-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json b/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json new file mode 100644 index 00000000000..8b9e6ad6b77 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9742-f8rf-87v4", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-1239" + ], + "details": "The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1239" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3042291%40elementskit-lite&new=3042291%40elementskit-lite&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1822fd58-0dba-4b15-9702-32e3aa4405b3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9886-cqjq-qrvc/GHSA-9886-cqjq-qrvc.json b/advisories/unreviewed/2024/03/GHSA-9886-cqjq-qrvc/GHSA-9886-cqjq-qrvc.json index ac8965e183f..e5892ac91b3 100644 --- a/advisories/unreviewed/2024/03/GHSA-9886-cqjq-qrvc/GHSA-9886-cqjq-qrvc.json +++ b/advisories/unreviewed/2024/03/GHSA-9886-cqjq-qrvc/GHSA-9886-cqjq-qrvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9886-cqjq-qrvc", - "modified": "2024-03-14T03:31:14Z", + "modified": "2024-03-16T03:30:59Z", "published": "2024-03-13T06:30:51Z", "aliases": [ "CVE-2024-2400" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T55OZ7JOMLNT5ICM4DTCZOJZD6TZICKO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VIKPDCUMQNF2DFB7TU3V4ISJ7WFJH7YI" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-9gmf-mg2v-j8r6/GHSA-9gmf-mg2v-j8r6.json b/advisories/unreviewed/2024/03/GHSA-9gmf-mg2v-j8r6/GHSA-9gmf-mg2v-j8r6.json new file mode 100644 index 00000000000..dc0a4eba1a6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9gmf-mg2v-j8r6/GHSA-9gmf-mg2v-j8r6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gmf-mg2v-j8r6", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51491" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Averta Depicter Slider.This issue affects Depicter Slider: from n/a through 2.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/depicter/wordpress-depicter-slider-plugin-2-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gwh7-h623-wx42/GHSA-gwh7-h623-wx42.json b/advisories/unreviewed/2024/03/GHSA-gwh7-h623-wx42/GHSA-gwh7-h623-wx42.json new file mode 100644 index 00000000000..35179d93d06 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gwh7-h623-wx42/GHSA-gwh7-h623-wx42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwh7-h623-wx42", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51489" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/polldaddy/wordpress-crowdsignal-polls-ratings-plugin-3-0-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h47f-gx76-rcqj/GHSA-h47f-gx76-rcqj.json b/advisories/unreviewed/2024/03/GHSA-h47f-gx76-rcqj/GHSA-h47f-gx76-rcqj.json new file mode 100644 index 00000000000..2170131120d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h47f-gx76-rcqj/GHSA-h47f-gx76-rcqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h47f-gx76-rcqj", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51521" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/quiz-master-next/wordpress-quiz-and-survey-master-plugin-8-1-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hq26-fq88-3f4h/GHSA-hq26-fq88-3f4h.json b/advisories/unreviewed/2024/03/GHSA-hq26-fq88-3f4h/GHSA-hq26-fq88-3f4h.json new file mode 100644 index 00000000000..ff9e7a22905 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hq26-fq88-3f4h/GHSA-hq26-fq88-3f4h.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq26-fq88-3f4h", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-2294" + ], + "details": "The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capability to access arbitrary files on the server, which can contain sensitive information. This only impacts sites hosted on Windows servers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2294" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/backuply/trunk/functions.php#L1615" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/backuply/trunk/main/ajax.php#L78" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050547%40backuply&new=3050547%40backuply&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be3bd1f2-092c-47c4-a4e4-3365e107c57f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json b/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json new file mode 100644 index 00000000000..462ae0166a1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvmw-753q-r77g", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2024-2042" + ], + "details": "The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2042" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementskit-lite/tags/3.0.4/widgets/image-accordion/image-accordion.php#L962" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050248%40elementskit-lite&new=3050248%40elementskit-lite&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be4ce3e6-8baa-419f-a48e-4256c306fbc1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pjqg-r9g3-49qj/GHSA-pjqg-r9g3-49qj.json b/advisories/unreviewed/2024/03/GHSA-pjqg-r9g3-49qj/GHSA-pjqg-r9g3-49qj.json new file mode 100644 index 00000000000..89bf88a40b7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pjqg-r9g3-49qj/GHSA-pjqg-r9g3-49qj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjqg-r9g3-49qj", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51512" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in WBW Product Table by WBW.This issue affects Product Table by WBW: from n/a through 1.8.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-product-tables/wordpress-product-table-by-wbw-plugin-1-8-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rh76-8g69-p8g8/GHSA-rh76-8g69-p8g8.json b/advisories/unreviewed/2024/03/GHSA-rh76-8g69-p8g8/GHSA-rh76-8g69-p8g8.json new file mode 100644 index 00000000000..dc5c1f551be --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rh76-8g69-p8g8/GHSA-rh76-8g69-p8g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh76-8g69-p8g8", + "modified": "2024-03-16T03:30:59Z", + "published": "2024-03-16T03:30:59Z", + "aliases": [ + "CVE-2023-51487" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ari-stream-quiz/wordpress-ari-stream-quiz-wordpress-quizzes-builder-plugin-1-2-32-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-16T02:15:07Z" + } +} \ No newline at end of file