Publish Advisories

GHSA-782x-9xpx-3gm4
GHSA-cqvv-r3g3-26rf
GHSA-cxg7-94vc-m5j2
This commit is contained in:
advisory-database[bot]
2023-10-23 03:31:22 +00:00
parent 2e400f2695
commit 24e7a0e224
3 changed files with 131 additions and 0 deletions
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-782x-9xpx-3gm4",
"modified": "2023-10-23T03:30:30Z",
"published": "2023-10-23T03:30:30Z",
"aliases": [
"CVE-2023-5702"
],
"details": "A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5702"
},
{
"type": "WEB",
"url": "https://github.com/GTA12138/vul/blob/main/Viessmann/Vitogate300_Document_Unauthorized_Access.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243140"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243140"
}
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqvv-r3g3-26rf",
"modified": "2023-10-23T03:30:30Z",
"published": "2023-10-23T03:30:30Z",
"aliases": [
"CVE-2023-46324"
],
"details": "pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46324"
},
{
"type": "WEB",
"url": "https://github.com/free5gc/udm/pull/20"
},
{
"type": "WEB",
"url": "https://github.com/free5gc/udm/compare/v1.1.1...v1.2.0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxg7-94vc-m5j2",
"modified": "2023-10-23T03:30:30Z",
"published": "2023-10-23T03:30:30Z",
"aliases": [
"CVE-2023-5701"
],
"details": "A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input <xss onclick=\"alert(1)\" style=display:block>Click here</xss> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243139. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5701"
},
{
"type": "WEB",
"url": "https://github.com/victorootnice/victorootnice.github.io/blob/main/2023/bbp-01.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243139"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243139"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}