diff --git a/advisories/unreviewed/2023/10/GHSA-782x-9xpx-3gm4/GHSA-782x-9xpx-3gm4.json b/advisories/unreviewed/2023/10/GHSA-782x-9xpx-3gm4/GHSA-782x-9xpx-3gm4.json new file mode 100644 index 00000000000..afe2db8e968 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-782x-9xpx-3gm4/GHSA-782x-9xpx-3gm4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-782x-9xpx-3gm4", + "modified": "2023-10-23T03:30:30Z", + "published": "2023-10-23T03:30:30Z", + "aliases": [ + "CVE-2023-5702" + ], + "details": "A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5702" + }, + { + "type": "WEB", + "url": "https://github.com/GTA12138/vul/blob/main/Viessmann/Vitogate300_Document_Unauthorized_Access.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243140" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-cqvv-r3g3-26rf/GHSA-cqvv-r3g3-26rf.json b/advisories/unreviewed/2023/10/GHSA-cqvv-r3g3-26rf/GHSA-cqvv-r3g3-26rf.json new file mode 100644 index 00000000000..2847c970cfe --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-cqvv-r3g3-26rf/GHSA-cqvv-r3g3-26rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqvv-r3g3-26rf", + "modified": "2023-10-23T03:30:30Z", + "published": "2023-10-23T03:30:30Z", + "aliases": [ + "CVE-2023-46324" + ], + "details": "pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46324" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/udm/pull/20" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/udm/compare/v1.1.1...v1.2.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-cxg7-94vc-m5j2/GHSA-cxg7-94vc-m5j2.json b/advisories/unreviewed/2023/10/GHSA-cxg7-94vc-m5j2/GHSA-cxg7-94vc-m5j2.json new file mode 100644 index 00000000000..9bb9f119765 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-cxg7-94vc-m5j2/GHSA-cxg7-94vc-m5j2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxg7-94vc-m5j2", + "modified": "2023-10-23T03:30:30Z", + "published": "2023-10-23T03:30:30Z", + "aliases": [ + "CVE-2023-5701" + ], + "details": "A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input Click here leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243139. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5701" + }, + { + "type": "WEB", + "url": "https://github.com/victorootnice/victorootnice.github.io/blob/main/2023/bbp-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243139" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file