From 2e400f2695c96c2a6bad4199d81f53d6faae472c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 23 Oct 2023 00:31:32 +0000 Subject: [PATCH] Publish Advisories GHSA-39q6-4vrm-fv3g GHSA-3jr9-479w-vh8c GHSA-3vj4-3g37-rf7w GHSA-47h2-h6q2-ghrw GHSA-4qg2-wr83-m4mf GHSA-5mrw-cpfj-cjh6 GHSA-5q5q-4pvv-q47c GHSA-8cgf-r9f6-hj56 GHSA-c89h-9543-w7hx GHSA-h9qg-8cx4-mh74 GHSA-jh7f-2hf7-8vxp GHSA-jq2h-j9qf-53rv GHSA-mvw9-7543-rjjg GHSA-r4wr-j2mc-r37v GHSA-vwhm-7rfg-7rqc GHSA-whr7-4gp3-wpwc GHSA-xq99-q5xg-8fq7 --- .../GHSA-39q6-4vrm-fv3g.json | 4 ++ .../GHSA-3jr9-479w-vh8c.json | 46 +++++++++++++++++++ .../GHSA-3vj4-3g37-rf7w.json | 38 +++++++++++++++ .../GHSA-47h2-h6q2-ghrw.json | 35 ++++++++++++++ .../GHSA-4qg2-wr83-m4mf.json | 46 +++++++++++++++++++ .../GHSA-5mrw-cpfj-cjh6.json | 46 +++++++++++++++++++ .../GHSA-5q5q-4pvv-q47c.json | 38 +++++++++++++++ .../GHSA-8cgf-r9f6-hj56.json | 46 +++++++++++++++++++ .../GHSA-c89h-9543-w7hx.json | 38 +++++++++++++++ .../GHSA-h9qg-8cx4-mh74.json | 39 ++++++++++++++++ .../GHSA-jh7f-2hf7-8vxp.json | 46 +++++++++++++++++++ .../GHSA-jq2h-j9qf-53rv.json | 39 ++++++++++++++++ .../GHSA-mvw9-7543-rjjg.json | 39 ++++++++++++++++ .../GHSA-r4wr-j2mc-r37v.json | 46 +++++++++++++++++++ .../GHSA-vwhm-7rfg-7rqc.json | 39 ++++++++++++++++ .../GHSA-whr7-4gp3-wpwc.json | 46 +++++++++++++++++++ .../GHSA-xq99-q5xg-8fq7.json | 46 +++++++++++++++++++ 17 files changed, 677 insertions(+) create mode 100644 advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json create mode 100644 advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json create mode 100644 advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json create mode 100644 advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json create mode 100644 advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json create mode 100644 advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json create mode 100644 advisories/unreviewed/2023/10/GHSA-8cgf-r9f6-hj56/GHSA-8cgf-r9f6-hj56.json create mode 100644 advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json create mode 100644 advisories/unreviewed/2023/10/GHSA-h9qg-8cx4-mh74/GHSA-h9qg-8cx4-mh74.json create mode 100644 advisories/unreviewed/2023/10/GHSA-jh7f-2hf7-8vxp/GHSA-jh7f-2hf7-8vxp.json create mode 100644 advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json create mode 100644 advisories/unreviewed/2023/10/GHSA-mvw9-7543-rjjg/GHSA-mvw9-7543-rjjg.json create mode 100644 advisories/unreviewed/2023/10/GHSA-r4wr-j2mc-r37v/GHSA-r4wr-j2mc-r37v.json create mode 100644 advisories/unreviewed/2023/10/GHSA-vwhm-7rfg-7rqc/GHSA-vwhm-7rfg-7rqc.json create mode 100644 advisories/unreviewed/2023/10/GHSA-whr7-4gp3-wpwc/GHSA-whr7-4gp3-wpwc.json create mode 100644 advisories/unreviewed/2023/10/GHSA-xq99-q5xg-8fq7/GHSA-xq99-q5xg-8fq7.json diff --git a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json index efc40400269..b1559869d6d 100644 --- a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json +++ b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230908-0004/" diff --git a/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json new file mode 100644 index 00000000000..4b1e872aab7 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jr9-479w-vh8c", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5695" + ], + "details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25alert(9860) leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5695" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243133" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json new file mode 100644 index 00000000000..318f43cd938 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vj4-3g37-rf7w", + "modified": "2023-10-23T00:30:20Z", + "published": "2023-10-23T00:30:20Z", + "aliases": [ + "CVE-2023-46085" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46085" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json new file mode 100644 index 00000000000..132f69f7d8d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47h2-h6q2-ghrw", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-46319" + ], + "details": "WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46319" + }, + { + "type": "WEB", + "url": "https://www.wallix.com/support/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json new file mode 100644 index 00000000000..594f0292305 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qg2-wr83-m4mf", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5700" + ], + "details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5700" + }, + { + "type": "WEB", + "url": "https://github.com/istlnight/cve/blob/main/NS-ASG-sql-uploadiscgwrouteconf.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json new file mode 100644 index 00000000000..c6f0f0dc3c6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mrw-cpfj-cjh6", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5698" + ], + "details": "A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905-->alert(9523)alert(9206)alert(1234)