From 2e400f2695c96c2a6bad4199d81f53d6faae472c Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Mon, 23 Oct 2023 00:31:32 +0000
Subject: [PATCH] Publish Advisories
GHSA-39q6-4vrm-fv3g
GHSA-3jr9-479w-vh8c
GHSA-3vj4-3g37-rf7w
GHSA-47h2-h6q2-ghrw
GHSA-4qg2-wr83-m4mf
GHSA-5mrw-cpfj-cjh6
GHSA-5q5q-4pvv-q47c
GHSA-8cgf-r9f6-hj56
GHSA-c89h-9543-w7hx
GHSA-h9qg-8cx4-mh74
GHSA-jh7f-2hf7-8vxp
GHSA-jq2h-j9qf-53rv
GHSA-mvw9-7543-rjjg
GHSA-r4wr-j2mc-r37v
GHSA-vwhm-7rfg-7rqc
GHSA-whr7-4gp3-wpwc
GHSA-xq99-q5xg-8fq7
---
.../GHSA-39q6-4vrm-fv3g.json | 4 ++
.../GHSA-3jr9-479w-vh8c.json | 46 +++++++++++++++++++
.../GHSA-3vj4-3g37-rf7w.json | 38 +++++++++++++++
.../GHSA-47h2-h6q2-ghrw.json | 35 ++++++++++++++
.../GHSA-4qg2-wr83-m4mf.json | 46 +++++++++++++++++++
.../GHSA-5mrw-cpfj-cjh6.json | 46 +++++++++++++++++++
.../GHSA-5q5q-4pvv-q47c.json | 38 +++++++++++++++
.../GHSA-8cgf-r9f6-hj56.json | 46 +++++++++++++++++++
.../GHSA-c89h-9543-w7hx.json | 38 +++++++++++++++
.../GHSA-h9qg-8cx4-mh74.json | 39 ++++++++++++++++
.../GHSA-jh7f-2hf7-8vxp.json | 46 +++++++++++++++++++
.../GHSA-jq2h-j9qf-53rv.json | 39 ++++++++++++++++
.../GHSA-mvw9-7543-rjjg.json | 39 ++++++++++++++++
.../GHSA-r4wr-j2mc-r37v.json | 46 +++++++++++++++++++
.../GHSA-vwhm-7rfg-7rqc.json | 39 ++++++++++++++++
.../GHSA-whr7-4gp3-wpwc.json | 46 +++++++++++++++++++
.../GHSA-xq99-q5xg-8fq7.json | 46 +++++++++++++++++++
17 files changed, 677 insertions(+)
create mode 100644 advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-8cgf-r9f6-hj56/GHSA-8cgf-r9f6-hj56.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-h9qg-8cx4-mh74/GHSA-h9qg-8cx4-mh74.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-jh7f-2hf7-8vxp/GHSA-jh7f-2hf7-8vxp.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-mvw9-7543-rjjg/GHSA-mvw9-7543-rjjg.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-r4wr-j2mc-r37v/GHSA-r4wr-j2mc-r37v.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-vwhm-7rfg-7rqc/GHSA-vwhm-7rfg-7rqc.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-whr7-4gp3-wpwc/GHSA-whr7-4gp3-wpwc.json
create mode 100644 advisories/unreviewed/2023/10/GHSA-xq99-q5xg-8fq7/GHSA-xq99-q5xg-8fq7.json
diff --git a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json
index efc40400269..b1559869d6d 100644
--- a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json
+++ b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final"
},
+ {
+ "type": "WEB",
+ "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html"
+ },
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230908-0004/"
diff --git a/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json
new file mode 100644
index 00000000000..4b1e872aab7
--- /dev/null
+++ b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3jr9-479w-vh8c",
+ "modified": "2023-10-23T00:30:21Z",
+ "published": "2023-10-23T00:30:21Z",
+ "aliases": [
+ "CVE-2023-5695"
+ ],
+ "details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25 leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5695"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%203.pdf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.243133"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.243133"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
new file mode 100644
index 00000000000..318f43cd938
--- /dev/null
+++ b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3vj4-3g37-rf7w",
+ "modified": "2023-10-23T00:30:20Z",
+ "published": "2023-10-23T00:30:20Z",
+ "aliases": [
+ "CVE-2023-46085"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46085"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
new file mode 100644
index 00000000000..132f69f7d8d
--- /dev/null
+++ b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-47h2-h6q2-ghrw",
+ "modified": "2023-10-23T00:30:21Z",
+ "published": "2023-10-23T00:30:21Z",
+ "aliases": [
+ "CVE-2023-46319"
+ ],
+ "details": "WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46319"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wallix.com/support/alerts/"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json
new file mode 100644
index 00000000000..594f0292305
--- /dev/null
+++ b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4qg2-wr83-m4mf",
+ "modified": "2023-10-23T00:30:21Z",
+ "published": "2023-10-23T00:30:21Z",
+ "aliases": [
+ "CVE-2023-5700"
+ ],
+ "details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/istlnight/cve/blob/main/NS-ASG-sql-uploadiscgwrouteconf.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.243138"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.243138"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json
new file mode 100644
index 00000000000..c6f0f0dc3c6
--- /dev/null
+++ b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5mrw-cpfj-cjh6",
+ "modified": "2023-10-23T00:30:21Z",
+ "published": "2023-10-23T00:30:21Z",
+ "aliases": [
+ "CVE-2023-5698"
+ ],
+ "details": "A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905-->