Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-12 15:31:27 +00:00
parent 6705436424
commit 2e8c406ed8
40 changed files with 887 additions and 34 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94jh-j374-9r3j",
"modified": "2023-12-01T22:49:26Z",
"modified": "2024-01-12T15:30:24Z",
"published": "2023-11-16T09:30:24Z",
"aliases": [
"CVE-2023-26031"
@@ -63,6 +63,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/q9qpdlv952gb4kphpndd5phvl7fkh71r"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0001/"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p62-6cg9-f5f5",
"modified": "2024-01-04T15:26:43Z",
"modified": "2024-01-12T15:30:24Z",
"published": "2023-12-09T00:35:05Z",
"aliases": [
"CVE-2023-6337"
@@ -89,6 +89,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/vault"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0006/"
}
],
"database_specific": {
@@ -40,6 +40,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2375"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0005/"
}
],
"database_specific": {
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/268073"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0004/"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7087207"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0008/"
},
{
"type": "WEB",
"url": "https://sqlite.org/forum/forumpost/5bcbf4571c"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/252048"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0002/"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7087218"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v254-5m89-3qf2",
"modified": "2023-12-19T15:30:29Z",
"modified": "2024-01-12T15:30:24Z",
"published": "2023-12-13T09:30:32Z",
"aliases": [
"CVE-2023-6534"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-23:17.pf.asc"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0007/"
}
],
"database_specific": {
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/269367"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240112-0003/"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7087203"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pv4-q67j-8w9h",
"modified": "2024-01-12T15:30:32Z",
"published": "2024-01-12T15:30:32Z",
"aliases": [
"CVE-2023-49261"
],
"details": "The \"tokenKey\" value used in user authorization is visible in the HTML source of the login page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49261"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2024/01/CVE-2023-49253/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T15:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w7q-mj4w-9cm2",
"modified": "2024-01-12T15:30:32Z",
"published": "2024-01-12T15:30:32Z",
"aliases": [
"CVE-2023-6955"
],
"details": "An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group. ",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6955"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/432188"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T14:15:49Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37m4-w5jp-r3px",
"modified": "2024-01-12T15:30:28Z",
"published": "2024-01-12T15:30:28Z",
"aliases": [
"CVE-2023-51790"
],
"details": "Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51790"
},
{
"type": "WEB",
"url": "https://github.com/Piwigo/AdminTools/issues/21"
},
{
"type": "WEB",
"url": "https://github.com/Piwigo/Piwigo/issues/2069"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T13:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3836-7r6q-99c9",
"modified": "2024-01-12T15:30:32Z",
"published": "2024-01-12T15:30:32Z",
"aliases": [
"CVE-2023-51949"
],
"details": "Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51949"
},
{
"type": "WEB",
"url": "https://github.com/cui2shark/security/blob/main/Added%20CSRF%20in%20Role%20Controller.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T15:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44hp-hmpq-cgw3",
"modified": "2024-01-11T00:30:25Z",
"modified": "2024-01-12T15:30:26Z",
"published": "2024-01-11T00:30:25Z",
"aliases": [
"CVE-2023-40430"
],
"details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user consent.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T22:15:48Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hqq-f6h3-3pgp",
"modified": "2024-01-11T00:30:25Z",
"modified": "2024-01-12T15:30:26Z",
"published": "2024-01-11T00:30:25Z",
"aliases": [
"CVE-2023-41994"
],
"details": "A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T22:15:49Z"
@@ -44,6 +44,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74",
"CWE-90"
],
"severity": "HIGH",
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58jj-f9fm-h5qv",
"modified": "2024-01-12T15:30:28Z",
"published": "2024-01-12T15:30:28Z",
"aliases": [
"CVE-2023-51806"
],
"details": "File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51806"
},
{
"type": "WEB",
"url": "https://github.com/ujcms/ujcms/issues/8"
},
{
"type": "WEB",
"url": "https://github.com/ujcms/ujcms"
},
{
"type": "WEB",
"url": "https://www.ujcms.com/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T13:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hmw-x4vw-66rw",
"modified": "2024-01-11T00:30:26Z",
"modified": "2024-01-12T15:30:26Z",
"published": "2024-01-11T00:30:26Z",
"aliases": [
"CVE-2023-42929"
],
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T22:15:50Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q5j-r39w-wc64",
"modified": "2024-01-12T15:30:32Z",
"published": "2024-01-12T15:30:32Z",
"aliases": [
"CVE-2023-4812"
],
"details": "An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4812"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2115574"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/424398"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T14:15:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vwc-p62x-pm8g",
"modified": "2024-01-12T15:30:29Z",
"published": "2024-01-12T15:30:29Z",
"aliases": [
"CVE-2023-52026"
],
"details": "TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52026"
},
{
"type": "WEB",
"url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setTelnetCfg/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T13:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66qh-r598-w33q",
"modified": "2024-01-08T12:30:31Z",
"modified": "2024-01-12T15:30:25Z",
"published": "2024-01-08T12:30:31Z",
"aliases": [
"CVE-2023-5091"
],
"details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-08T10:15:11Z"

Some files were not shown because too many files have changed in this diff Show More