diff --git a/advisories/github-reviewed/2023/11/GHSA-94jh-j374-9r3j/GHSA-94jh-j374-9r3j.json b/advisories/github-reviewed/2023/11/GHSA-94jh-j374-9r3j/GHSA-94jh-j374-9r3j.json index 38552a4b53a..a48803dd757 100644 --- a/advisories/github-reviewed/2023/11/GHSA-94jh-j374-9r3j/GHSA-94jh-j374-9r3j.json +++ b/advisories/github-reviewed/2023/11/GHSA-94jh-j374-9r3j/GHSA-94jh-j374-9r3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94jh-j374-9r3j", - "modified": "2023-12-01T22:49:26Z", + "modified": "2024-01-12T15:30:24Z", "published": "2023-11-16T09:30:24Z", "aliases": [ "CVE-2023-26031" @@ -63,6 +63,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/q9qpdlv952gb4kphpndd5phvl7fkh71r" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0001/" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json b/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json index 579f6a2fa0e..d2321a3ad59 100644 --- a/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json +++ b/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p62-6cg9-f5f5", - "modified": "2024-01-04T15:26:43Z", + "modified": "2024-01-12T15:30:24Z", "published": "2023-12-09T00:35:05Z", "aliases": [ "CVE-2023-6337" @@ -89,6 +89,10 @@ { "type": "PACKAGE", "url": "https://github.com/hashicorp/vault" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0006/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-33qr-2xwr-95pw/GHSA-33qr-2xwr-95pw.json b/advisories/unreviewed/2023/12/GHSA-33qr-2xwr-95pw/GHSA-33qr-2xwr-95pw.json index 39eda9dd2b0..ccfd4cca30e 100644 --- a/advisories/unreviewed/2023/12/GHSA-33qr-2xwr-95pw/GHSA-33qr-2xwr-95pw.json +++ b/advisories/unreviewed/2023/12/GHSA-33qr-2xwr-95pw/GHSA-33qr-2xwr-95pw.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2375" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0005/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-6wj8-32mg-qhm6/GHSA-6wj8-32mg-qhm6.json b/advisories/unreviewed/2023/12/GHSA-6wj8-32mg-qhm6/GHSA-6wj8-32mg-qhm6.json index cc9c5b3b8ef..d0fba5b57c7 100644 --- a/advisories/unreviewed/2023/12/GHSA-6wj8-32mg-qhm6/GHSA-6wj8-32mg-qhm6.json +++ b/advisories/unreviewed/2023/12/GHSA-6wj8-32mg-qhm6/GHSA-6wj8-32mg-qhm6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/268073" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0004/" + }, { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7087207" diff --git a/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json b/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json index 74f2ecd6b4e..5c5dc0ef20f 100644 --- a/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json +++ b/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0008/" + }, { "type": "WEB", "url": "https://sqlite.org/forum/forumpost/5bcbf4571c" diff --git a/advisories/unreviewed/2023/12/GHSA-rvgg-67r2-wwmp/GHSA-rvgg-67r2-wwmp.json b/advisories/unreviewed/2023/12/GHSA-rvgg-67r2-wwmp/GHSA-rvgg-67r2-wwmp.json index 59d313c0af7..d6dc932bb22 100644 --- a/advisories/unreviewed/2023/12/GHSA-rvgg-67r2-wwmp/GHSA-rvgg-67r2-wwmp.json +++ b/advisories/unreviewed/2023/12/GHSA-rvgg-67r2-wwmp/GHSA-rvgg-67r2-wwmp.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/252048" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0002/" + }, { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7087218" diff --git a/advisories/unreviewed/2023/12/GHSA-v254-5m89-3qf2/GHSA-v254-5m89-3qf2.json b/advisories/unreviewed/2023/12/GHSA-v254-5m89-3qf2/GHSA-v254-5m89-3qf2.json index a3294857741..8de1c65a253 100644 --- a/advisories/unreviewed/2023/12/GHSA-v254-5m89-3qf2/GHSA-v254-5m89-3qf2.json +++ b/advisories/unreviewed/2023/12/GHSA-v254-5m89-3qf2/GHSA-v254-5m89-3qf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v254-5m89-3qf2", - "modified": "2023-12-19T15:30:29Z", + "modified": "2024-01-12T15:30:24Z", "published": "2023-12-13T09:30:32Z", "aliases": [ "CVE-2023-6534" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-23:17.pf.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0007/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-w6g4-j7xw-wrv7/GHSA-w6g4-j7xw-wrv7.json b/advisories/unreviewed/2023/12/GHSA-w6g4-j7xw-wrv7/GHSA-w6g4-j7xw-wrv7.json index aa905f5f65a..b56f07910ba 100644 --- a/advisories/unreviewed/2023/12/GHSA-w6g4-j7xw-wrv7/GHSA-w6g4-j7xw-wrv7.json +++ b/advisories/unreviewed/2023/12/GHSA-w6g4-j7xw-wrv7/GHSA-w6g4-j7xw-wrv7.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/269367" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240112-0003/" + }, { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7087203" diff --git a/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json b/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json new file mode 100644 index 00000000000..bac15b988b1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2pv4-q67j-8w9h/GHSA-2pv4-q67j-8w9h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pv4-q67j-8w9h", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49261" + ], + "details": "The \"tokenKey\" value used in user authorization is visible in the HTML source of the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49261" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json b/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json new file mode 100644 index 00000000000..fa64ec862d7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w7q-mj4w-9cm2", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-6955" + ], + "details": "An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6955" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/432188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-37m4-w5jp-r3px/GHSA-37m4-w5jp-r3px.json b/advisories/unreviewed/2024/01/GHSA-37m4-w5jp-r3px/GHSA-37m4-w5jp-r3px.json new file mode 100644 index 00000000000..8a094166cec --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-37m4-w5jp-r3px/GHSA-37m4-w5jp-r3px.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37m4-w5jp-r3px", + "modified": "2024-01-12T15:30:28Z", + "published": "2024-01-12T15:30:28Z", + "aliases": [ + "CVE-2023-51790" + ], + "details": "Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51790" + }, + { + "type": "WEB", + "url": "https://github.com/Piwigo/AdminTools/issues/21" + }, + { + "type": "WEB", + "url": "https://github.com/Piwigo/Piwigo/issues/2069" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3836-7r6q-99c9/GHSA-3836-7r6q-99c9.json b/advisories/unreviewed/2024/01/GHSA-3836-7r6q-99c9/GHSA-3836-7r6q-99c9.json new file mode 100644 index 00000000000..19472508827 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3836-7r6q-99c9/GHSA-3836-7r6q-99c9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3836-7r6q-99c9", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-51949" + ], + "details": "Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51949" + }, + { + "type": "WEB", + "url": "https://github.com/cui2shark/security/blob/main/Added%20CSRF%20in%20Role%20Controller.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-44hp-hmpq-cgw3/GHSA-44hp-hmpq-cgw3.json b/advisories/unreviewed/2024/01/GHSA-44hp-hmpq-cgw3/GHSA-44hp-hmpq-cgw3.json index a2422602ae7..0d66d22d4b9 100644 --- a/advisories/unreviewed/2024/01/GHSA-44hp-hmpq-cgw3/GHSA-44hp-hmpq-cgw3.json +++ b/advisories/unreviewed/2024/01/GHSA-44hp-hmpq-cgw3/GHSA-44hp-hmpq-cgw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44hp-hmpq-cgw3", - "modified": "2024-01-11T00:30:25Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-40430" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user consent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:48Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4hqq-f6h3-3pgp/GHSA-4hqq-f6h3-3pgp.json b/advisories/unreviewed/2024/01/GHSA-4hqq-f6h3-3pgp/GHSA-4hqq-f6h3-3pgp.json index 2bc2fcaa806..492120ab565 100644 --- a/advisories/unreviewed/2024/01/GHSA-4hqq-f6h3-3pgp/GHSA-4hqq-f6h3-3pgp.json +++ b/advisories/unreviewed/2024/01/GHSA-4hqq-f6h3-3pgp/GHSA-4hqq-f6h3-3pgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hqq-f6h3-3pgp", - "modified": "2024-01-11T00:30:25Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-41994" ], "details": "A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:49Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json index 819b234ffd0..7b4a1357e26 100644 --- a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json +++ b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-90" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-58jj-f9fm-h5qv/GHSA-58jj-f9fm-h5qv.json b/advisories/unreviewed/2024/01/GHSA-58jj-f9fm-h5qv/GHSA-58jj-f9fm-h5qv.json new file mode 100644 index 00000000000..a851eea069f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-58jj-f9fm-h5qv/GHSA-58jj-f9fm-h5qv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58jj-f9fm-h5qv", + "modified": "2024-01-12T15:30:28Z", + "published": "2024-01-12T15:30:28Z", + "aliases": [ + "CVE-2023-51806" + ], + "details": "File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51806" + }, + { + "type": "WEB", + "url": "https://github.com/ujcms/ujcms/issues/8" + }, + { + "type": "WEB", + "url": "https://github.com/ujcms/ujcms" + }, + { + "type": "WEB", + "url": "https://www.ujcms.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5hmw-x4vw-66rw/GHSA-5hmw-x4vw-66rw.json b/advisories/unreviewed/2024/01/GHSA-5hmw-x4vw-66rw/GHSA-5hmw-x4vw-66rw.json index a232c07db4e..aa8064b546e 100644 --- a/advisories/unreviewed/2024/01/GHSA-5hmw-x4vw-66rw/GHSA-5hmw-x4vw-66rw.json +++ b/advisories/unreviewed/2024/01/GHSA-5hmw-x4vw-66rw/GHSA-5hmw-x4vw-66rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hmw-x4vw-66rw", - "modified": "2024-01-11T00:30:26Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:26Z", "aliases": [ "CVE-2023-42929" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:50Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5q5j-r39w-wc64/GHSA-5q5j-r39w-wc64.json b/advisories/unreviewed/2024/01/GHSA-5q5j-r39w-wc64/GHSA-5q5j-r39w-wc64.json new file mode 100644 index 00000000000..79b1a050f8d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5q5j-r39w-wc64/GHSA-5q5j-r39w-wc64.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q5j-r39w-wc64", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-4812" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4812" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2115574" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/424398" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5vwc-p62x-pm8g/GHSA-5vwc-p62x-pm8g.json b/advisories/unreviewed/2024/01/GHSA-5vwc-p62x-pm8g/GHSA-5vwc-p62x-pm8g.json new file mode 100644 index 00000000000..4a757f3de3c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5vwc-p62x-pm8g/GHSA-5vwc-p62x-pm8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vwc-p62x-pm8g", + "modified": "2024-01-12T15:30:29Z", + "published": "2024-01-12T15:30:29Z", + "aliases": [ + "CVE-2023-52026" + ], + "details": "TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52026" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setTelnetCfg/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json b/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json index 8d999900612..b2b280ccb72 100644 --- a/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json +++ b/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66qh-r598-w33q", - "modified": "2024-01-08T12:30:31Z", + "modified": "2024-01-12T15:30:25Z", "published": "2024-01-08T12:30:31Z", "aliases": [ "CVE-2023-5091" ], "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-08T10:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-72pr-8c6x-68jq/GHSA-72pr-8c6x-68jq.json b/advisories/unreviewed/2024/01/GHSA-72pr-8c6x-68jq/GHSA-72pr-8c6x-68jq.json index 3f75eb5d6a4..f3c513fb16d 100644 --- a/advisories/unreviewed/2024/01/GHSA-72pr-8c6x-68jq/GHSA-72pr-8c6x-68jq.json +++ b/advisories/unreviewed/2024/01/GHSA-72pr-8c6x-68jq/GHSA-72pr-8c6x-68jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72pr-8c6x-68jq", - "modified": "2024-01-11T00:30:25Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-42826" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:49Z" diff --git a/advisories/unreviewed/2024/01/GHSA-797c-p7mm-pf4h/GHSA-797c-p7mm-pf4h.json b/advisories/unreviewed/2024/01/GHSA-797c-p7mm-pf4h/GHSA-797c-p7mm-pf4h.json new file mode 100644 index 00000000000..52b5d70d522 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-797c-p7mm-pf4h/GHSA-797c-p7mm-pf4h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-797c-p7mm-pf4h", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-2030" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2030" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1929929" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/407252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json b/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json new file mode 100644 index 00000000000..33150f96baf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gxp-rm68-3f88", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49258" + ], + "details": "User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at \"/gui/terminal_tool.cgi\" in the \"data\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49258" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json b/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json new file mode 100644 index 00000000000..5054d56a5cd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8549-4c5j-x7g2", + "modified": "2024-01-12T15:30:31Z", + "published": "2024-01-12T15:30:31Z", + "aliases": [ + "CVE-2023-0437" + ], + "details": "When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0437" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/CDRIVER-4747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8p4h-69c2-3352/GHSA-8p4h-69c2-3352.json b/advisories/unreviewed/2024/01/GHSA-8p4h-69c2-3352/GHSA-8p4h-69c2-3352.json new file mode 100644 index 00000000000..e68fae1c673 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8p4h-69c2-3352/GHSA-8p4h-69c2-3352.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p4h-69c2-3352", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49262" + ], + "details": "The authentication mechanism can be bypassed by overflowing the value of the Cookie \"authentication\" field, provided there is an active user session.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49262" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9h8x-j6vr-8v9f/GHSA-9h8x-j6vr-8v9f.json b/advisories/unreviewed/2024/01/GHSA-9h8x-j6vr-8v9f/GHSA-9h8x-j6vr-8v9f.json index 3e452891058..5bfdfd2a59c 100644 --- a/advisories/unreviewed/2024/01/GHSA-9h8x-j6vr-8v9f/GHSA-9h8x-j6vr-8v9f.json +++ b/advisories/unreviewed/2024/01/GHSA-9h8x-j6vr-8v9f/GHSA-9h8x-j6vr-8v9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9h8x-j6vr-8v9f", - "modified": "2024-01-11T00:30:25Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-41987" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:49Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9pqq-c77f-g45f/GHSA-9pqq-c77f-g45f.json b/advisories/unreviewed/2024/01/GHSA-9pqq-c77f-g45f/GHSA-9pqq-c77f-g45f.json new file mode 100644 index 00000000000..5567ff0736d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9pqq-c77f-g45f/GHSA-9pqq-c77f-g45f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pqq-c77f-g45f", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49254" + ], + "details": "Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the \"destination\" field of the network test tools. This is similar to the vulnerability CVE-2021-28151 mitigated on the user interface level by blacklisting characters with JavaScript, however, it can still be exploited by sending POST requests directly.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49254" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cfv4-qcjx-m9hp/GHSA-cfv4-qcjx-m9hp.json b/advisories/unreviewed/2024/01/GHSA-cfv4-qcjx-m9hp/GHSA-cfv4-qcjx-m9hp.json index 48da5b86e2d..7b4a869b1a6 100644 --- a/advisories/unreviewed/2024/01/GHSA-cfv4-qcjx-m9hp/GHSA-cfv4-qcjx-m9hp.json +++ b/advisories/unreviewed/2024/01/GHSA-cfv4-qcjx-m9hp/GHSA-cfv4-qcjx-m9hp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfv4-qcjx-m9hp", - "modified": "2024-01-11T00:30:26Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:26Z", "aliases": [ "CVE-2023-42876" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to a denial-of-service or potentially disclose memory contents.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:50Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cj5p-x443-5mhx/GHSA-cj5p-x443-5mhx.json b/advisories/unreviewed/2024/01/GHSA-cj5p-x443-5mhx/GHSA-cj5p-x443-5mhx.json index 3220cda5418..164e2ae83d3 100644 --- a/advisories/unreviewed/2024/01/GHSA-cj5p-x443-5mhx/GHSA-cj5p-x443-5mhx.json +++ b/advisories/unreviewed/2024/01/GHSA-cj5p-x443-5mhx/GHSA-cj5p-x443-5mhx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj5p-x443-5mhx", - "modified": "2024-01-11T00:30:26Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:26Z", "aliases": [ "CVE-2023-42933" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to gain elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:50Z" diff --git a/advisories/unreviewed/2024/01/GHSA-frfj-qx44-ggmv/GHSA-frfj-qx44-ggmv.json b/advisories/unreviewed/2024/01/GHSA-frfj-qx44-ggmv/GHSA-frfj-qx44-ggmv.json new file mode 100644 index 00000000000..e525495eea9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-frfj-qx44-ggmv/GHSA-frfj-qx44-ggmv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frfj-qx44-ggmv", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49259" + ], + "details": "The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49259" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json b/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json new file mode 100644 index 00000000000..cc697801202 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw6m-hgqv-hr8c", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49255" + ], + "details": "The router console is accessible without authentication at \"data\" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of the authenticated one. If the logged in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49255" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mgg5-84cv-fc3c/GHSA-mgg5-84cv-fc3c.json b/advisories/unreviewed/2024/01/GHSA-mgg5-84cv-fc3c/GHSA-mgg5-84cv-fc3c.json new file mode 100644 index 00000000000..e9743ceab45 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mgg5-84cv-fc3c/GHSA-mgg5-84cv-fc3c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgg5-84cv-fc3c", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-7028" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7028" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2293343" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/436084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mm6p-hjx4-8rx3/GHSA-mm6p-hjx4-8rx3.json b/advisories/unreviewed/2024/01/GHSA-mm6p-hjx4-8rx3/GHSA-mm6p-hjx4-8rx3.json new file mode 100644 index 00000000000..be4ef506194 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mm6p-hjx4-8rx3/GHSA-mm6p-hjx4-8rx3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm6p-hjx4-8rx3", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49253" + ], + "details": "Root user password is hardcoded into the device and cannot be changed in the user interface.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49253" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v473-p3hx-3j46/GHSA-v473-p3hx-3j46.json b/advisories/unreviewed/2024/01/GHSA-v473-p3hx-3j46/GHSA-v473-p3hx-3j46.json new file mode 100644 index 00000000000..2d132dc5623 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v473-p3hx-3j46/GHSA-v473-p3hx-3j46.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v473-p3hx-3j46", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49257" + ], + "details": "An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49257" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json b/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json new file mode 100644 index 00000000000..5304c12584c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v64q-49fj-whh5", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49260" + ], + "details": "An XSS attack can be performed by changing the MOTD banner and pointing the victim to the \"terminal_tool.cgi\" path. It can be used together with the vulnerability CVE-2023-49255.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49260" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wcp2-36p3-v9xg/GHSA-wcp2-36p3-v9xg.json b/advisories/unreviewed/2024/01/GHSA-wcp2-36p3-v9xg/GHSA-wcp2-36p3-v9xg.json index fbfd90c811a..8ed4de0c428 100644 --- a/advisories/unreviewed/2024/01/GHSA-wcp2-36p3-v9xg/GHSA-wcp2-36p3-v9xg.json +++ b/advisories/unreviewed/2024/01/GHSA-wcp2-36p3-v9xg/GHSA-wcp2-36p3-v9xg.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://github.com/wuzhicms/wuzhicms/issues/208" + }, + { + "type": "WEB", + "url": "https://gist.github.com/n0Sleeper/544b38c95715b13efadab329692c8aea" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-wq5j-2jwc-3h38/GHSA-wq5j-2jwc-3h38.json b/advisories/unreviewed/2024/01/GHSA-wq5j-2jwc-3h38/GHSA-wq5j-2jwc-3h38.json index ece5344f74a..d2b4871dba2 100644 --- a/advisories/unreviewed/2024/01/GHSA-wq5j-2jwc-3h38/GHSA-wq5j-2jwc-3h38.json +++ b/advisories/unreviewed/2024/01/GHSA-wq5j-2jwc-3h38/GHSA-wq5j-2jwc-3h38.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq5j-2jwc-3h38", - "modified": "2024-01-09T03:30:22Z", + "modified": "2024-01-12T15:30:25Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2023-51717" ], "details": "Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-09T02:15:45Z" diff --git a/advisories/unreviewed/2024/01/GHSA-x7v8-7cpc-hv73/GHSA-x7v8-7cpc-hv73.json b/advisories/unreviewed/2024/01/GHSA-x7v8-7cpc-hv73/GHSA-x7v8-7cpc-hv73.json new file mode 100644 index 00000000000..b169e2310b6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x7v8-7cpc-hv73/GHSA-x7v8-7cpc-hv73.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7v8-7cpc-hv73", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-5356" + ], + "details": "Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5356" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2188868" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/427154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xqfv-g7r7-7v7j/GHSA-xqfv-g7r7-7v7j.json b/advisories/unreviewed/2024/01/GHSA-xqfv-g7r7-7v7j/GHSA-xqfv-g7r7-7v7j.json index 0d9fdc4c781..97003077dfe 100644 --- a/advisories/unreviewed/2024/01/GHSA-xqfv-g7r7-7v7j/GHSA-xqfv-g7r7-7v7j.json +++ b/advisories/unreviewed/2024/01/GHSA-xqfv-g7r7-7v7j/GHSA-xqfv-g7r7-7v7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqfv-g7r7-7v7j", - "modified": "2024-01-11T00:30:25Z", + "modified": "2024-01-12T15:30:26Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-40411" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-10T22:15:48Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xw39-57rx-4hr5/GHSA-xw39-57rx-4hr5.json b/advisories/unreviewed/2024/01/GHSA-xw39-57rx-4hr5/GHSA-xw39-57rx-4hr5.json new file mode 100644 index 00000000000..b0398ddf3ca --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xw39-57rx-4hr5/GHSA-xw39-57rx-4hr5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw39-57rx-4hr5", + "modified": "2024-01-12T15:30:32Z", + "published": "2024-01-12T15:30:32Z", + "aliases": [ + "CVE-2023-49256" + ], + "details": "It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49256" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-49253/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-49253/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T15:15:09Z" + } +} \ No newline at end of file