From 32957f83b298011239fe0d5bfd2ec095f44457fd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Nov 2023 03:31:34 +0000 Subject: [PATCH] Publish Advisories GHSA-frgf-8jr5-j2jv GHSA-3c2c-v8x8-23vv GHSA-9qr8-h5jr-2gmw GHSA-6589-j38p-mm8c GHSA-2gg2-2h66-3xcr GHSA-2xpc-6r4r-v2hh GHSA-4mgj-2pcm-grp4 GHSA-7vf8-rmp2-v23x GHSA-hw7v-x4gj-9m6p GHSA-m3mr-93pv-j56f GHSA-mhqf-p484-rpwx GHSA-qjvv-485h-mp82 GHSA-qr7v-3hq9-cr46 GHSA-wjmw-g7qq-g6h2 GHSA-wx7j-q638-34vf --- .../GHSA-frgf-8jr5-j2jv.json | 4 +++ .../GHSA-3c2c-v8x8-23vv.json | 8 +++++ .../GHSA-9qr8-h5jr-2gmw.json | 4 +++ .../GHSA-6589-j38p-mm8c.json | 24 ++++++++++--- .../GHSA-2gg2-2h66-3xcr.json | 13 ++++--- .../GHSA-2xpc-6r4r-v2hh.json | 2 +- .../GHSA-4mgj-2pcm-grp4.json | 13 ++++--- .../GHSA-7vf8-rmp2-v23x.json | 35 +++++++++++++++++++ .../GHSA-hw7v-x4gj-9m6p.json | 13 ++++--- .../GHSA-m3mr-93pv-j56f.json | 35 +++++++++++++++++++ .../GHSA-mhqf-p484-rpwx.json | 35 +++++++++++++++++++ .../GHSA-qjvv-485h-mp82.json | 4 +-- .../GHSA-qr7v-3hq9-cr46.json | 35 +++++++++++++++++++ .../GHSA-wjmw-g7qq-g6h2.json | 11 +++--- .../GHSA-wx7j-q638-34vf.json | 11 +++--- 15 files changed, 217 insertions(+), 30 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json diff --git a/advisories/github-reviewed/2023/10/GHSA-frgf-8jr5-j2jv/GHSA-frgf-8jr5-j2jv.json b/advisories/github-reviewed/2023/10/GHSA-frgf-8jr5-j2jv/GHSA-frgf-8jr5-j2jv.json index 708d82953ee..bb01bbd17dc 100644 --- a/advisories/github-reviewed/2023/10/GHSA-frgf-8jr5-j2jv/GHSA-frgf-8jr5-j2jv.json +++ b/advisories/github-reviewed/2023/10/GHSA-frgf-8jr5-j2jv/GHSA-frgf-8jr5-j2jv.json @@ -75,6 +75,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rmagick/CVE-2023-5349.yml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-3c2c-v8x8-23vv/GHSA-3c2c-v8x8-23vv.json b/advisories/unreviewed/2022/05/GHSA-3c2c-v8x8-23vv/GHSA-3c2c-v8x8-23vv.json index 4a912fe27a5..cd552329d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c2c-v8x8-23vv/GHSA-3c2c-v8x8-23vv.json +++ b/advisories/unreviewed/2022/05/GHSA-3c2c-v8x8-23vv/GHSA-3c2c-v8x8-23vv.json @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0883" }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/91163" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/security-bulletin-power-hardware-management-console-hmc-cve-2014-0883" + }, { "type": "WEB", "url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1019972" diff --git a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json index 228a69dc2f8..9aacdde2cd8 100644 --- a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json +++ b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2023-0001" }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/08/10" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/11/08/2" diff --git a/advisories/unreviewed/2023/09/GHSA-6589-j38p-mm8c/GHSA-6589-j38p-mm8c.json b/advisories/unreviewed/2023/09/GHSA-6589-j38p-mm8c/GHSA-6589-j38p-mm8c.json index 56ce278118b..8b084cf3fc7 100644 --- a/advisories/unreviewed/2023/09/GHSA-6589-j38p-mm8c/GHSA-6589-j38p-mm8c.json +++ b/advisories/unreviewed/2023/09/GHSA-6589-j38p-mm8c/GHSA-6589-j38p-mm8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6589-j38p-mm8c", - "modified": "2023-09-27T15:30:39Z", + "modified": "2023-11-09T03:30:18Z", "published": "2023-09-27T15:30:39Z", "aliases": [ "CVE-2023-5157" @@ -21,6 +21,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5157" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5683" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5684" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6821" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6822" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5157" @@ -32,11 +48,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-09-27T15:19:41Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2gg2-2h66-3xcr/GHSA-2gg2-2h66-3xcr.json b/advisories/unreviewed/2023/11/GHSA-2gg2-2h66-3xcr/GHSA-2gg2-2h66-3xcr.json index 58675c02d54..e4ba6f305b5 100644 --- a/advisories/unreviewed/2023/11/GHSA-2gg2-2h66-3xcr/GHSA-2gg2-2h66-3xcr.json +++ b/advisories/unreviewed/2023/11/GHSA-2gg2-2h66-3xcr/GHSA-2gg2-2h66-3xcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gg2-2h66-3xcr", - "modified": "2023-11-02T00:30:32Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-02T00:30:32Z", "aliases": [ "CVE-2023-44025" ], "details": "SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2xpc-6r4r-v2hh/GHSA-2xpc-6r4r-v2hh.json b/advisories/unreviewed/2023/11/GHSA-2xpc-6r4r-v2hh/GHSA-2xpc-6r4r-v2hh.json index 80456de35ef..c18eb2691c2 100644 --- a/advisories/unreviewed/2023/11/GHSA-2xpc-6r4r-v2hh/GHSA-2xpc-6r4r-v2hh.json +++ b/advisories/unreviewed/2023/11/GHSA-2xpc-6r4r-v2hh/GHSA-2xpc-6r4r-v2hh.json @@ -33,6 +33,6 @@ "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T17:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json b/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json index 2391bbe9e28..4e4f3e88502 100644 --- a/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json +++ b/advisories/unreviewed/2023/11/GHSA-4mgj-2pcm-grp4/GHSA-4mgj-2pcm-grp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mgj-2pcm-grp4", - "modified": "2023-11-02T00:30:32Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-02T00:30:32Z", "aliases": [ "CVE-2023-44954" ], "details": "Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T23:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json b/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json new file mode 100644 index 00000000000..23815376cb9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vf8-rmp2-v23x", + "modified": "2023-11-09T03:30:19Z", + "published": "2023-11-09T03:30:19Z", + "aliases": [ + "CVE-2023-47007" + ], + "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_391B8 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47007" + }, + { + "type": "WEB", + "url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/2/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hw7v-x4gj-9m6p/GHSA-hw7v-x4gj-9m6p.json b/advisories/unreviewed/2023/11/GHSA-hw7v-x4gj-9m6p/GHSA-hw7v-x4gj-9m6p.json index b5d782a1fb0..f665e9269a0 100644 --- a/advisories/unreviewed/2023/11/GHSA-hw7v-x4gj-9m6p/GHSA-hw7v-x4gj-9m6p.json +++ b/advisories/unreviewed/2023/11/GHSA-hw7v-x4gj-9m6p/GHSA-hw7v-x4gj-9m6p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw7v-x4gj-9m6p", - "modified": "2023-11-01T21:30:19Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-01T21:30:19Z", "aliases": [ "CVE-2023-46482" ], "details": "SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T19:15:45Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json b/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json new file mode 100644 index 00000000000..a7bc7acfde9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3mr-93pv-j56f", + "modified": "2023-11-09T03:30:19Z", + "published": "2023-11-09T03:30:19Z", + "aliases": [ + "CVE-2023-47006" + ], + "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ipaddr field in the sub_6FC74 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47006" + }, + { + "type": "WEB", + "url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/1/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json b/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json new file mode 100644 index 00000000000..e8cfe0490b5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhqf-p484-rpwx", + "modified": "2023-11-09T03:30:19Z", + "published": "2023-11-09T03:30:19Z", + "aliases": [ + "CVE-2023-47005" + ], + "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_ln 2C318 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47005" + }, + { + "type": "WEB", + "url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/3/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qjvv-485h-mp82/GHSA-qjvv-485h-mp82.json b/advisories/unreviewed/2023/11/GHSA-qjvv-485h-mp82/GHSA-qjvv-485h-mp82.json index dc1fe101d09..acf7d8c6421 100644 --- a/advisories/unreviewed/2023/11/GHSA-qjvv-485h-mp82/GHSA-qjvv-485h-mp82.json +++ b/advisories/unreviewed/2023/11/GHSA-qjvv-485h-mp82/GHSA-qjvv-485h-mp82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjvv-485h-mp82", - "modified": "2023-11-02T00:30:32Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-02T00:30:32Z", "aliases": [ "CVE-2023-45201" @@ -37,6 +37,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T22:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json b/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json new file mode 100644 index 00000000000..93f1a31ed2c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr7v-3hq9-cr46", + "modified": "2023-11-09T03:30:19Z", + "published": "2023-11-09T03:30:19Z", + "aliases": [ + "CVE-2023-47008" + ], + "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the ifname field in the sub_4CCE4 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47008" + }, + { + "type": "WEB", + "url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/4/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json b/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json index 89c94496614..d2bd94d92bc 100644 --- a/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json +++ b/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjmw-g7qq-g6h2", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5766" ], "details": "\n\nA remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T18:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wx7j-q638-34vf/GHSA-wx7j-q638-34vf.json b/advisories/unreviewed/2023/11/GHSA-wx7j-q638-34vf/GHSA-wx7j-q638-34vf.json index 4b400487782..fcbef9ee7e2 100644 --- a/advisories/unreviewed/2023/11/GHSA-wx7j-q638-34vf/GHSA-wx7j-q638-34vf.json +++ b/advisories/unreviewed/2023/11/GHSA-wx7j-q638-34vf/GHSA-wx7j-q638-34vf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx7j-q638-34vf", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-09T03:30:19Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5765" ], "details": "Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T18:15:10Z" } } \ No newline at end of file