diff --git a/advisories/unreviewed/2023/07/GHSA-2cv5-qvq3-6276/GHSA-2cv5-qvq3-6276.json b/advisories/unreviewed/2023/07/GHSA-2cv5-qvq3-6276/GHSA-2cv5-qvq3-6276.json new file mode 100644 index 00000000000..162d117d859 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2cv5-qvq3-6276/GHSA-2cv5-qvq3-6276.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cv5-qvq3-6276", + "modified": "2023-07-08T09:30:26Z", + "published": "2023-07-08T09:30:26Z", + "aliases": [ + "CVE-2023-3552" + ], + "details": "Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3552" + }, + { + "type": "WEB", + "url": "https://github.com/nilsteampassnet/teampass/commit/8acb4dacc2d008a4186a4e13cc143e978f113955" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/aeb2f43f-0602-4ac6-9685-273e87ff4ded" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2rhg-hqq9-8xjh/GHSA-2rhg-hqq9-8xjh.json b/advisories/unreviewed/2023/07/GHSA-2rhg-hqq9-8xjh/GHSA-2rhg-hqq9-8xjh.json new file mode 100644 index 00000000000..9dd17f9906e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2rhg-hqq9-8xjh/GHSA-2rhg-hqq9-8xjh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rhg-hqq9-8xjh", + "modified": "2023-07-08T09:30:27Z", + "published": "2023-07-08T09:30:27Z", + "aliases": [ + "CVE-2023-3553" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3553" + }, + { + "type": "WEB", + "url": "https://github.com/nilsteampassnet/teampass/commit/e9f90b746fdde135da3c7fbe4fa22fe2bd32e66b" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/857f002a-2794-4807-aa5d-2f340de01870" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-97hm-2mfr-2p97/GHSA-97hm-2mfr-2p97.json b/advisories/unreviewed/2023/07/GHSA-97hm-2mfr-2p97/GHSA-97hm-2mfr-2p97.json new file mode 100644 index 00000000000..28f3bb5a270 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-97hm-2mfr-2p97/GHSA-97hm-2mfr-2p97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97hm-2mfr-2p97", + "modified": "2023-07-08T09:30:24Z", + "published": "2023-07-08T09:30:24Z", + "aliases": [ + "CVE-2023-3551" + ], + "details": " Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3551" + }, + { + "type": "WEB", + "url": "https://github.com/nilsteampassnet/teampass/commit/cc6abc76aa46ed4a27736c1d2f21e432a5d54e6f" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/cf8878ff-6cd9-49be-b313-7ac2a94fc7f7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file