From 3497398150cb58f6a9abe9366a5bb1fa4bfdba13 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 13 May 2023 03:31:39 +0000 Subject: [PATCH] Publish Advisories GHSA-29ww-cjvv-3x39 GHSA-36r6-mm7x-rqmm GHSA-4wv9-rjh2-6fhw GHSA-5h8h-fq9x-xjw5 GHSA-629m-cwhq-hcx4 GHSA-9vv9-vx4p-wx8p GHSA-ccrw-rwvf-gh8w GHSA-cpgg-rjvm-32fx GHSA-fc7x-6gvp-3rvc GHSA-gwcj-j6gp-p955 GHSA-j23x-w7m9-8c47 GHSA-j4q3-cq76-4p2r GHSA-jwhc-74h7-9587 GHSA-r9vr-4rjx-2pxv GHSA-rxv4-3q25-g562 GHSA-wq24-fr27-25xc --- .../2023/05/GHSA-29ww-cjvv-3x39/GHSA-29ww-cjvv-3x39.json | 7 +++++-- .../2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json | 9 ++++++--- .../2023/05/GHSA-4wv9-rjh2-6fhw/GHSA-4wv9-rjh2-6fhw.json | 9 ++++++--- .../2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json | 7 +++++-- .../2023/05/GHSA-629m-cwhq-hcx4/GHSA-629m-cwhq-hcx4.json | 7 +++++-- .../2023/05/GHSA-9vv9-vx4p-wx8p/GHSA-9vv9-vx4p-wx8p.json | 7 +++++-- .../2023/05/GHSA-ccrw-rwvf-gh8w/GHSA-ccrw-rwvf-gh8w.json | 7 +++++-- .../2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json | 9 ++++++--- .../2023/05/GHSA-fc7x-6gvp-3rvc/GHSA-fc7x-6gvp-3rvc.json | 9 ++++++--- .../2023/05/GHSA-gwcj-j6gp-p955/GHSA-gwcj-j6gp-p955.json | 9 ++++++--- .../2023/05/GHSA-j23x-w7m9-8c47/GHSA-j23x-w7m9-8c47.json | 7 +++++-- .../2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json | 7 +++++-- .../2023/05/GHSA-jwhc-74h7-9587/GHSA-jwhc-74h7-9587.json | 9 ++++++--- .../2023/05/GHSA-r9vr-4rjx-2pxv/GHSA-r9vr-4rjx-2pxv.json | 7 +++++-- .../2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json | 7 +++++-- .../2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json | 7 +++++-- 16 files changed, 86 insertions(+), 38 deletions(-) diff --git a/advisories/unreviewed/2023/05/GHSA-29ww-cjvv-3x39/GHSA-29ww-cjvv-3x39.json b/advisories/unreviewed/2023/05/GHSA-29ww-cjvv-3x39/GHSA-29ww-cjvv-3x39.json index 3c75f91bcee..ae5244af3d1 100644 --- a/advisories/unreviewed/2023/05/GHSA-29ww-cjvv-3x39/GHSA-29ww-cjvv-3x39.json +++ b/advisories/unreviewed/2023/05/GHSA-29ww-cjvv-3x39/GHSA-29ww-cjvv-3x39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29ww-cjvv-3x39", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28181" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json b/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json index b0de7d3cdda..626573cd216 100644 --- a/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json +++ b/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36r6-mm7x-rqmm", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28200" ], "details": "A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-4wv9-rjh2-6fhw/GHSA-4wv9-rjh2-6fhw.json b/advisories/unreviewed/2023/05/GHSA-4wv9-rjh2-6fhw/GHSA-4wv9-rjh2-6fhw.json index 7680d289b11..69b7d936cbd 100644 --- a/advisories/unreviewed/2023/05/GHSA-4wv9-rjh2-6fhw/GHSA-4wv9-rjh2-6fhw.json +++ b/advisories/unreviewed/2023/05/GHSA-4wv9-rjh2-6fhw/GHSA-4wv9-rjh2-6fhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wv9-rjh2-6fhw", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27946" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json b/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json index c68dbbbede5..c76fc308a92 100644 --- a/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json +++ b/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h8h-fq9x-xjw5", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27945" ], "details": "This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3. A sandboxed app may be able to collect system logs", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-629m-cwhq-hcx4/GHSA-629m-cwhq-hcx4.json b/advisories/unreviewed/2023/05/GHSA-629m-cwhq-hcx4/GHSA-629m-cwhq-hcx4.json index 85be5fa53b8..8345b19da57 100644 --- a/advisories/unreviewed/2023/05/GHSA-629m-cwhq-hcx4/GHSA-629m-cwhq-hcx4.json +++ b/advisories/unreviewed/2023/05/GHSA-629m-cwhq-hcx4/GHSA-629m-cwhq-hcx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-629m-cwhq-hcx4", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28190" ], "details": "A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sensitive data", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-9vv9-vx4p-wx8p/GHSA-9vv9-vx4p-wx8p.json b/advisories/unreviewed/2023/05/GHSA-9vv9-vx4p-wx8p/GHSA-9vv9-vx4p-wx8p.json index 0c94a939da9..622f8940abf 100644 --- a/advisories/unreviewed/2023/05/GHSA-9vv9-vx4p-wx8p/GHSA-9vv9-vx4p-wx8p.json +++ b/advisories/unreviewed/2023/05/GHSA-9vv9-vx4p-wx8p/GHSA-9vv9-vx4p-wx8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vv9-vx4p-wx8p", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28189" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to view sensitive information", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-ccrw-rwvf-gh8w/GHSA-ccrw-rwvf-gh8w.json b/advisories/unreviewed/2023/05/GHSA-ccrw-rwvf-gh8w/GHSA-ccrw-rwvf-gh8w.json index e554a01affb..dc5fc294152 100644 --- a/advisories/unreviewed/2023/05/GHSA-ccrw-rwvf-gh8w/GHSA-ccrw-rwvf-gh8w.json +++ b/advisories/unreviewed/2023/05/GHSA-ccrw-rwvf-gh8w/GHSA-ccrw-rwvf-gh8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccrw-rwvf-gh8w", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28180" ], "details": "A denial-of-service issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. A user in a privileged network position may be able to cause a denial-of-service", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json b/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json index ad6e11caacb..24decb61e79 100644 --- a/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json +++ b/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpgg-rjvm-32fx", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27961" ], "details": "Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, watchOS 9.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. Importing a maliciously crafted calendar invitation may exfiltrate user information", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-fc7x-6gvp-3rvc/GHSA-fc7x-6gvp-3rvc.json b/advisories/unreviewed/2023/05/GHSA-fc7x-6gvp-3rvc/GHSA-fc7x-6gvp-3rvc.json index 6390fea834c..5a75647c2b7 100644 --- a/advisories/unreviewed/2023/05/GHSA-fc7x-6gvp-3rvc/GHSA-fc7x-6gvp-3rvc.json +++ b/advisories/unreviewed/2023/05/GHSA-fc7x-6gvp-3rvc/GHSA-fc7x-6gvp-3rvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc7x-6gvp-3rvc", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27952" ], "details": "A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-gwcj-j6gp-p955/GHSA-gwcj-j6gp-p955.json b/advisories/unreviewed/2023/05/GHSA-gwcj-j6gp-p955/GHSA-gwcj-j6gp-p955.json index 4487b94c3d1..17597e15570 100644 --- a/advisories/unreviewed/2023/05/GHSA-gwcj-j6gp-p955/GHSA-gwcj-j6gp-p955.json +++ b/advisories/unreviewed/2023/05/GHSA-gwcj-j6gp-p955/GHSA-gwcj-j6gp-p955.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwcj-j6gp-p955", - "modified": "2023-05-08T21:31:08Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:08Z", "aliases": [ "CVE-2023-28192" ], "details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-j23x-w7m9-8c47/GHSA-j23x-w7m9-8c47.json b/advisories/unreviewed/2023/05/GHSA-j23x-w7m9-8c47/GHSA-j23x-w7m9-8c47.json index c6e0b6e77dc..7ff09c7dc61 100644 --- a/advisories/unreviewed/2023/05/GHSA-j23x-w7m9-8c47/GHSA-j23x-w7m9-8c47.json +++ b/advisories/unreviewed/2023/05/GHSA-j23x-w7m9-8c47/GHSA-j23x-w7m9-8c47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j23x-w7m9-8c47", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27958" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json b/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json index 0a8e1626f5d..c5d4a1f4868 100644 --- a/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json +++ b/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4q3-cq76-4p2r", - "modified": "2023-05-08T21:31:06Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:06Z", "aliases": [ "CVE-2023-27932" ], "details": "This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. Processing maliciously crafted web content may bypass Same Origin Policy", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-jwhc-74h7-9587/GHSA-jwhc-74h7-9587.json b/advisories/unreviewed/2023/05/GHSA-jwhc-74h7-9587/GHSA-jwhc-74h7-9587.json index a98986a2ee3..d904564acca 100644 --- a/advisories/unreviewed/2023/05/GHSA-jwhc-74h7-9587/GHSA-jwhc-74h7-9587.json +++ b/advisories/unreviewed/2023/05/GHSA-jwhc-74h7-9587/GHSA-jwhc-74h7-9587.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwhc-74h7-9587", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27949" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-r9vr-4rjx-2pxv/GHSA-r9vr-4rjx-2pxv.json b/advisories/unreviewed/2023/05/GHSA-r9vr-4rjx-2pxv/GHSA-r9vr-4rjx-2pxv.json index efd71e6b99c..c0bbbdba7e2 100644 --- a/advisories/unreviewed/2023/05/GHSA-r9vr-4rjx-2pxv/GHSA-r9vr-4rjx-2pxv.json +++ b/advisories/unreviewed/2023/05/GHSA-r9vr-4rjx-2pxv/GHSA-r9vr-4rjx-2pxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r9vr-4rjx-2pxv", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27951" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json b/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json index ac39752b4af..94722d8afeb 100644 --- a/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json +++ b/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxv4-3q25-g562", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27944" ], "details": "This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json b/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json index 49eb31b8c5e..aa65efb77c0 100644 --- a/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json +++ b/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq24-fr27-25xc", - "modified": "2023-05-08T21:31:06Z", + "modified": "2023-05-13T03:30:15Z", "published": "2023-05-08T21:31:06Z", "aliases": [ "CVE-2023-27933" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, watchOS 9.4, tvOS 16.4, iOS 16.4 and iPadOS 16.4. An app with root privileges may be able to execute arbitrary code with kernel privileges", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [