Publish Advisories

GHSA-wv3p-jvhj-v4jc
GHSA-m4q9-68f2-5wc6
GHSA-22q6-rw64-5gjj
GHSA-23xf-gc3r-v6rr
GHSA-3pfh-89x5-83xr
GHSA-46hm-73m4-wgrq
GHSA-78g4-c5r9-6gh7
GHSA-984g-wqfw-h3fh
GHSA-c7wh-g26h-jp33
GHSA-f8q5-x346-4rf5
GHSA-gg2h-rxjc-7jx5
GHSA-ggvf-r5vr-g67r
GHSA-jg83-rjrf-gwrc
GHSA-v79h-64cf-gw4x
GHSA-w365-qpc6-8w95
GHSA-w9wr-4926-mh54
GHSA-xrgq-7wvh-c25q
This commit is contained in:
advisory-database[bot]
2023-07-11 00:34:40 +00:00
parent bf4f0c29f8
commit 37843a5271
17 changed files with 272 additions and 18 deletions
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47927"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00011.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4q9-68f2-5wc6",
"modified": "2023-06-28T21:30:29Z",
"modified": "2023-07-11T00:33:18Z",
"published": "2023-06-28T21:30:29Z",
"aliases": [
"CVE-2021-25827"
],
"details": "Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22q6-rw64-5gjj",
"modified": "2023-07-05T06:30:28Z",
"modified": "2023-07-11T00:33:18Z",
"published": "2023-07-05T06:30:28Z",
"aliases": [
"CVE-2023-35786"
],
"details": "Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23xf-gc3r-v6rr",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-30956"
],
"details": "A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30956"
},
{
"type": "WEB",
"url": "https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46hm-73m4-wgrq",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-30963"
],
"details": "A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30963"
},
{
"type": "WEB",
"url": "https://palantir.safebase.us/?tcuUid=3c6b63b7-fb67-4202-a94a-9c83515efb8a"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"severity": null,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-984g-wqfw-h3fh",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-24489"
],
"details": "\nA vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24489"
},
{
"type": "WEB",
"url": "https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7wh-g26h-jp33",
"modified": "2023-07-05T15:30:24Z",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-05T15:30:24Z",
"aliases": [
"CVE-2021-46891"
],
"details": "Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-863"
],
"severity": null,
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg2h-rxjc-7jx5",
"modified": "2023-07-05T12:30:16Z",
"modified": "2023-07-11T00:33:18Z",
"published": "2023-07-05T12:30:16Z",
"aliases": [
"CVE-2021-46890"
],
"details": "Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": null,
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg83-rjrf-gwrc",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-24490"
],
"details": "Users with only access to launch VDA applications can launch an unauthorized desktop\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24490"
},
{
"type": "WEB",
"url": "https://support.citrix.com/article/CTX559370/windows-and-linux-virtual-delivery-agent-for-cvad-and-citrix-daas-security-bulletin-cve202324490"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-704"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w365-qpc6-8w95",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-30960"
],
"details": "A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30960"
},
{
"type": "WEB",
"url": "https://palantir.safebase.us/?tcuUid=115d9bf4-201f-4cfe-b2fc-219e3a2d945b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9wr-4926-mh54",
"modified": "2023-07-05T15:30:24Z",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-05T15:30:24Z",
"aliases": [
"CVE-2023-35972"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrgq-7wvh-c25q",
"modified": "2023-07-11T00:33:19Z",
"published": "2023-07-11T00:33:19Z",
"aliases": [
"CVE-2023-3608"
],
"details": "A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3608"
},
{
"type": "WEB",
"url": "https://github.com/cq535454518/cve/blob/main/RG-BCR810W.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.233477"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.233477"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}