diff --git a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json index 6b4b5cdcd03..d49a2d423fd 100644 --- a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json +++ b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47927" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00011.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/" diff --git a/advisories/unreviewed/2023/06/GHSA-m4q9-68f2-5wc6/GHSA-m4q9-68f2-5wc6.json b/advisories/unreviewed/2023/06/GHSA-m4q9-68f2-5wc6/GHSA-m4q9-68f2-5wc6.json index 818482218cd..0171aee447f 100644 --- a/advisories/unreviewed/2023/06/GHSA-m4q9-68f2-5wc6/GHSA-m4q9-68f2-5wc6.json +++ b/advisories/unreviewed/2023/06/GHSA-m4q9-68f2-5wc6/GHSA-m4q9-68f2-5wc6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4q9-68f2-5wc6", - "modified": "2023-06-28T21:30:29Z", + "modified": "2023-07-11T00:33:18Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2021-25827" ], "details": "Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-22q6-rw64-5gjj/GHSA-22q6-rw64-5gjj.json b/advisories/unreviewed/2023/07/GHSA-22q6-rw64-5gjj/GHSA-22q6-rw64-5gjj.json index ecb2b33737b..80c8acd1759 100644 --- a/advisories/unreviewed/2023/07/GHSA-22q6-rw64-5gjj/GHSA-22q6-rw64-5gjj.json +++ b/advisories/unreviewed/2023/07/GHSA-22q6-rw64-5gjj/GHSA-22q6-rw64-5gjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22q6-rw64-5gjj", - "modified": "2023-07-05T06:30:28Z", + "modified": "2023-07-11T00:33:18Z", "published": "2023-07-05T06:30:28Z", "aliases": [ "CVE-2023-35786" ], "details": "Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-23xf-gc3r-v6rr/GHSA-23xf-gc3r-v6rr.json b/advisories/unreviewed/2023/07/GHSA-23xf-gc3r-v6rr/GHSA-23xf-gc3r-v6rr.json new file mode 100644 index 00000000000..3266a5b7c44 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-23xf-gc3r-v6rr/GHSA-23xf-gc3r-v6rr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23xf-gc3r-v6rr", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-30956" + ], + "details": "A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30956" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3pfh-89x5-83xr/GHSA-3pfh-89x5-83xr.json b/advisories/unreviewed/2023/07/GHSA-3pfh-89x5-83xr/GHSA-3pfh-89x5-83xr.json index b71326fe923..7c7b970b434 100644 --- a/advisories/unreviewed/2023/07/GHSA-3pfh-89x5-83xr/GHSA-3pfh-89x5-83xr.json +++ b/advisories/unreviewed/2023/07/GHSA-3pfh-89x5-83xr/GHSA-3pfh-89x5-83xr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-46hm-73m4-wgrq/GHSA-46hm-73m4-wgrq.json b/advisories/unreviewed/2023/07/GHSA-46hm-73m4-wgrq/GHSA-46hm-73m4-wgrq.json new file mode 100644 index 00000000000..b6594c81ca3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-46hm-73m4-wgrq/GHSA-46hm-73m4-wgrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46hm-73m4-wgrq", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-30963" + ], + "details": "A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30963" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=3c6b63b7-fb67-4202-a94a-9c83515efb8a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-78g4-c5r9-6gh7/GHSA-78g4-c5r9-6gh7.json b/advisories/unreviewed/2023/07/GHSA-78g4-c5r9-6gh7/GHSA-78g4-c5r9-6gh7.json index 48f9fc2e193..edcbe99cf61 100644 --- a/advisories/unreviewed/2023/07/GHSA-78g4-c5r9-6gh7/GHSA-78g4-c5r9-6gh7.json +++ b/advisories/unreviewed/2023/07/GHSA-78g4-c5r9-6gh7/GHSA-78g4-c5r9-6gh7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": null, diff --git a/advisories/unreviewed/2023/07/GHSA-984g-wqfw-h3fh/GHSA-984g-wqfw-h3fh.json b/advisories/unreviewed/2023/07/GHSA-984g-wqfw-h3fh/GHSA-984g-wqfw-h3fh.json new file mode 100644 index 00000000000..02e1afe47bb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-984g-wqfw-h3fh/GHSA-984g-wqfw-h3fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-984g-wqfw-h3fh", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-24489" + ], + "details": "\nA vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24489" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json b/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json index 9788115aa45..42d94edfd80 100644 --- a/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json +++ b/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c7wh-g26h-jp33", - "modified": "2023-07-05T15:30:24Z", + "modified": "2023-07-11T00:33:19Z", "published": "2023-07-05T15:30:24Z", "aliases": [ "CVE-2021-46891" ], "details": "Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-863" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-f8q5-x346-4rf5/GHSA-f8q5-x346-4rf5.json b/advisories/unreviewed/2023/07/GHSA-f8q5-x346-4rf5/GHSA-f8q5-x346-4rf5.json index 6914c6ae7e9..aa5c4049d72 100644 --- a/advisories/unreviewed/2023/07/GHSA-f8q5-x346-4rf5/GHSA-f8q5-x346-4rf5.json +++ b/advisories/unreviewed/2023/07/GHSA-f8q5-x346-4rf5/GHSA-f8q5-x346-4rf5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-gg2h-rxjc-7jx5/GHSA-gg2h-rxjc-7jx5.json b/advisories/unreviewed/2023/07/GHSA-gg2h-rxjc-7jx5/GHSA-gg2h-rxjc-7jx5.json index 16e06be6363..9accf27f8be 100644 --- a/advisories/unreviewed/2023/07/GHSA-gg2h-rxjc-7jx5/GHSA-gg2h-rxjc-7jx5.json +++ b/advisories/unreviewed/2023/07/GHSA-gg2h-rxjc-7jx5/GHSA-gg2h-rxjc-7jx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gg2h-rxjc-7jx5", - "modified": "2023-07-05T12:30:16Z", + "modified": "2023-07-11T00:33:18Z", "published": "2023-07-05T12:30:16Z", "aliases": [ "CVE-2021-46890" ], "details": "Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-ggvf-r5vr-g67r/GHSA-ggvf-r5vr-g67r.json b/advisories/unreviewed/2023/07/GHSA-ggvf-r5vr-g67r/GHSA-ggvf-r5vr-g67r.json index 529c97ee1eb..17df9773619 100644 --- a/advisories/unreviewed/2023/07/GHSA-ggvf-r5vr-g67r/GHSA-ggvf-r5vr-g67r.json +++ b/advisories/unreviewed/2023/07/GHSA-ggvf-r5vr-g67r/GHSA-ggvf-r5vr-g67r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jg83-rjrf-gwrc/GHSA-jg83-rjrf-gwrc.json b/advisories/unreviewed/2023/07/GHSA-jg83-rjrf-gwrc/GHSA-jg83-rjrf-gwrc.json new file mode 100644 index 00000000000..7432062d24a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jg83-rjrf-gwrc/GHSA-jg83-rjrf-gwrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg83-rjrf-gwrc", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-24490" + ], + "details": "Users with only access to launch VDA applications can launch an unauthorized desktop\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24490" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX559370/windows-and-linux-virtual-delivery-agent-for-cvad-and-citrix-daas-security-bulletin-cve202324490" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v79h-64cf-gw4x/GHSA-v79h-64cf-gw4x.json b/advisories/unreviewed/2023/07/GHSA-v79h-64cf-gw4x/GHSA-v79h-64cf-gw4x.json index 1ffeafc1167..2a5a1e890b5 100644 --- a/advisories/unreviewed/2023/07/GHSA-v79h-64cf-gw4x/GHSA-v79h-64cf-gw4x.json +++ b/advisories/unreviewed/2023/07/GHSA-v79h-64cf-gw4x/GHSA-v79h-64cf-gw4x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-704" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-w365-qpc6-8w95/GHSA-w365-qpc6-8w95.json b/advisories/unreviewed/2023/07/GHSA-w365-qpc6-8w95/GHSA-w365-qpc6-8w95.json new file mode 100644 index 00000000000..90e71703e64 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w365-qpc6-8w95/GHSA-w365-qpc6-8w95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w365-qpc6-8w95", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-30960" + ], + "details": "A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30960" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=115d9bf4-201f-4cfe-b2fc-219e3a2d945b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json b/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json index 26e67d32525..2de17b5387a 100644 --- a/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json +++ b/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9wr-4926-mh54", - "modified": "2023-07-05T15:30:24Z", + "modified": "2023-07-11T00:33:19Z", "published": "2023-07-05T15:30:24Z", "aliases": [ "CVE-2023-35972" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-xrgq-7wvh-c25q/GHSA-xrgq-7wvh-c25q.json b/advisories/unreviewed/2023/07/GHSA-xrgq-7wvh-c25q/GHSA-xrgq-7wvh-c25q.json new file mode 100644 index 00000000000..260a788c137 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xrgq-7wvh-c25q/GHSA-xrgq-7wvh-c25q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrgq-7wvh-c25q", + "modified": "2023-07-11T00:33:19Z", + "published": "2023-07-11T00:33:19Z", + "aliases": [ + "CVE-2023-3608" + ], + "details": "A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3608" + }, + { + "type": "WEB", + "url": "https://github.com/cq535454518/cve/blob/main/RG-BCR810W.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233477" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file