Publish Advisories

GHSA-42g3-3jwm-63rx
GHSA-c2f6-rf2r-6j6f
GHSA-v672-5x3h-57qp
GHSA-vpp3-hpcm-v944
GHSA-wgrw-fj3v-fhc5
This commit is contained in:
advisory-database[bot]
2023-12-18 21:41:00 +00:00
parent f7bc073956
commit 3ebf67f71e
5 changed files with 25 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42g3-3jwm-63rx",
"modified": "2023-12-13T19:29:01Z",
"modified": "2023-12-18T21:39:35Z",
"published": "2023-12-13T15:30:58Z",
"aliases": [
"CVE-2023-47325"
@@ -9,7 +9,10 @@
"summary": "Broken access control in Silverpeas",
"details": "Silverpeas Core 6.3.1 administrative \"Bin\" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2f6-rf2r-6j6f",
"modified": "2023-12-13T19:33:53Z",
"modified": "2023-12-18T21:40:27Z",
"published": "2023-12-13T18:31:04Z",
"aliases": [
"CVE-2023-50776"
@@ -9,7 +9,10 @@
"summary": "Tokens stored in plain text by PaaSLane Estimate Plugin ",
"details": "Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v672-5x3h-57qp",
"modified": "2023-12-13T19:41:45Z",
"modified": "2023-12-18T21:40:06Z",
"published": "2023-12-13T18:31:04Z",
"aliases": [
"CVE-2023-50775"
@@ -9,7 +9,10 @@
"summary": " Cross-site request forgery vulnerability in Jenkins Deployment Dashboard Plugin",
"details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpp3-hpcm-v944",
"modified": "2023-12-13T19:28:42Z",
"modified": "2023-12-18T21:39:30Z",
"published": "2023-12-13T15:30:58Z",
"aliases": [
"CVE-2023-47327"
@@ -9,7 +9,10 @@
"summary": "Broken access control in Silverpeas",
"details": "The \"Create a Space\" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgrw-fj3v-fhc5",
"modified": "2023-12-13T19:29:16Z",
"modified": "2023-12-18T21:39:40Z",
"published": "2023-12-13T15:30:58Z",
"aliases": [
"CVE-2023-47324"
@@ -9,7 +9,10 @@
"summary": "Cross-site Scripting in silverpeas",
"details": "Silverpeas Core 6.3.1 and prior are vulnerable to Cross Site Scripting (XSS) via the message/notification feature.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{