Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-06-27 21:32:05 +00:00
parent 54efd10e27
commit 4037c79272
75 changed files with 759 additions and 86 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fvj-4grr-mv9j",
"modified": "2022-01-15T00:03:22Z",
"modified": "2023-06-27T21:30:42Z",
"published": "2022-01-11T00:00:57Z",
"aliases": [
"CVE-2022-22265"
],
"details": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-703",
"CWE-755"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgwx-697g-22hm",
"modified": "2022-01-27T00:03:48Z",
"modified": "2023-06-27T21:30:43Z",
"published": "2022-01-20T00:01:57Z",
"aliases": [
"CVE-2022-22166"
],
"details": "An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause an rdp crash and thereby a Denial of Service (DoS). If a BGP update message is received over an established BGP session where a BGP SR-TE policy tunnel attribute is malformed and BGP update tracing flag is enabled, the rpd will core. This issue can happen with any BGP session as long as the previous conditions are met. This issue can not propagate as the crash occurs as soon as the malformed update is received. This issue affects Juniper Networks Junos OS: 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R2-S2, 21.1R3. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgrp-9rqg-rqhp",
"modified": "2022-02-02T00:02:02Z",
"modified": "2023-06-27T21:30:43Z",
"published": "2022-01-26T00:00:49Z",
"aliases": [
"CVE-2022-23008"
],
"details": "On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the \"user\" or \"admin\" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-94"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2q7-5g93-322p",
"modified": "2022-01-16T00:01:04Z",
"modified": "2023-06-27T21:30:43Z",
"published": "2022-01-11T00:00:54Z",
"aliases": [
"CVE-2022-22272"
],
"details": "Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"severity": "LOW",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf8r-2pp6-7vqp",
"modified": "2022-01-20T00:02:50Z",
"modified": "2023-06-27T21:30:43Z",
"published": "2022-01-11T00:00:51Z",
"aliases": [
"CVE-2022-22288"
],
"details": "Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"severity": "HIGH",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-191",
"CWE-269"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhfm-vpj4-vj2f",
"modified": "2022-02-16T00:02:06Z",
"modified": "2023-06-27T21:30:44Z",
"published": "2022-02-11T00:00:50Z",
"aliases": [
"CVE-2022-21825"
],
"details": "An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-863"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mv97-qj5h-25f3",
"modified": "2022-02-09T00:01:05Z",
"modified": "2023-06-27T21:30:43Z",
"published": "2022-02-09T00:01:05Z",
"aliases": [
"CVE-2022-23134"
],
"details": "After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -37,6 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-287",
"CWE-863"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwwv-v58h-qcvw",
"modified": "2022-02-19T00:01:46Z",
"modified": "2023-06-27T21:30:44Z",
"published": "2022-02-12T00:00:40Z",
"aliases": [
"CVE-2022-23433"
],
"details": "Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-863"
],
"severity": "MODERATE",
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-1284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-1284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-1284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-116",
"CWE-352"
],
"severity": "MODERATE",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-424",
"CWE-425"
],
"severity": "MODERATE",
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -29,6 +29,7 @@
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-639",
"CWE-863"
],
"severity": "HIGH",
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-125"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -40,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-732"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More