Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-03 21:31:54 +00:00
parent 4897bff795
commit 46fdae4465
28 changed files with 531 additions and 68 deletions
@@ -1,23 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5v9r-788c-wc8p",
"modified": "2023-12-30T03:30:19Z",
"modified": "2024-01-03T21:30:51Z",
"published": "2023-12-30T03:30:19Z",
"aliases": [
"CVE-2023-41542"
],
"summary": "Jeecg Boot SQL injection vulnerability",
"details": "SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jeecgframework.boot:jeecg-boot-common"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.5.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41542"
},
{
"type": "PACKAGE",
"url": "https://github.com/jeecgboot/jeecg-boot"
},
{
"type": "WEB",
"url": "https://pho3n1x-web.github.io/2023/09/15/CVE-2023-41542%28JeecgBoot_sql%29/"
@@ -27,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-03T21:30:51Z",
"nvd_published_at": "2023-12-30T02:15:08Z"
}
}
@@ -0,0 +1,100 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfxf-76hv-v4w4",
"modified": "2024-01-03T21:30:17Z",
"published": "2024-01-03T21:30:17Z",
"aliases": [
],
"summary": "User-provided environment values allow execution on macOS agents",
"details": "### Impact\nAgents running on macOS could be susceptible to unexpected code execution through user supplied environment variables.\n\n### Patches\nFixed in versions 14.2.4, 13.4.13 and 12.4.31.\n\n### References\n* Fix PR: https://github.com/gravitational/teleport/pull/36132\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "https://github.com/gravitational/teleport"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "14.0.0"
},
{
"fixed": "14.2.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "https://github.com/gravitational/teleport"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "13.0.0"
},
{
"fixed": "13.4.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "https://github.com/gravitational/teleport"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "12.4.31"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/gravitational/teleport/security/advisories/GHSA-vfxf-76hv-v4w4"
},
{
"type": "WEB",
"url": "https://github.com/gravitational/teleport/pull/36132"
},
{
"type": "WEB",
"url": "https://github.com/gravitational/teleport/commit/fcc97de9f99dfec8696ecfd620672a26f29cf9ac"
},
{
"type": "PACKAGE",
"url": "https://github.com/gravitational/teleport"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-01-03T21:30:17Z",
"nvd_published_at": null
}
}
@@ -40,6 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-918"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p39m-p32x-h8jq",
"modified": "2022-05-24T17:09:02Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2022-05-24T17:09:02Z",
"aliases": [
"CVE-2019-15592"
],
"details": "GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj2q-5f6j-5xf4",
"modified": "2023-09-28T15:30:17Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-09-28T15:30:17Z",
"aliases": [
"CVE-2023-5215"
@@ -36,9 +36,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-241",
"CWE-252"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-28T14:15:26Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-276r-vcw2-xfq4",
"modified": "2023-12-26T09:30:20Z",
"modified": "2024-01-03T21:30:31Z",
"published": "2023-12-26T09:30:20Z",
"aliases": [
"CVE-2023-51363"
],
"details": "VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T08:15:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rcv-jmj4-w65f",
"modified": "2023-12-25T06:30:20Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:20Z",
"aliases": [
"CVE-2022-39822"
],
"details": "In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4prj-w93p-4j89",
"modified": "2023-12-25T06:30:20Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:20Z",
"aliases": [
"CVE-2022-39818"
],
"details": "In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75jg-c8f9-x2rh",
"modified": "2023-12-22T06:30:26Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-22T06:30:26Z",
"aliases": [
"CVE-2023-24609"
],
"details": "Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-22T04:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-868h-653q-w2q2",
"modified": "2023-12-25T09:30:19Z",
"modified": "2024-01-03T21:30:31Z",
"published": "2023-12-25T09:30:19Z",
"aliases": [
"CVE-2023-28872"
],
"details": "Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\\Temp\\NcpSupport* location.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T07:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88cv-mw5r-6xcj",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:31Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2023-49328"
],
"details": "On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rj5-9jpj-cqqh",
"modified": "2023-12-25T06:30:20Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:20Z",
"aliases": [
"CVE-2023-51771"
],
"details": "In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T05:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccq5-7ghx-j6xg",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2022-41762"
],
"details": "An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gv74-v3v2-h2x9",
"modified": "2023-12-25T06:30:20Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:20Z",
"aliases": [
"CVE-2022-41761"
],
"details": "An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8h3-f8x2-6ggh",
"modified": "2023-12-25T06:30:20Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:20Z",
"aliases": [
"CVE-2022-39820"
],
"details": "In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc49-g522-pmh5",
"modified": "2023-12-25T09:30:19Z",
"modified": "2024-01-03T21:30:31Z",
"published": "2023-12-25T09:30:19Z",
"aliases": [
"CVE-2023-31297"
],
"details": "An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T07:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v6x9-c2q6-xc4w",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2022-41760"
],
"details": "An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcc2-j3rm-53wf",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2022-43675"
],
"details": "An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjxw-62pr-vrfg",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:31Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2023-51772"
],
"details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click on the Help icon, observe that there is a browser window for the One Identity website, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wfg4-v93p-7mj4",
"modified": "2023-12-25T06:30:21Z",
"modified": "2024-01-03T21:30:30Z",
"published": "2023-12-25T06:30:21Z",
"aliases": [
"CVE-2023-48654"
],
"details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-25T06:15:08Z"

Some files were not shown because too many files have changed in this diff Show More