From 46fdae44659f5224269e37451e9483f1105d3759 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jan 2024 21:31:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5v9r-788c-wc8p.json | 33 +++++- .../GHSA-vfxf-76hv-v4w4.json | 100 ++++++++++++++++++ .../GHSA-6669-q2h5-85q9.json | 1 + .../GHSA-p39m-p32x-h8jq.json | 9 +- .../GHSA-fj2q-5f6j-5xf4.json | 5 +- .../GHSA-276r-vcw2-xfq4.json | 9 +- .../GHSA-3rcv-jmj4-w65f.json | 11 +- .../GHSA-4prj-w93p-4j89.json | 11 +- .../GHSA-75jg-c8f9-x2rh.json | 11 +- .../GHSA-868h-653q-w2q2.json | 11 +- .../GHSA-88cv-mw5r-6xcj.json | 11 +- .../GHSA-9rj5-9jpj-cqqh.json | 11 +- .../GHSA-ccq5-7ghx-j6xg.json | 11 +- .../GHSA-gv74-v3v2-h2x9.json | 11 +- .../GHSA-h8h3-f8x2-6ggh.json | 11 +- .../GHSA-pc49-g522-pmh5.json | 11 +- .../GHSA-v6x9-c2q6-xc4w.json | 11 +- .../GHSA-vcc2-j3rm-53wf.json | 11 +- .../GHSA-vjxw-62pr-vrfg.json | 11 +- .../GHSA-wfg4-v93p-7mj4.json | 9 +- .../GHSA-445x-c8qq-qfr9.json | 35 ++++++ .../GHSA-4fr6-x37h-wjwr.json | 35 ++++++ .../GHSA-4j56-jg72-x59r.json | 38 +++++++ .../GHSA-8v3x-2g6f-gc4c.json | 38 +++++++ .../GHSA-cj4v-24xq-mcm6.json | 35 ++++++ .../GHSA-cjpg-8x68-w7r7.json | 35 ++++++ .../GHSA-phvj-2xc5-g994.json | 39 +++++++ .../GHSA-rf4q-9m5j-m24r.json | 35 ++++++ 28 files changed, 531 insertions(+), 68 deletions(-) rename advisories/{unreviewed => github-reviewed}/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json (52%) create mode 100644 advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-445x-c8qq-qfr9/GHSA-445x-c8qq-qfr9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4j56-jg72-x59r/GHSA-4j56-jg72-x59r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8v3x-2g6f-gc4c/GHSA-8v3x-2g6f-gc4c.json create mode 100644 advisories/unreviewed/2024/01/GHSA-cj4v-24xq-mcm6/GHSA-cj4v-24xq-mcm6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-phvj-2xc5-g994/GHSA-phvj-2xc5-g994.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rf4q-9m5j-m24r/GHSA-rf4q-9m5j-m24r.json diff --git a/advisories/unreviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json b/advisories/github-reviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json similarity index 52% rename from advisories/unreviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json rename to advisories/github-reviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json index d7417ad8fe7..c1c0f5b52ac 100644 --- a/advisories/unreviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json +++ b/advisories/github-reviewed/2023/12/GHSA-5v9r-788c-wc8p/GHSA-5v9r-788c-wc8p.json @@ -1,23 +1,46 @@ { "schema_version": "1.4.0", "id": "GHSA-5v9r-788c-wc8p", - "modified": "2023-12-30T03:30:19Z", + "modified": "2024-01-03T21:30:51Z", "published": "2023-12-30T03:30:19Z", "aliases": [ "CVE-2023-41542" ], + "summary": "Jeecg Boot SQL injection vulnerability", "details": "SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jeecgframework.boot:jeecg-boot-common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.5.3" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41542" }, + { + "type": "PACKAGE", + "url": "https://github.com/jeecgboot/jeecg-boot" + }, { "type": "WEB", "url": "https://pho3n1x-web.github.io/2023/09/15/CVE-2023-41542%28JeecgBoot_sql%29/" @@ -27,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-03T21:30:51Z", "nvd_published_at": "2023-12-30T02:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json b/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json new file mode 100644 index 00000000000..4939dfaafac --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfxf-76hv-v4w4", + "modified": "2024-01-03T21:30:17Z", + "published": "2024-01-03T21:30:17Z", + "aliases": [ + + ], + "summary": "User-provided environment values allow execution on macOS agents", + "details": "### Impact\nAgents running on macOS could be susceptible to unexpected code execution through user supplied environment variables.\n\n### Patches\nFixed in versions 14.2.4, 13.4.13 and 12.4.31.\n\n### References\n* Fix PR: https://github.com/gravitational/teleport/pull/36132\n", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "https://github.com/gravitational/teleport" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "14.0.0" + }, + { + "fixed": "14.2.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "https://github.com/gravitational/teleport" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + }, + { + "fixed": "13.4.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "https://github.com/gravitational/teleport" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "12.4.31" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gravitational/teleport/security/advisories/GHSA-vfxf-76hv-v4w4" + }, + { + "type": "WEB", + "url": "https://github.com/gravitational/teleport/pull/36132" + }, + { + "type": "WEB", + "url": "https://github.com/gravitational/teleport/commit/fcc97de9f99dfec8696ecfd620672a26f29cf9ac" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gravitational/teleport" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-03T21:30:17Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/03/GHSA-6669-q2h5-85q9/GHSA-6669-q2h5-85q9.json b/advisories/unreviewed/2022/03/GHSA-6669-q2h5-85q9/GHSA-6669-q2h5-85q9.json index e729d881b0f..febe61e9f67 100644 --- a/advisories/unreviewed/2022/03/GHSA-6669-q2h5-85q9/GHSA-6669-q2h5-85q9.json +++ b/advisories/unreviewed/2022/03/GHSA-6669-q2h5-85q9/GHSA-6669-q2h5-85q9.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-918" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-p39m-p32x-h8jq/GHSA-p39m-p32x-h8jq.json b/advisories/unreviewed/2022/05/GHSA-p39m-p32x-h8jq/GHSA-p39m-p32x-h8jq.json index ae543b01bb9..c0c3eb2edeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-p39m-p32x-h8jq/GHSA-p39m-p32x-h8jq.json +++ b/advisories/unreviewed/2022/05/GHSA-p39m-p32x-h8jq/GHSA-p39m-p32x-h8jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p39m-p32x-h8jq", - "modified": "2022-05-24T17:09:02Z", + "modified": "2024-01-03T21:30:30Z", "published": "2022-05-24T17:09:02Z", "aliases": [ "CVE-2019-15592" ], "details": "GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-fj2q-5f6j-5xf4/GHSA-fj2q-5f6j-5xf4.json b/advisories/unreviewed/2023/09/GHSA-fj2q-5f6j-5xf4/GHSA-fj2q-5f6j-5xf4.json index efd299ce5db..f2c3acce537 100644 --- a/advisories/unreviewed/2023/09/GHSA-fj2q-5f6j-5xf4/GHSA-fj2q-5f6j-5xf4.json +++ b/advisories/unreviewed/2023/09/GHSA-fj2q-5f6j-5xf4/GHSA-fj2q-5f6j-5xf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj2q-5f6j-5xf4", - "modified": "2023-09-28T15:30:17Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-09-28T15:30:17Z", "aliases": [ "CVE-2023-5215" @@ -36,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-241", "CWE-252" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-28T14:15:26Z" diff --git a/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json b/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json index 410140f6b11..3818281e9a4 100644 --- a/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json +++ b/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-276r-vcw2-xfq4", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-03T21:30:31Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-51363" ], "details": "VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json b/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json index f74da5ca816..2e7dd717ac5 100644 --- a/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json +++ b/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rcv-jmj4-w65f", - "modified": "2023-12-25T06:30:20Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:20Z", "aliases": [ "CVE-2022-39822" ], "details": "In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json b/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json index 7668e020601..e2b30ecd34c 100644 --- a/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json +++ b/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4prj-w93p-4j89", - "modified": "2023-12-25T06:30:20Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:20Z", "aliases": [ "CVE-2022-39818" ], "details": "In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-75jg-c8f9-x2rh/GHSA-75jg-c8f9-x2rh.json b/advisories/unreviewed/2023/12/GHSA-75jg-c8f9-x2rh/GHSA-75jg-c8f9-x2rh.json index 1bd908824fc..7ca6eeb2ed6 100644 --- a/advisories/unreviewed/2023/12/GHSA-75jg-c8f9-x2rh/GHSA-75jg-c8f9-x2rh.json +++ b/advisories/unreviewed/2023/12/GHSA-75jg-c8f9-x2rh/GHSA-75jg-c8f9-x2rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75jg-c8f9-x2rh", - "modified": "2023-12-22T06:30:26Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-22T06:30:26Z", "aliases": [ "CVE-2023-24609" ], "details": "Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-22T04:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json b/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json index 9d4bb83443a..2967dac37b7 100644 --- a/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json +++ b/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-868h-653q-w2q2", - "modified": "2023-12-25T09:30:19Z", + "modified": "2024-01-03T21:30:31Z", "published": "2023-12-25T09:30:19Z", "aliases": [ "CVE-2023-28872" ], "details": "Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\\Temp\\NcpSupport* location.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T07:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json b/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json index c7da53de119..12a130bf784 100644 --- a/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json +++ b/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88cv-mw5r-6xcj", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:31Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2023-49328" ], "details": "On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json b/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json index 234a4580485..50eb1607018 100644 --- a/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json +++ b/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rj5-9jpj-cqqh", - "modified": "2023-12-25T06:30:20Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:20Z", "aliases": [ "CVE-2023-51771" ], "details": "In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T05:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json b/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json index d16ce4a2c1a..c5f217c9e6d 100644 --- a/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json +++ b/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccq5-7ghx-j6xg", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2022-41762" ], "details": "An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json b/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json index d2121fdf955..230a5e582c3 100644 --- a/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json +++ b/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv74-v3v2-h2x9", - "modified": "2023-12-25T06:30:20Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:20Z", "aliases": [ "CVE-2022-41761" ], "details": "An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json b/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json index 948293a4cb5..d7c109202c5 100644 --- a/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json +++ b/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8h3-f8x2-6ggh", - "modified": "2023-12-25T06:30:20Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:20Z", "aliases": [ "CVE-2022-39820" ], "details": "In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json b/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json index c0e09154d50..b1b7022b27d 100644 --- a/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json +++ b/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc49-g522-pmh5", - "modified": "2023-12-25T09:30:19Z", + "modified": "2024-01-03T21:30:31Z", "published": "2023-12-25T09:30:19Z", "aliases": [ "CVE-2023-31297" ], "details": "An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T07:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json b/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json index 816a834c0d6..0fb40bff550 100644 --- a/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json +++ b/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6x9-c2q6-xc4w", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2022-41760" ], "details": "An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json b/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json index 0d636699c68..d19269af5e5 100644 --- a/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json +++ b/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcc2-j3rm-53wf", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2022-43675" ], "details": "An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json index 26f6a169968..8cf369986a7 100644 --- a/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json +++ b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjxw-62pr-vrfg", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:31Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2023-51772" ], "details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click on the Help icon, observe that there is a browser window for the One Identity website, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json b/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json index 1f9ccbf308e..21b1cb03073 100644 --- a/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json +++ b/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfg4-v93p-7mj4", - "modified": "2023-12-25T06:30:21Z", + "modified": "2024-01-03T21:30:30Z", "published": "2023-12-25T06:30:21Z", "aliases": [ "CVE-2023-48654" ], "details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-25T06:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-445x-c8qq-qfr9/GHSA-445x-c8qq-qfr9.json b/advisories/unreviewed/2024/01/GHSA-445x-c8qq-qfr9/GHSA-445x-c8qq-qfr9.json new file mode 100644 index 00000000000..0b948dbe7a3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-445x-c8qq-qfr9/GHSA-445x-c8qq-qfr9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-445x-c8qq-qfr9", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-50090" + ], + "details": "Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50090" + }, + { + "type": "WEB", + "url": "https://lemono.fun/thoughts/UReport2-RCE.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json new file mode 100644 index 00000000000..dd92e1afdb4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fr6-x37h-wjwr", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-5880" + ], + "details": "When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser. \n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5880" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garage-door-opener-multiple-vulnerabilities/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4j56-jg72-x59r/GHSA-4j56-jg72-x59r.json b/advisories/unreviewed/2024/01/GHSA-4j56-jg72-x59r/GHSA-4j56-jg72-x59r.json new file mode 100644 index 00000000000..b422daef6ce --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4j56-jg72-x59r/GHSA-4j56-jg72-x59r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j56-jg72-x59r", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-6338" + ], + "details": "Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6338" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-121183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8v3x-2g6f-gc4c/GHSA-8v3x-2g6f-gc4c.json b/advisories/unreviewed/2024/01/GHSA-8v3x-2g6f-gc4c/GHSA-8v3x-2g6f-gc4c.json new file mode 100644 index 00000000000..a8ad8b3ad89 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8v3x-2g6f-gc4c/GHSA-8v3x-2g6f-gc4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v3x-2g6f-gc4c", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-6540" + ], + "details": "A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6540" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/419251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cj4v-24xq-mcm6/GHSA-cj4v-24xq-mcm6.json b/advisories/unreviewed/2024/01/GHSA-cj4v-24xq-mcm6/GHSA-cj4v-24xq-mcm6.json new file mode 100644 index 00000000000..92ce3e5b2bd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cj4v-24xq-mcm6/GHSA-cj4v-24xq-mcm6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj4v-24xq-mcm6", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-5879" + ], + "details": "Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5879" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garage-door-opener-multiple-vulnerabilities/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json b/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json new file mode 100644 index 00000000000..1771646c570 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cjpg-8x68-w7r7/GHSA-cjpg-8x68-w7r7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjpg-8x68-w7r7", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-5881" + ], + "details": "Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) \"Garage Door Control Module Setup\" and modify the Garage door's SSID settings. \n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5881" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garage-door-opener-multiple-vulnerabilities/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-phvj-2xc5-g994/GHSA-phvj-2xc5-g994.json b/advisories/unreviewed/2024/01/GHSA-phvj-2xc5-g994/GHSA-phvj-2xc5-g994.json new file mode 100644 index 00000000000..4853b8a3c40 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-phvj-2xc5-g994/GHSA-phvj-2xc5-g994.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phvj-2xc5-g994", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-46929" + ], + "details": "An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46929" + }, + { + "type": "WEB", + "url": "https://github.com/gpac/gpac/issues/2662" + }, + { + "type": "WEB", + "url": "https://github.com/gpac/gpac/commit/4248def5d24325aeb0e35cacde3d56c9411816a6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rf4q-9m5j-m24r/GHSA-rf4q-9m5j-m24r.json b/advisories/unreviewed/2024/01/GHSA-rf4q-9m5j-m24r/GHSA-rf4q-9m5j-m24r.json new file mode 100644 index 00000000000..499d932d3f4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rf4q-9m5j-m24r/GHSA-rf4q-9m5j-m24r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf4q-9m5j-m24r", + "modified": "2024-01-03T21:30:31Z", + "published": "2024-01-03T21:30:31Z", + "aliases": [ + "CVE-2023-49442" + ], + "details": "Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49442" + }, + { + "type": "WEB", + "url": "https://lemono.fun/thoughts/JEECG-RCE.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T21:15:08Z" + } +} \ No newline at end of file