diff --git a/advisories/github-reviewed/2020/09/GHSA-gjc9-932x-c59p/GHSA-gjc9-932x-c59p.json b/advisories/github-reviewed/2020/09/GHSA-gjc9-932x-c59p/GHSA-gjc9-932x-c59p.json index 04afd87db28..6916b3bd5d1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gjc9-932x-c59p/GHSA-gjc9-932x-c59p.json +++ b/advisories/github-reviewed/2020/09/GHSA-gjc9-932x-c59p/GHSA-gjc9-932x-c59p.json @@ -3,14 +3,10 @@ "id": "GHSA-gjc9-932x-c59p", "modified": "2023-07-25T20:40:16Z", "published": "2020-09-03T00:34:33Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in leaflet-gpx", "details": "Version 1.0.1 of `leaflet-gpx` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised.\n\nUsers may consider a downgrade to version 1.0.0", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -29,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:41:10Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-gvg7-pp82-cff3/GHSA-gvg7-pp82-cff3.json b/advisories/github-reviewed/2020/09/GHSA-gvg7-pp82-cff3/GHSA-gvg7-pp82-cff3.json index 6d8d0e710f8..41e744d042b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gvg7-pp82-cff3/GHSA-gvg7-pp82-cff3.json +++ b/advisories/github-reviewed/2020/09/GHSA-gvg7-pp82-cff3/GHSA-gvg7-pp82-cff3.json @@ -8,9 +8,7 @@ ], "summary": "Cross-Site Scripting in c3", "details": "Affected versions of `c3` are vulnerable to cross-site scripting via improper sanitization of HTML in rendered tooltips. \n\n\n\n## Recommendation\n\nUpdate to 0.4.11 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-h6mq-3cj6-h738/GHSA-h6mq-3cj6-h738.json b/advisories/github-reviewed/2020/09/GHSA-h6mq-3cj6-h738/GHSA-h6mq-3cj6-h738.json index abf9273366d..c38e2c88f33 100644 --- a/advisories/github-reviewed/2020/09/GHSA-h6mq-3cj6-h738/GHSA-h6mq-3cj6-h738.json +++ b/advisories/github-reviewed/2020/09/GHSA-h6mq-3cj6-h738/GHSA-h6mq-3cj6-h738.json @@ -3,9 +3,7 @@ "id": "GHSA-h6mq-3cj6-h738", "modified": "2021-10-01T16:12:36Z", "published": "2020-09-03T23:21:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "Reverse Tabnabbing in showdown", "details": "Versions of `showdown` prior to 1.9.1 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.\n\n\n## Recommendation\n\nUpgrade to version 1.9.1 or later.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-m5pf-5894-jmx7/GHSA-m5pf-5894-jmx7.json b/advisories/github-reviewed/2020/09/GHSA-m5pf-5894-jmx7/GHSA-m5pf-5894-jmx7.json index db843121233..f07d14e17b6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-m5pf-5894-jmx7/GHSA-m5pf-5894-jmx7.json +++ b/advisories/github-reviewed/2020/09/GHSA-m5pf-5894-jmx7/GHSA-m5pf-5894-jmx7.json @@ -3,14 +3,10 @@ "id": "GHSA-m5pf-5894-jmx7", "modified": "2023-07-25T20:37:38Z", "published": "2020-09-03T19:08:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sailclothjs", "details": "Version 1.2.6 of `sailclothjs` contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment. It's also recommended to evaluate your application to determine whether or not user data was compromised.\n\nUsers may consider a downgrade to 1.2.5", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -29,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:47:11Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-v6vv-hhqc-6hh2/GHSA-v6vv-hhqc-6hh2.json b/advisories/github-reviewed/2020/09/GHSA-v6vv-hhqc-6hh2/GHSA-v6vv-hhqc-6hh2.json index f3d7001d2c1..9f948163d49 100644 --- a/advisories/github-reviewed/2020/09/GHSA-v6vv-hhqc-6hh2/GHSA-v6vv-hhqc-6hh2.json +++ b/advisories/github-reviewed/2020/09/GHSA-v6vv-hhqc-6hh2/GHSA-v6vv-hhqc-6hh2.json @@ -3,14 +3,10 @@ "id": "GHSA-v6vv-hhqc-6hh2", "modified": "2023-07-25T20:30:52Z", "published": "2020-09-03T19:15:37Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in pyramid-proportion", "details": "Version 1.0.5 of `pyramid-proportion` contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment. It's also recommended to evaluate your application to determine whether or not user data was compromised.\n\nUsers may consider a downgrade to version 1.0.4.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -29,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:47:29Z", diff --git a/advisories/github-reviewed/2021/11/GHSA-r64m-qchj-hrjp/GHSA-r64m-qchj-hrjp.json b/advisories/github-reviewed/2021/11/GHSA-r64m-qchj-hrjp/GHSA-r64m-qchj-hrjp.json index 1b5362129e5..e752c00ddaf 100644 --- a/advisories/github-reviewed/2021/11/GHSA-r64m-qchj-hrjp/GHSA-r64m-qchj-hrjp.json +++ b/advisories/github-reviewed/2021/11/GHSA-r64m-qchj-hrjp/GHSA-r64m-qchj-hrjp.json @@ -3,14 +3,10 @@ "id": "GHSA-r64m-qchj-hrjp", "modified": "2021-11-24T19:58:48Z", "published": "2021-11-24T20:05:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Webcache Poisoning in shopware/platform and shopware/core", "details": "### Impact\nWebcache Poisoning via X-Forwarded-Prefix and sub-request\n\n### Patches\nWe recommend updating to the current version 6.4.6.1. You can get the update to 6.4.6.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\nWorkarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/11/GHSA-r8wq-qrxc-hmcm/GHSA-r8wq-qrxc-hmcm.json b/advisories/github-reviewed/2021/11/GHSA-r8wq-qrxc-hmcm/GHSA-r8wq-qrxc-hmcm.json index ae2fd0259d9..add6486a81f 100644 --- a/advisories/github-reviewed/2021/11/GHSA-r8wq-qrxc-hmcm/GHSA-r8wq-qrxc-hmcm.json +++ b/advisories/github-reviewed/2021/11/GHSA-r8wq-qrxc-hmcm/GHSA-r8wq-qrxc-hmcm.json @@ -3,9 +3,7 @@ "id": "GHSA-r8wq-qrxc-hmcm", "modified": "2021-11-26T18:26:27Z", "published": "2021-11-29T17:58:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "ReDoS in LDAP schema parser", "details": "https://github.com/python-ldap/python-ldap/issues/424\n\n### Impact\nThe LDAP schema parser of python-ldap 3.3.1 and earlier are vulnerable to a regular expression denial-of-service attack. The issue affects clients that use ``ldap.schema`` package to parse LDAP schema definitions from an untrusted source.\n\n### Patches\nThe upcoming release of python-ldap 3.4.0 will contain a workaround to prevent ReDoS attacks. The schema parser refuses schema definitions with an excessive amount of backslashes.\n\n### Workarounds\nAs a workaround, users can check input for excessive amount of backslashes in schemas. More than a dozen backslashes per line are atypical.\n\n### References\n[CWE-1333](https://cwe.mitre.org/data/definitions/1333.html)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [python-ldap](https://github.com/python-ldap/python-ldap) tracker\n", "severity": [ diff --git a/advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json b/advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json index 6a129aa6f7a..3165a3f3ff7 100644 --- a/advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json +++ b/advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json @@ -3,14 +3,10 @@ "id": "GHSA-2g8g-63j4-9w3r", "modified": "2021-11-29T19:39:57Z", "published": "2021-12-01T18:29:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend", "details": "The templating library used by the scaffolder backend assumes that templates are trusted which is an undesired property of the scaffolder-backend. This has now been mitigated by sandboxing the template code execution.\n\n### Impact\nA malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template yaml definition itself and not by user input data.\n\n### Patches\nThis is vulnerability is patched in version `0.15.14` of `@backstage/plugin-scaffolder-backend`.\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in the [Backstage repository](https://github.com/backstage/backstage)\n* Visit our chat, linked to in [Backstage README](https://github.com/backstage/backstage)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-11-29T19:39:57Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-6r7c-6w96-8pvw/GHSA-6r7c-6w96-8pvw.json b/advisories/github-reviewed/2021/12/GHSA-6r7c-6w96-8pvw/GHSA-6r7c-6w96-8pvw.json index f3c67ce239a..a91a6cde28b 100644 --- a/advisories/github-reviewed/2021/12/GHSA-6r7c-6w96-8pvw/GHSA-6r7c-6w96-8pvw.json +++ b/advisories/github-reviewed/2021/12/GHSA-6r7c-6w96-8pvw/GHSA-6r7c-6w96-8pvw.json @@ -3,9 +3,7 @@ "id": "GHSA-6r7c-6w96-8pvw", "modified": "2022-01-04T18:56:03Z", "published": "2021-12-07T21:21:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "Remote Code Execution in AjaxNetProfessional", "details": "### Overview\n\nAffected versions of this package are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.\n\n### Description\n\nSerialization is a process of converting an object into a sequence of bytes which can be persisted to a disk or database or can be sent through streams. The reverse process of creating object from sequence of bytes is called deserialization. Serialization is commonly used for communication (sharing objects between multiple hosts) and persistence (store the object state in a file or a database). It is an integral part of popular protocols like Remote Method Invocation (RMI), Java Management Extension (JMX), Java Messaging System (JMS), Action Message Format (AMF), Java Server Faces (JSF) ViewState, etc.\n\nDeserialization of untrusted data (CWE-502), is when the application deserializes untrusted data without sufficiently verifying that the resulting data will be valid, letting the attacker to control the state or the flow of the execution.\n\nJava deserialization issues have been known for years. However, interest in the issue intensified greatly in 2015, when classes that could be abused to achieve remote code execution were found in a popular library (Apache Commons Collection). These classes were used in zero-days affecting IBM WebSphere, Oracle WebLogic and many other products.\n\nAn attacker just needs to identify a piece of software that has both a vulnerable class on its path, and performs deserialization on untrusted data. Then all they need to do is send the payload into the deserializer, getting the command executed.\n\nDevelopers put too much trust in Java Object Serialization. Some even de-serialize objects pre-authentication. When deserializing an Object in Java you typically cast it to an expected type, and therefore Java's strict type system will ensure you only get valid object trees. Unfortunately, by the time the type checking happens, platform code has already created and executed significant logic. So, before the final type is checked a lot of code is executed from the readObject() methods of various objects, all of which is out of the developer's control. By combining the readObject() methods of various classes which are available on the classpath of the vulnerable application an attacker can execute functions (including calling Runtime.exec() to execute local OS commands).\n\n### Releases\n\nReleases before version 21.11.29.1 are affected. Please be careful to download any binary DLL from other web sites, especially we found NuGet packages not owned by us that contain vulnerable versions.\n\n### Workarounds\n\nThere is no workaround available that addresses all issues except updating to latest version from GitHub.\n\n### References\n\nFind original CVE posting here: https://security.snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971\n\nNote: the official Ajax.NET Professional (AjaxPro) NuGet package is available here: https://www.nuget.org/packages/AjaxNetProfessional/\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue on this GitHub repository\n", "severity": [ diff --git a/advisories/github-reviewed/2021/12/GHSA-9jp8-cwwx-p64q/GHSA-9jp8-cwwx-p64q.json b/advisories/github-reviewed/2021/12/GHSA-9jp8-cwwx-p64q/GHSA-9jp8-cwwx-p64q.json index 9b16addf950..4c759e1227c 100644 --- a/advisories/github-reviewed/2021/12/GHSA-9jp8-cwwx-p64q/GHSA-9jp8-cwwx-p64q.json +++ b/advisories/github-reviewed/2021/12/GHSA-9jp8-cwwx-p64q/GHSA-9jp8-cwwx-p64q.json @@ -3,14 +3,10 @@ "id": "GHSA-9jp8-cwwx-p64q", "modified": "2021-11-29T20:55:01Z", "published": "2021-12-01T18:28:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext", "details": "The rich text editor does not escape attribute data when previewing custom tags. This means XSS is possible if custom tags are used, for users who have access to editing rich text content. Frontend content view is not affected, but the vulnerability could be used by editors to attack other editors. The fix ensures custom tag attribute data is escaped in the editor.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -50,9 +46,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-11-29T20:53:06Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-m7r6-43v2-49vf/GHSA-m7r6-43v2-49vf.json b/advisories/github-reviewed/2022/05/GHSA-m7r6-43v2-49vf/GHSA-m7r6-43v2-49vf.json index 425576ee59e..48d0052d29f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-m7r6-43v2-49vf/GHSA-m7r6-43v2-49vf.json +++ b/advisories/github-reviewed/2022/05/GHSA-m7r6-43v2-49vf/GHSA-m7r6-43v2-49vf.json @@ -8,9 +8,7 @@ ], "summary": "Mongrel vulnerable to directory traversal via double-encoded sequences", "details": "Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 (1.0.3 and prior are not affected) and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP request containing double-encoded sequences (`.%252e`).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json b/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json index 2b3ac19132e..6c851e528a9 100644 --- a/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json +++ b/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json @@ -3,14 +3,10 @@ "id": "GHSA-cp47-r258-q626", "modified": "2023-03-02T23:36:22Z", "published": "2023-03-02T23:36:22Z", - "aliases": [ - - ], + "aliases": [], "summary": " Vega vulnerable to arbitrary code execution when clicking href links", "details": " Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -78,9 +74,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-03-02T23:36:22Z", diff --git a/advisories/github-reviewed/2024/01/GHSA-58j9-j2fj-v8f4/GHSA-58j9-j2fj-v8f4.json b/advisories/github-reviewed/2024/01/GHSA-58j9-j2fj-v8f4/GHSA-58j9-j2fj-v8f4.json index fef5b2fef02..f12b6ca6024 100644 --- a/advisories/github-reviewed/2024/01/GHSA-58j9-j2fj-v8f4/GHSA-58j9-j2fj-v8f4.json +++ b/advisories/github-reviewed/2024/01/GHSA-58j9-j2fj-v8f4/GHSA-58j9-j2fj-v8f4.json @@ -3,9 +3,7 @@ "id": "GHSA-58j9-j2fj-v8f4", "modified": "2024-01-19T20:31:21Z", "published": "2024-01-19T20:31:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface", "details": "SurrealDB depends on the `tungstenite` and `tokio-tungstenite` crates used by the `axum` crate, which handles connections to the SurrealDB WebSocket interface. On versions before `0.20.1`, the `tungstenite` crate presented an issue which allowed the parsing of HTTP headers during the client handshake to continuously consume high CPU when the headers were very long. All affected crates have been updated in SurrealDB version `1.1.0`.\n\nFrom the original advisory for [CVE-2023-43669](https://nvd.nist.gov/vuln/detail/CVE-2023-43669):\n\"The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).\"\n\n### Impact\n\nA remote unauthenticated attacker may cause a SurrealDB server that exposes its WebSocket interface to consume high CPU by sending an HTTP request with a very long header to the WebSocket interface, potentially leading to denial of service.\n\n### Patches\n\n- Version 1.1.0 and later are not affected by this issue.\n\n### Workarounds\n\nUsers unable to update may be able to limit access to the WebSocket interface (i.e. the `/rpc` endpoint) via reverse proxy if not in use or only used by a limited number of trusted clients. Alternatively, a reverse proxy may be used to strip or truncate request headers exceeding a reasonable length before reaching the SurrealDB server.\n\n### References\n\n- #2807\n- https://nvd.nist.gov/vuln/detail/CVE-2023-43669\n- https://rustsec.org/advisories/RUSTSEC-2023-0065.html\n- https://github.com/snapview/tungstenite-rs/issues/376", "severity": [ @@ -66,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-19T20:31:21Z", diff --git a/advisories/github-reviewed/2024/01/GHSA-wg2x-rv86-mmpx/GHSA-wg2x-rv86-mmpx.json b/advisories/github-reviewed/2024/01/GHSA-wg2x-rv86-mmpx/GHSA-wg2x-rv86-mmpx.json index b0c8086c7e8..08d2f589526 100644 --- a/advisories/github-reviewed/2024/01/GHSA-wg2x-rv86-mmpx/GHSA-wg2x-rv86-mmpx.json +++ b/advisories/github-reviewed/2024/01/GHSA-wg2x-rv86-mmpx/GHSA-wg2x-rv86-mmpx.json @@ -3,14 +3,10 @@ "id": "GHSA-wg2x-rv86-mmpx", "modified": "2024-01-19T22:07:47Z", "published": "2024-01-19T22:07:47Z", - "aliases": [ - - ], + "aliases": [], "summary": "SPV Merkle proof malleability allows the maintainer to prove invalid transactions", "details": "## Summary\nBy publishing specially crafted transactions on the Bitcoin blockchain, the SPV maintainer can produce seemingly valid SPV proofs for fraudulent transactions.\n\nThe issue was originally identified by Least Authority in the tBTC Bridge V2 Security Audit Report as _Issue B: Bitcoin SPV Merkle Proofs Can Be Faked_. A mitigation was believed to have been in place, but this turned out to contain an error, and the issue had not been effectively mitigated.\n\n### Details\nThis is achieved by creating a 64-byte transaction that the fraudulent transaction treats as a node in its merkle proof:\n\nThe attacker creates the malicious transaction `E` and calculates an unusual but valid transaction `D`, so that the last 32 bytes of `D` are a part of the merkle proof of `E`:\n\n```\nD = foo | hash256(E')\nE' = bar | hash256(E)\n```\n\n`foo` and `bar` are arbitrary 32-byte values selected to facilitate this attack.\n\nThe attacker can then publish `D` and wait for it to be mined. A valid SPV proof for `D` can then be transformed into a proof for `E` by prepending `bar` and `foo` to the merkle proof, and changing the transaction index into one matching `E`'s implied position in the merkle tree.\n\nCalculating a suitable value for `E'` has been estimated to require between 2\\^60 to 2\\^81 operations. By contrast, the current Bitcoin hashrate is approximately 2\\^69. Thus the cost of performing the requisite brute-force is at most similar to, or possibly up to 1,000,000 times lower than, the cost of mining 6 Bitcoin blocks at the current difficulty.\n\n### Impact\nThe vulnerability does not enable the SPV maintainer to do anything they would not have been able to do otherwise. However, the ability to bypass the need to mine 6 blocks at the current difficulty makes abusing the SPV maintainer position significantly cheaper.\n\n### Patches\nAdding the coinbase transaction and its merkle proof into the SPV proofs prevents this issue, by increasing the brute-force required to 2\\^224. If the length of the coinbase proof matches the length of the transaction proof, and both proofs are valid for the same header, we can trust that the exploit has not been abused for the transaction.\n\n### Workarounds\nThe trusted SPV maintainer position prevents this issue\n\n### References\n[Weaknesses in Bitcoin’s Merkle Root Construction](https://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190225/a27d8837/attachment-0001.pdf)\n\n[Leaf-Node weakness in Bitcoin Merkle Tree Design](https://bitslog.com/2018/06/09/leaf-node-weakness-in-bitcoin-merkle-tree-design/)\n\n[SPV proof verification vulnerable to potential (but expensive to exploit) Merkle tree problem \\#192](https://github.com/summa-tx/bitcoin-spv/issues/192)\n\n[tBTC Bridge V2 Security Audit Report](https://leastauthority.com/static/publications/LeastAuthority_KeepNetwork_tBTC_Bridge_v2_Updated_Final_Audit_Report.pdf)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -66,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-19T22:07:47Z", diff --git a/advisories/unreviewed/2021/11/GHSA-244r-jx38-mgcg/GHSA-244r-jx38-mgcg.json b/advisories/unreviewed/2021/11/GHSA-244r-jx38-mgcg/GHSA-244r-jx38-mgcg.json index 7f72a0ebbde..e508af7a858 100644 --- a/advisories/unreviewed/2021/11/GHSA-244r-jx38-mgcg/GHSA-244r-jx38-mgcg.json +++ b/advisories/unreviewed/2021/11/GHSA-244r-jx38-mgcg/GHSA-244r-jx38-mgcg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-2cjm-p78p-rjpj/GHSA-2cjm-p78p-rjpj.json b/advisories/unreviewed/2021/11/GHSA-2cjm-p78p-rjpj/GHSA-2cjm-p78p-rjpj.json index a9c6294c7bc..3639d606e35 100644 --- a/advisories/unreviewed/2021/11/GHSA-2cjm-p78p-rjpj/GHSA-2cjm-p78p-rjpj.json +++ b/advisories/unreviewed/2021/11/GHSA-2cjm-p78p-rjpj/GHSA-2cjm-p78p-rjpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-2hf9-98xv-3h7h/GHSA-2hf9-98xv-3h7h.json b/advisories/unreviewed/2021/11/GHSA-2hf9-98xv-3h7h/GHSA-2hf9-98xv-3h7h.json index e435ac9da36..3b6e099eb1a 100644 --- a/advisories/unreviewed/2021/11/GHSA-2hf9-98xv-3h7h/GHSA-2hf9-98xv-3h7h.json +++ b/advisories/unreviewed/2021/11/GHSA-2hf9-98xv-3h7h/GHSA-2hf9-98xv-3h7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3286-68f5-pqwv/GHSA-3286-68f5-pqwv.json b/advisories/unreviewed/2021/11/GHSA-3286-68f5-pqwv/GHSA-3286-68f5-pqwv.json index 05af3c84f2f..65ad12de000 100644 --- a/advisories/unreviewed/2021/11/GHSA-3286-68f5-pqwv/GHSA-3286-68f5-pqwv.json +++ b/advisories/unreviewed/2021/11/GHSA-3286-68f5-pqwv/GHSA-3286-68f5-pqwv.json @@ -7,12 +7,8 @@ "CVE-2021-42358" ], "details": "The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3h35-4jmf-3v47/GHSA-3h35-4jmf-3v47.json b/advisories/unreviewed/2021/11/GHSA-3h35-4jmf-3v47/GHSA-3h35-4jmf-3v47.json index 8a19747d783..e9cd9771555 100644 --- a/advisories/unreviewed/2021/11/GHSA-3h35-4jmf-3v47/GHSA-3h35-4jmf-3v47.json +++ b/advisories/unreviewed/2021/11/GHSA-3h35-4jmf-3v47/GHSA-3h35-4jmf-3v47.json @@ -7,12 +7,8 @@ "CVE-2020-7882" ], "details": "Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3m7g-q8jw-q449/GHSA-3m7g-q8jw-q449.json b/advisories/unreviewed/2021/11/GHSA-3m7g-q8jw-q449/GHSA-3m7g-q8jw-q449.json index f5f7b812548..44acaed38fa 100644 --- a/advisories/unreviewed/2021/11/GHSA-3m7g-q8jw-q449/GHSA-3m7g-q8jw-q449.json +++ b/advisories/unreviewed/2021/11/GHSA-3m7g-q8jw-q449/GHSA-3m7g-q8jw-q449.json @@ -7,12 +7,8 @@ "CVE-2021-44203" ], "details": "Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3qm9-v325-gx6g/GHSA-3qm9-v325-gx6g.json b/advisories/unreviewed/2021/11/GHSA-3qm9-v325-gx6g/GHSA-3qm9-v325-gx6g.json index eea6751ce49..09911371a0b 100644 --- a/advisories/unreviewed/2021/11/GHSA-3qm9-v325-gx6g/GHSA-3qm9-v325-gx6g.json +++ b/advisories/unreviewed/2021/11/GHSA-3qm9-v325-gx6g/GHSA-3qm9-v325-gx6g.json @@ -7,12 +7,8 @@ "CVE-2021-33490" ], "details": "OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3rf7-6c99-mx43/GHSA-3rf7-6c99-mx43.json b/advisories/unreviewed/2021/11/GHSA-3rf7-6c99-mx43/GHSA-3rf7-6c99-mx43.json index 462fa5dad42..33bbfcc75f5 100644 --- a/advisories/unreviewed/2021/11/GHSA-3rf7-6c99-mx43/GHSA-3rf7-6c99-mx43.json +++ b/advisories/unreviewed/2021/11/GHSA-3rf7-6c99-mx43/GHSA-3rf7-6c99-mx43.json @@ -7,12 +7,8 @@ "CVE-2021-36807" ], "details": "An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-3v4q-ppc4-rfgv/GHSA-3v4q-ppc4-rfgv.json b/advisories/unreviewed/2021/11/GHSA-3v4q-ppc4-rfgv/GHSA-3v4q-ppc4-rfgv.json index 6f32a12df2c..dee60556ad7 100644 --- a/advisories/unreviewed/2021/11/GHSA-3v4q-ppc4-rfgv/GHSA-3v4q-ppc4-rfgv.json +++ b/advisories/unreviewed/2021/11/GHSA-3v4q-ppc4-rfgv/GHSA-3v4q-ppc4-rfgv.json @@ -7,12 +7,8 @@ "CVE-2021-24860" ], "details": "The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-42jq-8pvg-2649/GHSA-42jq-8pvg-2649.json b/advisories/unreviewed/2021/11/GHSA-42jq-8pvg-2649/GHSA-42jq-8pvg-2649.json index 1b213399fdb..8a40e02ab05 100644 --- a/advisories/unreviewed/2021/11/GHSA-42jq-8pvg-2649/GHSA-42jq-8pvg-2649.json +++ b/advisories/unreviewed/2021/11/GHSA-42jq-8pvg-2649/GHSA-42jq-8pvg-2649.json @@ -7,12 +7,8 @@ "CVE-2021-43691" ], "details": "An unspecified version of tripexpress is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER[\"argv\"] then there is a path manipulation vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-42vq-32v8-j5v7/GHSA-42vq-32v8-j5v7.json b/advisories/unreviewed/2021/11/GHSA-42vq-32v8-j5v7/GHSA-42vq-32v8-j5v7.json index 46a7a2394f0..ff1f37ba04d 100644 --- a/advisories/unreviewed/2021/11/GHSA-42vq-32v8-j5v7/GHSA-42vq-32v8-j5v7.json +++ b/advisories/unreviewed/2021/11/GHSA-42vq-32v8-j5v7/GHSA-42vq-32v8-j5v7.json @@ -7,12 +7,8 @@ "CVE-2021-43695" ], "details": "An unspecified version of issabelPBX is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-43f7-xpq7-4gc9/GHSA-43f7-xpq7-4gc9.json b/advisories/unreviewed/2021/11/GHSA-43f7-xpq7-4gc9/GHSA-43f7-xpq7-4gc9.json index 751b130e883..7c2593d29c0 100644 --- a/advisories/unreviewed/2021/11/GHSA-43f7-xpq7-4gc9/GHSA-43f7-xpq7-4gc9.json +++ b/advisories/unreviewed/2021/11/GHSA-43f7-xpq7-4gc9/GHSA-43f7-xpq7-4gc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-48gh-jfp3-mc7v/GHSA-48gh-jfp3-mc7v.json b/advisories/unreviewed/2021/11/GHSA-48gh-jfp3-mc7v/GHSA-48gh-jfp3-mc7v.json index 35c7d6043b4..da24b816d79 100644 --- a/advisories/unreviewed/2021/11/GHSA-48gh-jfp3-mc7v/GHSA-48gh-jfp3-mc7v.json +++ b/advisories/unreviewed/2021/11/GHSA-48gh-jfp3-mc7v/GHSA-48gh-jfp3-mc7v.json @@ -7,12 +7,8 @@ "CVE-2021-37004" ], "details": "There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-4cpf-hvfq-qwq6/GHSA-4cpf-hvfq-qwq6.json b/advisories/unreviewed/2021/11/GHSA-4cpf-hvfq-qwq6/GHSA-4cpf-hvfq-qwq6.json index 5029ad64a3a..22956fe252e 100644 --- a/advisories/unreviewed/2021/11/GHSA-4cpf-hvfq-qwq6/GHSA-4cpf-hvfq-qwq6.json +++ b/advisories/unreviewed/2021/11/GHSA-4cpf-hvfq-qwq6/GHSA-4cpf-hvfq-qwq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-4jw2-qgm3-j49h/GHSA-4jw2-qgm3-j49h.json b/advisories/unreviewed/2021/11/GHSA-4jw2-qgm3-j49h/GHSA-4jw2-qgm3-j49h.json index 2b42f8105aa..309aab89c4b 100644 --- a/advisories/unreviewed/2021/11/GHSA-4jw2-qgm3-j49h/GHSA-4jw2-qgm3-j49h.json +++ b/advisories/unreviewed/2021/11/GHSA-4jw2-qgm3-j49h/GHSA-4jw2-qgm3-j49h.json @@ -7,12 +7,8 @@ "CVE-2021-38002" ], "details": "Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-4q83-54pp-rmxj/GHSA-4q83-54pp-rmxj.json b/advisories/unreviewed/2021/11/GHSA-4q83-54pp-rmxj/GHSA-4q83-54pp-rmxj.json index a701eb8b6ce..9dbd1a748e7 100644 --- a/advisories/unreviewed/2021/11/GHSA-4q83-54pp-rmxj/GHSA-4q83-54pp-rmxj.json +++ b/advisories/unreviewed/2021/11/GHSA-4q83-54pp-rmxj/GHSA-4q83-54pp-rmxj.json @@ -7,12 +7,8 @@ "CVE-2021-24768" ], "details": "The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-4rpr-3cr6-vg8r/GHSA-4rpr-3cr6-vg8r.json b/advisories/unreviewed/2021/11/GHSA-4rpr-3cr6-vg8r/GHSA-4rpr-3cr6-vg8r.json index f33b1a55516..7240c530959 100644 --- a/advisories/unreviewed/2021/11/GHSA-4rpr-3cr6-vg8r/GHSA-4rpr-3cr6-vg8r.json +++ b/advisories/unreviewed/2021/11/GHSA-4rpr-3cr6-vg8r/GHSA-4rpr-3cr6-vg8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-53q2-99ph-73wh/GHSA-53q2-99ph-73wh.json b/advisories/unreviewed/2021/11/GHSA-53q2-99ph-73wh/GHSA-53q2-99ph-73wh.json index 10b267a5cb8..d7f54de25aa 100644 --- a/advisories/unreviewed/2021/11/GHSA-53q2-99ph-73wh/GHSA-53q2-99ph-73wh.json +++ b/advisories/unreviewed/2021/11/GHSA-53q2-99ph-73wh/GHSA-53q2-99ph-73wh.json @@ -7,12 +7,8 @@ "CVE-2021-36916" ], "details": "The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function \"hmwp_get_user_ip\" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as \"X-Forwarded-For.\" As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-5647-h66r-5vj6/GHSA-5647-h66r-5vj6.json b/advisories/unreviewed/2021/11/GHSA-5647-h66r-5vj6/GHSA-5647-h66r-5vj6.json index d8eb6dc3534..9df4d8c59ff 100644 --- a/advisories/unreviewed/2021/11/GHSA-5647-h66r-5vj6/GHSA-5647-h66r-5vj6.json +++ b/advisories/unreviewed/2021/11/GHSA-5647-h66r-5vj6/GHSA-5647-h66r-5vj6.json @@ -7,12 +7,8 @@ "CVE-2021-38685" ], "details": "A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR FW 5.1.6 build 20211109 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-594j-f97m-jvvm/GHSA-594j-f97m-jvvm.json b/advisories/unreviewed/2021/11/GHSA-594j-f97m-jvvm/GHSA-594j-f97m-jvvm.json index f74476263e9..cb1ddea9563 100644 --- a/advisories/unreviewed/2021/11/GHSA-594j-f97m-jvvm/GHSA-594j-f97m-jvvm.json +++ b/advisories/unreviewed/2021/11/GHSA-594j-f97m-jvvm/GHSA-594j-f97m-jvvm.json @@ -7,12 +7,8 @@ "CVE-2021-33489" ], "details": "OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-5mr6-hrm2-p724/GHSA-5mr6-hrm2-p724.json b/advisories/unreviewed/2021/11/GHSA-5mr6-hrm2-p724/GHSA-5mr6-hrm2-p724.json index 0b2c33dd0c7..a2818e514f3 100644 --- a/advisories/unreviewed/2021/11/GHSA-5mr6-hrm2-p724/GHSA-5mr6-hrm2-p724.json +++ b/advisories/unreviewed/2021/11/GHSA-5mr6-hrm2-p724/GHSA-5mr6-hrm2-p724.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-5q55-ghjj-wjrp/GHSA-5q55-ghjj-wjrp.json b/advisories/unreviewed/2021/11/GHSA-5q55-ghjj-wjrp/GHSA-5q55-ghjj-wjrp.json index d4403f15ae0..eaa9feecefc 100644 --- a/advisories/unreviewed/2021/11/GHSA-5q55-ghjj-wjrp/GHSA-5q55-ghjj-wjrp.json +++ b/advisories/unreviewed/2021/11/GHSA-5q55-ghjj-wjrp/GHSA-5q55-ghjj-wjrp.json @@ -7,12 +7,8 @@ "CVE-2021-36884" ], "details": "Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-5q57-j272-7x8p/GHSA-5q57-j272-7x8p.json b/advisories/unreviewed/2021/11/GHSA-5q57-j272-7x8p/GHSA-5q57-j272-7x8p.json index 146976363c6..c31b4f70eb6 100644 --- a/advisories/unreviewed/2021/11/GHSA-5q57-j272-7x8p/GHSA-5q57-j272-7x8p.json +++ b/advisories/unreviewed/2021/11/GHSA-5q57-j272-7x8p/GHSA-5q57-j272-7x8p.json @@ -7,12 +7,8 @@ "CVE-2021-37019" ], "details": "There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-6q2x-x543-fr35/GHSA-6q2x-x543-fr35.json b/advisories/unreviewed/2021/11/GHSA-6q2x-x543-fr35/GHSA-6q2x-x543-fr35.json index 84bd0b9d451..243c134d405 100644 --- a/advisories/unreviewed/2021/11/GHSA-6q2x-x543-fr35/GHSA-6q2x-x543-fr35.json +++ b/advisories/unreviewed/2021/11/GHSA-6q2x-x543-fr35/GHSA-6q2x-x543-fr35.json @@ -7,12 +7,8 @@ "CVE-2021-37031" ], "details": "There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-6x8r-c56m-hh3p/GHSA-6x8r-c56m-hh3p.json b/advisories/unreviewed/2021/11/GHSA-6x8r-c56m-hh3p/GHSA-6x8r-c56m-hh3p.json index 95ab0f80fc7..a267ea73382 100644 --- a/advisories/unreviewed/2021/11/GHSA-6x8r-c56m-hh3p/GHSA-6x8r-c56m-hh3p.json +++ b/advisories/unreviewed/2021/11/GHSA-6x8r-c56m-hh3p/GHSA-6x8r-c56m-hh3p.json @@ -7,12 +7,8 @@ "CVE-2021-26611" ], "details": "HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7fmj-f47p-w477/GHSA-7fmj-f47p-w477.json b/advisories/unreviewed/2021/11/GHSA-7fmj-f47p-w477/GHSA-7fmj-f47p-w477.json index ff1811c165b..4db144f20a6 100644 --- a/advisories/unreviewed/2021/11/GHSA-7fmj-f47p-w477/GHSA-7fmj-f47p-w477.json +++ b/advisories/unreviewed/2021/11/GHSA-7fmj-f47p-w477/GHSA-7fmj-f47p-w477.json @@ -7,12 +7,8 @@ "CVE-2021-44201" ], "details": "Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7frp-922c-3gc5/GHSA-7frp-922c-3gc5.json b/advisories/unreviewed/2021/11/GHSA-7frp-922c-3gc5/GHSA-7frp-922c-3gc5.json index 899e4578d0d..00f1d6c9aa1 100644 --- a/advisories/unreviewed/2021/11/GHSA-7frp-922c-3gc5/GHSA-7frp-922c-3gc5.json +++ b/advisories/unreviewed/2021/11/GHSA-7frp-922c-3gc5/GHSA-7frp-922c-3gc5.json @@ -7,12 +7,8 @@ "CVE-2021-42269" ], "details": "Adobe Animate version 21.0.9 (and earlier) are affected by a use-after-free vulnerability in the processing of a malformed FLA file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7q87-cj95-29mc/GHSA-7q87-cj95-29mc.json b/advisories/unreviewed/2021/11/GHSA-7q87-cj95-29mc/GHSA-7q87-cj95-29mc.json index 117f44eb1b8..66a2a009689 100644 --- a/advisories/unreviewed/2021/11/GHSA-7q87-cj95-29mc/GHSA-7q87-cj95-29mc.json +++ b/advisories/unreviewed/2021/11/GHSA-7q87-cj95-29mc/GHSA-7q87-cj95-29mc.json @@ -7,12 +7,8 @@ "CVE-2021-42785" ], "details": "Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7q8m-h35w-p957/GHSA-7q8m-h35w-p957.json b/advisories/unreviewed/2021/11/GHSA-7q8m-h35w-p957/GHSA-7q8m-h35w-p957.json index a38fb5b30f6..f62a686006e 100644 --- a/advisories/unreviewed/2021/11/GHSA-7q8m-h35w-p957/GHSA-7q8m-h35w-p957.json +++ b/advisories/unreviewed/2021/11/GHSA-7q8m-h35w-p957/GHSA-7q8m-h35w-p957.json @@ -7,12 +7,8 @@ "CVE-2021-43697" ], "details": "An unspecified version of Workerman-ThinkPHP-Redis is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET{C('VAR_JSONP_HANDLER')] then there is a XSS vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7r7f-rxmv-c4j3/GHSA-7r7f-rxmv-c4j3.json b/advisories/unreviewed/2021/11/GHSA-7r7f-rxmv-c4j3/GHSA-7r7f-rxmv-c4j3.json index c5aea761ea7..6cd2e0f4bf2 100644 --- a/advisories/unreviewed/2021/11/GHSA-7r7f-rxmv-c4j3/GHSA-7r7f-rxmv-c4j3.json +++ b/advisories/unreviewed/2021/11/GHSA-7r7f-rxmv-c4j3/GHSA-7r7f-rxmv-c4j3.json @@ -7,12 +7,8 @@ "CVE-2021-42364" ], "details": "The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-7xq9-wjv7-m6g7/GHSA-7xq9-wjv7-m6g7.json b/advisories/unreviewed/2021/11/GHSA-7xq9-wjv7-m6g7/GHSA-7xq9-wjv7-m6g7.json index edc60c2fc5f..5feeac6ee52 100644 --- a/advisories/unreviewed/2021/11/GHSA-7xq9-wjv7-m6g7/GHSA-7xq9-wjv7-m6g7.json +++ b/advisories/unreviewed/2021/11/GHSA-7xq9-wjv7-m6g7/GHSA-7xq9-wjv7-m6g7.json @@ -7,12 +7,8 @@ "CVE-2021-0658" ], "details": "In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672107.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-83h5-88j7-5q7w/GHSA-83h5-88j7-5q7w.json b/advisories/unreviewed/2021/11/GHSA-83h5-88j7-5q7w/GHSA-83h5-88j7-5q7w.json index 430e25769d7..50c012106c1 100644 --- a/advisories/unreviewed/2021/11/GHSA-83h5-88j7-5q7w/GHSA-83h5-88j7-5q7w.json +++ b/advisories/unreviewed/2021/11/GHSA-83h5-88j7-5q7w/GHSA-83h5-88j7-5q7w.json @@ -7,12 +7,8 @@ "CVE-2021-37026" ], "details": "There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-84q3-jrvx-62cp/GHSA-84q3-jrvx-62cp.json b/advisories/unreviewed/2021/11/GHSA-84q3-jrvx-62cp/GHSA-84q3-jrvx-62cp.json index ec531d0134b..28ddbb86d0e 100644 --- a/advisories/unreviewed/2021/11/GHSA-84q3-jrvx-62cp/GHSA-84q3-jrvx-62cp.json +++ b/advisories/unreviewed/2021/11/GHSA-84q3-jrvx-62cp/GHSA-84q3-jrvx-62cp.json @@ -7,12 +7,8 @@ "CVE-2021-37010" ], "details": "There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-8cqg-gfwc-rcm7/GHSA-8cqg-gfwc-rcm7.json b/advisories/unreviewed/2021/11/GHSA-8cqg-gfwc-rcm7/GHSA-8cqg-gfwc-rcm7.json index ed516157d31..499fd5bb481 100644 --- a/advisories/unreviewed/2021/11/GHSA-8cqg-gfwc-rcm7/GHSA-8cqg-gfwc-rcm7.json +++ b/advisories/unreviewed/2021/11/GHSA-8cqg-gfwc-rcm7/GHSA-8cqg-gfwc-rcm7.json @@ -7,12 +7,8 @@ "CVE-2021-37017" ], "details": "There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-8h56-96mw-r96r/GHSA-8h56-96mw-r96r.json b/advisories/unreviewed/2021/11/GHSA-8h56-96mw-r96r/GHSA-8h56-96mw-r96r.json index cf0eb5db41b..9cfa62466fe 100644 --- a/advisories/unreviewed/2021/11/GHSA-8h56-96mw-r96r/GHSA-8h56-96mw-r96r.json +++ b/advisories/unreviewed/2021/11/GHSA-8h56-96mw-r96r/GHSA-8h56-96mw-r96r.json @@ -7,12 +7,8 @@ "CVE-2021-42365" ], "details": "The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.13. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-8h5w-h3fr-4whw/GHSA-8h5w-h3fr-4whw.json b/advisories/unreviewed/2021/11/GHSA-8h5w-h3fr-4whw/GHSA-8h5w-h3fr-4whw.json index 4cac1f3399f..65d6ebf3d8a 100644 --- a/advisories/unreviewed/2021/11/GHSA-8h5w-h3fr-4whw/GHSA-8h5w-h3fr-4whw.json +++ b/advisories/unreviewed/2021/11/GHSA-8h5w-h3fr-4whw/GHSA-8h5w-h3fr-4whw.json @@ -7,12 +7,8 @@ "CVE-2021-0656" ], "details": "In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05709376; Issue ID: ALPS05709376.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-8j4x-5882-263f/GHSA-8j4x-5882-263f.json b/advisories/unreviewed/2021/11/GHSA-8j4x-5882-263f/GHSA-8j4x-5882-263f.json index 86327f07d33..9054791f0cf 100644 --- a/advisories/unreviewed/2021/11/GHSA-8j4x-5882-263f/GHSA-8j4x-5882-263f.json +++ b/advisories/unreviewed/2021/11/GHSA-8j4x-5882-263f/GHSA-8j4x-5882-263f.json @@ -7,12 +7,8 @@ "CVE-2021-42363" ], "details": "The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-8qjr-j6r8-5cw7/GHSA-8qjr-j6r8-5cw7.json b/advisories/unreviewed/2021/11/GHSA-8qjr-j6r8-5cw7/GHSA-8qjr-j6r8-5cw7.json index 060ba015039..82305fc682a 100644 --- a/advisories/unreviewed/2021/11/GHSA-8qjr-j6r8-5cw7/GHSA-8qjr-j6r8-5cw7.json +++ b/advisories/unreviewed/2021/11/GHSA-8qjr-j6r8-5cw7/GHSA-8qjr-j6r8-5cw7.json @@ -7,12 +7,8 @@ "CVE-2021-24889" ], "details": "The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-986q-37xh-j7h2/GHSA-986q-37xh-j7h2.json b/advisories/unreviewed/2021/11/GHSA-986q-37xh-j7h2/GHSA-986q-37xh-j7h2.json index cc917746eca..cea5f52812a 100644 --- a/advisories/unreviewed/2021/11/GHSA-986q-37xh-j7h2/GHSA-986q-37xh-j7h2.json +++ b/advisories/unreviewed/2021/11/GHSA-986q-37xh-j7h2/GHSA-986q-37xh-j7h2.json @@ -7,12 +7,8 @@ "CVE-2021-24915" ], "details": "The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-9c2r-7f3h-qc57/GHSA-9c2r-7f3h-qc57.json b/advisories/unreviewed/2021/11/GHSA-9c2r-7f3h-qc57/GHSA-9c2r-7f3h-qc57.json index 49bf0357745..f2a8477286a 100644 --- a/advisories/unreviewed/2021/11/GHSA-9c2r-7f3h-qc57/GHSA-9c2r-7f3h-qc57.json +++ b/advisories/unreviewed/2021/11/GHSA-9c2r-7f3h-qc57/GHSA-9c2r-7f3h-qc57.json @@ -7,12 +7,8 @@ "CVE-2021-0670" ], "details": "In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05654663; Issue ID: ALPS05654663.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-9fhm-63v7-pp72/GHSA-9fhm-63v7-pp72.json b/advisories/unreviewed/2021/11/GHSA-9fhm-63v7-pp72/GHSA-9fhm-63v7-pp72.json index 480eee88232..a5eb2b19449 100644 --- a/advisories/unreviewed/2021/11/GHSA-9fhm-63v7-pp72/GHSA-9fhm-63v7-pp72.json +++ b/advisories/unreviewed/2021/11/GHSA-9fhm-63v7-pp72/GHSA-9fhm-63v7-pp72.json @@ -7,12 +7,8 @@ "CVE-2021-39353" ], "details": "The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-9fv2-2p6h-wc29/GHSA-9fv2-2p6h-wc29.json b/advisories/unreviewed/2021/11/GHSA-9fv2-2p6h-wc29/GHSA-9fv2-2p6h-wc29.json index 94359c818fa..acd48bf7ffa 100644 --- a/advisories/unreviewed/2021/11/GHSA-9fv2-2p6h-wc29/GHSA-9fv2-2p6h-wc29.json +++ b/advisories/unreviewed/2021/11/GHSA-9fv2-2p6h-wc29/GHSA-9fv2-2p6h-wc29.json @@ -7,12 +7,8 @@ "CVE-2021-24883" ], "details": "The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-9q3v-827r-c9mw/GHSA-9q3v-827r-c9mw.json b/advisories/unreviewed/2021/11/GHSA-9q3v-827r-c9mw/GHSA-9q3v-827r-c9mw.json index df588926241..a8022cd2472 100644 --- a/advisories/unreviewed/2021/11/GHSA-9q3v-827r-c9mw/GHSA-9q3v-827r-c9mw.json +++ b/advisories/unreviewed/2021/11/GHSA-9q3v-827r-c9mw/GHSA-9q3v-827r-c9mw.json @@ -7,12 +7,8 @@ "CVE-2021-24755" ], "details": "The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-9vc7-frrv-8mwx/GHSA-9vc7-frrv-8mwx.json b/advisories/unreviewed/2021/11/GHSA-9vc7-frrv-8mwx/GHSA-9vc7-frrv-8mwx.json index d3881c38c26..c00a93dff2a 100644 --- a/advisories/unreviewed/2021/11/GHSA-9vc7-frrv-8mwx/GHSA-9vc7-frrv-8mwx.json +++ b/advisories/unreviewed/2021/11/GHSA-9vc7-frrv-8mwx/GHSA-9vc7-frrv-8mwx.json @@ -7,12 +7,8 @@ "CVE-2021-20846" ], "details": "Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-9wxc-375c-cvq2/GHSA-9wxc-375c-cvq2.json b/advisories/unreviewed/2021/11/GHSA-9wxc-375c-cvq2/GHSA-9wxc-375c-cvq2.json index 1fa42deb16d..fa77c3667ff 100644 --- a/advisories/unreviewed/2021/11/GHSA-9wxc-375c-cvq2/GHSA-9wxc-375c-cvq2.json +++ b/advisories/unreviewed/2021/11/GHSA-9wxc-375c-cvq2/GHSA-9wxc-375c-cvq2.json @@ -7,12 +7,8 @@ "CVE-2021-43557" ], "details": "The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains \"^/internal/\", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same issue. And it may affect the developer's custom plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-c2cr-q5v4-8ccv/GHSA-c2cr-q5v4-8ccv.json b/advisories/unreviewed/2021/11/GHSA-c2cr-q5v4-8ccv/GHSA-c2cr-q5v4-8ccv.json index 6be982f78bd..9515a04516b 100644 --- a/advisories/unreviewed/2021/11/GHSA-c2cr-q5v4-8ccv/GHSA-c2cr-q5v4-8ccv.json +++ b/advisories/unreviewed/2021/11/GHSA-c2cr-q5v4-8ccv/GHSA-c2cr-q5v4-8ccv.json @@ -7,12 +7,8 @@ "CVE-2021-44198" ], "details": "DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-c34h-vxpx-r4j2/GHSA-c34h-vxpx-r4j2.json b/advisories/unreviewed/2021/11/GHSA-c34h-vxpx-r4j2/GHSA-c34h-vxpx-r4j2.json index b72c8f7da53..bb6f17d4d99 100644 --- a/advisories/unreviewed/2021/11/GHSA-c34h-vxpx-r4j2/GHSA-c34h-vxpx-r4j2.json +++ b/advisories/unreviewed/2021/11/GHSA-c34h-vxpx-r4j2/GHSA-c34h-vxpx-r4j2.json @@ -7,12 +7,8 @@ "CVE-2021-24899" ], "details": "The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-cgv7-mrmg-p534/GHSA-cgv7-mrmg-p534.json b/advisories/unreviewed/2021/11/GHSA-cgv7-mrmg-p534/GHSA-cgv7-mrmg-p534.json index 53a2875dd14..cbddc137e70 100644 --- a/advisories/unreviewed/2021/11/GHSA-cgv7-mrmg-p534/GHSA-cgv7-mrmg-p534.json +++ b/advisories/unreviewed/2021/11/GHSA-cgv7-mrmg-p534/GHSA-cgv7-mrmg-p534.json @@ -7,12 +7,8 @@ "CVE-2021-37022" ], "details": "There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-cjj6-wmgg-xg75/GHSA-cjj6-wmgg-xg75.json b/advisories/unreviewed/2021/11/GHSA-cjj6-wmgg-xg75/GHSA-cjj6-wmgg-xg75.json index 395b0f690d2..207e76b524e 100644 --- a/advisories/unreviewed/2021/11/GHSA-cjj6-wmgg-xg75/GHSA-cjj6-wmgg-xg75.json +++ b/advisories/unreviewed/2021/11/GHSA-cjj6-wmgg-xg75/GHSA-cjj6-wmgg-xg75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-cpcp-g87h-g6h3/GHSA-cpcp-g87h-g6h3.json b/advisories/unreviewed/2021/11/GHSA-cpcp-g87h-g6h3/GHSA-cpcp-g87h-g6h3.json index 78a427cb852..b7df5e9a631 100644 --- a/advisories/unreviewed/2021/11/GHSA-cpcp-g87h-g6h3/GHSA-cpcp-g87h-g6h3.json +++ b/advisories/unreviewed/2021/11/GHSA-cpcp-g87h-g6h3/GHSA-cpcp-g87h-g6h3.json @@ -7,12 +7,8 @@ "CVE-2021-43268" ], "details": "An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-cqc3-xrjw-8pwv/GHSA-cqc3-xrjw-8pwv.json b/advisories/unreviewed/2021/11/GHSA-cqc3-xrjw-8pwv/GHSA-cqc3-xrjw-8pwv.json index 0b140f55699..bc9d384fb86 100644 --- a/advisories/unreviewed/2021/11/GHSA-cqc3-xrjw-8pwv/GHSA-cqc3-xrjw-8pwv.json +++ b/advisories/unreviewed/2021/11/GHSA-cqc3-xrjw-8pwv/GHSA-cqc3-xrjw-8pwv.json @@ -7,12 +7,8 @@ "CVE-2021-24749" ], "details": "The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-crhj-frp3-x49w/GHSA-crhj-frp3-x49w.json b/advisories/unreviewed/2021/11/GHSA-crhj-frp3-x49w/GHSA-crhj-frp3-x49w.json index 976de887225..2422efd14fc 100644 --- a/advisories/unreviewed/2021/11/GHSA-crhj-frp3-x49w/GHSA-crhj-frp3-x49w.json +++ b/advisories/unreviewed/2021/11/GHSA-crhj-frp3-x49w/GHSA-crhj-frp3-x49w.json @@ -7,12 +7,8 @@ "CVE-2021-42783" ], "details": "Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to execute administrative actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-crr7-h45x-f39h/GHSA-crr7-h45x-f39h.json b/advisories/unreviewed/2021/11/GHSA-crr7-h45x-f39h/GHSA-crr7-h45x-f39h.json index ffe348b7a60..2ba77518e79 100644 --- a/advisories/unreviewed/2021/11/GHSA-crr7-h45x-f39h/GHSA-crr7-h45x-f39h.json +++ b/advisories/unreviewed/2021/11/GHSA-crr7-h45x-f39h/GHSA-crr7-h45x-f39h.json @@ -7,12 +7,8 @@ "CVE-2021-38980" ], "details": "IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-cvpr-72qq-65cc/GHSA-cvpr-72qq-65cc.json b/advisories/unreviewed/2021/11/GHSA-cvpr-72qq-65cc/GHSA-cvpr-72qq-65cc.json index d10ae2345c1..dd7bd39eeb7 100644 --- a/advisories/unreviewed/2021/11/GHSA-cvpr-72qq-65cc/GHSA-cvpr-72qq-65cc.json +++ b/advisories/unreviewed/2021/11/GHSA-cvpr-72qq-65cc/GHSA-cvpr-72qq-65cc.json @@ -7,12 +7,8 @@ "CVE-2021-25269" ], "details": "A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-f2j4-5mw5-qhr4/GHSA-f2j4-5mw5-qhr4.json b/advisories/unreviewed/2021/11/GHSA-f2j4-5mw5-qhr4/GHSA-f2j4-5mw5-qhr4.json index b5f7f08f129..3aeb1c08dcd 100644 --- a/advisories/unreviewed/2021/11/GHSA-f2j4-5mw5-qhr4/GHSA-f2j4-5mw5-qhr4.json +++ b/advisories/unreviewed/2021/11/GHSA-f2j4-5mw5-qhr4/GHSA-f2j4-5mw5-qhr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-f648-43x4-7j96/GHSA-f648-43x4-7j96.json b/advisories/unreviewed/2021/11/GHSA-f648-43x4-7j96/GHSA-f648-43x4-7j96.json index 38f485fa57e..78b84cca284 100644 --- a/advisories/unreviewed/2021/11/GHSA-f648-43x4-7j96/GHSA-f648-43x4-7j96.json +++ b/advisories/unreviewed/2021/11/GHSA-f648-43x4-7j96/GHSA-f648-43x4-7j96.json @@ -7,12 +7,8 @@ "CVE-2021-24751" ], "details": "The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-f8mh-c4m8-wxw7/GHSA-f8mh-c4m8-wxw7.json b/advisories/unreviewed/2021/11/GHSA-f8mh-c4m8-wxw7/GHSA-f8mh-c4m8-wxw7.json index 5b2e1d828b6..2947c890ba6 100644 --- a/advisories/unreviewed/2021/11/GHSA-f8mh-c4m8-wxw7/GHSA-f8mh-c4m8-wxw7.json +++ b/advisories/unreviewed/2021/11/GHSA-f8mh-c4m8-wxw7/GHSA-f8mh-c4m8-wxw7.json @@ -7,12 +7,8 @@ "CVE-2021-43581" ], "details": "An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. The specific issue exists within the parsing of U3D files. Incorrect use of the LibJpeg source manager inside the U3D library, and crafted data in a U3D file, can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-fj36-8fj3-c7q3/GHSA-fj36-8fj3-c7q3.json b/advisories/unreviewed/2021/11/GHSA-fj36-8fj3-c7q3/GHSA-fj36-8fj3-c7q3.json index c16526d37b7..9a34e32882e 100644 --- a/advisories/unreviewed/2021/11/GHSA-fj36-8fj3-c7q3/GHSA-fj36-8fj3-c7q3.json +++ b/advisories/unreviewed/2021/11/GHSA-fj36-8fj3-c7q3/GHSA-fj36-8fj3-c7q3.json @@ -7,12 +7,8 @@ "CVE-2021-44037" ], "details": "Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-fr68-g2qf-53vm/GHSA-fr68-g2qf-53vm.json b/advisories/unreviewed/2021/11/GHSA-fr68-g2qf-53vm/GHSA-fr68-g2qf-53vm.json index ee5321ec2d1..1c78995053e 100644 --- a/advisories/unreviewed/2021/11/GHSA-fr68-g2qf-53vm/GHSA-fr68-g2qf-53vm.json +++ b/advisories/unreviewed/2021/11/GHSA-fr68-g2qf-53vm/GHSA-fr68-g2qf-53vm.json @@ -7,12 +7,8 @@ "CVE-2021-37006" ], "details": "There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-fwq9-g6rm-rj33/GHSA-fwq9-g6rm-rj33.json b/advisories/unreviewed/2021/11/GHSA-fwq9-g6rm-rj33/GHSA-fwq9-g6rm-rj33.json index 0ba622af2bb..d9e80ac52da 100644 --- a/advisories/unreviewed/2021/11/GHSA-fwq9-g6rm-rj33/GHSA-fwq9-g6rm-rj33.json +++ b/advisories/unreviewed/2021/11/GHSA-fwq9-g6rm-rj33/GHSA-fwq9-g6rm-rj33.json @@ -7,12 +7,8 @@ "CVE-2021-36299" ], "details": "Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-g46v-hp5m-3wgf/GHSA-g46v-hp5m-3wgf.json b/advisories/unreviewed/2021/11/GHSA-g46v-hp5m-3wgf/GHSA-g46v-hp5m-3wgf.json index a1a60db60ef..c6065790bde 100644 --- a/advisories/unreviewed/2021/11/GHSA-g46v-hp5m-3wgf/GHSA-g46v-hp5m-3wgf.json +++ b/advisories/unreviewed/2021/11/GHSA-g46v-hp5m-3wgf/GHSA-g46v-hp5m-3wgf.json @@ -7,12 +7,8 @@ "CVE-2021-44200" ], "details": "Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-g767-52f6-24gr/GHSA-g767-52f6-24gr.json b/advisories/unreviewed/2021/11/GHSA-g767-52f6-24gr/GHSA-g767-52f6-24gr.json index cc2c26e4d60..65edc5cf5ad 100644 --- a/advisories/unreviewed/2021/11/GHSA-g767-52f6-24gr/GHSA-g767-52f6-24gr.json +++ b/advisories/unreviewed/2021/11/GHSA-g767-52f6-24gr/GHSA-g767-52f6-24gr.json @@ -7,12 +7,8 @@ "CVE-2021-27026" ], "details": "A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-g7gp-62jw-j6c8/GHSA-g7gp-62jw-j6c8.json b/advisories/unreviewed/2021/11/GHSA-g7gp-62jw-j6c8/GHSA-g7gp-62jw-j6c8.json index 5ac3c08e72f..08a27a06699 100644 --- a/advisories/unreviewed/2021/11/GHSA-g7gp-62jw-j6c8/GHSA-g7gp-62jw-j6c8.json +++ b/advisories/unreviewed/2021/11/GHSA-g7gp-62jw-j6c8/GHSA-g7gp-62jw-j6c8.json @@ -7,12 +7,8 @@ "CVE-2021-40756" ], "details": "Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-gcvg-gpgp-f6cf/GHSA-gcvg-gpgp-f6cf.json b/advisories/unreviewed/2021/11/GHSA-gcvg-gpgp-f6cf/GHSA-gcvg-gpgp-f6cf.json index 282d9d9b549..e873ad268ce 100644 --- a/advisories/unreviewed/2021/11/GHSA-gcvg-gpgp-f6cf/GHSA-gcvg-gpgp-f6cf.json +++ b/advisories/unreviewed/2021/11/GHSA-gcvg-gpgp-f6cf/GHSA-gcvg-gpgp-f6cf.json @@ -7,12 +7,8 @@ "CVE-2021-24927" ], "details": "The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-gfh7-x68m-493m/GHSA-gfh7-x68m-493m.json b/advisories/unreviewed/2021/11/GHSA-gfh7-x68m-493m/GHSA-gfh7-x68m-493m.json index 5b59ec92995..a8ca858f49b 100644 --- a/advisories/unreviewed/2021/11/GHSA-gfh7-x68m-493m/GHSA-gfh7-x68m-493m.json +++ b/advisories/unreviewed/2021/11/GHSA-gfh7-x68m-493m/GHSA-gfh7-x68m-493m.json @@ -7,12 +7,8 @@ "CVE-2021-24748" ], "details": "The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-gmxx-4882-2mxv/GHSA-gmxx-4882-2mxv.json b/advisories/unreviewed/2021/11/GHSA-gmxx-4882-2mxv/GHSA-gmxx-4882-2mxv.json index b2b1aa80cde..efbcc79d532 100644 --- a/advisories/unreviewed/2021/11/GHSA-gmxx-4882-2mxv/GHSA-gmxx-4882-2mxv.json +++ b/advisories/unreviewed/2021/11/GHSA-gmxx-4882-2mxv/GHSA-gmxx-4882-2mxv.json @@ -7,12 +7,8 @@ "CVE-2021-40131" ], "details": "A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit this vulnerability by adding malicious code to the configuration by using the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code in the context of the interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-gpv9-mf3p-h34x/GHSA-gpv9-mf3p-h34x.json b/advisories/unreviewed/2021/11/GHSA-gpv9-mf3p-h34x/GHSA-gpv9-mf3p-h34x.json index 019e5e9dd65..ff3a8a6b9ca 100644 --- a/advisories/unreviewed/2021/11/GHSA-gpv9-mf3p-h34x/GHSA-gpv9-mf3p-h34x.json +++ b/advisories/unreviewed/2021/11/GHSA-gpv9-mf3p-h34x/GHSA-gpv9-mf3p-h34x.json @@ -7,12 +7,8 @@ "CVE-2021-20844" ], "details": "Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-h8rj-qxf5-m5r5/GHSA-h8rj-qxf5-m5r5.json b/advisories/unreviewed/2021/11/GHSA-h8rj-qxf5-m5r5/GHSA-h8rj-qxf5-m5r5.json index d8027209189..b8724ca76ee 100644 --- a/advisories/unreviewed/2021/11/GHSA-h8rj-qxf5-m5r5/GHSA-h8rj-qxf5-m5r5.json +++ b/advisories/unreviewed/2021/11/GHSA-h8rj-qxf5-m5r5/GHSA-h8rj-qxf5-m5r5.json @@ -7,12 +7,8 @@ "CVE-2021-37997" ], "details": "Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-hj8f-mh7g-pc82/GHSA-hj8f-mh7g-pc82.json b/advisories/unreviewed/2021/11/GHSA-hj8f-mh7g-pc82/GHSA-hj8f-mh7g-pc82.json index 2b60a47e6c5..5d5d77767f1 100644 --- a/advisories/unreviewed/2021/11/GHSA-hj8f-mh7g-pc82/GHSA-hj8f-mh7g-pc82.json +++ b/advisories/unreviewed/2021/11/GHSA-hj8f-mh7g-pc82/GHSA-hj8f-mh7g-pc82.json @@ -7,12 +7,8 @@ "CVE-2021-22356" ], "details": "There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; NGFW Module V500R005C00SPC100, V500R005C00SPC200; Secospace USG6300 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6600 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; USG9500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-hw2w-x847-8444/GHSA-hw2w-x847-8444.json b/advisories/unreviewed/2021/11/GHSA-hw2w-x847-8444/GHSA-hw2w-x847-8444.json index e2f6bfe39ea..49e748adbd4 100644 --- a/advisories/unreviewed/2021/11/GHSA-hw2w-x847-8444/GHSA-hw2w-x847-8444.json +++ b/advisories/unreviewed/2021/11/GHSA-hw2w-x847-8444/GHSA-hw2w-x847-8444.json @@ -7,12 +7,8 @@ "CVE-2021-36843" ], "details": "Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-hw84-h4fr-vvvc/GHSA-hw84-h4fr-vvvc.json b/advisories/unreviewed/2021/11/GHSA-hw84-h4fr-vvvc/GHSA-hw84-h4fr-vvvc.json index ae2011acf24..bb91ef5e44f 100644 --- a/advisories/unreviewed/2021/11/GHSA-hw84-h4fr-vvvc/GHSA-hw84-h4fr-vvvc.json +++ b/advisories/unreviewed/2021/11/GHSA-hw84-h4fr-vvvc/GHSA-hw84-h4fr-vvvc.json @@ -7,12 +7,8 @@ "CVE-2021-26248" ], "details": "Philips MRI 1.5T and MRI 3T Version 5.x.x assigns an owner who is outside the intended control sphere to a resource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-hxmm-5xh3-pqcx/GHSA-hxmm-5xh3-pqcx.json b/advisories/unreviewed/2021/11/GHSA-hxmm-5xh3-pqcx/GHSA-hxmm-5xh3-pqcx.json index 9ed367e074a..158ef0228f4 100644 --- a/advisories/unreviewed/2021/11/GHSA-hxmm-5xh3-pqcx/GHSA-hxmm-5xh3-pqcx.json +++ b/advisories/unreviewed/2021/11/GHSA-hxmm-5xh3-pqcx/GHSA-hxmm-5xh3-pqcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-j244-24xw-9prp/GHSA-j244-24xw-9prp.json b/advisories/unreviewed/2021/11/GHSA-j244-24xw-9prp/GHSA-j244-24xw-9prp.json index 48937a10f4e..7e537a96e75 100644 --- a/advisories/unreviewed/2021/11/GHSA-j244-24xw-9prp/GHSA-j244-24xw-9prp.json +++ b/advisories/unreviewed/2021/11/GHSA-j244-24xw-9prp/GHSA-j244-24xw-9prp.json @@ -7,12 +7,8 @@ "CVE-2021-33495" ], "details": "OX App Suite 7.10.5 allows XSS via an OX Chat system message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-j2p2-prgf-5285/GHSA-j2p2-prgf-5285.json b/advisories/unreviewed/2021/11/GHSA-j2p2-prgf-5285/GHSA-j2p2-prgf-5285.json index 2e7ac679b87..1cc13139981 100644 --- a/advisories/unreviewed/2021/11/GHSA-j2p2-prgf-5285/GHSA-j2p2-prgf-5285.json +++ b/advisories/unreviewed/2021/11/GHSA-j2p2-prgf-5285/GHSA-j2p2-prgf-5285.json @@ -7,12 +7,8 @@ "CVE-2021-40774" ], "details": "Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-j464-8gjj-h5jc/GHSA-j464-8gjj-h5jc.json b/advisories/unreviewed/2021/11/GHSA-j464-8gjj-h5jc/GHSA-j464-8gjj-h5jc.json index 3c9dd12db4f..05ecb677584 100644 --- a/advisories/unreviewed/2021/11/GHSA-j464-8gjj-h5jc/GHSA-j464-8gjj-h5jc.json +++ b/advisories/unreviewed/2021/11/GHSA-j464-8gjj-h5jc/GHSA-j464-8gjj-h5jc.json @@ -7,12 +7,8 @@ "CVE-2021-24876" ], "details": "The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-j9qp-w82r-g5cf/GHSA-j9qp-w82r-g5cf.json b/advisories/unreviewed/2021/11/GHSA-j9qp-w82r-g5cf/GHSA-j9qp-w82r-g5cf.json index 29731957e6a..6f23e27b3c3 100644 --- a/advisories/unreviewed/2021/11/GHSA-j9qp-w82r-g5cf/GHSA-j9qp-w82r-g5cf.json +++ b/advisories/unreviewed/2021/11/GHSA-j9qp-w82r-g5cf/GHSA-j9qp-w82r-g5cf.json @@ -7,12 +7,8 @@ "CVE-2021-24918" ], "details": "The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-j9w2-qr3r-xr77/GHSA-j9w2-qr3r-xr77.json b/advisories/unreviewed/2021/11/GHSA-j9w2-qr3r-xr77/GHSA-j9w2-qr3r-xr77.json index 907267fcee7..332528e1c58 100644 --- a/advisories/unreviewed/2021/11/GHSA-j9w2-qr3r-xr77/GHSA-j9w2-qr3r-xr77.json +++ b/advisories/unreviewed/2021/11/GHSA-j9w2-qr3r-xr77/GHSA-j9w2-qr3r-xr77.json @@ -7,12 +7,8 @@ "CVE-2021-24745" ], "details": "The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-jgc5-v5wh-xr99/GHSA-jgc5-v5wh-xr99.json b/advisories/unreviewed/2021/11/GHSA-jgc5-v5wh-xr99/GHSA-jgc5-v5wh-xr99.json index 6a2995c6a49..5cb6e608740 100644 --- a/advisories/unreviewed/2021/11/GHSA-jgc5-v5wh-xr99/GHSA-jgc5-v5wh-xr99.json +++ b/advisories/unreviewed/2021/11/GHSA-jgc5-v5wh-xr99/GHSA-jgc5-v5wh-xr99.json @@ -7,12 +7,8 @@ "CVE-2021-29328" ], "details": "OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-m2hr-vhr6-jvq7/GHSA-m2hr-vhr6-jvq7.json b/advisories/unreviewed/2021/11/GHSA-m2hr-vhr6-jvq7/GHSA-m2hr-vhr6-jvq7.json index 95efdc2a9ff..4ac7c2c2638 100644 --- a/advisories/unreviewed/2021/11/GHSA-m2hr-vhr6-jvq7/GHSA-m2hr-vhr6-jvq7.json +++ b/advisories/unreviewed/2021/11/GHSA-m2hr-vhr6-jvq7/GHSA-m2hr-vhr6-jvq7.json @@ -7,12 +7,8 @@ "CVE-2021-37035" ], "details": "There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-m882-7wv7-pwjj/GHSA-m882-7wv7-pwjj.json b/advisories/unreviewed/2021/11/GHSA-m882-7wv7-pwjj/GHSA-m882-7wv7-pwjj.json index 60ca0c94ab8..6da9c9cd799 100644 --- a/advisories/unreviewed/2021/11/GHSA-m882-7wv7-pwjj/GHSA-m882-7wv7-pwjj.json +++ b/advisories/unreviewed/2021/11/GHSA-m882-7wv7-pwjj/GHSA-m882-7wv7-pwjj.json @@ -7,12 +7,8 @@ "CVE-2021-38890" ], "details": "IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-mc62-gcf9-pqxh/GHSA-mc62-gcf9-pqxh.json b/advisories/unreviewed/2021/11/GHSA-mc62-gcf9-pqxh/GHSA-mc62-gcf9-pqxh.json index 5a45d9a9e0e..cc613f3c737 100644 --- a/advisories/unreviewed/2021/11/GHSA-mc62-gcf9-pqxh/GHSA-mc62-gcf9-pqxh.json +++ b/advisories/unreviewed/2021/11/GHSA-mc62-gcf9-pqxh/GHSA-mc62-gcf9-pqxh.json @@ -7,12 +7,8 @@ "CVE-2021-44094" ], "details": "ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-mg5m-225h-2mpp/GHSA-mg5m-225h-2mpp.json b/advisories/unreviewed/2021/11/GHSA-mg5m-225h-2mpp/GHSA-mg5m-225h-2mpp.json index dfac7e5959f..bb851c1a989 100644 --- a/advisories/unreviewed/2021/11/GHSA-mg5m-225h-2mpp/GHSA-mg5m-225h-2mpp.json +++ b/advisories/unreviewed/2021/11/GHSA-mg5m-225h-2mpp/GHSA-mg5m-225h-2mpp.json @@ -7,12 +7,8 @@ "CVE-2021-43698" ], "details": "An unspecified version of phpWhois is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET['query'] then there is a XSS vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-mhw5-2mx2-2jh7/GHSA-mhw5-2mx2-2jh7.json b/advisories/unreviewed/2021/11/GHSA-mhw5-2mx2-2jh7/GHSA-mhw5-2mx2-2jh7.json index 2c6d2586f30..a7fa8df964d 100644 --- a/advisories/unreviewed/2021/11/GHSA-mhw5-2mx2-2jh7/GHSA-mhw5-2mx2-2jh7.json +++ b/advisories/unreviewed/2021/11/GHSA-mhw5-2mx2-2jh7/GHSA-mhw5-2mx2-2jh7.json @@ -7,12 +7,8 @@ "CVE-2021-38004" ], "details": "Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-mjvc-frcm-6323/GHSA-mjvc-frcm-6323.json b/advisories/unreviewed/2021/11/GHSA-mjvc-frcm-6323/GHSA-mjvc-frcm-6323.json index 3b482aed5cc..a419c6eedaf 100644 --- a/advisories/unreviewed/2021/11/GHSA-mjvc-frcm-6323/GHSA-mjvc-frcm-6323.json +++ b/advisories/unreviewed/2021/11/GHSA-mjvc-frcm-6323/GHSA-mjvc-frcm-6323.json @@ -7,12 +7,8 @@ "CVE-2021-39995" ], "details": "Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-p28m-984w-v8w8/GHSA-p28m-984w-v8w8.json b/advisories/unreviewed/2021/11/GHSA-p28m-984w-v8w8/GHSA-p28m-984w-v8w8.json index 27fa23e4c48..9aa52bf8faf 100644 --- a/advisories/unreviewed/2021/11/GHSA-p28m-984w-v8w8/GHSA-p28m-984w-v8w8.json +++ b/advisories/unreviewed/2021/11/GHSA-p28m-984w-v8w8/GHSA-p28m-984w-v8w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pfm6-x9q4-rphr/GHSA-pfm6-x9q4-rphr.json b/advisories/unreviewed/2021/11/GHSA-pfm6-x9q4-rphr/GHSA-pfm6-x9q4-rphr.json index bf4765b6f7e..d9aa52ae0c2 100644 --- a/advisories/unreviewed/2021/11/GHSA-pfm6-x9q4-rphr/GHSA-pfm6-x9q4-rphr.json +++ b/advisories/unreviewed/2021/11/GHSA-pfm6-x9q4-rphr/GHSA-pfm6-x9q4-rphr.json @@ -7,12 +7,8 @@ "CVE-2021-37938" ], "details": "It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pp89-rwqv-pgh4/GHSA-pp89-rwqv-pgh4.json b/advisories/unreviewed/2021/11/GHSA-pp89-rwqv-pgh4/GHSA-pp89-rwqv-pgh4.json index f74ad390ab4..917d17e5774 100644 --- a/advisories/unreviewed/2021/11/GHSA-pp89-rwqv-pgh4/GHSA-pp89-rwqv-pgh4.json +++ b/advisories/unreviewed/2021/11/GHSA-pp89-rwqv-pgh4/GHSA-pp89-rwqv-pgh4.json @@ -7,12 +7,8 @@ "CVE-2021-38001" ], "details": "Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-ppc2-fq53-r63f/GHSA-ppc2-fq53-r63f.json b/advisories/unreviewed/2021/11/GHSA-ppc2-fq53-r63f/GHSA-ppc2-fq53-r63f.json index 875bc802f80..fa8978f2179 100644 --- a/advisories/unreviewed/2021/11/GHSA-ppc2-fq53-r63f/GHSA-ppc2-fq53-r63f.json +++ b/advisories/unreviewed/2021/11/GHSA-ppc2-fq53-r63f/GHSA-ppc2-fq53-r63f.json @@ -7,12 +7,8 @@ "CVE-2021-0665" ], "details": "In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672113; Issue ID: ALPS05672113.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pr36-w94p-68r3/GHSA-pr36-w94p-68r3.json b/advisories/unreviewed/2021/11/GHSA-pr36-w94p-68r3/GHSA-pr36-w94p-68r3.json index f51185e8ad5..fa1099aeb20 100644 --- a/advisories/unreviewed/2021/11/GHSA-pr36-w94p-68r3/GHSA-pr36-w94p-68r3.json +++ b/advisories/unreviewed/2021/11/GHSA-pr36-w94p-68r3/GHSA-pr36-w94p-68r3.json @@ -7,12 +7,8 @@ "CVE-2021-37999" ], "details": "Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pr6v-cc4g-cpxj/GHSA-pr6v-cc4g-cpxj.json b/advisories/unreviewed/2021/11/GHSA-pr6v-cc4g-cpxj/GHSA-pr6v-cc4g-cpxj.json index e0c58a38ed9..3d3986ddef0 100644 --- a/advisories/unreviewed/2021/11/GHSA-pr6v-cc4g-cpxj/GHSA-pr6v-cc4g-cpxj.json +++ b/advisories/unreviewed/2021/11/GHSA-pr6v-cc4g-cpxj/GHSA-pr6v-cc4g-cpxj.json @@ -7,12 +7,8 @@ "CVE-2021-3552" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone 6.24.1-1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pv89-7xp2-fhgx/GHSA-pv89-7xp2-fhgx.json b/advisories/unreviewed/2021/11/GHSA-pv89-7xp2-fhgx/GHSA-pv89-7xp2-fhgx.json index cddbaf7e6f5..76f11ce000c 100644 --- a/advisories/unreviewed/2021/11/GHSA-pv89-7xp2-fhgx/GHSA-pv89-7xp2-fhgx.json +++ b/advisories/unreviewed/2021/11/GHSA-pv89-7xp2-fhgx/GHSA-pv89-7xp2-fhgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-pwjr-xrcx-fg7p/GHSA-pwjr-xrcx-fg7p.json b/advisories/unreviewed/2021/11/GHSA-pwjr-xrcx-fg7p/GHSA-pwjr-xrcx-fg7p.json index ad6926131ad..b1dc20df10e 100644 --- a/advisories/unreviewed/2021/11/GHSA-pwjr-xrcx-fg7p/GHSA-pwjr-xrcx-fg7p.json +++ b/advisories/unreviewed/2021/11/GHSA-pwjr-xrcx-fg7p/GHSA-pwjr-xrcx-fg7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-px36-5x6h-5x8g/GHSA-px36-5x6h-5x8g.json b/advisories/unreviewed/2021/11/GHSA-px36-5x6h-5x8g/GHSA-px36-5x6h-5x8g.json index 9279acaadd3..8a2a1ec8101 100644 --- a/advisories/unreviewed/2021/11/GHSA-px36-5x6h-5x8g/GHSA-px36-5x6h-5x8g.json +++ b/advisories/unreviewed/2021/11/GHSA-px36-5x6h-5x8g/GHSA-px36-5x6h-5x8g.json @@ -7,12 +7,8 @@ "CVE-2021-43409" ], "details": "The \"WPO365 | LOGIN\" WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data. In this case, the XSS payload can be submitted by any anonymous user, the payload then renders and executes when a WordPress administrator authenticates and accesses the WordPress Dashboard. The injected payload can carry out actions on behalf of the administrator including adding other administrative users and changing application settings. This flaw could be exploited to ultimately provide full control of the affected system to the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-qg28-72m5-qqm8/GHSA-qg28-72m5-qqm8.json b/advisories/unreviewed/2021/11/GHSA-qg28-72m5-qqm8/GHSA-qg28-72m5-qqm8.json index 080ecab3c21..7460f6dac88 100644 --- a/advisories/unreviewed/2021/11/GHSA-qg28-72m5-qqm8/GHSA-qg28-72m5-qqm8.json +++ b/advisories/unreviewed/2021/11/GHSA-qg28-72m5-qqm8/GHSA-qg28-72m5-qqm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-qmx3-vr4p-7jgf/GHSA-qmx3-vr4p-7jgf.json b/advisories/unreviewed/2021/11/GHSA-qmx3-vr4p-7jgf/GHSA-qmx3-vr4p-7jgf.json index 183bd6669aa..6912f5e87b4 100644 --- a/advisories/unreviewed/2021/11/GHSA-qmx3-vr4p-7jgf/GHSA-qmx3-vr4p-7jgf.json +++ b/advisories/unreviewed/2021/11/GHSA-qmx3-vr4p-7jgf/GHSA-qmx3-vr4p-7jgf.json @@ -7,12 +7,8 @@ "CVE-2021-24811" ], "details": "The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-qq52-whh8-7p62/GHSA-qq52-whh8-7p62.json b/advisories/unreviewed/2021/11/GHSA-qq52-whh8-7p62/GHSA-qq52-whh8-7p62.json index 1900988a3fc..d95c629faee 100644 --- a/advisories/unreviewed/2021/11/GHSA-qq52-whh8-7p62/GHSA-qq52-whh8-7p62.json +++ b/advisories/unreviewed/2021/11/GHSA-qq52-whh8-7p62/GHSA-qq52-whh8-7p62.json @@ -7,12 +7,8 @@ "CVE-2021-29323" ], "details": "OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-qx47-qw9g-58j7/GHSA-qx47-qw9g-58j7.json b/advisories/unreviewed/2021/11/GHSA-qx47-qw9g-58j7/GHSA-qx47-qw9g-58j7.json index 779a0b4b63a..ec4dce14ab5 100644 --- a/advisories/unreviewed/2021/11/GHSA-qx47-qw9g-58j7/GHSA-qx47-qw9g-58j7.json +++ b/advisories/unreviewed/2021/11/GHSA-qx47-qw9g-58j7/GHSA-qx47-qw9g-58j7.json @@ -7,12 +7,8 @@ "CVE-2021-38147" ], "details": "Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-r24c-4jp9-g34v/GHSA-r24c-4jp9-g34v.json b/advisories/unreviewed/2021/11/GHSA-r24c-4jp9-g34v/GHSA-r24c-4jp9-g34v.json index c6da4c7fba5..d7d1ec40365 100644 --- a/advisories/unreviewed/2021/11/GHSA-r24c-4jp9-g34v/GHSA-r24c-4jp9-g34v.json +++ b/advisories/unreviewed/2021/11/GHSA-r24c-4jp9-g34v/GHSA-r24c-4jp9-g34v.json @@ -7,12 +7,8 @@ "CVE-2021-44199" ], "details": "DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-r2fw-784h-2378/GHSA-r2fw-784h-2378.json b/advisories/unreviewed/2021/11/GHSA-r2fw-784h-2378/GHSA-r2fw-784h-2378.json index af170c565bb..32f3778cac9 100644 --- a/advisories/unreviewed/2021/11/GHSA-r2fw-784h-2378/GHSA-r2fw-784h-2378.json +++ b/advisories/unreviewed/2021/11/GHSA-r2fw-784h-2378/GHSA-r2fw-784h-2378.json @@ -7,12 +7,8 @@ "CVE-2021-24908" ], "details": "The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-r328-rm4m-mx6q/GHSA-r328-rm4m-mx6q.json b/advisories/unreviewed/2021/11/GHSA-r328-rm4m-mx6q/GHSA-r328-rm4m-mx6q.json index 542344acd5f..0b1432db183 100644 --- a/advisories/unreviewed/2021/11/GHSA-r328-rm4m-mx6q/GHSA-r328-rm4m-mx6q.json +++ b/advisories/unreviewed/2021/11/GHSA-r328-rm4m-mx6q/GHSA-r328-rm4m-mx6q.json @@ -7,12 +7,8 @@ "CVE-2021-36300" ], "details": "iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-rmxv-c5fj-rxfg/GHSA-rmxv-c5fj-rxfg.json b/advisories/unreviewed/2021/11/GHSA-rmxv-c5fj-rxfg/GHSA-rmxv-c5fj-rxfg.json index a7c725a216a..79e2b8edb3c 100644 --- a/advisories/unreviewed/2021/11/GHSA-rmxv-c5fj-rxfg/GHSA-rmxv-c5fj-rxfg.json +++ b/advisories/unreviewed/2021/11/GHSA-rmxv-c5fj-rxfg/GHSA-rmxv-c5fj-rxfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-rw92-2qph-cjf9/GHSA-rw92-2qph-cjf9.json b/advisories/unreviewed/2021/11/GHSA-rw92-2qph-cjf9/GHSA-rw92-2qph-cjf9.json index 91d07bdaa9b..75630211a0d 100644 --- a/advisories/unreviewed/2021/11/GHSA-rw92-2qph-cjf9/GHSA-rw92-2qph-cjf9.json +++ b/advisories/unreviewed/2021/11/GHSA-rw92-2qph-cjf9/GHSA-rw92-2qph-cjf9.json @@ -7,12 +7,8 @@ "CVE-2021-22049" ], "details": "The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-rwj2-f84g-w7hc/GHSA-rwj2-f84g-w7hc.json b/advisories/unreviewed/2021/11/GHSA-rwj2-f84g-w7hc/GHSA-rwj2-f84g-w7hc.json index e2f9a63af4b..ce7c128b9e4 100644 --- a/advisories/unreviewed/2021/11/GHSA-rwj2-f84g-w7hc/GHSA-rwj2-f84g-w7hc.json +++ b/advisories/unreviewed/2021/11/GHSA-rwj2-f84g-w7hc/GHSA-rwj2-f84g-w7hc.json @@ -7,12 +7,8 @@ "CVE-2021-42267" ], "details": "Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-v4hj-9626-74p6/GHSA-v4hj-9626-74p6.json b/advisories/unreviewed/2021/11/GHSA-v4hj-9626-74p6/GHSA-v4hj-9626-74p6.json index 7dfbc04d0d8..155efbd8f4c 100644 --- a/advisories/unreviewed/2021/11/GHSA-v4hj-9626-74p6/GHSA-v4hj-9626-74p6.json +++ b/advisories/unreviewed/2021/11/GHSA-v4hj-9626-74p6/GHSA-v4hj-9626-74p6.json @@ -7,12 +7,8 @@ "CVE-2021-44219" ], "details": "Gin-Vue-Admin before 2.4.6 mishandles a SQL database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-v75m-35ph-56m2/GHSA-v75m-35ph-56m2.json b/advisories/unreviewed/2021/11/GHSA-v75m-35ph-56m2/GHSA-v75m-35ph-56m2.json index b1e0e40ea99..e3e3b219139 100644 --- a/advisories/unreviewed/2021/11/GHSA-v75m-35ph-56m2/GHSA-v75m-35ph-56m2.json +++ b/advisories/unreviewed/2021/11/GHSA-v75m-35ph-56m2/GHSA-v75m-35ph-56m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-v76f-9rjc-pm62/GHSA-v76f-9rjc-pm62.json b/advisories/unreviewed/2021/11/GHSA-v76f-9rjc-pm62/GHSA-v76f-9rjc-pm62.json index c0f36a4685d..d2d81659c92 100644 --- a/advisories/unreviewed/2021/11/GHSA-v76f-9rjc-pm62/GHSA-v76f-9rjc-pm62.json +++ b/advisories/unreviewed/2021/11/GHSA-v76f-9rjc-pm62/GHSA-v76f-9rjc-pm62.json @@ -7,12 +7,8 @@ "CVE-2021-0619" ], "details": "In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561395; Issue ID: ALPS05561395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-vmwh-g38p-m7q2/GHSA-vmwh-g38p-m7q2.json b/advisories/unreviewed/2021/11/GHSA-vmwh-g38p-m7q2/GHSA-vmwh-g38p-m7q2.json index 1df93fabd3a..6a026d98ba5 100644 --- a/advisories/unreviewed/2021/11/GHSA-vmwh-g38p-m7q2/GHSA-vmwh-g38p-m7q2.json +++ b/advisories/unreviewed/2021/11/GHSA-vmwh-g38p-m7q2/GHSA-vmwh-g38p-m7q2.json @@ -7,12 +7,8 @@ "CVE-2021-33493" ], "details": "The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-vq3m-v9x8-5263/GHSA-vq3m-v9x8-5263.json b/advisories/unreviewed/2021/11/GHSA-vq3m-v9x8-5263/GHSA-vq3m-v9x8-5263.json index 432a3d36f2c..0cf26c6c062 100644 --- a/advisories/unreviewed/2021/11/GHSA-vq3m-v9x8-5263/GHSA-vq3m-v9x8-5263.json +++ b/advisories/unreviewed/2021/11/GHSA-vq3m-v9x8-5263/GHSA-vq3m-v9x8-5263.json @@ -7,12 +7,8 @@ "CVE-2021-24729" ], "details": "The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-vvvp-px4m-56p7/GHSA-vvvp-px4m-56p7.json b/advisories/unreviewed/2021/11/GHSA-vvvp-px4m-56p7/GHSA-vvvp-px4m-56p7.json index e60e974ca85..457f05fcd1e 100644 --- a/advisories/unreviewed/2021/11/GHSA-vvvp-px4m-56p7/GHSA-vvvp-px4m-56p7.json +++ b/advisories/unreviewed/2021/11/GHSA-vvvp-px4m-56p7/GHSA-vvvp-px4m-56p7.json @@ -7,12 +7,8 @@ "CVE-2021-34800" ], "details": "Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-w34q-q55c-hxw9/GHSA-w34q-q55c-hxw9.json b/advisories/unreviewed/2021/11/GHSA-w34q-q55c-hxw9/GHSA-w34q-q55c-hxw9.json index 6093092d815..3f8073e8561 100644 --- a/advisories/unreviewed/2021/11/GHSA-w34q-q55c-hxw9/GHSA-w34q-q55c-hxw9.json +++ b/advisories/unreviewed/2021/11/GHSA-w34q-q55c-hxw9/GHSA-w34q-q55c-hxw9.json @@ -7,12 +7,8 @@ "CVE-2021-37025" ], "details": "There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-w922-rmxr-g296/GHSA-w922-rmxr-g296.json b/advisories/unreviewed/2021/11/GHSA-w922-rmxr-g296/GHSA-w922-rmxr-g296.json index 25a0c2759a4..2a9c914eab5 100644 --- a/advisories/unreviewed/2021/11/GHSA-w922-rmxr-g296/GHSA-w922-rmxr-g296.json +++ b/advisories/unreviewed/2021/11/GHSA-w922-rmxr-g296/GHSA-w922-rmxr-g296.json @@ -7,12 +7,8 @@ "CVE-2021-43693" ], "details": "vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-w963-p4h4-878h/GHSA-w963-p4h4-878h.json b/advisories/unreviewed/2021/11/GHSA-w963-p4h4-878h/GHSA-w963-p4h4-878h.json index 9d553ee3d6a..90113e87056 100644 --- a/advisories/unreviewed/2021/11/GHSA-w963-p4h4-878h/GHSA-w963-p4h4-878h.json +++ b/advisories/unreviewed/2021/11/GHSA-w963-p4h4-878h/GHSA-w963-p4h4-878h.json @@ -7,12 +7,8 @@ "CVE-2021-42525" ], "details": "Acrobat Animate versions 21.0.9 (and earlier)is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-w98p-v8rr-93f3/GHSA-w98p-v8rr-93f3.json b/advisories/unreviewed/2021/11/GHSA-w98p-v8rr-93f3/GHSA-w98p-v8rr-93f3.json index b78ff040272..9f77bbaf5c2 100644 --- a/advisories/unreviewed/2021/11/GHSA-w98p-v8rr-93f3/GHSA-w98p-v8rr-93f3.json +++ b/advisories/unreviewed/2021/11/GHSA-w98p-v8rr-93f3/GHSA-w98p-v8rr-93f3.json @@ -7,12 +7,8 @@ "CVE-2021-37033" ], "details": "There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-w9xh-7f24-r92w/GHSA-w9xh-7f24-r92w.json b/advisories/unreviewed/2021/11/GHSA-w9xh-7f24-r92w/GHSA-w9xh-7f24-r92w.json index a11fcb6386c..9f02a238a81 100644 --- a/advisories/unreviewed/2021/11/GHSA-w9xh-7f24-r92w/GHSA-w9xh-7f24-r92w.json +++ b/advisories/unreviewed/2021/11/GHSA-w9xh-7f24-r92w/GHSA-w9xh-7f24-r92w.json @@ -7,12 +7,8 @@ "CVE-2021-42524" ], "details": "Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wg38-4947-72vf/GHSA-wg38-4947-72vf.json b/advisories/unreviewed/2021/11/GHSA-wg38-4947-72vf/GHSA-wg38-4947-72vf.json index e8e143c25d2..365ac224f65 100644 --- a/advisories/unreviewed/2021/11/GHSA-wg38-4947-72vf/GHSA-wg38-4947-72vf.json +++ b/advisories/unreviewed/2021/11/GHSA-wg38-4947-72vf/GHSA-wg38-4947-72vf.json @@ -7,12 +7,8 @@ "CVE-2021-24875" ], "details": "The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wh35-hg5g-vr4x/GHSA-wh35-hg5g-vr4x.json b/advisories/unreviewed/2021/11/GHSA-wh35-hg5g-vr4x/GHSA-wh35-hg5g-vr4x.json index 1a0fcd87571..22ce6f99340 100644 --- a/advisories/unreviewed/2021/11/GHSA-wh35-hg5g-vr4x/GHSA-wh35-hg5g-vr4x.json +++ b/advisories/unreviewed/2021/11/GHSA-wh35-hg5g-vr4x/GHSA-wh35-hg5g-vr4x.json @@ -7,12 +7,8 @@ "CVE-2021-36003" ], "details": "Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wh5j-hw7g-r9fm/GHSA-wh5j-hw7g-r9fm.json b/advisories/unreviewed/2021/11/GHSA-wh5j-hw7g-r9fm/GHSA-wh5j-hw7g-r9fm.json index 6f23315ae59..fb348ef5d72 100644 --- a/advisories/unreviewed/2021/11/GHSA-wh5j-hw7g-r9fm/GHSA-wh5j-hw7g-r9fm.json +++ b/advisories/unreviewed/2021/11/GHSA-wh5j-hw7g-r9fm/GHSA-wh5j-hw7g-r9fm.json @@ -7,12 +7,8 @@ "CVE-2017-20008" ], "details": "The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wm6p-qp26-2h9v/GHSA-wm6p-qp26-2h9v.json b/advisories/unreviewed/2021/11/GHSA-wm6p-qp26-2h9v/GHSA-wm6p-qp26-2h9v.json index bf510ed546c..18e9545364a 100644 --- a/advisories/unreviewed/2021/11/GHSA-wm6p-qp26-2h9v/GHSA-wm6p-qp26-2h9v.json +++ b/advisories/unreviewed/2021/11/GHSA-wm6p-qp26-2h9v/GHSA-wm6p-qp26-2h9v.json @@ -7,12 +7,8 @@ "CVE-2021-36313" ], "details": "Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it may be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wmfg-8f6m-hx38/GHSA-wmfg-8f6m-hx38.json b/advisories/unreviewed/2021/11/GHSA-wmfg-8f6m-hx38/GHSA-wmfg-8f6m-hx38.json index 8bd06ca21c8..2a63a8dcbc6 100644 --- a/advisories/unreviewed/2021/11/GHSA-wmfg-8f6m-hx38/GHSA-wmfg-8f6m-hx38.json +++ b/advisories/unreviewed/2021/11/GHSA-wmfg-8f6m-hx38/GHSA-wmfg-8f6m-hx38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-wmx3-62wg-53jp/GHSA-wmx3-62wg-53jp.json b/advisories/unreviewed/2021/11/GHSA-wmx3-62wg-53jp/GHSA-wmx3-62wg-53jp.json index cae1d5378ce..36433c698d1 100644 --- a/advisories/unreviewed/2021/11/GHSA-wmx3-62wg-53jp/GHSA-wmx3-62wg-53jp.json +++ b/advisories/unreviewed/2021/11/GHSA-wmx3-62wg-53jp/GHSA-wmx3-62wg-53jp.json @@ -7,12 +7,8 @@ "CVE-2021-36919" ], "details": "Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-x652-4f75-gmq8/GHSA-x652-4f75-gmq8.json b/advisories/unreviewed/2021/11/GHSA-x652-4f75-gmq8/GHSA-x652-4f75-gmq8.json index c13dd054a79..5feec27e568 100644 --- a/advisories/unreviewed/2021/11/GHSA-x652-4f75-gmq8/GHSA-x652-4f75-gmq8.json +++ b/advisories/unreviewed/2021/11/GHSA-x652-4f75-gmq8/GHSA-x652-4f75-gmq8.json @@ -7,12 +7,8 @@ "CVE-2021-1125" ], "details": "NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/11/GHSA-x7r8-5fvw-c54g/GHSA-x7r8-5fvw-c54g.json b/advisories/unreviewed/2021/11/GHSA-x7r8-5fvw-c54g/GHSA-x7r8-5fvw-c54g.json index d539137a9ba..7f6fcf07640 100644 --- a/advisories/unreviewed/2021/11/GHSA-x7r8-5fvw-c54g/GHSA-x7r8-5fvw-c54g.json +++ b/advisories/unreviewed/2021/11/GHSA-x7r8-5fvw-c54g/GHSA-x7r8-5fvw-c54g.json @@ -7,12 +7,8 @@ "CVE-2021-44202" ], "details": "Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2fvx-vhr6-r4cv/GHSA-2fvx-vhr6-r4cv.json b/advisories/unreviewed/2021/12/GHSA-2fvx-vhr6-r4cv/GHSA-2fvx-vhr6-r4cv.json index 755f5b532a5..35d20417028 100644 --- a/advisories/unreviewed/2021/12/GHSA-2fvx-vhr6-r4cv/GHSA-2fvx-vhr6-r4cv.json +++ b/advisories/unreviewed/2021/12/GHSA-2fvx-vhr6-r4cv/GHSA-2fvx-vhr6-r4cv.json @@ -7,12 +7,8 @@ "CVE-2021-42123" ], "details": "Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2x6g-9jmv-rxr5/GHSA-2x6g-9jmv-rxr5.json b/advisories/unreviewed/2021/12/GHSA-2x6g-9jmv-rxr5/GHSA-2x6g-9jmv-rxr5.json index 7676ac32979..2d266abd54a 100644 --- a/advisories/unreviewed/2021/12/GHSA-2x6g-9jmv-rxr5/GHSA-2x6g-9jmv-rxr5.json +++ b/advisories/unreviewed/2021/12/GHSA-2x6g-9jmv-rxr5/GHSA-2x6g-9jmv-rxr5.json @@ -7,12 +7,8 @@ "CVE-2021-38999" ], "details": "IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-336r-gxpp-8vj2/GHSA-336r-gxpp-8vj2.json b/advisories/unreviewed/2021/12/GHSA-336r-gxpp-8vj2/GHSA-336r-gxpp-8vj2.json index e71bdb2ae88..d39b238b389 100644 --- a/advisories/unreviewed/2021/12/GHSA-336r-gxpp-8vj2/GHSA-336r-gxpp-8vj2.json +++ b/advisories/unreviewed/2021/12/GHSA-336r-gxpp-8vj2/GHSA-336r-gxpp-8vj2.json @@ -7,12 +7,8 @@ "CVE-2021-29863" ], "details": "IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerability is due to an incomplete fix for CVE-2020-4786. IBM X-Force ID: 206087.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3hxq-v55q-xvxq/GHSA-3hxq-v55q-xvxq.json b/advisories/unreviewed/2021/12/GHSA-3hxq-v55q-xvxq/GHSA-3hxq-v55q-xvxq.json index 2eca0955dc0..2aceb96c636 100644 --- a/advisories/unreviewed/2021/12/GHSA-3hxq-v55q-xvxq/GHSA-3hxq-v55q-xvxq.json +++ b/advisories/unreviewed/2021/12/GHSA-3hxq-v55q-xvxq/GHSA-3hxq-v55q-xvxq.json @@ -7,12 +7,8 @@ "CVE-2021-42119" ], "details": "Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated users with Object Modification privileges to inject arbitrary HTML and JavaScript in object attributes, which is then rendered in the Search Functionality, to alter the intended functionality and steal cookies, the latter allowing for account takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3q67-fwp6-mgfc/GHSA-3q67-fwp6-mgfc.json b/advisories/unreviewed/2021/12/GHSA-3q67-fwp6-mgfc/GHSA-3q67-fwp6-mgfc.json index 49589296de9..4664a0fcbc7 100644 --- a/advisories/unreviewed/2021/12/GHSA-3q67-fwp6-mgfc/GHSA-3q67-fwp6-mgfc.json +++ b/advisories/unreviewed/2021/12/GHSA-3q67-fwp6-mgfc/GHSA-3q67-fwp6-mgfc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3rm9-3r67-x775/GHSA-3rm9-3r67-x775.json b/advisories/unreviewed/2021/12/GHSA-3rm9-3r67-x775/GHSA-3rm9-3r67-x775.json index f4406f5a539..afa0c205d80 100644 --- a/advisories/unreviewed/2021/12/GHSA-3rm9-3r67-x775/GHSA-3rm9-3r67-x775.json +++ b/advisories/unreviewed/2021/12/GHSA-3rm9-3r67-x775/GHSA-3rm9-3r67-x775.json @@ -7,12 +7,8 @@ "CVE-2021-33271" ], "details": "D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_80046EB4 in /formSetPortTr. This vulnerability is triggered via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3w54-g522-46ww/GHSA-3w54-g522-46ww.json b/advisories/unreviewed/2021/12/GHSA-3w54-g522-46ww/GHSA-3w54-g522-46ww.json index 4488870cbc1..e09c1a31325 100644 --- a/advisories/unreviewed/2021/12/GHSA-3w54-g522-46ww/GHSA-3w54-g522-46ww.json +++ b/advisories/unreviewed/2021/12/GHSA-3w54-g522-46ww/GHSA-3w54-g522-46ww.json @@ -7,12 +7,8 @@ "CVE-2021-41678" ], "details": "A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-47v6-26pv-9rpw/GHSA-47v6-26pv-9rpw.json b/advisories/unreviewed/2021/12/GHSA-47v6-26pv-9rpw/GHSA-47v6-26pv-9rpw.json index d268efc4c59..9a7339bfb50 100644 --- a/advisories/unreviewed/2021/12/GHSA-47v6-26pv-9rpw/GHSA-47v6-26pv-9rpw.json +++ b/advisories/unreviewed/2021/12/GHSA-47v6-26pv-9rpw/GHSA-47v6-26pv-9rpw.json @@ -7,12 +7,8 @@ "CVE-2021-36329" ], "details": "Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4gcr-hp5v-7hfv/GHSA-4gcr-hp5v-7hfv.json b/advisories/unreviewed/2021/12/GHSA-4gcr-hp5v-7hfv/GHSA-4gcr-hp5v-7hfv.json index 12f37833c99..c932a080033 100644 --- a/advisories/unreviewed/2021/12/GHSA-4gcr-hp5v-7hfv/GHSA-4gcr-hp5v-7hfv.json +++ b/advisories/unreviewed/2021/12/GHSA-4gcr-hp5v-7hfv/GHSA-4gcr-hp5v-7hfv.json @@ -7,12 +7,8 @@ "CVE-2021-38958" ], "details": "IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-4xjc-qqh2-pgwj/GHSA-4xjc-qqh2-pgwj.json b/advisories/unreviewed/2021/12/GHSA-4xjc-qqh2-pgwj/GHSA-4xjc-qqh2-pgwj.json index 89aabc72345..d0e5cc4680d 100644 --- a/advisories/unreviewed/2021/12/GHSA-4xjc-qqh2-pgwj/GHSA-4xjc-qqh2-pgwj.json +++ b/advisories/unreviewed/2021/12/GHSA-4xjc-qqh2-pgwj/GHSA-4xjc-qqh2-pgwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-52rq-pjr4-f69g/GHSA-52rq-pjr4-f69g.json b/advisories/unreviewed/2021/12/GHSA-52rq-pjr4-f69g/GHSA-52rq-pjr4-f69g.json index 24f05416dbb..142d8293489 100644 --- a/advisories/unreviewed/2021/12/GHSA-52rq-pjr4-f69g/GHSA-52rq-pjr4-f69g.json +++ b/advisories/unreviewed/2021/12/GHSA-52rq-pjr4-f69g/GHSA-52rq-pjr4-f69g.json @@ -7,12 +7,8 @@ "CVE-2021-33268" ], "details": "D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-52xf-jjg9-gfxx/GHSA-52xf-jjg9-gfxx.json b/advisories/unreviewed/2021/12/GHSA-52xf-jjg9-gfxx/GHSA-52xf-jjg9-gfxx.json index 81d63c902bd..83d9cc63941 100644 --- a/advisories/unreviewed/2021/12/GHSA-52xf-jjg9-gfxx/GHSA-52xf-jjg9-gfxx.json +++ b/advisories/unreviewed/2021/12/GHSA-52xf-jjg9-gfxx/GHSA-52xf-jjg9-gfxx.json @@ -7,12 +7,8 @@ "CVE-2021-42121" ], "details": "Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s date attribute(s) allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format into date fields, which leads to breaking the object page that the date field is present.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-54vf-jrm9-p98w/GHSA-54vf-jrm9-p98w.json b/advisories/unreviewed/2021/12/GHSA-54vf-jrm9-p98w/GHSA-54vf-jrm9-p98w.json index 9301a66764c..bfbc32e1dc3 100644 --- a/advisories/unreviewed/2021/12/GHSA-54vf-jrm9-p98w/GHSA-54vf-jrm9-p98w.json +++ b/advisories/unreviewed/2021/12/GHSA-54vf-jrm9-p98w/GHSA-54vf-jrm9-p98w.json @@ -7,12 +7,8 @@ "CVE-2020-7879" ], "details": "This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-63hh-fhh6-2jjc/GHSA-63hh-fhh6-2jjc.json b/advisories/unreviewed/2021/12/GHSA-63hh-fhh6-2jjc/GHSA-63hh-fhh6-2jjc.json index f1e3b159f98..b920fabb98a 100644 --- a/advisories/unreviewed/2021/12/GHSA-63hh-fhh6-2jjc/GHSA-63hh-fhh6-2jjc.json +++ b/advisories/unreviewed/2021/12/GHSA-63hh-fhh6-2jjc/GHSA-63hh-fhh6-2jjc.json @@ -7,12 +7,8 @@ "CVE-2021-44230" ], "details": "PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6fqj-w26x-q42v/GHSA-6fqj-w26x-q42v.json b/advisories/unreviewed/2021/12/GHSA-6fqj-w26x-q42v/GHSA-6fqj-w26x-q42v.json index 6e33fb2356e..af325e900b6 100644 --- a/advisories/unreviewed/2021/12/GHSA-6fqj-w26x-q42v/GHSA-6fqj-w26x-q42v.json +++ b/advisories/unreviewed/2021/12/GHSA-6fqj-w26x-q42v/GHSA-6fqj-w26x-q42v.json @@ -7,12 +7,8 @@ "CVE-2021-20400" ], "details": "IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6h6j-2q73-8prq/GHSA-6h6j-2q73-8prq.json b/advisories/unreviewed/2021/12/GHSA-6h6j-2q73-8prq/GHSA-6h6j-2q73-8prq.json index 2b78364e47b..638ec0dcbaa 100644 --- a/advisories/unreviewed/2021/12/GHSA-6h6j-2q73-8prq/GHSA-6h6j-2q73-8prq.json +++ b/advisories/unreviewed/2021/12/GHSA-6h6j-2q73-8prq/GHSA-6h6j-2q73-8prq.json @@ -7,12 +7,8 @@ "CVE-2021-43202" ], "details": "In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-6rm2-rq6j-h85r/GHSA-6rm2-rq6j-h85r.json b/advisories/unreviewed/2021/12/GHSA-6rm2-rq6j-h85r/GHSA-6rm2-rq6j-h85r.json index a64637f3e2e..754df9911ca 100644 --- a/advisories/unreviewed/2021/12/GHSA-6rm2-rq6j-h85r/GHSA-6rm2-rq6j-h85r.json +++ b/advisories/unreviewed/2021/12/GHSA-6rm2-rq6j-h85r/GHSA-6rm2-rq6j-h85r.json @@ -7,12 +7,8 @@ "CVE-2021-43685" ], "details": "libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-78qj-g3hj-mgxf/GHSA-78qj-g3hj-mgxf.json b/advisories/unreviewed/2021/12/GHSA-78qj-g3hj-mgxf/GHSA-78qj-g3hj-mgxf.json index 73d49b93f8f..694243af266 100644 --- a/advisories/unreviewed/2021/12/GHSA-78qj-g3hj-mgxf/GHSA-78qj-g3hj-mgxf.json +++ b/advisories/unreviewed/2021/12/GHSA-78qj-g3hj-mgxf/GHSA-78qj-g3hj-mgxf.json @@ -7,12 +7,8 @@ "CVE-2020-7880" ], "details": "The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7gx5-3645-vjvq/GHSA-7gx5-3645-vjvq.json b/advisories/unreviewed/2021/12/GHSA-7gx5-3645-vjvq/GHSA-7gx5-3645-vjvq.json index 5dfa2894a38..0950f404839 100644 --- a/advisories/unreviewed/2021/12/GHSA-7gx5-3645-vjvq/GHSA-7gx5-3645-vjvq.json +++ b/advisories/unreviewed/2021/12/GHSA-7gx5-3645-vjvq/GHSA-7gx5-3645-vjvq.json @@ -7,12 +7,8 @@ "CVE-2021-38967" ], "details": "IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7h7c-cpx6-6cg3/GHSA-7h7c-cpx6-6cg3.json b/advisories/unreviewed/2021/12/GHSA-7h7c-cpx6-6cg3/GHSA-7h7c-cpx6-6cg3.json index 9010d0816af..5e9823712e9 100644 --- a/advisories/unreviewed/2021/12/GHSA-7h7c-cpx6-6cg3/GHSA-7h7c-cpx6-6cg3.json +++ b/advisories/unreviewed/2021/12/GHSA-7h7c-cpx6-6cg3/GHSA-7h7c-cpx6-6cg3.json @@ -7,12 +7,8 @@ "CVE-2021-36328" ], "details": "Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7pq6-99v4-7fp6/GHSA-7pq6-99v4-7fp6.json b/advisories/unreviewed/2021/12/GHSA-7pq6-99v4-7fp6/GHSA-7pq6-99v4-7fp6.json index 277e73237b5..a1138dbac9d 100644 --- a/advisories/unreviewed/2021/12/GHSA-7pq6-99v4-7fp6/GHSA-7pq6-99v4-7fp6.json +++ b/advisories/unreviewed/2021/12/GHSA-7pq6-99v4-7fp6/GHSA-7pq6-99v4-7fp6.json @@ -7,12 +7,8 @@ "CVE-2021-42122" ], "details": "Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format, which makes the affected attribute non-editable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8jcw-2h4x-29pq/GHSA-8jcw-2h4x-29pq.json b/advisories/unreviewed/2021/12/GHSA-8jcw-2h4x-29pq/GHSA-8jcw-2h4x-29pq.json index 790e7c942c6..de601f02385 100644 --- a/advisories/unreviewed/2021/12/GHSA-8jcw-2h4x-29pq/GHSA-8jcw-2h4x-29pq.json +++ b/advisories/unreviewed/2021/12/GHSA-8jcw-2h4x-29pq/GHSA-8jcw-2h4x-29pq.json @@ -7,12 +7,8 @@ "CVE-2021-3726" ], "details": "# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**: [a263cdac](https://github.com/ohmyzsh/ohmyzsh/commit/a263cdac). **Impacted areas**: - `title` function in `lib/termsupport.zsh`. - Custom user code using the `title` function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c5f9-ppjj-3g7p/GHSA-c5f9-ppjj-3g7p.json b/advisories/unreviewed/2021/12/GHSA-c5f9-ppjj-3g7p/GHSA-c5f9-ppjj-3g7p.json index e232750475b..af6f1aeb37b 100644 --- a/advisories/unreviewed/2021/12/GHSA-c5f9-ppjj-3g7p/GHSA-c5f9-ppjj-3g7p.json +++ b/advisories/unreviewed/2021/12/GHSA-c5f9-ppjj-3g7p/GHSA-c5f9-ppjj-3g7p.json @@ -7,12 +7,8 @@ "CVE-2021-41679" ], "details": "A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c725-jmgq-pg3j/GHSA-c725-jmgq-pg3j.json b/advisories/unreviewed/2021/12/GHSA-c725-jmgq-pg3j/GHSA-c725-jmgq-pg3j.json index 4454aacf434..3912604eb57 100644 --- a/advisories/unreviewed/2021/12/GHSA-c725-jmgq-pg3j/GHSA-c725-jmgq-pg3j.json +++ b/advisories/unreviewed/2021/12/GHSA-c725-jmgq-pg3j/GHSA-c725-jmgq-pg3j.json @@ -7,12 +7,8 @@ "CVE-2021-33267" ], "details": "D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80034d60 in /formStaticDHCP. This vulnerability is triggered via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cc26-r5w9-6vgv/GHSA-cc26-r5w9-6vgv.json b/advisories/unreviewed/2021/12/GHSA-cc26-r5w9-6vgv/GHSA-cc26-r5w9-6vgv.json index 69734112d9f..d4216d568cc 100644 --- a/advisories/unreviewed/2021/12/GHSA-cc26-r5w9-6vgv/GHSA-cc26-r5w9-6vgv.json +++ b/advisories/unreviewed/2021/12/GHSA-cc26-r5w9-6vgv/GHSA-cc26-r5w9-6vgv.json @@ -7,12 +7,8 @@ "CVE-2021-43282" ], "details": "An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cvj9-h36c-4whf/GHSA-cvj9-h36c-4whf.json b/advisories/unreviewed/2021/12/GHSA-cvj9-h36c-4whf/GHSA-cvj9-h36c-4whf.json index 992c24def8c..2a1860aa0e6 100644 --- a/advisories/unreviewed/2021/12/GHSA-cvj9-h36c-4whf/GHSA-cvj9-h36c-4whf.json +++ b/advisories/unreviewed/2021/12/GHSA-cvj9-h36c-4whf/GHSA-cvj9-h36c-4whf.json @@ -7,12 +7,8 @@ "CVE-2021-41677" ], "details": "A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f8r6-c3hp-ccv4/GHSA-f8r6-c3hp-ccv4.json b/advisories/unreviewed/2021/12/GHSA-f8r6-c3hp-ccv4/GHSA-f8r6-c3hp-ccv4.json index f9f8b713aee..c57a56637ec 100644 --- a/advisories/unreviewed/2021/12/GHSA-f8r6-c3hp-ccv4/GHSA-f8r6-c3hp-ccv4.json +++ b/advisories/unreviewed/2021/12/GHSA-f8r6-c3hp-ccv4/GHSA-f8r6-c3hp-ccv4.json @@ -7,12 +7,8 @@ "CVE-2021-3769" ], "details": "# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. **Fixed in**: [b3ba9978](https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978). **Impacted areas**: - `pygmalion` theme. - `pygmalion-virtualenv` theme. - `refined` theme.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gm54-mw9w-8cv2/GHSA-gm54-mw9w-8cv2.json b/advisories/unreviewed/2021/12/GHSA-gm54-mw9w-8cv2/GHSA-gm54-mw9w-8cv2.json index e1d58dbd583..8df93f3e05a 100644 --- a/advisories/unreviewed/2021/12/GHSA-gm54-mw9w-8cv2/GHSA-gm54-mw9w-8cv2.json +++ b/advisories/unreviewed/2021/12/GHSA-gm54-mw9w-8cv2/GHSA-gm54-mw9w-8cv2.json @@ -7,12 +7,8 @@ "CVE-2021-42776" ], "details": "CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gwwm-ppmm-xxq6/GHSA-gwwm-ppmm-xxq6.json b/advisories/unreviewed/2021/12/GHSA-gwwm-ppmm-xxq6/GHSA-gwwm-ppmm-xxq6.json index 6f9de8bb717..32410ce1e3e 100644 --- a/advisories/unreviewed/2021/12/GHSA-gwwm-ppmm-xxq6/GHSA-gwwm-ppmm-xxq6.json +++ b/advisories/unreviewed/2021/12/GHSA-gwwm-ppmm-xxq6/GHSA-gwwm-ppmm-xxq6.json @@ -7,12 +7,8 @@ "CVE-2021-33274" ], "details": "D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80040af8 in /formWlanSetup. This vulnerability is triggered via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gxxj-4c9f-hrvw/GHSA-gxxj-4c9f-hrvw.json b/advisories/unreviewed/2021/12/GHSA-gxxj-4c9f-hrvw/GHSA-gxxj-4c9f-hrvw.json index df50cec4f91..13317120bff 100644 --- a/advisories/unreviewed/2021/12/GHSA-gxxj-4c9f-hrvw/GHSA-gxxj-4c9f-hrvw.json +++ b/advisories/unreviewed/2021/12/GHSA-gxxj-4c9f-hrvw/GHSA-gxxj-4c9f-hrvw.json @@ -7,12 +7,8 @@ "CVE-2021-36326" ], "details": "Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h3rh-w865-mg39/GHSA-h3rh-w865-mg39.json b/advisories/unreviewed/2021/12/GHSA-h3rh-w865-mg39/GHSA-h3rh-w865-mg39.json index a7d4488d561..d1a87e553ec 100644 --- a/advisories/unreviewed/2021/12/GHSA-h3rh-w865-mg39/GHSA-h3rh-w865-mg39.json +++ b/advisories/unreviewed/2021/12/GHSA-h3rh-w865-mg39/GHSA-h3rh-w865-mg39.json @@ -7,12 +7,8 @@ "CVE-2021-39000" ], "details": "IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hf8m-4ppx-hx3q/GHSA-hf8m-4ppx-hx3q.json b/advisories/unreviewed/2021/12/GHSA-hf8m-4ppx-hx3q/GHSA-hf8m-4ppx-hx3q.json index 94fe6c8b91a..dc2693509bb 100644 --- a/advisories/unreviewed/2021/12/GHSA-hf8m-4ppx-hx3q/GHSA-hf8m-4ppx-hx3q.json +++ b/advisories/unreviewed/2021/12/GHSA-hf8m-4ppx-hx3q/GHSA-hf8m-4ppx-hx3q.json @@ -7,12 +7,8 @@ "CVE-2021-42115" ], "details": "Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hjpq-rp56-x2qm/GHSA-hjpq-rp56-x2qm.json b/advisories/unreviewed/2021/12/GHSA-hjpq-rp56-x2qm/GHSA-hjpq-rp56-x2qm.json index 6eb5a04d251..f4b5dc4847d 100644 --- a/advisories/unreviewed/2021/12/GHSA-hjpq-rp56-x2qm/GHSA-hjpq-rp56-x2qm.json +++ b/advisories/unreviewed/2021/12/GHSA-hjpq-rp56-x2qm/GHSA-hjpq-rp56-x2qm.json @@ -7,12 +7,8 @@ "CVE-2021-42120" ], "details": "Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification privileges to insert arbitrarily long strings, eventually leading to exhaustion of the underlying resource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hrg9-9393-48xc/GHSA-hrg9-9393-48xc.json b/advisories/unreviewed/2021/12/GHSA-hrg9-9393-48xc/GHSA-hrg9-9393-48xc.json index 31530f7e1cc..a28c82cf8a4 100644 --- a/advisories/unreviewed/2021/12/GHSA-hrg9-9393-48xc/GHSA-hrg9-9393-48xc.json +++ b/advisories/unreviewed/2021/12/GHSA-hrg9-9393-48xc/GHSA-hrg9-9393-48xc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jwgw-m7r5-wr43/GHSA-jwgw-m7r5-wr43.json b/advisories/unreviewed/2021/12/GHSA-jwgw-m7r5-wr43/GHSA-jwgw-m7r5-wr43.json index d4269ebdcc7..4b2c2a8bea6 100644 --- a/advisories/unreviewed/2021/12/GHSA-jwgw-m7r5-wr43/GHSA-jwgw-m7r5-wr43.json +++ b/advisories/unreviewed/2021/12/GHSA-jwgw-m7r5-wr43/GHSA-jwgw-m7r5-wr43.json @@ -7,12 +7,8 @@ "CVE-2021-36330" ], "details": "Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jxgv-3jv5-8mh9/GHSA-jxgv-3jv5-8mh9.json b/advisories/unreviewed/2021/12/GHSA-jxgv-3jv5-8mh9/GHSA-jxgv-3jv5-8mh9.json index 2da864dbcef..24aad963f07 100644 --- a/advisories/unreviewed/2021/12/GHSA-jxgv-3jv5-8mh9/GHSA-jxgv-3jv5-8mh9.json +++ b/advisories/unreviewed/2021/12/GHSA-jxgv-3jv5-8mh9/GHSA-jxgv-3jv5-8mh9.json @@ -7,12 +7,8 @@ "CVE-2021-42544" ], "details": "Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m596-5xhq-4mfp/GHSA-m596-5xhq-4mfp.json b/advisories/unreviewed/2021/12/GHSA-m596-5xhq-4mfp/GHSA-m596-5xhq-4mfp.json index 1d6345217d6..6ccfe6e64a9 100644 --- a/advisories/unreviewed/2021/12/GHSA-m596-5xhq-4mfp/GHSA-m596-5xhq-4mfp.json +++ b/advisories/unreviewed/2021/12/GHSA-m596-5xhq-4mfp/GHSA-m596-5xhq-4mfp.json @@ -7,12 +7,8 @@ "CVE-2021-26612" ], "details": "An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mqvw-2h8p-cf8g/GHSA-mqvw-2h8p-cf8g.json b/advisories/unreviewed/2021/12/GHSA-mqvw-2h8p-cf8g/GHSA-mqvw-2h8p-cf8g.json index 09351866cfc..f1ea1069b35 100644 --- a/advisories/unreviewed/2021/12/GHSA-mqvw-2h8p-cf8g/GHSA-mqvw-2h8p-cf8g.json +++ b/advisories/unreviewed/2021/12/GHSA-mqvw-2h8p-cf8g/GHSA-mqvw-2h8p-cf8g.json @@ -7,12 +7,8 @@ "CVE-2021-42545" ], "details": "An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mw64-2c3h-ccp9/GHSA-mw64-2c3h-ccp9.json b/advisories/unreviewed/2021/12/GHSA-mw64-2c3h-ccp9/GHSA-mw64-2c3h-ccp9.json index 6747b9f9aeb..e9f625849d5 100644 --- a/advisories/unreviewed/2021/12/GHSA-mw64-2c3h-ccp9/GHSA-mw64-2c3h-ccp9.json +++ b/advisories/unreviewed/2021/12/GHSA-mw64-2c3h-ccp9/GHSA-mw64-2c3h-ccp9.json @@ -7,12 +7,8 @@ "CVE-2021-43283" ], "details": "An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute features. An attacker would thus be able to use this vulnerability to open a reverse shell on the device with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mxmv-qp6q-4xjp/GHSA-mxmv-qp6q-4xjp.json b/advisories/unreviewed/2021/12/GHSA-mxmv-qp6q-4xjp/GHSA-mxmv-qp6q-4xjp.json index 12fa459ab49..b6bbdf5fc4b 100644 --- a/advisories/unreviewed/2021/12/GHSA-mxmv-qp6q-4xjp/GHSA-mxmv-qp6q-4xjp.json +++ b/advisories/unreviewed/2021/12/GHSA-mxmv-qp6q-4xjp/GHSA-mxmv-qp6q-4xjp.json @@ -7,12 +7,8 @@ "CVE-2021-40101" ], "details": "An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pf6c-6jfw-4cwc/GHSA-pf6c-6jfw-4cwc.json b/advisories/unreviewed/2021/12/GHSA-pf6c-6jfw-4cwc/GHSA-pf6c-6jfw-4cwc.json index 60fa23235ff..88d8b21b3fd 100644 --- a/advisories/unreviewed/2021/12/GHSA-pf6c-6jfw-4cwc/GHSA-pf6c-6jfw-4cwc.json +++ b/advisories/unreviewed/2021/12/GHSA-pf6c-6jfw-4cwc/GHSA-pf6c-6jfw-4cwc.json @@ -7,12 +7,8 @@ "CVE-2021-42099" ], "details": "Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pq7g-984r-4j7x/GHSA-pq7g-984r-4j7x.json b/advisories/unreviewed/2021/12/GHSA-pq7g-984r-4j7x/GHSA-pq7g-984r-4j7x.json index cc62d27d93f..47f60bcd556 100644 --- a/advisories/unreviewed/2021/12/GHSA-pq7g-984r-4j7x/GHSA-pq7g-984r-4j7x.json +++ b/advisories/unreviewed/2021/12/GHSA-pq7g-984r-4j7x/GHSA-pq7g-984r-4j7x.json @@ -7,12 +7,8 @@ "CVE-2021-42564" ], "details": "An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '