From 4c6b31aba5a8621e8ac3043243b5ede2adfdaa3a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 16 Dec 2023 00:31:32 +0000 Subject: [PATCH] Publish Advisories GHSA-f37h-q8pq-cxqp GHSA-xgfv-h6v5-c2rq --- .../GHSA-f37h-q8pq-cxqp.json | 38 +++++++++++++++++++ .../GHSA-xgfv-h6v5-c2rq.json | 38 +++++++++++++++++++ 2 files changed, 76 insertions(+) create mode 100644 advisories/unreviewed/2023/12/GHSA-f37h-q8pq-cxqp/GHSA-f37h-q8pq-cxqp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-xgfv-h6v5-c2rq/GHSA-xgfv-h6v5-c2rq.json diff --git a/advisories/unreviewed/2023/12/GHSA-f37h-q8pq-cxqp/GHSA-f37h-q8pq-cxqp.json b/advisories/unreviewed/2023/12/GHSA-f37h-q8pq-cxqp/GHSA-f37h-q8pq-cxqp.json new file mode 100644 index 00000000000..a6401c81131 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-f37h-q8pq-cxqp/GHSA-f37h-q8pq-cxqp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f37h-q8pq-cxqp", + "modified": "2023-12-16T00:30:17Z", + "published": "2023-12-16T00:30:17Z", + "aliases": [ + "CVE-2023-28022" + ], + "details": "HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28022" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108433" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xgfv-h6v5-c2rq/GHSA-xgfv-h6v5-c2rq.json b/advisories/unreviewed/2023/12/GHSA-xgfv-h6v5-c2rq/GHSA-xgfv-h6v5-c2rq.json new file mode 100644 index 00000000000..8393510d254 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xgfv-h6v5-c2rq/GHSA-xgfv-h6v5-c2rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgfv-h6v5-c2rq", + "modified": "2023-12-16T00:30:17Z", + "published": "2023-12-16T00:30:17Z", + "aliases": [ + "CVE-2023-27317" + ], + "details": "ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a \nvulnerability which will cause all SAS-attached FIPS 140-2 drives to \nbecome unlocked after a system reboot or power cycle or a single \nSAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This\n could lead to disclosure of sensitive information to an attacker with \nphysical access to the unlocked drives. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27317" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/NTAP-20231215-0001/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T23:15:07Z" + } +} \ No newline at end of file