diff --git a/advisories/unreviewed/2024/01/GHSA-2vwj-p4xr-gwcv/GHSA-2vwj-p4xr-gwcv.json b/advisories/unreviewed/2024/01/GHSA-2vwj-p4xr-gwcv/GHSA-2vwj-p4xr-gwcv.json new file mode 100644 index 00000000000..e7c1249ca86 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2vwj-p4xr-gwcv/GHSA-2vwj-p4xr-gwcv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vwj-p4xr-gwcv", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23174" + ], + "details": "An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeholder, pagetriage-filter-date-range-to, pagetriage-filter-date-range-from, pagetriage-filter-date-range-heading, pagetriage-filter-set-button, or pagetriage-filter-reset-button message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23174" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/PageTriage/+/989177" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T347704" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-37v9-q385-wr5j/GHSA-37v9-q385-wr5j.json b/advisories/unreviewed/2024/01/GHSA-37v9-q385-wr5j/GHSA-37v9-q385-wr5j.json new file mode 100644 index 00000000000..34e1c963e73 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-37v9-q385-wr5j/GHSA-37v9-q385-wr5j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37v9-q385-wr5j", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23179" + ], + "details": "An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23179" + }, + { + "type": "WEB", + "url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T347746" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-46pr-fphr-qq4h/GHSA-46pr-fphr-qq4h.json b/advisories/unreviewed/2024/01/GHSA-46pr-fphr-qq4h/GHSA-46pr-fphr-qq4h.json new file mode 100644 index 00000000000..b427c5e4736 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-46pr-fphr-qq4h/GHSA-46pr-fphr-qq4h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46pr-fphr-qq4h", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23171" + ], + "details": "An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows XSS via the x-xss language setting for internationalization (i18n).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23171" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I70d71c409193e904684dfb706d424b0a815fa6f6" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T348343" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6h75-q28h-667c/GHSA-6h75-q28h-667c.json b/advisories/unreviewed/2024/01/GHSA-6h75-q28h-667c/GHSA-6h75-q28h-667c.json new file mode 100644 index 00000000000..f04d69b6d95 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6h75-q28h-667c/GHSA-6h75-q28h-667c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h75-q28h-667c", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23172" + ], + "details": "An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23172" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/989179" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T347708" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json new file mode 100644 index 00000000000..f879a48a6c0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjg8-pr7m-gj33", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2022-48620" + ], + "details": "uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48620" + }, + { + "type": "WEB", + "url": "https://github.com/troglobit/libuev/issues/27" + }, + { + "type": "WEB", + "url": "https://github.com/troglobit/libuev/commit/2d9f1c9ce655cc38511aeeb6e95ac30914f7aec9" + }, + { + "type": "WEB", + "url": "https://github.com/troglobit/libuev/compare/v2.4.0...v2.4.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jhv9-m2c5-2xm6/GHSA-jhv9-m2c5-2xm6.json b/advisories/unreviewed/2024/01/GHSA-jhv9-m2c5-2xm6/GHSA-jhv9-m2c5-2xm6.json new file mode 100644 index 00000000000..64f4994547b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jhv9-m2c5-2xm6/GHSA-jhv9-m2c5-2xm6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv9-m2c5-2xm6", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2022-4961" + ], + "details": "A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file platform-shop\\src\\main\\resources\\com\\platform\\dao\\OrderDao.xml. The manipulation of the argument sidx/order leads to sql injection. The associated identifier of this vulnerability is VDB-250243.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4961" + }, + { + "type": "WEB", + "url": "https://gitee.com/fuyang_lipengjun/platform/issues/I5XC79" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250243" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T05:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rhpm-63w5-79rg/GHSA-rhpm-63w5-79rg.json b/advisories/unreviewed/2024/01/GHSA-rhpm-63w5-79rg/GHSA-rhpm-63w5-79rg.json new file mode 100644 index 00000000000..ac1592c20e7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rhpm-63w5-79rg/GHSA-rhpm-63w5-79rg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhpm-63w5-79rg", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23173" + ], + "details": "An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows XSS via artist, album, and position parameters because of applied filter values in drilldown/CargoAppliedFilter.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23173" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/965214" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T348687" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json b/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json new file mode 100644 index 00000000000..cad6f49cff0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwvh-g99g-xv29", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23178" + ], + "details": "An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23178" + }, + { + "type": "WEB", + "url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T349312" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wxvx-9q6r-rvc3/GHSA-wxvx-9q6r-rvc3.json b/advisories/unreviewed/2024/01/GHSA-wxvx-9q6r-rvc3/GHSA-wxvx-9q6r-rvc3.json new file mode 100644 index 00000000000..b57a9ba299e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wxvx-9q6r-rvc3/GHSA-wxvx-9q6r-rvc3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxvx-9q6r-rvc3", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-0393" + ], + "details": "Rejected reason: This CVE ID was unused by the CNA.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0393" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json b/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json new file mode 100644 index 00000000000..dc51c6ae775 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj97-9w9q-ffjp", + "modified": "2024-01-12T06:30:16Z", + "published": "2024-01-12T06:30:16Z", + "aliases": [ + "CVE-2024-23177" + ], + "details": "An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23177" + }, + { + "type": "WEB", + "url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T348979" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T06:15:47Z" + } +} \ No newline at end of file