From 540ba4c2eab2ee204114464d2a4bb9c7c7022748 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 Feb 2024 12:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-jx73-f6rp-8fxv GHSA-68qx-6vr4-qq4p GHSA-c57v-4vg5-cm2x GHSA-phfx-2gmw-mfx5 GHSA-qfm6-2jf8-7v9r --- .../GHSA-jx73-f6rp-8fxv.json | 4 +- .../GHSA-68qx-6vr4-qq4p.json | 46 +++++++++++++++++++ .../GHSA-c57v-4vg5-cm2x.json | 42 +++++++++++++++++ .../GHSA-phfx-2gmw-mfx5.json | 46 +++++++++++++++++++ .../GHSA-qfm6-2jf8-7v9r.json | 46 +++++++++++++++++++ 5 files changed, 182 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-68qx-6vr4-qq4p/GHSA-68qx-6vr4-qq4p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json create mode 100644 advisories/unreviewed/2024/02/GHSA-phfx-2gmw-mfx5/GHSA-phfx-2gmw-mfx5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qfm6-2jf8-7v9r/GHSA-qfm6-2jf8-7v9r.json diff --git a/advisories/unreviewed/2023/07/GHSA-jx73-f6rp-8fxv/GHSA-jx73-f6rp-8fxv.json b/advisories/unreviewed/2023/07/GHSA-jx73-f6rp-8fxv/GHSA-jx73-f6rp-8fxv.json index cebc1b4e549..a9015b1d991 100644 --- a/advisories/unreviewed/2023/07/GHSA-jx73-f6rp-8fxv/GHSA-jx73-f6rp-8fxv.json +++ b/advisories/unreviewed/2023/07/GHSA-jx73-f6rp-8fxv/GHSA-jx73-f6rp-8fxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx73-f6rp-8fxv", - "modified": "2023-07-06T21:14:56Z", + "modified": "2024-02-07T12:30:25Z", "published": "2023-07-06T21:14:56Z", "aliases": [ "CVE-2022-47436" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-10T11:15:10Z" diff --git a/advisories/unreviewed/2024/02/GHSA-68qx-6vr4-qq4p/GHSA-68qx-6vr4-qq4p.json b/advisories/unreviewed/2024/02/GHSA-68qx-6vr4-qq4p/GHSA-68qx-6vr4-qq4p.json new file mode 100644 index 00000000000..d65f812d36b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-68qx-6vr4-qq4p/GHSA-68qx-6vr4-qq4p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68qx-6vr4-qq4p", + "modified": "2024-02-07T12:30:26Z", + "published": "2024-02-07T12:30:26Z", + "aliases": [ + "CVE-2024-1110" + ], + "details": "The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin's settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1110" + }, + { + "type": "WEB", + "url": "https://github.com/podlove/podlove-publisher/commit/7873ff520631087e2f10737860cdcd64d53187ba" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032008%40podlove-podcasting-plugin-for-wordpress&new=3032008%40podlove-podcasting-plugin-for-wordpress&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2c9cf461-572c-4be8-96e6-659acf3208f3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json b/advisories/unreviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json new file mode 100644 index 00000000000..593ae3827f3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c57v-4vg5-cm2x", + "modified": "2024-02-07T12:30:25Z", + "published": "2024-02-07T12:30:25Z", + "aliases": [ + "CVE-2023-51437" + ], + "details": "Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification.\nUsers are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users should also consider updating the configured secret in the `saslJaasServerRoleTokenSignerSecretPath` file.\n\nAny component matching an above version running the SASL Authentication Provider is affected. That includes the Pulsar Broker, Proxy, Websocket Proxy, or Function Worker.\n\n2.11 Pulsar users should upgrade to at least 2.11.3.\n3.0 Pulsar users should upgrade to at least 3.0.2.\n3.1 Pulsar users should upgrade to at least 3.1.1.\nAny users running Pulsar 2.8, 2.9, 2.10, and earlier should upgrade to one of the above patched versions.\n\nFor additional details on this attack vector, please refer to https://codahale.com/a-lesson-in-timing-attacks/ .\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51437" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/5kgmvvolf5tzp5rz9xjwfg2ncwvqqgl5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/07/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-phfx-2gmw-mfx5/GHSA-phfx-2gmw-mfx5.json b/advisories/unreviewed/2024/02/GHSA-phfx-2gmw-mfx5/GHSA-phfx-2gmw-mfx5.json new file mode 100644 index 00000000000..69e1589cc07 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-phfx-2gmw-mfx5/GHSA-phfx-2gmw-mfx5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phfx-2gmw-mfx5", + "modified": "2024-02-07T12:30:26Z", + "published": "2024-02-07T12:30:26Z", + "aliases": [ + "CVE-2024-1118" + ], + "details": "The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1118" + }, + { + "type": "WEB", + "url": "https://github.com/podlove/podlove-subscribe-button-wp-plugin/commit/b16b7a2e98db4c642ca671b0aede4dbfce4578b3" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032152%40podlove-subscribe-button&new=3032152%40podlove-subscribe-button&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f234f05f-e377-4e89-81e1-f47ff44eebc5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qfm6-2jf8-7v9r/GHSA-qfm6-2jf8-7v9r.json b/advisories/unreviewed/2024/02/GHSA-qfm6-2jf8-7v9r/GHSA-qfm6-2jf8-7v9r.json new file mode 100644 index 00000000000..8e7c9c4298a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qfm6-2jf8-7v9r/GHSA-qfm6-2jf8-7v9r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfm6-2jf8-7v9r", + "modified": "2024-02-07T12:30:26Z", + "published": "2024-02-07T12:30:26Z", + "aliases": [ + "CVE-2024-1109" + ], + "details": "The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to export the plugin's tracking data and podcast information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1109" + }, + { + "type": "WEB", + "url": "https://github.com/podlove/podlove-publisher/commit/0ac83d1955aa964a358833b1b5ce790fff45b3f4" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032008%40podlove-podcasting-plugin-for-wordpress&new=3032008%40podlove-podcasting-plugin-for-wordpress&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a7b25b66-e9d1-448d-8367-cce4c0dec635?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T11:15:08Z" + } +} \ No newline at end of file