From 543d0cc566cedd26fae5eebef1cd3e24aed086b1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jan 2024 12:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-66qh-r598-w33q GHSA-6fv2-72fv-rm3x GHSA-7gp2-x65v-77wx GHSA-p6w5-j5f6-qqgm --- .../GHSA-66qh-r598-w33q.json | 35 ++++++++++++++ .../GHSA-6fv2-72fv-rm3x.json | 46 +++++++++++++++++++ .../GHSA-7gp2-x65v-77wx.json | 46 +++++++++++++++++++ .../GHSA-p6w5-j5f6-qqgm.json | 46 +++++++++++++++++++ 4 files changed, 173 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6fv2-72fv-rm3x/GHSA-6fv2-72fv-rm3x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7gp2-x65v-77wx/GHSA-7gp2-x65v-77wx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p6w5-j5f6-qqgm/GHSA-p6w5-j5f6-qqgm.json diff --git a/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json b/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json new file mode 100644 index 00000000000..8d999900612 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-66qh-r598-w33q/GHSA-66qh-r598-w33q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66qh-r598-w33q", + "modified": "2024-01-08T12:30:31Z", + "published": "2024-01-08T12:30:31Z", + "aliases": [ + "CVE-2023-5091" + ], + "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5091" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6fv2-72fv-rm3x/GHSA-6fv2-72fv-rm3x.json b/advisories/unreviewed/2024/01/GHSA-6fv2-72fv-rm3x/GHSA-6fv2-72fv-rm3x.json new file mode 100644 index 00000000000..bce63bc04f7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6fv2-72fv-rm3x/GHSA-6fv2-72fv-rm3x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fv2-72fv-rm3x", + "modified": "2024-01-08T12:30:32Z", + "published": "2024-01-08T12:30:32Z", + "aliases": [ + "CVE-2024-0307" + ], + "details": "A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0307" + }, + { + "type": "WEB", + "url": "https://github.com/VistaAX/vulnerablility/blob/main/Dynamic%20Lab%20Management%20System%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249874" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249874" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7gp2-x65v-77wx/GHSA-7gp2-x65v-77wx.json b/advisories/unreviewed/2024/01/GHSA-7gp2-x65v-77wx/GHSA-7gp2-x65v-77wx.json new file mode 100644 index 00000000000..3dccfe1be6f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7gp2-x65v-77wx/GHSA-7gp2-x65v-77wx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gp2-x65v-77wx", + "modified": "2024-01-08T12:30:32Z", + "published": "2024-01-08T12:30:32Z", + "aliases": [ + "CVE-2024-0308" + ], + "details": "A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. The manipulation of the argument p_url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249875.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0308" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/2E2JG2PClHGF" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249875" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249875" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p6w5-j5f6-qqgm/GHSA-p6w5-j5f6-qqgm.json b/advisories/unreviewed/2024/01/GHSA-p6w5-j5f6-qqgm/GHSA-p6w5-j5f6-qqgm.json new file mode 100644 index 00000000000..5fc424e100f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p6w5-j5f6-qqgm/GHSA-p6w5-j5f6-qqgm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6w5-j5f6-qqgm", + "modified": "2024-01-08T12:30:32Z", + "published": "2024-01-08T12:30:32Z", + "aliases": [ + "CVE-2023-6921" + ], + "details": "Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6921" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-6921/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-6921/" + }, + { + "type": "WEB", + "url": "https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T12:15:46Z" + } +} \ No newline at end of file