Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-12-06 21:32:52 +00:00
parent 8f515cdea6
commit 612ba0b929
45 changed files with 314 additions and 115 deletions
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://github.com/jenkinsci/folder-auth-plugin/security/advisories/GHSA-5vjc-qx43-r747"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/folder-auth-plugin/commit/085df580c22902820ebba77b1201fabff098efc4"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/folder-auth-plugin"
@@ -40,6 +40,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27200"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/folder-auth-plugin/commit/085df580c22902820ebba77b1201fabff098efc4"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/folder-auth-plugin"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjx7-957f-w3qg",
"modified": "2023-11-30T18:31:18Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-11-30T18:31:18Z",
"aliases": [
"CVE-2023-48803"
],
"details": "In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T18:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-269h-hc79-qjpf",
"modified": "2023-12-01T00:31:01Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-12-01T00:31:01Z",
"aliases": [
"CVE-2023-46389"
],
"details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vv4-6qfr-v4vp",
"modified": "2023-12-01T00:31:01Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T00:31:01Z",
"aliases": [
"CVE-2023-47307"
],
"details": "Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-35"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h9p-fmw3-6wpv",
"modified": "2023-12-01T00:31:00Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-12-01T00:31:00Z",
"aliases": [
"CVE-2023-46386"
],
"details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-35"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5458-8382-84h9",
"modified": "2023-12-05T00:31:07Z",
"modified": "2023-12-06T21:30:59Z",
"published": "2023-12-05T00:31:07Z",
"aliases": [
"CVE-2023-21215"
],
"details": "There is elevation of privilege.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-04T23:15:22Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5795-893f-fhqm",
"modified": "2023-12-01T03:30:35Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T03:30:35Z",
"aliases": [
"CVE-2023-43454"
],
"details": "An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-01T02:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jjc-r23c-5j3p",
"modified": "2023-12-01T00:31:01Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T00:31:01Z",
"aliases": [
"CVE-2023-46956"
],
"details": "SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74f3-25qj-395v",
"modified": "2023-12-01T00:31:00Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-12-01T00:31:00Z",
"aliases": [
"CVE-2023-46387"
],
"details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-798r-fxxx-hvxj",
"modified": "2023-12-06T21:30:59Z",
"published": "2023-12-06T21:30:59Z",
"aliases": [
"CVE-2023-46751"
],
"details": "An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46751"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707264"
},
{
"type": "WEB",
"url": "https://ghostscript.com/"
},
{
"type": "WEB",
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=dcdbc595c13c9d11d235702dff46bb74c80f7698"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-06T20:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-846m-xqw6-w8rv",
"modified": "2023-12-02T00:31:05Z",
"modified": "2023-12-06T21:30:59Z",
"published": "2023-12-02T00:31:05Z",
"aliases": [
"CVE-2023-48886"
],
"details": "A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-01T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84gg-pfmr-wx79",
"modified": "2023-12-01T03:30:35Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T03:30:35Z",
"aliases": [
"CVE-2023-48016"
],
"details": "Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-01T03:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85qr-ggvx-pgjx",
"modified": "2023-12-01T00:31:00Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-12-01T00:31:00Z",
"aliases": [
"CVE-2023-46383"
],
"details": "LOYTEC electronics GmbH LINX Configurator 7.4.10 uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qhh-c53m-4q69",
"modified": "2023-12-01T18:30:26Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T18:30:26Z",
"aliases": [
"CVE-2023-48842"
],
"details": "D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-01T16:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vjx-qhgp-wfvm",
"modified": "2023-12-01T00:31:00Z",
"modified": "2023-12-06T21:30:57Z",
"published": "2023-12-01T00:31:00Z",
"aliases": [
"CVE-2023-46384"
],
"details": "LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-30T23:15:07Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg44-3c54-5q5h",
"modified": "2023-12-01T15:31:21Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T15:31:21Z",
"aliases": [
"CVE-2023-28896"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-261"
"CWE-261",
"CWE-326"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f52g-mqvx-jmjp",
"modified": "2023-12-01T15:31:21Z",
"modified": "2023-12-06T21:30:58Z",
"published": "2023-12-01T15:31:21Z",
"aliases": [
"CVE-2023-28895"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-259"
"CWE-259",
"CWE-798"
],
"severity": "LOW",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More