diff --git a/advisories/github-reviewed/2022/03/GHSA-5vjc-qx43-r747/GHSA-5vjc-qx43-r747.json b/advisories/github-reviewed/2022/03/GHSA-5vjc-qx43-r747/GHSA-5vjc-qx43-r747.json index 2b526c6b682..42be7fa03a7 100644 --- a/advisories/github-reviewed/2022/03/GHSA-5vjc-qx43-r747/GHSA-5vjc-qx43-r747.json +++ b/advisories/github-reviewed/2022/03/GHSA-5vjc-qx43-r747/GHSA-5vjc-qx43-r747.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://github.com/jenkinsci/folder-auth-plugin/security/advisories/GHSA-5vjc-qx43-r747" }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/folder-auth-plugin/commit/085df580c22902820ebba77b1201fabff098efc4" + }, { "type": "PACKAGE", "url": "https://github.com/jenkinsci/folder-auth-plugin" diff --git a/advisories/github-reviewed/2022/03/GHSA-chr6-386q-4m3v/GHSA-chr6-386q-4m3v.json b/advisories/github-reviewed/2022/03/GHSA-chr6-386q-4m3v/GHSA-chr6-386q-4m3v.json index 75db3a33ccf..5ad017017c9 100644 --- a/advisories/github-reviewed/2022/03/GHSA-chr6-386q-4m3v/GHSA-chr6-386q-4m3v.json +++ b/advisories/github-reviewed/2022/03/GHSA-chr6-386q-4m3v/GHSA-chr6-386q-4m3v.json @@ -40,6 +40,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27200" }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/folder-auth-plugin/commit/085df580c22902820ebba77b1201fabff098efc4" + }, { "type": "PACKAGE", "url": "https://github.com/jenkinsci/folder-auth-plugin" diff --git a/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json b/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json index 8575c6c9d40..8875f0b0d98 100644 --- a/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json +++ b/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjx7-957f-w3qg", - "modified": "2023-11-30T18:31:18Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-11-30T18:31:18Z", "aliases": [ "CVE-2023-48803" ], "details": "In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T18:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json b/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json index abc6ac87e08..3cc808dcfa5 100644 --- a/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json +++ b/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-269h-hc79-qjpf", - "modified": "2023-12-01T00:31:01Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:01Z", "aliases": [ "CVE-2023-46389" ], "details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-2vv4-6qfr-v4vp/GHSA-2vv4-6qfr-v4vp.json b/advisories/unreviewed/2023/12/GHSA-2vv4-6qfr-v4vp/GHSA-2vv4-6qfr-v4vp.json index ad4f2240092..c6e64a16807 100644 --- a/advisories/unreviewed/2023/12/GHSA-2vv4-6qfr-v4vp/GHSA-2vv4-6qfr-v4vp.json +++ b/advisories/unreviewed/2023/12/GHSA-2vv4-6qfr-v4vp/GHSA-2vv4-6qfr-v4vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vv4-6qfr-v4vp", - "modified": "2023-12-01T00:31:01Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T00:31:01Z", "aliases": [ "CVE-2023-47307" ], "details": "Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-395p-v3qv-q9fr/GHSA-395p-v3qv-q9fr.json b/advisories/unreviewed/2023/12/GHSA-395p-v3qv-q9fr/GHSA-395p-v3qv-q9fr.json index cfb0112361f..6262673bfb8 100644 --- a/advisories/unreviewed/2023/12/GHSA-395p-v3qv-q9fr/GHSA-395p-v3qv-q9fr.json +++ b/advisories/unreviewed/2023/12/GHSA-395p-v3qv-q9fr/GHSA-395p-v3qv-q9fr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json b/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json index 683ec76820b..6bdacd63b43 100644 --- a/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json +++ b/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h9p-fmw3-6wpv", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46386" ], "details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-3x3c-pjw5-pjr2/GHSA-3x3c-pjw5-pjr2.json b/advisories/unreviewed/2023/12/GHSA-3x3c-pjw5-pjr2/GHSA-3x3c-pjw5-pjr2.json index 5490a70924f..f0e9ab22a2d 100644 --- a/advisories/unreviewed/2023/12/GHSA-3x3c-pjw5-pjr2/GHSA-3x3c-pjw5-pjr2.json +++ b/advisories/unreviewed/2023/12/GHSA-3x3c-pjw5-pjr2/GHSA-3x3c-pjw5-pjr2.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-5458-8382-84h9/GHSA-5458-8382-84h9.json b/advisories/unreviewed/2023/12/GHSA-5458-8382-84h9/GHSA-5458-8382-84h9.json index b877f34e377..e400f022aa7 100644 --- a/advisories/unreviewed/2023/12/GHSA-5458-8382-84h9/GHSA-5458-8382-84h9.json +++ b/advisories/unreviewed/2023/12/GHSA-5458-8382-84h9/GHSA-5458-8382-84h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5458-8382-84h9", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21215" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-5795-893f-fhqm/GHSA-5795-893f-fhqm.json b/advisories/unreviewed/2023/12/GHSA-5795-893f-fhqm/GHSA-5795-893f-fhqm.json index 6f006204b90..a2166eafa3a 100644 --- a/advisories/unreviewed/2023/12/GHSA-5795-893f-fhqm/GHSA-5795-893f-fhqm.json +++ b/advisories/unreviewed/2023/12/GHSA-5795-893f-fhqm/GHSA-5795-893f-fhqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5795-893f-fhqm", - "modified": "2023-12-01T03:30:35Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T03:30:35Z", "aliases": [ "CVE-2023-43454" ], "details": "An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T02:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-5jjc-r23c-5j3p/GHSA-5jjc-r23c-5j3p.json b/advisories/unreviewed/2023/12/GHSA-5jjc-r23c-5j3p/GHSA-5jjc-r23c-5j3p.json index 5fdbd782eb6..d85ddcdc813 100644 --- a/advisories/unreviewed/2023/12/GHSA-5jjc-r23c-5j3p/GHSA-5jjc-r23c-5j3p.json +++ b/advisories/unreviewed/2023/12/GHSA-5jjc-r23c-5j3p/GHSA-5jjc-r23c-5j3p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jjc-r23c-5j3p", - "modified": "2023-12-01T00:31:01Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T00:31:01Z", "aliases": [ "CVE-2023-46956" ], "details": "SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json b/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json index 5efa3009079..db4ab5792c9 100644 --- a/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json +++ b/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74f3-25qj-395v", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46387" ], "details": "LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-798r-fxxx-hvxj/GHSA-798r-fxxx-hvxj.json b/advisories/unreviewed/2023/12/GHSA-798r-fxxx-hvxj/GHSA-798r-fxxx-hvxj.json new file mode 100644 index 00000000000..abb98604762 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-798r-fxxx-hvxj/GHSA-798r-fxxx-hvxj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798r-fxxx-hvxj", + "modified": "2023-12-06T21:30:59Z", + "published": "2023-12-06T21:30:59Z", + "aliases": [ + "CVE-2023-46751" + ], + "details": "An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46751" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707264" + }, + { + "type": "WEB", + "url": "https://ghostscript.com/" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=dcdbc595c13c9d11d235702dff46bb74c80f7698" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-06T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-846m-xqw6-w8rv/GHSA-846m-xqw6-w8rv.json b/advisories/unreviewed/2023/12/GHSA-846m-xqw6-w8rv/GHSA-846m-xqw6-w8rv.json index bc602e83ca2..421f5efb8d7 100644 --- a/advisories/unreviewed/2023/12/GHSA-846m-xqw6-w8rv/GHSA-846m-xqw6-w8rv.json +++ b/advisories/unreviewed/2023/12/GHSA-846m-xqw6-w8rv/GHSA-846m-xqw6-w8rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-846m-xqw6-w8rv", - "modified": "2023-12-02T00:31:05Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-02T00:31:05Z", "aliases": [ "CVE-2023-48886" ], "details": "A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-84gg-pfmr-wx79/GHSA-84gg-pfmr-wx79.json b/advisories/unreviewed/2023/12/GHSA-84gg-pfmr-wx79/GHSA-84gg-pfmr-wx79.json index 04da9cf2cb4..b5eeaee4cea 100644 --- a/advisories/unreviewed/2023/12/GHSA-84gg-pfmr-wx79/GHSA-84gg-pfmr-wx79.json +++ b/advisories/unreviewed/2023/12/GHSA-84gg-pfmr-wx79/GHSA-84gg-pfmr-wx79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84gg-pfmr-wx79", - "modified": "2023-12-01T03:30:35Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T03:30:35Z", "aliases": [ "CVE-2023-48016" ], "details": "Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T03:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json b/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json index 16b7a9b44b6..47dc73e3e44 100644 --- a/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json +++ b/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-85qr-ggvx-pgjx", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46383" ], "details": "LOYTEC electronics GmbH LINX Configurator 7.4.10 uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json b/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json index fd3a5edc1b9..12f38a31a05 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json +++ b/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qhh-c53m-4q69", - "modified": "2023-12-01T18:30:26Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T18:30:26Z", "aliases": [ "CVE-2023-48842" ], "details": "D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T16:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json b/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json index 1b6dfc655e1..7cfb49489f5 100644 --- a/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json +++ b/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vjx-qhgp-wfvm", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46384" ], "details": "LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-cg44-3c54-5q5h/GHSA-cg44-3c54-5q5h.json b/advisories/unreviewed/2023/12/GHSA-cg44-3c54-5q5h/GHSA-cg44-3c54-5q5h.json index 12342257195..4cdb7a20088 100644 --- a/advisories/unreviewed/2023/12/GHSA-cg44-3c54-5q5h/GHSA-cg44-3c54-5q5h.json +++ b/advisories/unreviewed/2023/12/GHSA-cg44-3c54-5q5h/GHSA-cg44-3c54-5q5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg44-3c54-5q5h", - "modified": "2023-12-01T15:31:21Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T15:31:21Z", "aliases": [ "CVE-2023-28896" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-326" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-f52g-mqvx-jmjp/GHSA-f52g-mqvx-jmjp.json b/advisories/unreviewed/2023/12/GHSA-f52g-mqvx-jmjp/GHSA-f52g-mqvx-jmjp.json index c20a87e0629..89321740ab6 100644 --- a/advisories/unreviewed/2023/12/GHSA-f52g-mqvx-jmjp/GHSA-f52g-mqvx-jmjp.json +++ b/advisories/unreviewed/2023/12/GHSA-f52g-mqvx-jmjp/GHSA-f52g-mqvx-jmjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f52g-mqvx-jmjp", - "modified": "2023-12-01T15:31:21Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T15:31:21Z", "aliases": [ "CVE-2023-28895" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-fv9m-x5m2-3pqm/GHSA-fv9m-x5m2-3pqm.json b/advisories/unreviewed/2023/12/GHSA-fv9m-x5m2-3pqm/GHSA-fv9m-x5m2-3pqm.json index 30d1ed98684..2e724f0655a 100644 --- a/advisories/unreviewed/2023/12/GHSA-fv9m-x5m2-3pqm/GHSA-fv9m-x5m2-3pqm.json +++ b/advisories/unreviewed/2023/12/GHSA-fv9m-x5m2-3pqm/GHSA-fv9m-x5m2-3pqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv9m-x5m2-3pqm", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21164" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-g2v5-2pcr-q98p/GHSA-g2v5-2pcr-q98p.json b/advisories/unreviewed/2023/12/GHSA-g2v5-2pcr-q98p/GHSA-g2v5-2pcr-q98p.json index 1854fec5fb0..0c910b4da0a 100644 --- a/advisories/unreviewed/2023/12/GHSA-g2v5-2pcr-q98p/GHSA-g2v5-2pcr-q98p.json +++ b/advisories/unreviewed/2023/12/GHSA-g2v5-2pcr-q98p/GHSA-g2v5-2pcr-q98p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2v5-2pcr-q98p", - "modified": "2023-12-01T03:30:34Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T03:30:34Z", "aliases": [ "CVE-2023-43453" ], "details": "An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T02:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json b/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json index 6ae1a3be180..952888dbad8 100644 --- a/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json +++ b/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5c9-vc82-389p", - "modified": "2023-12-01T15:31:22Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T15:31:22Z", "aliases": [ "CVE-2023-4518" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-g9j7-3mmj-7gq9/GHSA-g9j7-3mmj-7gq9.json b/advisories/unreviewed/2023/12/GHSA-g9j7-3mmj-7gq9/GHSA-g9j7-3mmj-7gq9.json new file mode 100644 index 00000000000..ca721eba73e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-g9j7-3mmj-7gq9/GHSA-g9j7-3mmj-7gq9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9j7-3mmj-7gq9", + "modified": "2023-12-06T21:30:59Z", + "published": "2023-12-06T21:30:59Z", + "aliases": [ + "CVE-2023-48123" + ], + "details": "An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48123" + }, + { + "type": "WEB", + "url": "https://github.com/pfsense/pfsense/commit/f72618c4abb61ea6346938d0c93df9078736b775" + }, + { + "type": "WEB", + "url": "https://docs.netgate.com/downloads/pfSense-SA-23_11.webgui.asc" + }, + { + "type": "WEB", + "url": "https://redmine.pfsense.org/issues/14809" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-06T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gc2r-5q9g-j8gq/GHSA-gc2r-5q9g-j8gq.json b/advisories/unreviewed/2023/12/GHSA-gc2r-5q9g-j8gq/GHSA-gc2r-5q9g-j8gq.json index f5b1b41f985..d8f8d84f1b7 100644 --- a/advisories/unreviewed/2023/12/GHSA-gc2r-5q9g-j8gq/GHSA-gc2r-5q9g-j8gq.json +++ b/advisories/unreviewed/2023/12/GHSA-gc2r-5q9g-j8gq/GHSA-gc2r-5q9g-j8gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc2r-5q9g-j8gq", - "modified": "2023-12-02T00:31:05Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-02T00:31:05Z", "aliases": [ "CVE-2023-48801" ], "details": "In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-ghgw-5fv7-r238/GHSA-ghgw-5fv7-r238.json b/advisories/unreviewed/2023/12/GHSA-ghgw-5fv7-r238/GHSA-ghgw-5fv7-r238.json index c5a59357532..c93ed15ac9e 100644 --- a/advisories/unreviewed/2023/12/GHSA-ghgw-5fv7-r238/GHSA-ghgw-5fv7-r238.json +++ b/advisories/unreviewed/2023/12/GHSA-ghgw-5fv7-r238/GHSA-ghgw-5fv7-r238.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghgw-5fv7-r238", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21166" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hpmw-w222-jm7v/GHSA-hpmw-w222-jm7v.json b/advisories/unreviewed/2023/12/GHSA-hpmw-w222-jm7v/GHSA-hpmw-w222-jm7v.json index a133025980c..2d903a9733f 100644 --- a/advisories/unreviewed/2023/12/GHSA-hpmw-w222-jm7v/GHSA-hpmw-w222-jm7v.json +++ b/advisories/unreviewed/2023/12/GHSA-hpmw-w222-jm7v/GHSA-hpmw-w222-jm7v.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json b/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json index 7f2624a99fb..6b9ce0c76cf 100644 --- a/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json +++ b/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw83-99pm-pwrr", - "modified": "2023-12-01T18:30:26Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T18:30:26Z", "aliases": [ "CVE-2023-48893" ], "details": "Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/staff_act.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T16:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json b/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json index e348a6d9802..080a8e3ebb4 100644 --- a/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json +++ b/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqgq-x29j-jv5r", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21216" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jrr9-w96c-8wpv/GHSA-jrr9-w96c-8wpv.json b/advisories/unreviewed/2023/12/GHSA-jrr9-w96c-8wpv/GHSA-jrr9-w96c-8wpv.json index 7ae1f7a4f4a..46525d3cf55 100644 --- a/advisories/unreviewed/2023/12/GHSA-jrr9-w96c-8wpv/GHSA-jrr9-w96c-8wpv.json +++ b/advisories/unreviewed/2023/12/GHSA-jrr9-w96c-8wpv/GHSA-jrr9-w96c-8wpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrr9-w96c-8wpv", - "modified": "2023-12-01T12:30:49Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T12:30:49Z", "aliases": [ "CVE-2023-5427" ], "details": "A local non-privileged user can make improper GPU processing operations to gain access to already freed memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T11:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-m695-35xv-pjcm/GHSA-m695-35xv-pjcm.json b/advisories/unreviewed/2023/12/GHSA-m695-35xv-pjcm/GHSA-m695-35xv-pjcm.json index 10513b89d21..057912a231c 100644 --- a/advisories/unreviewed/2023/12/GHSA-m695-35xv-pjcm/GHSA-m695-35xv-pjcm.json +++ b/advisories/unreviewed/2023/12/GHSA-m695-35xv-pjcm/GHSA-m695-35xv-pjcm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/12/GHSA-m73r-2fp3-47jw/GHSA-m73r-2fp3-47jw.json b/advisories/unreviewed/2023/12/GHSA-m73r-2fp3-47jw/GHSA-m73r-2fp3-47jw.json index eb873f7a031..877fdde0d95 100644 --- a/advisories/unreviewed/2023/12/GHSA-m73r-2fp3-47jw/GHSA-m73r-2fp3-47jw.json +++ b/advisories/unreviewed/2023/12/GHSA-m73r-2fp3-47jw/GHSA-m73r-2fp3-47jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m73r-2fp3-47jw", - "modified": "2023-12-01T03:30:35Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T03:30:35Z", "aliases": [ "CVE-2023-43455" ], "details": "An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T02:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mhcq-ppww-6wf5/GHSA-mhcq-ppww-6wf5.json b/advisories/unreviewed/2023/12/GHSA-mhcq-ppww-6wf5/GHSA-mhcq-ppww-6wf5.json index 741ba2f0306..b85d9e53a87 100644 --- a/advisories/unreviewed/2023/12/GHSA-mhcq-ppww-6wf5/GHSA-mhcq-ppww-6wf5.json +++ b/advisories/unreviewed/2023/12/GHSA-mhcq-ppww-6wf5/GHSA-mhcq-ppww-6wf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhcq-ppww-6wf5", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21218" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-phhw-p62x-84wp/GHSA-phhw-p62x-84wp.json b/advisories/unreviewed/2023/12/GHSA-phhw-p62x-84wp/GHSA-phhw-p62x-84wp.json index 8c1a1743504..4d24b3d6bc4 100644 --- a/advisories/unreviewed/2023/12/GHSA-phhw-p62x-84wp/GHSA-phhw-p62x-84wp.json +++ b/advisories/unreviewed/2023/12/GHSA-phhw-p62x-84wp/GHSA-phhw-p62x-84wp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phhw-p62x-84wp", - "modified": "2023-12-01T18:30:25Z", + "modified": "2023-12-06T21:30:58Z", "published": "2023-12-01T18:30:25Z", "aliases": [ "CVE-2023-48813" ], "details": "Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-01T16:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-rcjw-44p8-ppj6/GHSA-rcjw-44p8-ppj6.json b/advisories/unreviewed/2023/12/GHSA-rcjw-44p8-ppj6/GHSA-rcjw-44p8-ppj6.json index bdf764caa40..991f16791ea 100644 --- a/advisories/unreviewed/2023/12/GHSA-rcjw-44p8-ppj6/GHSA-rcjw-44p8-ppj6.json +++ b/advisories/unreviewed/2023/12/GHSA-rcjw-44p8-ppj6/GHSA-rcjw-44p8-ppj6.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://jira.atlassian.com/browse/CONFSERVER-93415" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/CONFSERVER-93502" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-rw69-wr48-w7px/GHSA-rw69-wr48-w7px.json b/advisories/unreviewed/2023/12/GHSA-rw69-wr48-w7px/GHSA-rw69-wr48-w7px.json index f873f677d4c..9d69ec37ee6 100644 --- a/advisories/unreviewed/2023/12/GHSA-rw69-wr48-w7px/GHSA-rw69-wr48-w7px.json +++ b/advisories/unreviewed/2023/12/GHSA-rw69-wr48-w7px/GHSA-rw69-wr48-w7px.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-297" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-vhhx-835c-qvwj/GHSA-vhhx-835c-qvwj.json b/advisories/unreviewed/2023/12/GHSA-vhhx-835c-qvwj/GHSA-vhhx-835c-qvwj.json index 3d95c88d9d4..55ddb5b90d4 100644 --- a/advisories/unreviewed/2023/12/GHSA-vhhx-835c-qvwj/GHSA-vhhx-835c-qvwj.json +++ b/advisories/unreviewed/2023/12/GHSA-vhhx-835c-qvwj/GHSA-vhhx-835c-qvwj.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://https://www.ibm.com/support/pages/node/7082784" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7082784" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-vvx8-mpx4-rjqm/GHSA-vvx8-mpx4-rjqm.json b/advisories/unreviewed/2023/12/GHSA-vvx8-mpx4-rjqm/GHSA-vvx8-mpx4-rjqm.json index 2d79b6c5e2c..139759a868d 100644 --- a/advisories/unreviewed/2023/12/GHSA-vvx8-mpx4-rjqm/GHSA-vvx8-mpx4-rjqm.json +++ b/advisories/unreviewed/2023/12/GHSA-vvx8-mpx4-rjqm/GHSA-vvx8-mpx4-rjqm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-vwqh-rcfq-pqf7/GHSA-vwqh-rcfq-pqf7.json b/advisories/unreviewed/2023/12/GHSA-vwqh-rcfq-pqf7/GHSA-vwqh-rcfq-pqf7.json index 052476829de..aab0fbf44e9 100644 --- a/advisories/unreviewed/2023/12/GHSA-vwqh-rcfq-pqf7/GHSA-vwqh-rcfq-pqf7.json +++ b/advisories/unreviewed/2023/12/GHSA-vwqh-rcfq-pqf7/GHSA-vwqh-rcfq-pqf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwqh-rcfq-pqf7", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-48894" ], "details": "Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T22:15:09Z" diff --git a/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json b/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json index ff651f3ac8e..1774dddf9d5 100644 --- a/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json +++ b/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8fp-3787-pwgj", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46388" ], "details": "LOYTEC electronics GmbH LINX-212 6.2.4 and LINX-151 7.2.4 are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json b/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json index 21ddd03bfd5..a8c70e01bba 100644 --- a/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json +++ b/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whp9-r49x-695c", - "modified": "2023-12-01T00:31:00Z", + "modified": "2023-12-06T21:30:57Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46385" ], "details": "LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-30T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-x5v7-pg82-r947/GHSA-x5v7-pg82-r947.json b/advisories/unreviewed/2023/12/GHSA-x5v7-pg82-r947/GHSA-x5v7-pg82-r947.json index 238f64705a1..577bd8e295a 100644 --- a/advisories/unreviewed/2023/12/GHSA-x5v7-pg82-r947/GHSA-x5v7-pg82-r947.json +++ b/advisories/unreviewed/2023/12/GHSA-x5v7-pg82-r947/GHSA-x5v7-pg82-r947.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x5v7-pg82-r947", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21217" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-x6qm-hmv3-hj39/GHSA-x6qm-hmv3-hj39.json b/advisories/unreviewed/2023/12/GHSA-x6qm-hmv3-hj39/GHSA-x6qm-hmv3-hj39.json index 3948800d1c7..e6bd380a923 100644 --- a/advisories/unreviewed/2023/12/GHSA-x6qm-hmv3-hj39/GHSA-x6qm-hmv3-hj39.json +++ b/advisories/unreviewed/2023/12/GHSA-x6qm-hmv3-hj39/GHSA-x6qm-hmv3-hj39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6qm-hmv3-hj39", - "modified": "2023-12-03T03:30:21Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-03T03:30:21Z", "aliases": [ "CVE-2023-49926" ], "details": "app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-03T03:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json b/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json index 1342c0c6f08..f6376d03b33 100644 --- a/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json +++ b/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xh85-63vm-rw4g", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21163" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xw83-fhrh-mg6g/GHSA-xw83-fhrh-mg6g.json b/advisories/unreviewed/2023/12/GHSA-xw83-fhrh-mg6g/GHSA-xw83-fhrh-mg6g.json index 4e1b4a915b7..0d87135a908 100644 --- a/advisories/unreviewed/2023/12/GHSA-xw83-fhrh-mg6g/GHSA-xw83-fhrh-mg6g.json +++ b/advisories/unreviewed/2023/12/GHSA-xw83-fhrh-mg6g/GHSA-xw83-fhrh-mg6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw83-fhrh-mg6g", - "modified": "2023-12-05T00:31:07Z", + "modified": "2023-12-06T21:30:59Z", "published": "2023-12-05T00:31:07Z", "aliases": [ "CVE-2023-21162" ], "details": "There is elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-04T23:15:22Z"