From 61e86c8c2ba84008c2b2cafc4c961db8cba2a7b7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 25 Dec 2023 09:31:33 +0000 Subject: [PATCH] Publish Advisories GHSA-2x74-jrhg-mr4p GHSA-3253-93gv-fv6c GHSA-45pw-h44c-jmqc GHSA-7246-m99m-q4pq GHSA-7vjq-m92p-42wp GHSA-84m5-wq3j-47c4 GHSA-868h-653q-w2q2 GHSA-8cxx-7fx3-j6xj GHSA-9cxj-f8g7-43v7 GHSA-9rg4-33x9-wfrh GHSA-9w73-mrh2-35pj GHSA-ch6f-2w93-3p64 GHSA-g4qh-pgmq-g946 GHSA-j3jw-c3vp-jg36 GHSA-pc38-vvqw-jq9r GHSA-pc49-g522-pmh5 GHSA-q2rp-9vp9-fg3q GHSA-q565-26vc-vpx8 GHSA-qp42-5pj7-4ccm --- .../GHSA-2x74-jrhg-mr4p.json | 35 +++++++++++++++ .../GHSA-3253-93gv-fv6c.json | 43 +++++++++++++++++++ .../GHSA-45pw-h44c-jmqc.json | 43 +++++++++++++++++++ .../GHSA-7246-m99m-q4pq.json | 43 +++++++++++++++++++ .../GHSA-7vjq-m92p-42wp.json | 43 +++++++++++++++++++ .../GHSA-84m5-wq3j-47c4.json | 39 +++++++++++++++++ .../GHSA-868h-653q-w2q2.json | 35 +++++++++++++++ .../GHSA-8cxx-7fx3-j6xj.json | 43 +++++++++++++++++++ .../GHSA-9cxj-f8g7-43v7.json | 35 +++++++++++++++ .../GHSA-9rg4-33x9-wfrh.json | 39 +++++++++++++++++ .../GHSA-9w73-mrh2-35pj.json | 43 +++++++++++++++++++ .../GHSA-ch6f-2w93-3p64.json | 39 +++++++++++++++++ .../GHSA-g4qh-pgmq-g946.json | 43 +++++++++++++++++++ .../GHSA-j3jw-c3vp-jg36.json | 39 +++++++++++++++++ .../GHSA-pc38-vvqw-jq9r.json | 39 +++++++++++++++++ .../GHSA-pc49-g522-pmh5.json | 39 +++++++++++++++++ .../GHSA-q2rp-9vp9-fg3q.json | 35 +++++++++++++++ .../GHSA-q565-26vc-vpx8.json | 39 +++++++++++++++++ .../GHSA-qp42-5pj7-4ccm.json | 39 +++++++++++++++++ 19 files changed, 753 insertions(+) create mode 100644 advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3253-93gv-fv6c/GHSA-3253-93gv-fv6c.json create mode 100644 advisories/unreviewed/2023/12/GHSA-45pw-h44c-jmqc/GHSA-45pw-h44c-jmqc.json create mode 100644 advisories/unreviewed/2023/12/GHSA-7246-m99m-q4pq/GHSA-7246-m99m-q4pq.json create mode 100644 advisories/unreviewed/2023/12/GHSA-7vjq-m92p-42wp/GHSA-7vjq-m92p-42wp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-84m5-wq3j-47c4/GHSA-84m5-wq3j-47c4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json create mode 100644 advisories/unreviewed/2023/12/GHSA-8cxx-7fx3-j6xj/GHSA-8cxx-7fx3-j6xj.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9cxj-f8g7-43v7/GHSA-9cxj-f8g7-43v7.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9rg4-33x9-wfrh/GHSA-9rg4-33x9-wfrh.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9w73-mrh2-35pj/GHSA-9w73-mrh2-35pj.json create mode 100644 advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json create mode 100644 advisories/unreviewed/2023/12/GHSA-g4qh-pgmq-g946/GHSA-g4qh-pgmq-g946.json create mode 100644 advisories/unreviewed/2023/12/GHSA-j3jw-c3vp-jg36/GHSA-j3jw-c3vp-jg36.json create mode 100644 advisories/unreviewed/2023/12/GHSA-pc38-vvqw-jq9r/GHSA-pc38-vvqw-jq9r.json create mode 100644 advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json create mode 100644 advisories/unreviewed/2023/12/GHSA-q2rp-9vp9-fg3q/GHSA-q2rp-9vp9-fg3q.json create mode 100644 advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-qp42-5pj7-4ccm/GHSA-qp42-5pj7-4ccm.json diff --git a/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json b/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json new file mode 100644 index 00000000000..a7a08bda38b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x74-jrhg-mr4p", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-49954" + ], + "details": "The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49954" + }, + { + "type": "WEB", + "url": "https://cve-2023-49954.github.io/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3253-93gv-fv6c/GHSA-3253-93gv-fv6c.json b/advisories/unreviewed/2023/12/GHSA-3253-93gv-fv6c/GHSA-3253-93gv-fv6c.json new file mode 100644 index 00000000000..d51fda26910 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3253-93gv-fv6c/GHSA-3253-93gv-fv6c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3253-93gv-fv6c", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-36485" + ], + "details": "The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36485" + }, + { + "type": "WEB", + "url": "https://github.com/ILIAS-eLearning/ILIAS/pull/5987" + }, + { + "type": "WEB", + "url": "https://github.com/ILIAS-eLearning/ILIAS/pull/5988" + }, + { + "type": "WEB", + "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-45pw-h44c-jmqc/GHSA-45pw-h44c-jmqc.json b/advisories/unreviewed/2023/12/GHSA-45pw-h44c-jmqc/GHSA-45pw-h44c-jmqc.json new file mode 100644 index 00000000000..6134968aef0 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-45pw-h44c-jmqc/GHSA-45pw-h44c-jmqc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45pw-h44c-jmqc", + "modified": "2023-12-25T09:30:20Z", + "published": "2023-12-25T09:30:20Z", + "aliases": [ + "CVE-2023-37188" + ], + "details": "C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37188" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/issues/521" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/commit/425e8a9a59d49378d57e2116b6c9b0190a5986f5" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/compare/v2.9.2...v2.9.3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7246-m99m-q4pq/GHSA-7246-m99m-q4pq.json b/advisories/unreviewed/2023/12/GHSA-7246-m99m-q4pq/GHSA-7246-m99m-q4pq.json new file mode 100644 index 00000000000..ae6b550f650 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7246-m99m-q4pq/GHSA-7246-m99m-q4pq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7246-m99m-q4pq", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-38321" + ], + "details": "OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38321" + }, + { + "type": "WEB", + "url": "https://github.com/openNDS/openNDS/blob/master/ChangeLog" + }, + { + "type": "WEB", + "url": "https://openwrt.org/docs/guide-user/services/captive-portal/opennds" + }, + { + "type": "WEB", + "url": "https://source.sierrawireless.com/-/media/support_downloads/security-bulletins/pdf/swi-psa-2023-006-r3.ashx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7vjq-m92p-42wp/GHSA-7vjq-m92p-42wp.json b/advisories/unreviewed/2023/12/GHSA-7vjq-m92p-42wp/GHSA-7vjq-m92p-42wp.json new file mode 100644 index 00000000000..b7426f734d1 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7vjq-m92p-42wp/GHSA-7vjq-m92p-42wp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vjq-m92p-42wp", + "modified": "2023-12-25T09:30:20Z", + "published": "2023-12-25T09:30:20Z", + "aliases": [ + "CVE-2023-37186" + ], + "details": "C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37186" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/issues/522" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/commit/d55bfcd6804699e1435dc3e233fd76c8a5d3f9e3" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/compare/v2.9.2...v2.9.3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-84m5-wq3j-47c4/GHSA-84m5-wq3j-47c4.json b/advisories/unreviewed/2023/12/GHSA-84m5-wq3j-47c4/GHSA-84m5-wq3j-47c4.json new file mode 100644 index 00000000000..29a132e4bc3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-84m5-wq3j-47c4/GHSA-84m5-wq3j-47c4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84m5-wq3j-47c4", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2022-34267" + ], + "details": "An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34267" + }, + { + "type": "WEB", + "url": "https://www.rws.com/localization/products/trados-enterprise/worldserver/" + }, + { + "type": "WEB", + "url": "https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json b/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json new file mode 100644 index 00000000000..9d4bb83443a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-868h-653q-w2q2/GHSA-868h-653q-w2q2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-868h-653q-w2q2", + "modified": "2023-12-25T09:30:19Z", + "published": "2023-12-25T09:30:19Z", + "aliases": [ + "CVE-2023-28872" + ], + "details": "Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\\Temp\\NcpSupport* location.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28872" + }, + { + "type": "WEB", + "url": "https://herolab.usd.de/en/security-advisories/usd-2022-0006/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8cxx-7fx3-j6xj/GHSA-8cxx-7fx3-j6xj.json b/advisories/unreviewed/2023/12/GHSA-8cxx-7fx3-j6xj/GHSA-8cxx-7fx3-j6xj.json new file mode 100644 index 00000000000..6f167e4021b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8cxx-7fx3-j6xj/GHSA-8cxx-7fx3-j6xj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cxx-7fx3-j6xj", + "modified": "2023-12-25T09:30:19Z", + "published": "2023-12-25T09:30:19Z", + "aliases": [ + "CVE-2023-37185" + ], + "details": "C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37185" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/issues/519" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/commit/425e8a9a59d49378d57e2116b6c9b0190a5986f5" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/compare/v2.9.2...v2.9.3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9cxj-f8g7-43v7/GHSA-9cxj-f8g7-43v7.json b/advisories/unreviewed/2023/12/GHSA-9cxj-f8g7-43v7/GHSA-9cxj-f8g7-43v7.json new file mode 100644 index 00000000000..da6409bbc70 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9cxj-f8g7-43v7/GHSA-9cxj-f8g7-43v7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cxj-f8g7-43v7", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-31224" + ], + "details": "There is broken access control during authentication in Jamf Pro Server before 10.46.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31224" + }, + { + "type": "WEB", + "url": "https://learn.jamf.com/bundle/jamf-pro-release-notes-10.47.0/page/Resolved_Issues.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9rg4-33x9-wfrh/GHSA-9rg4-33x9-wfrh.json b/advisories/unreviewed/2023/12/GHSA-9rg4-33x9-wfrh/GHSA-9rg4-33x9-wfrh.json new file mode 100644 index 00000000000..411ea8fc22e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9rg4-33x9-wfrh/GHSA-9rg4-33x9-wfrh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rg4-33x9-wfrh", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-49944" + ], + "details": "The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49944" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/security" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt23-08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9w73-mrh2-35pj/GHSA-9w73-mrh2-35pj.json b/advisories/unreviewed/2023/12/GHSA-9w73-mrh2-35pj/GHSA-9w73-mrh2-35pj.json new file mode 100644 index 00000000000..d2a111df7d6 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9w73-mrh2-35pj/GHSA-9w73-mrh2-35pj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w73-mrh2-35pj", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-36486" + ], + "details": "The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36486" + }, + { + "type": "WEB", + "url": "https://github.com/ILIAS-eLearning/ILIAS/pull/5987" + }, + { + "type": "WEB", + "url": "https://github.com/ILIAS-eLearning/ILIAS/pull/5988" + }, + { + "type": "WEB", + "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json b/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json new file mode 100644 index 00000000000..c3c81d025b8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch6f-2w93-3p64", + "modified": "2023-12-25T09:30:20Z", + "published": "2023-12-25T09:30:20Z", + "aliases": [ + "CVE-2023-47091" + ], + "details": "An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47091" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu/2023-024/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-g4qh-pgmq-g946/GHSA-g4qh-pgmq-g946.json b/advisories/unreviewed/2023/12/GHSA-g4qh-pgmq-g946/GHSA-g4qh-pgmq-g946.json new file mode 100644 index 00000000000..1a29339511a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-g4qh-pgmq-g946/GHSA-g4qh-pgmq-g946.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4qh-pgmq-g946", + "modified": "2023-12-25T09:30:20Z", + "published": "2023-12-25T09:30:20Z", + "aliases": [ + "CVE-2023-37187" + ], + "details": "C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37187" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/issues/520" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/commit/425e8a9a59d49378d57e2116b6c9b0190a5986f5" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/compare/v2.9.2...v2.9.3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-j3jw-c3vp-jg36/GHSA-j3jw-c3vp-jg36.json b/advisories/unreviewed/2023/12/GHSA-j3jw-c3vp-jg36/GHSA-j3jw-c3vp-jg36.json new file mode 100644 index 00000000000..d2e852bb3f6 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-j3jw-c3vp-jg36/GHSA-j3jw-c3vp-jg36.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jw-c3vp-jg36", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-49226" + ], + "details": "An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49226" + }, + { + "type": "WEB", + "url": "https://www.synacktiv.com/publications%253Ffield_tags_target_id%253D4" + }, + { + "type": "WEB", + "url": "https://www.synacktiv.com/sites/default/files/2023-12/synacktiv-peplink-multiple-vulnerabilities.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-pc38-vvqw-jq9r/GHSA-pc38-vvqw-jq9r.json b/advisories/unreviewed/2023/12/GHSA-pc38-vvqw-jq9r/GHSA-pc38-vvqw-jq9r.json new file mode 100644 index 00000000000..7e5267d13c2 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-pc38-vvqw-jq9r/GHSA-pc38-vvqw-jq9r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc38-vvqw-jq9r", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-38826" + ], + "details": "A Cross Site Scripting (XSS) vulnerability exists in Follet Learning Solutions Destiny through 20.0_1U. via the handlewpesearchform.do. searchString.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38826" + }, + { + "type": "WEB", + "url": "https://github.com/Oracle-Security/CVEs/tree/main/Follett%20Learning%20Solutions/Destiny/CVE-2023-38826" + }, + { + "type": "WEB", + "url": "https://www.follettlearning.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json b/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json new file mode 100644 index 00000000000..c0e09154d50 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-pc49-g522-pmh5/GHSA-pc49-g522-pmh5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc49-g522-pmh5", + "modified": "2023-12-25T09:30:19Z", + "published": "2023-12-25T09:30:19Z", + "aliases": [ + "CVE-2023-31297" + ], + "details": "An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31297" + }, + { + "type": "WEB", + "url": "https://herolab.usd.de/en/security-advisories/usd-2022-0058/" + }, + { + "type": "WEB", + "url": "https://herolab.usd.de/security-advisories/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q2rp-9vp9-fg3q/GHSA-q2rp-9vp9-fg3q.json b/advisories/unreviewed/2023/12/GHSA-q2rp-9vp9-fg3q/GHSA-q2rp-9vp9-fg3q.json new file mode 100644 index 00000000000..d65e616ac19 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-q2rp-9vp9-fg3q/GHSA-q2rp-9vp9-fg3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2rp-9vp9-fg3q", + "modified": "2023-12-25T09:30:20Z", + "published": "2023-12-25T09:30:20Z", + "aliases": [ + "CVE-2023-47247" + ], + "details": "In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47247" + }, + { + "type": "WEB", + "url": "https://documentation.sysaid.com/docs/23334" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json b/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json new file mode 100644 index 00000000000..d36978602b1 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-q565-26vc-vpx8/GHSA-q565-26vc-vpx8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q565-26vc-vpx8", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2022-34268" + ], + "details": "An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34268" + }, + { + "type": "WEB", + "url": "https://www.rws.com/localization/products/trados-enterprise/worldserver/" + }, + { + "type": "WEB", + "url": "https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-qp42-5pj7-4ccm/GHSA-qp42-5pj7-4ccm.json b/advisories/unreviewed/2023/12/GHSA-qp42-5pj7-4ccm/GHSA-qp42-5pj7-4ccm.json new file mode 100644 index 00000000000..df9fe4e3f52 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-qp42-5pj7-4ccm/GHSA-qp42-5pj7-4ccm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp42-5pj7-4ccm", + "modified": "2023-12-25T09:30:21Z", + "published": "2023-12-25T09:30:21Z", + "aliases": [ + "CVE-2023-48652" + ], + "details": "Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48652" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/923-release-notes" + }, + { + "type": "WEB", + "url": "https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T08:15:07Z" + } +} \ No newline at end of file