From 67b773d299d541f0393d14e27ccb9b04f8bfeba5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Apr 2023 18:31:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6rww-x4m5-6j62.json | 9 ++-- .../GHSA-9j2c-vm53-wcvm.json | 11 +++-- .../GHSA-cgj3-cvg6-pcvh.json | 11 +++-- .../GHSA-f3hr-rv72-879p.json | 9 ++-- .../GHSA-f952-wvmx-6w24.json | 10 ++-- .../GHSA-m2q7-9c76-qc45.json | 9 ++-- .../GHSA-mhcf-92f4-9369.json | 11 +++-- .../GHSA-mrcj-939x-ph52.json | 9 ++-- .../GHSA-p9xg-3j9r-v8jf.json | 9 ++-- .../GHSA-v5g3-mw88-c3jm.json | 11 +++-- .../GHSA-v82w-4932-72hf.json | 11 +++-- .../GHSA-24q2-4vqq-qcx6.json | 11 +++-- .../GHSA-27pg-4cj6-8994.json | 43 +++++++++++++++++ .../GHSA-2jm2-q946-gq54.json | 9 ++-- .../GHSA-2qwv-xp73-79cx.json | 11 +++-- .../GHSA-4rmp-wcvv-c8xm.json | 11 +++-- .../GHSA-4x5j-gwp5-7hgh.json | 11 +++-- .../GHSA-587p-pvvj-3ghc.json | 47 +++++++++++++++++++ .../GHSA-5j59-hpwc-vm92.json | 47 +++++++++++++++++++ .../GHSA-64jx-9wjf-vr92.json | 39 +++++++++++++++ .../GHSA-7rjh-2m62-75vm.json | 11 +++-- .../GHSA-8785-3w2w-jpfr.json | 11 +++-- .../GHSA-88w6-3m63-r5j7.json | 11 +++-- .../GHSA-8r7j-pj39-v7xh.json | 11 +++-- .../GHSA-92pm-jgjf-wx6q.json | 9 ++-- .../GHSA-c9fv-v7xm-mfrf.json | 11 +++-- .../GHSA-cgw5-jvm7-6f73.json | 43 +++++++++++++++++ .../GHSA-ch7j-864f-m7r5.json | 11 +++-- .../GHSA-fcmf-jqfc-733w.json | 11 +++-- .../GHSA-g23c-4prh-q9fg.json | 11 +++-- .../GHSA-h266-6cqj-cxmw.json | 43 +++++++++++++++++ .../GHSA-h639-737x-65xp.json | 11 +++-- .../GHSA-m6x9-6mp2-f49x.json | 11 +++-- .../GHSA-ppr5-6jwg-4jm4.json | 11 +++-- .../GHSA-qr7h-8pv2-xvx2.json | 43 +++++++++++++++++ .../GHSA-r7cq-76xj-2g24.json | 9 ++-- .../GHSA-rff5-9cw2-46c6.json | 11 +++-- .../GHSA-wfwf-xhx7-3whj.json | 35 ++++++++++++++ .../GHSA-wrxf-x8rm-6ggg.json | 9 ++-- .../GHSA-wv94-3wc8-85h3.json | 11 +++-- .../GHSA-x57h-h95f-93cr.json | 11 +++-- 41 files changed, 562 insertions(+), 122 deletions(-) create mode 100644 advisories/unreviewed/2023/04/GHSA-27pg-4cj6-8994/GHSA-27pg-4cj6-8994.json create mode 100644 advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json create mode 100644 advisories/unreviewed/2023/04/GHSA-5j59-hpwc-vm92/GHSA-5j59-hpwc-vm92.json create mode 100644 advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json create mode 100644 advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json create mode 100644 advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json create mode 100644 advisories/unreviewed/2023/04/GHSA-qr7h-8pv2-xvx2/GHSA-qr7h-8pv2-xvx2.json create mode 100644 advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json diff --git a/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json b/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json index 36b01d29854..4bf40d7976c 100644 --- a/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json +++ b/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rww-x4m5-6j62", - "modified": "2023-03-29T21:30:21Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-29T21:30:21Z", "aliases": [ "CVE-2022-2825" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX V6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-9j2c-vm53-wcvm/GHSA-9j2c-vm53-wcvm.json b/advisories/unreviewed/2023/03/GHSA-9j2c-vm53-wcvm/GHSA-9j2c-vm53-wcvm.json index bc8781b94a7..804db326b27 100644 --- a/advisories/unreviewed/2023/03/GHSA-9j2c-vm53-wcvm/GHSA-9j2c-vm53-wcvm.json +++ b/advisories/unreviewed/2023/03/GHSA-9j2c-vm53-wcvm/GHSA-9j2c-vm53-wcvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9j2c-vm53-wcvm", - "modified": "2023-03-30T21:30:21Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-30T21:30:21Z", "aliases": [ "CVE-2023-27537" ], "details": "A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate \"handles\". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-cgj3-cvg6-pcvh/GHSA-cgj3-cvg6-pcvh.json b/advisories/unreviewed/2023/03/GHSA-cgj3-cvg6-pcvh/GHSA-cgj3-cvg6-pcvh.json index 331fe63d2ef..615be7544a6 100644 --- a/advisories/unreviewed/2023/03/GHSA-cgj3-cvg6-pcvh/GHSA-cgj3-cvg6-pcvh.json +++ b/advisories/unreviewed/2023/03/GHSA-cgj3-cvg6-pcvh/GHSA-cgj3-cvg6-pcvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgj3-cvg6-pcvh", - "modified": "2023-03-30T21:30:21Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-30T21:30:21Z", "aliases": [ "CVE-2023-27538" ], "details": "An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json index 33aa319e536..4a7146bbcbc 100644 --- a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json +++ b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3hr-rv72-879p", - "modified": "2023-03-31T21:30:40Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-31T21:30:40Z", "aliases": [ "CVE-2023-29137" ], "details": "An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-31T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json b/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json index 415f175214d..0a4d7fa8252 100644 --- a/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json +++ b/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f952-wvmx-6w24", - "modified": "2023-03-29T21:30:21Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-29T21:30:21Z", "aliases": [ "CVE-2022-2848" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX V6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json index d006812ecde..f3e2563da35 100644 --- a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json +++ b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2q7-9c76-qc45", - "modified": "2023-03-30T18:30:30Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-30T18:30:30Z", "aliases": [ "CVE-2023-29059" ], "details": "3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the Electron macOS application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T17:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-mhcf-92f4-9369/GHSA-mhcf-92f4-9369.json b/advisories/unreviewed/2023/03/GHSA-mhcf-92f4-9369/GHSA-mhcf-92f4-9369.json index f2fc24f3fd8..73f929ba27b 100644 --- a/advisories/unreviewed/2023/03/GHSA-mhcf-92f4-9369/GHSA-mhcf-92f4-9369.json +++ b/advisories/unreviewed/2023/03/GHSA-mhcf-92f4-9369/GHSA-mhcf-92f4-9369.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhcf-92f4-9369", - "modified": "2023-03-31T18:30:21Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-31T18:30:21Z", "aliases": [ "CVE-2022-3192" ], "details": "Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-31T17:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json index 3f611832602..1d038d8b734 100644 --- a/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json +++ b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrcj-939x-ph52", - "modified": "2023-03-29T21:30:18Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-29T21:30:18Z", "aliases": [ "CVE-2022-43638" ], "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18627.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-29T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json b/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json index 6e18b40f651..610eb3b3bd2 100644 --- a/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json +++ b/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9xg-3j9r-v8jf", - "modified": "2023-03-30T18:30:32Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-30T18:30:32Z", "aliases": [ "CVE-2022-30350" ], "details": "Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a \"white out\" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T16:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json b/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json index 99f677a7161..0855cdbf722 100644 --- a/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json +++ b/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5g3-mw88-c3jm", - "modified": "2023-03-31T21:30:40Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-31T21:30:40Z", "aliases": [ "CVE-2023-27160" ], "details": "forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-31T19:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json b/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json index 19db17033c5..42871a69e68 100644 --- a/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json +++ b/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v82w-4932-72hf", - "modified": "2023-03-30T18:30:32Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-03-30T18:30:32Z", "aliases": [ "CVE-2022-30351" ], "details": "PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded in the PDF file, to be leaked unintentionally. In cases where PDF text objects are present it is possible to copy-paste redacted information into the system clipboard. Once a document is \"locked\" and marked for redaction once, all redactions performed after this feature is triggered are vulnerable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-30T16:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-24q2-4vqq-qcx6/GHSA-24q2-4vqq-qcx6.json b/advisories/unreviewed/2023/04/GHSA-24q2-4vqq-qcx6/GHSA-24q2-4vqq-qcx6.json index e310db2ae2d..4bd3a7f43ee 100644 --- a/advisories/unreviewed/2023/04/GHSA-24q2-4vqq-qcx6/GHSA-24q2-4vqq-qcx6.json +++ b/advisories/unreviewed/2023/04/GHSA-24q2-4vqq-qcx6/GHSA-24q2-4vqq-qcx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24q2-4vqq-qcx6", - "modified": "2023-04-05T09:30:18Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-05T09:30:18Z", "aliases": [ "CVE-2023-0382" ], "details": "User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-05T07:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-27pg-4cj6-8994/GHSA-27pg-4cj6-8994.json b/advisories/unreviewed/2023/04/GHSA-27pg-4cj6-8994/GHSA-27pg-4cj6-8994.json new file mode 100644 index 00000000000..38ce9feb4d6 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-27pg-4cj6-8994/GHSA-27pg-4cj6-8994.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27pg-4cj6-8994", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:22Z", + "aliases": [ + "CVE-2023-1970" + ], + "details": "** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects the function Upload of the file application\\admin\\controller\\Upload.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225407. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1970" + }, + { + "type": "WEB", + "url": "https://tib36.github.io/2023/04/09/tpAdmin-RCE/" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225407" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225407" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json b/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json index c4a40261800..3b1677b3b7a 100644 --- a/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json +++ b/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jm2-q946-gq54", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-27734" ], "details": "An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-2qwv-xp73-79cx/GHSA-2qwv-xp73-79cx.json b/advisories/unreviewed/2023/04/GHSA-2qwv-xp73-79cx/GHSA-2qwv-xp73-79cx.json index 24d3aa85b83..fb2bb6067d4 100644 --- a/advisories/unreviewed/2023/04/GHSA-2qwv-xp73-79cx/GHSA-2qwv-xp73-79cx.json +++ b/advisories/unreviewed/2023/04/GHSA-2qwv-xp73-79cx/GHSA-2qwv-xp73-79cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qwv-xp73-79cx", - "modified": "2023-04-01T06:31:24Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-04-01T06:31:24Z", "aliases": [ "CVE-2023-0181" ], "details": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-01T05:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json index c88c7d66007..51f2371d344 100644 --- a/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json +++ b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rmp-wcvv-c8xm", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43772" ], "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json index 13cdc149814..4c8fc28af90 100644 --- a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json +++ b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x5j-gwp5-7hgh", - "modified": "2023-04-05T00:30:39Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0486" ], "details": "VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T23:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json b/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json new file mode 100644 index 00000000000..71e8c8e64b0 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-587p-pvvj-3ghc", + "modified": "2023-04-10T18:30:21Z", + "published": "2023-04-10T18:30:21Z", + "aliases": [ + "CVE-2015-10100" + ], + "details": "A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.11 is able to address this issue. The name of the patch is d0a19c6efcdc86d7093b369bc9e29a0629e57795. It is recommended to upgrade the affected component. The identifier VDB-225353 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10100" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/dynamic-widgets/commit/d0a19c6efcdc86d7093b369bc9e29a0629e57795" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/dynamic-widgets/releases/tag/1.5.11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225353" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-5j59-hpwc-vm92/GHSA-5j59-hpwc-vm92.json b/advisories/unreviewed/2023/04/GHSA-5j59-hpwc-vm92/GHSA-5j59-hpwc-vm92.json new file mode 100644 index 00000000000..fdf334c1500 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-5j59-hpwc-vm92/GHSA-5j59-hpwc-vm92.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j59-hpwc-vm92", + "modified": "2023-04-10T18:30:21Z", + "published": "2023-04-10T18:30:21Z", + "aliases": [ + "CVE-2018-25084" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.1.3 is able to address this issue. The name of the patch is f64b10d63bb19ca2228b0c2d561a1a6e5a3bf251. It is recommended to upgrade the affected component. VDB-225362 is the identifier assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25084" + }, + { + "type": "WEB", + "url": "https://github.com/pingidentity/ssam/commit/f64b10d63bb19ca2228b0c2d561a1a6e5a3bf251" + }, + { + "type": "WEB", + "url": "https://github.com/pingidentity/ssam/releases/tag/ssam-1.1.3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225362" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json b/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json new file mode 100644 index 00000000000..9bab841202d --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64jx-9wjf-vr92", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:22Z", + "aliases": [ + "CVE-2023-26986" + ], + "details": "An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26986" + }, + { + "type": "WEB", + "url": "https://gist.github.com/YZLCQX/0da0a438292a5479470c52dad8210462" + }, + { + "type": "WEB", + "url": "https://github.com/YZLCQX/Mailbox-remote-command-execution" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json b/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json index 747e916c4a8..92f816689c1 100644 --- a/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json +++ b/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rjh-2m62-75vm", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-27759" ], "details": "An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-426" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8785-3w2w-jpfr/GHSA-8785-3w2w-jpfr.json b/advisories/unreviewed/2023/04/GHSA-8785-3w2w-jpfr/GHSA-8785-3w2w-jpfr.json index e5cf5ee3032..089a2ebbf13 100644 --- a/advisories/unreviewed/2023/04/GHSA-8785-3w2w-jpfr/GHSA-8785-3w2w-jpfr.json +++ b/advisories/unreviewed/2023/04/GHSA-8785-3w2w-jpfr/GHSA-8785-3w2w-jpfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8785-3w2w-jpfr", - "modified": "2023-04-01T06:31:24Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-04-01T06:31:24Z", "aliases": [ "CVE-2023-0185" ], "details": "NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-681" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-01T05:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json index 65dd255d473..4767575b7f8 100644 --- a/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json +++ b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88w6-3m63-r5j7", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43938" ], "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json index 31ab0f4497c..4b37bf1d53b 100644 --- a/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json +++ b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8r7j-pj39-v7xh", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-4769" ], "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-209" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-92pm-jgjf-wx6q/GHSA-92pm-jgjf-wx6q.json b/advisories/unreviewed/2023/04/GHSA-92pm-jgjf-wx6q/GHSA-92pm-jgjf-wx6q.json index 6b9d88a09b4..1af8bf30443 100644 --- a/advisories/unreviewed/2023/04/GHSA-92pm-jgjf-wx6q/GHSA-92pm-jgjf-wx6q.json +++ b/advisories/unreviewed/2023/04/GHSA-92pm-jgjf-wx6q/GHSA-92pm-jgjf-wx6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92pm-jgjf-wx6q", - "modified": "2023-04-01T06:31:24Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-04-01T06:31:24Z", "aliases": [ "CVE-2023-0180" ], "details": "NVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-01T05:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json b/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json index e2fa82c6594..b385f40f43c 100644 --- a/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json +++ b/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c9fv-v7xm-mfrf", - "modified": "2023-04-01T06:31:24Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-04-01T06:31:24Z", "aliases": [ "CVE-2023-0182" ], "details": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service, information disclosure, and data tampering.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-01T05:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json b/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json new file mode 100644 index 00000000000..21f87fb7d6c --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgw5-jvm7-6f73", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:22Z", + "aliases": [ + "CVE-2023-1969" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225406 is the identifier assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1969" + }, + { + "type": "WEB", + "url": "https://github.com/Gear-D/bug_report/blob/main/SQLi-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225406" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225406" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json index a998941b06e..d9123a17874 100644 --- a/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json +++ b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch7j-864f-m7r5", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43941" ], "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json b/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json index 77ed2673f78..68b97353fa3 100644 --- a/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json +++ b/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fcmf-jqfc-733w", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-26921" ], "details": "OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json index 75f1d055bf4..8f56a823b3b 100644 --- a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json +++ b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g23c-4prh-q9fg", - "modified": "2023-04-05T00:30:39Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0357" ], "details": "Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T23:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json new file mode 100644 index 00000000000..70c506323d7 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h266-6cqj-cxmw", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:21Z", + "aliases": [ + "CVE-2023-27650" + ], + "details": "An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27650" + }, + { + "type": "WEB", + "url": "https://github.com/LianKee/SODA/blob/main/CVEs/CVE-2023-27650/CVE%20detail.md" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.apusapps.launcher" + }, + { + "type": "WEB", + "url": "https://www.apusapps.com/en/launcher" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json index e731c4e28c5..806442351b1 100644 --- a/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json +++ b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h639-737x-65xp", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-4770" ], "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-209" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json index 159845695fe..4701670c788 100644 --- a/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json +++ b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6x9-6mp2-f49x", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:22Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-4771" ], "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json b/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json index eaef1fb029e..8942ecb0268 100644 --- a/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json +++ b/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppr5-6jwg-4jm4", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-27760" ], "details": "An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-426" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-qr7h-8pv2-xvx2/GHSA-qr7h-8pv2-xvx2.json b/advisories/unreviewed/2023/04/GHSA-qr7h-8pv2-xvx2/GHSA-qr7h-8pv2-xvx2.json new file mode 100644 index 00000000000..d179674d460 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qr7h-8pv2-xvx2/GHSA-qr7h-8pv2-xvx2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr7h-8pv2-xvx2", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:22Z", + "aliases": [ + "CVE-2023-1971" + ], + "details": "** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994 tpAdmin 1.3.12. Affected is the function remote of the file application\\admin\\controller\\Upload.php. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225408. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1971" + }, + { + "type": "WEB", + "url": "https://tib36.github.io/2023/04/09/tpAdmin-SSRF/" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225408" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json b/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json index 9a338f2d04b..b0ec051c67a 100644 --- a/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json +++ b/advisories/unreviewed/2023/04/GHSA-r7cq-76xj-2g24/GHSA-r7cq-76xj-2g24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7cq-76xj-2g24", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43939" ], "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json b/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json index 0d22f97a638..8d7141ed921 100644 --- a/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json +++ b/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rff5-9cw2-46c6", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-21487" ], "details": "Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json b/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json new file mode 100644 index 00000000000..ec5a4b901b4 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfwf-xhx7-3whj", + "modified": "2023-04-10T18:30:22Z", + "published": "2023-04-10T18:30:22Z", + "aliases": [ + "CVE-2023-26919" + ], + "details": "delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26919" + }, + { + "type": "WEB", + "url": "https://github.com/javadelight/delight-nashorn-sandbox/issues/135" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-wrxf-x8rm-6ggg/GHSA-wrxf-x8rm-6ggg.json b/advisories/unreviewed/2023/04/GHSA-wrxf-x8rm-6ggg/GHSA-wrxf-x8rm-6ggg.json index ceb790f18b2..7272f6ded0c 100644 --- a/advisories/unreviewed/2023/04/GHSA-wrxf-x8rm-6ggg/GHSA-wrxf-x8rm-6ggg.json +++ b/advisories/unreviewed/2023/04/GHSA-wrxf-x8rm-6ggg/GHSA-wrxf-x8rm-6ggg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrxf-x8rm-6ggg", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-21514" ], "details": "An issue was discovered in Fluent Fluentd v.1.8.0 and Fluent-ui v.1.2.2 allows attackers to gain escilated privlidges and execute arbitrary code due to a default password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json b/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json index 36f08b2621d..f6f1f916f79 100644 --- a/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json +++ b/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv94-3wc8-85h3", - "modified": "2023-04-05T00:30:39Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0480" ], "details": "VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the application is vulnerable to CSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T23:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json index 7294233385b..a1b25394630 100644 --- a/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json +++ b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x57h-h95f-93cr", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T18:30:21Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43940" ], "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z"