Publish Advisories

GHSA-967w-7xjc-4wqj
GHSA-hvwp-rfc8-3www
GHSA-p6wv-4394-73p5
This commit is contained in:
advisory-database[bot]
2024-02-07 06:36:40 +00:00
parent 48aadfda88
commit 6c29977a64
3 changed files with 126 additions and 0 deletions
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-967w-7xjc-4wqj",
"modified": "2024-02-07T06:35:21Z",
"published": "2024-02-07T06:35:21Z",
"aliases": [
"CVE-2024-23446"
],
"details": "An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23446"
},
{
"type": "WEB",
"url": "https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686"
},
{
"type": "WEB",
"url": "https://www.elastic.co/community/security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T04:15:07Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvwp-rfc8-3www",
"modified": "2024-02-07T06:35:21Z",
"published": "2024-02-07T06:35:21Z",
"aliases": [
"CVE-2024-0256"
],
"details": "The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0256"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3029599/starbox"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0eafe473-9177-47c4-aa1e-2350cb827447?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T05:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6wv-4394-73p5",
"modified": "2024-02-07T06:35:21Z",
"published": "2024-02-07T06:35:21Z",
"aliases": [
"CVE-2024-23447"
],
"details": "An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23447"
},
{
"type": "WEB",
"url": "https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687"
},
{
"type": "WEB",
"url": "https://www.elastic.co/community/security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-07T04:15:07Z"
}
}