diff --git a/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json b/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json new file mode 100644 index 00000000000..4ea63baf3be --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-967w-7xjc-4wqj", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-23446" + ], + "details": "An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23446" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json b/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json new file mode 100644 index 00000000000..4ed4b7eddf9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvwp-rfc8-3www", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-0256" + ], + "details": "The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0256" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3029599/starbox" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0eafe473-9177-47c4-aa1e-2350cb827447?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json b/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json new file mode 100644 index 00000000000..6a792c1e96c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6wv-4394-73p5", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-23447" + ], + "details": "An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23447" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T04:15:07Z" + } +} \ No newline at end of file