From 6c29977a6463dfdbde5af194cff154177776ae3b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 Feb 2024 06:36:40 +0000 Subject: [PATCH] Publish Advisories GHSA-967w-7xjc-4wqj GHSA-hvwp-rfc8-3www GHSA-p6wv-4394-73p5 --- .../GHSA-967w-7xjc-4wqj.json | 42 +++++++++++++++++++ .../GHSA-hvwp-rfc8-3www.json | 42 +++++++++++++++++++ .../GHSA-p6wv-4394-73p5.json | 42 +++++++++++++++++++ 3 files changed, 126 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json diff --git a/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json b/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json new file mode 100644 index 00000000000..4ea63baf3be --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-967w-7xjc-4wqj/GHSA-967w-7xjc-4wqj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-967w-7xjc-4wqj", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-23446" + ], + "details": "An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23446" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json b/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json new file mode 100644 index 00000000000..4ed4b7eddf9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hvwp-rfc8-3www/GHSA-hvwp-rfc8-3www.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvwp-rfc8-3www", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-0256" + ], + "details": "The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0256" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3029599/starbox" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0eafe473-9177-47c4-aa1e-2350cb827447?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json b/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json new file mode 100644 index 00000000000..6a792c1e96c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p6wv-4394-73p5/GHSA-p6wv-4394-73p5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6wv-4394-73p5", + "modified": "2024-02-07T06:35:21Z", + "published": "2024-02-07T06:35:21Z", + "aliases": [ + "CVE-2024-23447" + ], + "details": "An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23447" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-07T04:15:07Z" + } +} \ No newline at end of file