Publish Advisories

GHSA-897q-36v3-jwhm
GHSA-cp56-rpr6-7673
GHSA-pcv9-72q8-27vc
GHSA-892h-r6cr-53g4
GHSA-9v7r-x7cv-v437
GHSA-rxv8-v965-v333
GHSA-vq7j-gx56-rxjh
GHSA-2mh6-g78c-5h6c
GHSA-679v-hh23-h5jh
GHSA-6jvj-rjjj-4gfr
GHSA-9c5w-974x-xjxh
GHSA-fj34-c7pj-j8xq
GHSA-hfr4-7364-jv2q
GHSA-mqx8-vg45-6p4q
GHSA-p3m2-9555-cgrw
GHSA-qmv3-76vc-754w
GHSA-v4vw-f7vp-84w3
GHSA-vx25-5r7c-m73f
This commit is contained in:
advisory-database[bot]
2023-10-20 15:31:37 +00:00
parent 6db1667d2c
commit 75165d47d9
18 changed files with 155 additions and 16 deletions
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0005/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0007/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcv9-72q8-27vc",
"modified": "2023-10-20T00:30:24Z",
"modified": "2023-10-20T15:30:26Z",
"published": "2023-08-07T15:30:27Z",
"aliases": [
"CVE-2023-4147"
@@ -49,6 +49,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0006/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2045"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
}
],
"database_specific": {
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2044"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
}
],
"database_specific": {
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2042"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
}
],
"database_specific": {
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2041"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0009/"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mh6-g78c-5h6c",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4819"
],
"details": "The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-2095"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231020-0001/"
}
],
"database_specific": {
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-401"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c5w-974x-xjxh",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4821"
],
"details": "The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj34-c7pj-j8xq",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4805"
],
"details": "The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfr4-7364-jv2q",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4820"
],
"details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqx8-vg45-6p4q",
"modified": "2023-10-16T21:30:26Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4687"
],
"details": "The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3m2-9555-cgrw",
"modified": "2023-10-16T21:30:26Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4691"
],
"details": "The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmv3-76vc-754w",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T15:30:28Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4861"
],
"details": "The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4vw-f7vp-84w3",
"modified": "2023-10-20T15:30:29Z",
"published": "2023-10-20T15:30:29Z",
"aliases": [
"CVE-2023-46287"
],
"details": "XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46287"
},
{
"type": "WEB",
"url": "https://github.com/NagVis/nagvis/pull/356"
},
{
"type": "WEB",
"url": "https://github.com/NagVis/nagvis/pull/356/commits/d660591b23e5cfea4d1be2d3fb8f3855aa6020fb"
},
{
"type": "WEB",
"url": "https://github.com/NagVis/nagvis/compare/nagvis-1.9.37...nagvis-1.9.38"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx25-5r7c-m73f",
"modified": "2023-10-20T15:30:29Z",
"published": "2023-10-20T15:30:29Z",
"aliases": [
"CVE-2023-3487"
],
"details": "\nAn integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3487"
},
{
"type": "WEB",
"url": "https://community.silabs.com/s/contentdocument/0698Y00000ZmXqLQAV"
},
{
"type": "WEB",
"url": "https://github.com/SiliconLabs/gecko_sdk/releases"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}