mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-897q-36v3-jwhm GHSA-cp56-rpr6-7673 GHSA-pcv9-72q8-27vc GHSA-892h-r6cr-53g4 GHSA-9v7r-x7cv-v437 GHSA-rxv8-v965-v333 GHSA-vq7j-gx56-rxjh GHSA-2mh6-g78c-5h6c GHSA-679v-hh23-h5jh GHSA-6jvj-rjjj-4gfr GHSA-9c5w-974x-xjxh GHSA-fj34-c7pj-j8xq GHSA-hfr4-7364-jv2q GHSA-mqx8-vg45-6p4q GHSA-p3m2-9555-cgrw GHSA-qmv3-76vc-754w GHSA-v4vw-f7vp-84w3 GHSA-vx25-5r7c-m73f
This commit is contained in:
@@ -33,6 +33,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0005/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -37,6 +37,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0007/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pcv9-72q8-27vc",
|
||||
"modified": "2023-10-20T00:30:24Z",
|
||||
"modified": "2023-10-20T15:30:26Z",
|
||||
"published": "2023-08-07T15:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4147"
|
||||
@@ -49,6 +49,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0006/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -36,6 +36,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-2045"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -36,6 +36,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-2044"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -36,6 +36,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-2042"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0004/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -36,6 +36,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-2041"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0009/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2mh6-g78c-5h6c",
|
||||
"modified": "2023-10-16T21:30:27Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4819"
|
||||
],
|
||||
"details": "The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -36,6 +36,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-2095"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231020-0001/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -28,7 +28,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
"CWE-20",
|
||||
"CWE-401"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9c5w-974x-xjxh",
|
||||
"modified": "2023-10-16T21:30:27Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4821"
|
||||
],
|
||||
"details": "The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fj34-c7pj-j8xq",
|
||||
"modified": "2023-10-16T21:30:27Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4805"
|
||||
],
|
||||
"details": "The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hfr4-7364-jv2q",
|
||||
"modified": "2023-10-16T21:30:27Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4820"
|
||||
],
|
||||
"details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mqx8-vg45-6p4q",
|
||||
"modified": "2023-10-16T21:30:26Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4687"
|
||||
],
|
||||
"details": "The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p3m2-9555-cgrw",
|
||||
"modified": "2023-10-16T21:30:26Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4691"
|
||||
],
|
||||
"details": "The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qmv3-76vc-754w",
|
||||
"modified": "2023-10-16T21:30:27Z",
|
||||
"modified": "2023-10-20T15:30:28Z",
|
||||
"published": "2023-10-16T21:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4861"
|
||||
],
|
||||
"details": "The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v4vw-f7vp-84w3",
|
||||
"modified": "2023-10-20T15:30:29Z",
|
||||
"published": "2023-10-20T15:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46287"
|
||||
],
|
||||
"details": "XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46287"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/NagVis/nagvis/pull/356"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/NagVis/nagvis/pull/356/commits/d660591b23e5cfea4d1be2d3fb8f3855aa6020fb"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/NagVis/nagvis/compare/nagvis-1.9.37...nagvis-1.9.38"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vx25-5r7c-m73f",
|
||||
"modified": "2023-10-20T15:30:29Z",
|
||||
"published": "2023-10-20T15:30:29Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3487"
|
||||
],
|
||||
"details": "\nAn integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3487"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://community.silabs.com/s/contentdocument/0698Y00000ZmXqLQAV"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SiliconLabs/gecko_sdk/releases"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user