From 75165d47d9d53cc949a27a4608b4ebc95e98da7d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Oct 2023 15:31:37 +0000 Subject: [PATCH] Publish Advisories GHSA-897q-36v3-jwhm GHSA-cp56-rpr6-7673 GHSA-pcv9-72q8-27vc GHSA-892h-r6cr-53g4 GHSA-9v7r-x7cv-v437 GHSA-rxv8-v965-v333 GHSA-vq7j-gx56-rxjh GHSA-2mh6-g78c-5h6c GHSA-679v-hh23-h5jh GHSA-6jvj-rjjj-4gfr GHSA-9c5w-974x-xjxh GHSA-fj34-c7pj-j8xq GHSA-hfr4-7364-jv2q GHSA-mqx8-vg45-6p4q GHSA-p3m2-9555-cgrw GHSA-qmv3-76vc-754w GHSA-v4vw-f7vp-84w3 GHSA-vx25-5r7c-m73f --- .../GHSA-897q-36v3-jwhm.json | 4 ++ .../GHSA-cp56-rpr6-7673.json | 4 ++ .../GHSA-pcv9-72q8-27vc.json | 6 ++- .../GHSA-892h-r6cr-53g4.json | 4 ++ .../GHSA-9v7r-x7cv-v437.json | 4 ++ .../GHSA-rxv8-v965-v333.json | 4 ++ .../GHSA-vq7j-gx56-rxjh.json | 4 ++ .../GHSA-2mh6-g78c-5h6c.json | 7 ++- .../GHSA-679v-hh23-h5jh.json | 4 ++ .../GHSA-6jvj-rjjj-4gfr.json | 3 +- .../GHSA-9c5w-974x-xjxh.json | 7 ++- .../GHSA-fj34-c7pj-j8xq.json | 7 ++- .../GHSA-hfr4-7364-jv2q.json | 7 ++- .../GHSA-mqx8-vg45-6p4q.json | 7 ++- .../GHSA-p3m2-9555-cgrw.json | 7 ++- .../GHSA-qmv3-76vc-754w.json | 7 ++- .../GHSA-v4vw-f7vp-84w3.json | 43 +++++++++++++++++++ .../GHSA-vx25-5r7c-m73f.json | 42 ++++++++++++++++++ 18 files changed, 155 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json create mode 100644 advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json diff --git a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json index 0473492b138..c9a235cf017 100644 --- a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json +++ b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0005/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json b/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json index ca3ecfc089c..9b60c334cbd 100644 --- a/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json +++ b/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0007/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json b/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json index 26293e06f4d..d59e488fe25 100644 --- a/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json +++ b/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcv9-72q8-27vc", - "modified": "2023-10-20T00:30:24Z", + "modified": "2023-10-20T15:30:26Z", "published": "2023-08-07T15:30:27Z", "aliases": [ "CVE-2023-4147" @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0006/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json b/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json index fed953b9f65..1b7d72b480a 100644 --- a/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json +++ b/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2045" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0004/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json b/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json index 049ec5e2dd1..33a8322e4b0 100644 --- a/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json +++ b/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2044" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0004/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json b/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json index ff20d3a072c..1203f0892d8 100644 --- a/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json +++ b/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2042" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0004/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json b/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json index 3124f352ed3..c26f00d7800 100644 --- a/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json +++ b/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2041" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0009/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json b/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json index ed15a9c3874..7f1b1c3e6c4 100644 --- a/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json +++ b/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mh6-g78c-5h6c", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-4819" ], "details": "The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-679v-hh23-h5jh/GHSA-679v-hh23-h5jh.json b/advisories/unreviewed/2023/10/GHSA-679v-hh23-h5jh/GHSA-679v-hh23-h5jh.json index 140be468d82..9a9ffbc531a 100644 --- a/advisories/unreviewed/2023/10/GHSA-679v-hh23-h5jh/GHSA-679v-hh23-h5jh.json +++ b/advisories/unreviewed/2023/10/GHSA-679v-hh23-h5jh/GHSA-679v-hh23-h5jh.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-2095" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231020-0001/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json b/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json index 6e47255ef85..123deadb4f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json +++ b/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-401" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json b/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json index 36ede18e71c..aeccf5a3cf2 100644 --- a/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json +++ b/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c5w-974x-xjxh", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-4821" ], "details": "The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json b/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json index 5017f6e5d00..c98da7611f8 100644 --- a/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json +++ b/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj34-c7pj-j8xq", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-4805" ], "details": "The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json b/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json index 27e871aa51e..60f2558222c 100644 --- a/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json +++ b/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfr4-7364-jv2q", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-4820" ], "details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json b/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json index b2a6c441d8f..f84cf9118e0 100644 --- a/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json +++ b/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqx8-vg45-6p4q", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4687" ], "details": "The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json b/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json index f48b8bd6eae..816c2a82000 100644 --- a/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json +++ b/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3m2-9555-cgrw", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4691" ], "details": "The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json b/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json index b1c0e139d01..0330d64e2f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json +++ b/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmv3-76vc-754w", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T15:30:28Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-4861" ], "details": "The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json b/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json new file mode 100644 index 00000000000..ec37067738f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4vw-f7vp-84w3", + "modified": "2023-10-20T15:30:29Z", + "published": "2023-10-20T15:30:29Z", + "aliases": [ + "CVE-2023-46287" + ], + "details": "XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46287" + }, + { + "type": "WEB", + "url": "https://github.com/NagVis/nagvis/pull/356" + }, + { + "type": "WEB", + "url": "https://github.com/NagVis/nagvis/pull/356/commits/d660591b23e5cfea4d1be2d3fb8f3855aa6020fb" + }, + { + "type": "WEB", + "url": "https://github.com/NagVis/nagvis/compare/nagvis-1.9.37...nagvis-1.9.38" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json new file mode 100644 index 00000000000..b7be93a6a25 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx25-5r7c-m73f", + "modified": "2023-10-20T15:30:29Z", + "published": "2023-10-20T15:30:29Z", + "aliases": [ + "CVE-2023-3487" + ], + "details": "\nAn integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3487" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/s/contentdocument/0698Y00000ZmXqLQAV" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/gecko_sdk/releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file