From 79750972676e20e625145390b385eb12cfe0a84e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 18 Feb 2024 09:32:06 +0000 Subject: [PATCH] Publish Advisories GHSA-3qwx-q6x9-637h GHSA-42jj-9j7q-98jv GHSA-g5q9-8p2x-frc4 GHSA-rmgv-92vx-xfh9 GHSA-x3rc-h9v8-w5jq --- .../GHSA-3qwx-q6x9-637h.json | 39 +++++++++++++++++++ .../GHSA-42jj-9j7q-98jv.json | 39 +++++++++++++++++++ .../GHSA-g5q9-8p2x-frc4.json | 39 +++++++++++++++++++ .../GHSA-rmgv-92vx-xfh9.json | 39 +++++++++++++++++++ .../GHSA-x3rc-h9v8-w5jq.json | 39 +++++++++++++++++++ 5 files changed, 195 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rmgv-92vx-xfh9/GHSA-rmgv-92vx-xfh9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x3rc-h9v8-w5jq/GHSA-x3rc-h9v8-w5jq.json diff --git a/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json b/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json new file mode 100644 index 00000000000..e9704d4f819 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qwx-q6x9-637h", + "modified": "2024-02-18T09:30:47Z", + "published": "2024-02-18T09:30:47Z", + "aliases": [ + "CVE-2023-52378" + ], + "details": "Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52378" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json b/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json new file mode 100644 index 00000000000..2271db2567d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-42jj-9j7q-98jv/GHSA-42jj-9j7q-98jv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42jj-9j7q-98jv", + "modified": "2024-02-18T09:30:47Z", + "published": "2024-02-18T09:30:47Z", + "aliases": [ + "CVE-2023-52381" + ], + "details": "Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52381" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json b/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json new file mode 100644 index 00000000000..1f237ebbe8a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5q9-8p2x-frc4", + "modified": "2024-02-18T09:30:47Z", + "published": "2024-02-18T09:30:47Z", + "aliases": [ + "CVE-2023-52380" + ], + "details": "Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52380" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rmgv-92vx-xfh9/GHSA-rmgv-92vx-xfh9.json b/advisories/unreviewed/2024/02/GHSA-rmgv-92vx-xfh9/GHSA-rmgv-92vx-xfh9.json new file mode 100644 index 00000000000..5380ae622d9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rmgv-92vx-xfh9/GHSA-rmgv-92vx-xfh9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmgv-92vx-xfh9", + "modified": "2024-02-18T09:30:47Z", + "published": "2024-02-18T09:30:47Z", + "aliases": [ + "CVE-2022-48621" + ], + "details": "Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48621" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x3rc-h9v8-w5jq/GHSA-x3rc-h9v8-w5jq.json b/advisories/unreviewed/2024/02/GHSA-x3rc-h9v8-w5jq/GHSA-x3rc-h9v8-w5jq.json new file mode 100644 index 00000000000..6562de4f9ff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x3rc-h9v8-w5jq/GHSA-x3rc-h9v8-w5jq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3rc-h9v8-w5jq", + "modified": "2024-02-18T09:30:47Z", + "published": "2024-02-18T09:30:47Z", + "aliases": [ + "CVE-2023-52379" + ], + "details": "Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52379" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T07:15:09Z" + } +} \ No newline at end of file