From 7cdf84a41df8a9b113cbad63b38d17faa0f0d79f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 28 Jul 2022 00:34:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9wxh-jjj5-67cv.json | 63 ++++++++++++++ .../GHSA-5m8f-v3gw-h94w.json | 59 +++++++++++++ .../GHSA-9772-cwx9-r4cj.json | 30 ++++++- .../GHSA-cv78-v957-jx34.json | 82 +++++++++++++++++++ .../GHSA-gwf7-vfjf-wf6x.json | 74 +++++++++++++++++ .../GHSA-qh9x-mc42-vg4g.json | 29 ++++++- .../GHSA-v64w-96p6-fx7w.json | 33 +++++++- .../GHSA-5469-c5p2-xv5g.json | 63 ++++++++++++++ .../GHSA-5834-xv5q-cgfw.json | 63 ++++++++++++++ .../GHSA-8274-h5jp-97vr.json | 60 ++++++++++++++ .../GHSA-c2pj-rr68-pw94.json | 67 +++++++++++++++ .../GHSA-cfcg-2qgr-v243.json | 63 ++++++++++++++ .../GHSA-m7gr-5w5g-36jf.json | 60 ++++++++++++++ .../GHSA-9wxh-jjj5-67cv.json | 37 --------- .../GHSA-5m8f-v3gw-h94w.json | 33 -------- .../GHSA-mcpv-3q7c-v7rr.json | 7 +- .../GHSA-g969-j9qm-fx8r.json | 4 + .../GHSA-48rh-rw8j-qvqv.json | 7 +- .../GHSA-5fjw-573q-gg89.json | 9 +- .../GHSA-5m64-chxv-wxq3.json | 7 +- .../GHSA-6cff-mj8v-fvr9.json | 3 +- .../GHSA-6jqc-mwfj-6xjc.json | 7 +- .../GHSA-7w22-h336-hrv9.json | 7 +- .../GHSA-889g-gr2g-424w.json | 7 +- .../GHSA-8xgg-pj9m-c8xj.json | 7 +- .../GHSA-98cv-g579-8fm6.json | 7 +- .../GHSA-cg8q-mvmc-qr6h.json | 7 +- .../GHSA-cpf5-2wrr-hcvc.json | 7 +- .../GHSA-cv78-v957-jx34.json | 37 --------- .../GHSA-gj89-qmxj-q494.json | 7 +- .../GHSA-gwf7-vfjf-wf6x.json | 33 -------- .../GHSA-h289-298g-xpjw.json | 9 +- .../GHSA-p57w-vp74-84r6.json | 7 +- .../GHSA-pc5m-rr8v-2phw.json | 7 +- .../GHSA-w4vm-8m9w-5qwm.json | 9 +- .../GHSA-wj9v-cg6p-qc9f.json | 9 +- .../GHSA-x7v8-768q-2m8h.json | 7 +- .../GHSA-xvv9-f9hm-rghr.json | 7 +- .../GHSA-22hp-fm45-6q7j.json | 41 ++++++++++ .../GHSA-2352-4x78-8g6v.json | 37 +++++++++ .../GHSA-243v-5pff-qqfj.json | 8 ++ .../GHSA-256m-rvq9-56mx.json | 4 + .../GHSA-268h-h8j2-2m45.json | 11 ++- .../GHSA-28gc-xw7v-735w.json | 11 ++- .../GHSA-29rh-32p4-4934.json | 11 ++- .../GHSA-2ccx-rp57-fp56.json | 37 +++++++++ .../GHSA-2j4w-p7qh-8g4g.json | 37 +++++++++ .../GHSA-2jg4-f9f6-jf7m.json | 11 ++- .../GHSA-2qh6-hhvv-m2ww.json | 37 +++++++++ .../GHSA-2v3j-gjfq-5ccx.json | 11 ++- .../GHSA-33vj-x2w7-j3gv.json | 37 +++++++++ .../GHSA-359g-8g36-v6qg.json | 33 ++++++++ .../GHSA-37rh-j9cp-x58f.json | 9 +- .../GHSA-3c2j-x8m7-hrhp.json | 9 +- .../GHSA-3crj-j3hg-7v57.json | 11 ++- .../GHSA-3fjx-v9x2-fjp6.json | 37 +++++++++ .../GHSA-3gw8-89v6-jfv4.json | 11 ++- .../GHSA-3h4v-m4g6-c2v8.json | 11 ++- .../GHSA-3jhc-73h5-x7fx.json | 11 ++- .../GHSA-3qv5-4cw7-x42h.json | 9 +- .../GHSA-3vvp-qmqj-rgmg.json | 11 ++- .../GHSA-3wmv-phhj-q327.json | 9 +- .../GHSA-3wr4-g3xj-q452.json | 11 ++- .../GHSA-429h-8m2j-j6cx.json | 11 ++- .../GHSA-449w-c77c-vmf6.json | 37 +++++++++ .../GHSA-44mg-h4h9-jj38.json | 11 ++- .../GHSA-45rr-gg9f-wfcm.json | 33 ++++++++ .../GHSA-476r-vp22-v7c4.json | 11 ++- .../GHSA-4f96-mfg4-qx5f.json | 9 +- .../GHSA-4h8q-jm55-4xg5.json | 11 ++- .../GHSA-4pgr-vxfc-4wm7.json | 11 ++- .../GHSA-4pqq-wq2g-6rcm.json | 37 +++++++++ .../GHSA-4pr4-pf4q-cm77.json | 9 +- .../GHSA-4r8m-m7vp-cj97.json | 11 ++- .../GHSA-4rx6-p6gq-rm2v.json | 11 ++- .../GHSA-4v86-x4wc-r83p.json | 4 + .../GHSA-4vqc-4jrp-pwj7.json | 9 +- .../GHSA-4wpp-r5j6-h3hv.json | 33 ++++++++ .../GHSA-545j-89fj-cfc3.json | 11 ++- .../GHSA-5469-c5p2-xv5g.json | 33 -------- .../GHSA-54c2-vr3w-mp8p.json | 37 +++++++++ .../GHSA-55c8-6r36-9g85.json | 11 ++- .../GHSA-568h-6mc5-cxwg.json | 37 +++++++++ .../GHSA-57f2-52wj-7vj6.json | 37 +++++++++ .../GHSA-57f2-pm75-ff3p.json | 11 ++- .../GHSA-59rr-qhh3-g554.json | 9 +- .../GHSA-5c97-346q-77p9.json | 11 ++- .../GHSA-5cvc-6x68-h8qf.json | 37 +++++++++ .../GHSA-5frp-v5h8-3hgc.json | 37 +++++++++ .../GHSA-5fwv-7q7m-cgxq.json | 37 +++++++++ .../GHSA-5mhw-r3wg-5qv3.json | 4 + .../GHSA-5mv2-vqq7-mq5h.json | 37 +++++++++ .../GHSA-5vgw-67rj-9pxh.json | 37 +++++++++ .../GHSA-5wmq-43vh-pf8j.json | 11 ++- .../GHSA-5x3f-7m52-9cgf.json | 37 +++++++++ .../GHSA-5xh5-qvf5-xpvp.json | 11 ++- .../GHSA-5xp2-7qfc-fwgc.json | 37 +++++++++ .../GHSA-62wh-m4jr-233r.json | 8 ++ .../GHSA-637x-cm53-gcgj.json | 4 + .../GHSA-63px-7j2g-6pfw.json | 37 +++++++++ .../GHSA-64g8-mc22-c972.json | 11 ++- .../GHSA-67gr-jwjp-pv3x.json | 9 +- .../GHSA-6954-h5c8-m29f.json | 37 +++++++++ .../GHSA-6ghr-92ff-p76m.json | 4 + .../GHSA-6x2v-hvx7-m5x7.json | 11 ++- .../GHSA-6x63-hrxg-2hjx.json | 37 +++++++++ .../GHSA-6xf5-c3cx-67pv.json | 37 +++++++++ .../GHSA-7425-c3x3-hhjq.json | 9 +- .../GHSA-75fc-fv3p-xh82.json | 37 +++++++++ .../GHSA-76pg-mr9v-5vwc.json | 37 +++++++++ .../GHSA-78fg-pvgg-6g3r.json | 37 +++++++++ .../GHSA-79x9-477g-w256.json | 37 +++++++++ .../GHSA-7f66-v639-c98w.json | 37 +++++++++ .../GHSA-7ghq-6v49-v396.json | 11 ++- .../GHSA-7j35-6pjq-q8rw.json | 11 ++- .../GHSA-7jfp-3xr4-m7m9.json | 11 ++- .../GHSA-7mhv-mcwq-rh85.json | 11 ++- .../GHSA-7ppp-q5f6-j96f.json | 11 ++- .../GHSA-8294-mv9c-7m5h.json | 37 +++++++++ .../GHSA-8528-c6m6-gppm.json | 37 +++++++++ .../GHSA-87cc-pvcr-mp5p.json | 11 ++- .../GHSA-87p7-px4m-hqv2.json | 33 ++++++++ .../GHSA-88wm-pv8r-fc9q.json | 36 ++++++++ .../GHSA-897m-9wc9-hrr8.json | 11 ++- .../GHSA-8995-37xw-9hjj.json | 9 +- .../GHSA-8fqx-rxr6-9fxc.json | 37 +++++++++ .../GHSA-8g36-x4m7-xxrc.json | 37 +++++++++ .../GHSA-8g4c-686x-3qcc.json | 9 +- .../GHSA-8gxf-mfg7-c3xr.json | 11 ++- .../GHSA-8hmj-5292-j8w9.json | 37 +++++++++ .../GHSA-8qg3-pfc8-ph4h.json | 9 +- .../GHSA-8qp3-mmfx-p4h5.json | 37 +++++++++ .../GHSA-8vjc-vph9-rg4j.json | 33 ++++++++ .../GHSA-8xwj-2wgh-gprh.json | 37 +++++++++ .../GHSA-93f5-xcv7-w96r.json | 11 ++- .../GHSA-93rr-jgp3-wcw3.json | 11 ++- .../GHSA-96p9-4wxh-2hwm.json | 11 ++- .../GHSA-975q-8v3h-8j23.json | 4 + .../GHSA-99mq-hw5m-gwjj.json | 37 +++++++++ .../GHSA-9cvx-cr48-6ghq.json | 11 ++- .../GHSA-9ggc-7v6w-qg26.json | 33 ++++++++ .../GHSA-9hx4-8365-w7gm.json | 37 +++++++++ .../GHSA-9jvf-2hr4-2rrp.json | 9 +- .../GHSA-9r87-pc5m-9w97.json | 37 +++++++++ .../GHSA-9v26-h3ph-p8v7.json | 4 + .../GHSA-9wq5-2p9c-q5w5.json | 11 ++- .../GHSA-9xhm-6w5p-335v.json | 37 +++++++++ .../GHSA-c2pj-rr68-pw94.json | 33 -------- .../GHSA-c49c-362q-5gfw.json | 11 ++- .../GHSA-c4wx-gc8f-7fj9.json | 33 ++++++++ .../GHSA-c786-7jf2-46w9.json | 4 + .../GHSA-c873-6fqc-4wg3.json | 11 ++- .../GHSA-cc4m-5453-r7jw.json | 9 +- .../GHSA-cfcg-2qgr-v243.json | 37 --------- .../GHSA-cjgm-9qhj-94wr.json | 11 ++- .../GHSA-cm5q-x57v-2v56.json | 37 +++++++++ .../GHSA-cm7j-p8hc-97vj.json | 37 +++++++++ .../GHSA-cp5r-xqjr-84gm.json | 37 +++++++++ .../GHSA-cpgc-248w-frqc.json | 37 +++++++++ .../GHSA-f956-64gx-m8ww.json | 33 ++++++++ .../GHSA-fc76-hxx9-92hh.json | 11 ++- .../GHSA-fcpx-28g7-cmwg.json | 37 +++++++++ .../GHSA-fg3r-9xrh-gr48.json | 11 ++- .../GHSA-fgqr-h6m4-c3j9.json | 11 ++- .../GHSA-fjpq-f574-jc45.json | 37 +++++++++ .../GHSA-fmmm-5p9f-xm6r.json | 11 ++- .../GHSA-fqhm-fjjv-7q8x.json | 37 +++++++++ .../GHSA-g33g-qhjr-v6fq.json | 11 ++- .../GHSA-g5mr-95rv-q4hc.json | 4 + .../GHSA-g78q-fxv7-624v.json | 37 +++++++++ .../GHSA-gjp8-5x9w-ghxm.json | 11 ++- .../GHSA-gm25-rhmw-47gf.json | 11 ++- .../GHSA-gmwx-qv5p-38rc.json | 9 +- .../GHSA-gq4p-4hxv-5rg9.json | 33 ++++++++ .../GHSA-grg9-xmwf-c24g.json | 11 ++- .../GHSA-h5rj-r648-659m.json | 33 ++++++++ .../GHSA-h89v-75wm-frq9.json | 11 ++- .../GHSA-h8vm-cr7c-cgqx.json | 11 ++- .../GHSA-hffq-2fq2-hfh5.json | 33 ++++++++ .../GHSA-hgp9-2c4w-x9mh.json | 37 +++++++++ .../GHSA-hgqp-g8j9-8x49.json | 9 +- .../GHSA-hh5c-64r3-fc9p.json | 37 +++++++++ .../GHSA-hjmg-3wv2-r885.json | 33 ++++++++ .../GHSA-hm53-hrhh-gwfq.json | 37 +++++++++ .../GHSA-hp4v-g8mj-wr2f.json | 37 +++++++++ .../GHSA-hp8r-2g6p-8j5q.json | 37 +++++++++ .../GHSA-hq75-6wcm-hc6g.json | 11 ++- .../GHSA-hqjf-3fq8-46pg.json | 11 ++- .../GHSA-hqrp-2gvr-75v6.json | 11 ++- .../GHSA-hrq4-ppwc-8jwx.json | 33 ++++++++ .../GHSA-hvpp-g2cx-76qq.json | 37 +++++++++ .../GHSA-hxf7-9rv9-88v6.json | 37 +++++++++ .../GHSA-j5qq-6rpm-qjgh.json | 37 +++++++++ .../GHSA-j896-j72w-cr32.json | 37 +++++++++ .../GHSA-j9gm-f3p3-j5g3.json | 11 ++- .../GHSA-jhg9-9m4g-q544.json | 11 ++- .../GHSA-jhvv-qgrh-gc45.json | 33 ++++++++ .../GHSA-jj8j-6jq7-gmvh.json | 37 +++++++++ .../GHSA-jj9f-2mf3-f7x2.json | 11 ++- .../GHSA-jjq6-7gx6-74fc.json | 37 +++++++++ .../GHSA-jr5r-25mv-wfhm.json | 11 ++- .../GHSA-jvjh-9r4q-8q5q.json | 37 +++++++++ .../GHSA-jvvx-hmmr-rhgg.json | 37 +++++++++ .../GHSA-jxg9-2ch7-f552.json | 33 ++++++++ .../GHSA-m2qh-3fm2-xvmg.json | 11 ++- .../GHSA-m2vc-45rr-qvfm.json | 11 ++- .../GHSA-m485-79jq-cxx7.json | 37 +++++++++ .../GHSA-m6jf-p94r-8589.json | 33 ++++++++ .../GHSA-m769-jr2m-2pmv.json | 33 ++++++++ .../GHSA-m7gr-5w5g-36jf.json | 33 -------- .../GHSA-m8w5-vwq3-gp8f.json | 37 +++++++++ .../GHSA-m9mx-49mx-whcc.json | 9 +- .../GHSA-mfx6-rr3j-xrqq.json | 11 ++- .../GHSA-mj46-hjj8-xr5c.json | 37 +++++++++ .../GHSA-mpv4-p366-wr6p.json | 33 ++++++++ .../GHSA-mq7q-47xg-285x.json | 11 ++- .../GHSA-mqpc-v236-v2qj.json | 37 +++++++++ .../GHSA-mr38-g7q2-x79p.json | 37 +++++++++ .../GHSA-mvf8-h6gv-86gj.json | 11 ++- .../GHSA-mw5h-pmch-3mmm.json | 11 ++- .../GHSA-mw6m-9c66-qq3h.json | 11 ++- .../GHSA-mx84-3frj-x7gc.json | 9 +- .../GHSA-mxcc-7h5m-x57r.json | 37 +++++++++ .../GHSA-p289-v2gf-9g82.json | 33 ++++++++ .../GHSA-p3qc-mh98-4vq5.json | 11 ++- .../GHSA-p45j-v622-3wj9.json | 11 ++- .../GHSA-p583-488v-vpxc.json | 11 ++- .../GHSA-p5r5-rww2-cg87.json | 11 ++- .../GHSA-p878-qvqr-h9fp.json | 37 +++++++++ .../GHSA-p954-47vj-3wxw.json | 37 +++++++++ .../GHSA-pfgj-6mxg-pmfv.json | 37 +++++++++ .../GHSA-pfqj-j743-cxwm.json | 11 ++- .../GHSA-pgm5-cr62-prxq.json | 8 ++ .../GHSA-pqrc-qr29-pr59.json | 11 ++- .../GHSA-prvj-qfjv-3x3f.json | 11 ++- .../GHSA-pw49-cjr4-3pqr.json | 11 ++- .../GHSA-pw4g-jcp5-63m9.json | 37 +++++++++ .../GHSA-q2p6-q4x9-rcrf.json | 9 +- .../GHSA-q72p-4w56-hx7h.json | 11 ++- .../GHSA-qcm2-hcg7-gmv8.json | 11 ++- .../GHSA-qf4p-7gqc-x6jx.json | 37 +++++++++ .../GHSA-qj9f-6hqx-22hw.json | 4 + .../GHSA-qx37-fp3m-qw6q.json | 11 ++- .../GHSA-qxhq-w389-3vq5.json | 4 + .../GHSA-r9xr-xfwx-6crw.json | 11 ++- .../GHSA-rcwq-vxfc-36p5.json | 37 +++++++++ .../GHSA-rjjm-wq7g-6hf4.json | 9 +- .../GHSA-rjx3-h5w4-7663.json | 11 ++- .../GHSA-rqqx-fvqx-539g.json | 37 +++++++++ .../GHSA-rw6g-9gmq-76ff.json | 9 +- .../GHSA-rx38-xpj5-528c.json | 9 +- .../GHSA-v3gw-vwrq-mq7v.json | 11 ++- .../GHSA-v3hv-r2rh-g9gw.json | 9 +- .../GHSA-v6fx-fw28-5wwr.json | 11 ++- .../GHSA-v878-67xw-grw2.json | 37 +++++++++ .../GHSA-v9c7-jfxg-gf53.json | 37 +++++++++ .../GHSA-vgp3-2wc7-6gv5.json | 37 +++++++++ .../GHSA-vgx6-62w9-6xwh.json | 11 ++- .../GHSA-vjp2-9hqr-v334.json | 9 +- .../GHSA-vm7v-r6xm-652p.json | 4 + .../GHSA-vp68-fm96-7v79.json | 37 +++++++++ .../GHSA-vp6f-wfqp-3623.json | 11 ++- .../GHSA-vpf7-q2rx-26mh.json | 37 +++++++++ .../GHSA-vrhf-cc97-jx2x.json | 4 + .../GHSA-vv62-xm44-43pw.json | 11 ++- .../GHSA-w26q-54h4-q58c.json | 11 ++- .../GHSA-w4gp-qv48-5jc9.json | 11 ++- .../GHSA-w4w4-8x3v-5mj3.json | 11 ++- .../GHSA-w75p-6382-63hg.json | 33 ++++++++ .../GHSA-w77j-2gh3-6mvp.json | 11 ++- .../GHSA-w785-44wh-9wr3.json | 37 +++++++++ .../GHSA-w7qx-54fx-55q8.json | 37 +++++++++ .../GHSA-w8gx-4r6w-3rx9.json | 37 +++++++++ .../GHSA-wc5v-h4fq-4g72.json | 33 ++++++++ .../GHSA-wcxw-9v7x-9r9c.json | 11 ++- .../GHSA-wp7f-3m97-grc2.json | 11 ++- .../GHSA-wpqf-f5ff-6c5w.json | 9 +- .../GHSA-wrmg-wv9p-r52j.json | 11 ++- .../GHSA-wwv7-h477-wrv7.json | 8 ++ .../GHSA-wwxv-fc92-xrw3.json | 37 +++++++++ .../GHSA-x2fp-wfrh-r34v.json | 36 ++++++++ .../GHSA-x4q2-hpmw-6w22.json | 41 ++++++++++ .../GHSA-x5fh-pc22-3jcj.json | 37 +++++++++ .../GHSA-x7w4-vfrh-fc3h.json | 37 +++++++++ .../GHSA-x92g-6c25-c2jv.json | 11 ++- .../GHSA-xgxg-m2p7-6pr3.json | 11 ++- .../GHSA-xjx8-665x-j9wh.json | 11 ++- .../GHSA-xmjp-848v-p77x.json | 37 +++++++++ .../GHSA-xp2f-9mx3-3c6p.json | 8 ++ .../GHSA-xpxr-m6jm-3qph.json | 37 +++++++++ .../GHSA-xrg3-35mw-8rhg.json | 11 ++- .../GHSA-xvm4-2pvm-hp3g.json | 9 +- .../GHSA-xvv2-cw9q-2m9r.json | 11 ++- .../GHSA-xw76-qw2j-v4fp.json | 11 ++- .../GHSA-xwjg-qxv6-28rv.json | 11 ++- .../GHSA-xxw8-ppw6-gv4w.json | 11 ++- 296 files changed, 5780 insertions(+), 806 deletions(-) create mode 100644 advisories/github-reviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json create mode 100644 advisories/github-reviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json (74%) create mode 100644 advisories/github-reviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json (69%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json (60%) create mode 100644 advisories/github-reviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json create mode 100644 advisories/github-reviewed/2022/07/GHSA-5834-xv5q-cgfw/GHSA-5834-xv5q-cgfw.json create mode 100644 advisories/github-reviewed/2022/07/GHSA-8274-h5jp-97vr/GHSA-8274-h5jp-97vr.json create mode 100644 advisories/github-reviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json create mode 100644 advisories/github-reviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json create mode 100644 advisories/github-reviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json delete mode 100644 advisories/unreviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json delete mode 100644 advisories/unreviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json create mode 100644 advisories/unreviewed/2022/07/GHSA-22hp-fm45-6q7j/GHSA-22hp-fm45-6q7j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-2352-4x78-8g6v/GHSA-2352-4x78-8g6v.json create mode 100644 advisories/unreviewed/2022/07/GHSA-2ccx-rp57-fp56/GHSA-2ccx-rp57-fp56.json create mode 100644 advisories/unreviewed/2022/07/GHSA-2j4w-p7qh-8g4g/GHSA-2j4w-p7qh-8g4g.json create mode 100644 advisories/unreviewed/2022/07/GHSA-2qh6-hhvv-m2ww/GHSA-2qh6-hhvv-m2ww.json create mode 100644 advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3fjx-v9x2-fjp6/GHSA-3fjx-v9x2-fjp6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-449w-c77c-vmf6/GHSA-449w-c77c-vmf6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-45rr-gg9f-wfcm/GHSA-45rr-gg9f-wfcm.json create mode 100644 advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json create mode 100644 advisories/unreviewed/2022/07/GHSA-4wpp-r5j6-h3hv/GHSA-4wpp-r5j6-h3hv.json delete mode 100644 advisories/unreviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json create mode 100644 advisories/unreviewed/2022/07/GHSA-54c2-vr3w-mp8p/GHSA-54c2-vr3w-mp8p.json create mode 100644 advisories/unreviewed/2022/07/GHSA-568h-6mc5-cxwg/GHSA-568h-6mc5-cxwg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-57f2-52wj-7vj6/GHSA-57f2-52wj-7vj6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5cvc-6x68-h8qf/GHSA-5cvc-6x68-h8qf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5frp-v5h8-3hgc/GHSA-5frp-v5h8-3hgc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5mv2-vqq7-mq5h/GHSA-5mv2-vqq7-mq5h.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5vgw-67rj-9pxh/GHSA-5vgw-67rj-9pxh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5x3f-7m52-9cgf/GHSA-5x3f-7m52-9cgf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5xp2-7qfc-fwgc/GHSA-5xp2-7qfc-fwgc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-63px-7j2g-6pfw/GHSA-63px-7j2g-6pfw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6954-h5c8-m29f/GHSA-6954-h5c8-m29f.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6x63-hrxg-2hjx/GHSA-6x63-hrxg-2hjx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6xf5-c3cx-67pv/GHSA-6xf5-c3cx-67pv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-75fc-fv3p-xh82/GHSA-75fc-fv3p-xh82.json create mode 100644 advisories/unreviewed/2022/07/GHSA-76pg-mr9v-5vwc/GHSA-76pg-mr9v-5vwc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-78fg-pvgg-6g3r/GHSA-78fg-pvgg-6g3r.json create mode 100644 advisories/unreviewed/2022/07/GHSA-79x9-477g-w256/GHSA-79x9-477g-w256.json create mode 100644 advisories/unreviewed/2022/07/GHSA-7f66-v639-c98w/GHSA-7f66-v639-c98w.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8294-mv9c-7m5h/GHSA-8294-mv9c-7m5h.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8528-c6m6-gppm/GHSA-8528-c6m6-gppm.json create mode 100644 advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8g36-x4m7-xxrc/GHSA-8g36-x4m7-xxrc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8qp3-mmfx-p4h5/GHSA-8qp3-mmfx-p4h5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8xwj-2wgh-gprh/GHSA-8xwj-2wgh-gprh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-99mq-hw5m-gwjj/GHSA-99mq-hw5m-gwjj.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9ggc-7v6w-qg26/GHSA-9ggc-7v6w-qg26.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9hx4-8365-w7gm/GHSA-9hx4-8365-w7gm.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9xhm-6w5p-335v/GHSA-9xhm-6w5p-335v.json delete mode 100644 advisories/unreviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json create mode 100644 advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json delete mode 100644 advisories/unreviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cm5q-x57v-2v56/GHSA-cm5q-x57v-2v56.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cm7j-p8hc-97vj/GHSA-cm7j-p8hc-97vj.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cp5r-xqjr-84gm/GHSA-cp5r-xqjr-84gm.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cpgc-248w-frqc/GHSA-cpgc-248w-frqc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f956-64gx-m8ww/GHSA-f956-64gx-m8ww.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fcpx-28g7-cmwg/GHSA-fcpx-28g7-cmwg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fjpq-f574-jc45/GHSA-fjpq-f574-jc45.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fqhm-fjjv-7q8x/GHSA-fqhm-fjjv-7q8x.json create mode 100644 advisories/unreviewed/2022/07/GHSA-g78q-fxv7-624v/GHSA-g78q-fxv7-624v.json create mode 100644 advisories/unreviewed/2022/07/GHSA-gq4p-4hxv-5rg9/GHSA-gq4p-4hxv-5rg9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-h5rj-r648-659m/GHSA-h5rj-r648-659m.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hgp9-2c4w-x9mh/GHSA-hgp9-2c4w-x9mh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hh5c-64r3-fc9p/GHSA-hh5c-64r3-fc9p.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hm53-hrhh-gwfq/GHSA-hm53-hrhh-gwfq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hp4v-g8mj-wr2f/GHSA-hp4v-g8mj-wr2f.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hp8r-2g6p-8j5q/GHSA-hp8r-2g6p-8j5q.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hvpp-g2cx-76qq/GHSA-hvpp-g2cx-76qq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hxf7-9rv9-88v6/GHSA-hxf7-9rv9-88v6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-j5qq-6rpm-qjgh/GHSA-j5qq-6rpm-qjgh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-j896-j72w-cr32/GHSA-j896-j72w-cr32.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jj8j-6jq7-gmvh/GHSA-jj8j-6jq7-gmvh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jvjh-9r4q-8q5q/GHSA-jvjh-9r4q-8q5q.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jvvx-hmmr-rhgg/GHSA-jvvx-hmmr-rhgg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jxg9-2ch7-f552/GHSA-jxg9-2ch7-f552.json create mode 100644 advisories/unreviewed/2022/07/GHSA-m485-79jq-cxx7/GHSA-m485-79jq-cxx7.json create mode 100644 advisories/unreviewed/2022/07/GHSA-m6jf-p94r-8589/GHSA-m6jf-p94r-8589.json create mode 100644 advisories/unreviewed/2022/07/GHSA-m769-jr2m-2pmv/GHSA-m769-jr2m-2pmv.json delete mode 100644 advisories/unreviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-m8w5-vwq3-gp8f/GHSA-m8w5-vwq3-gp8f.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mqpc-v236-v2qj/GHSA-mqpc-v236-v2qj.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mr38-g7q2-x79p/GHSA-mr38-g7q2-x79p.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mxcc-7h5m-x57r/GHSA-mxcc-7h5m-x57r.json create mode 100644 advisories/unreviewed/2022/07/GHSA-p289-v2gf-9g82/GHSA-p289-v2gf-9g82.json create mode 100644 advisories/unreviewed/2022/07/GHSA-p878-qvqr-h9fp/GHSA-p878-qvqr-h9fp.json create mode 100644 advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-pfgj-6mxg-pmfv/GHSA-pfgj-6mxg-pmfv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-pw4g-jcp5-63m9/GHSA-pw4g-jcp5-63m9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-qf4p-7gqc-x6jx/GHSA-qf4p-7gqc-x6jx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-rqqx-fvqx-539g/GHSA-rqqx-fvqx-539g.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v878-67xw-grw2/GHSA-v878-67xw-grw2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v9c7-jfxg-gf53/GHSA-v9c7-jfxg-gf53.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vgp3-2wc7-6gv5/GHSA-vgp3-2wc7-6gv5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vp68-fm96-7v79/GHSA-vp68-fm96-7v79.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vpf7-q2rx-26mh/GHSA-vpf7-q2rx-26mh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w75p-6382-63hg/GHSA-w75p-6382-63hg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w7qx-54fx-55q8/GHSA-w7qx-54fx-55q8.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w8gx-4r6w-3rx9/GHSA-w8gx-4r6w-3rx9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json create mode 100644 advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json create mode 100644 advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json create mode 100644 advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json create mode 100644 advisories/unreviewed/2022/07/GHSA-x7w4-vfrh-fc3h/GHSA-x7w4-vfrh-fc3h.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xmjp-848v-p77x/GHSA-xmjp-848v-p77x.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xpxr-m6jm-3qph/GHSA-xpxr-m6jm-3qph.json diff --git a/advisories/github-reviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json b/advisories/github-reviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json new file mode 100644 index 00000000000..406a827711f --- /dev/null +++ b/advisories/github-reviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9wxh-jjj5-67cv", + "modified": "2022-07-27T21:24:04Z", + "published": "2022-01-13T00:00:58Z", + "aliases": [ + "CVE-2022-20620" + ], + "summary": "Missing permission checks in SSH Agent Plugin allow enumerating credentials IDs", + "details": "Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allow attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins. An enumeration of credentials IDs in SSH Agent Plugin 1.23.2 requires the appropriate permissions.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:ssh-agent" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.23.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20620" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2189" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/01/12/6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jenkinsci/ssh-agent-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json b/advisories/github-reviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json new file mode 100644 index 00000000000..52ef1868624 --- /dev/null +++ b/advisories/github-reviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5m8f-v3gw-h94w", + "modified": "2022-07-27T21:24:40Z", + "published": "2022-02-16T00:01:28Z", + "aliases": [ + "CVE-2022-25187" + ], + "summary": "Support Core Plugin before 2.79.1 stores sensitive data in plain text", + "details": "Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. Support Core Plugin 2.79.1 adds a list of keywords whose associated values are redacted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:support-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.79.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25187" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2186" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jenkinsci/support-core-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json b/advisories/github-reviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json similarity index 74% rename from advisories/unreviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json rename to advisories/github-reviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json index 63912cca1da..03d3662154d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json +++ b/advisories/github-reviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json @@ -1,11 +1,12 @@ { "schema_version": "1.2.0", "id": "GHSA-9772-cwx9-r4cj", - "modified": "2022-05-14T02:05:09Z", + "modified": "2022-07-27T21:35:21Z", "published": "2022-05-14T02:05:09Z", "aliases": [ "CVE-2014-4616" ], + "summary": "simplejson before 2.6.1 vulnerable to array index error", "details": "Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "simplejson" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.6.1" + } + ] + } + ] + } ], "references": [ { @@ -56,14 +75,17 @@ { "type": "WEB", "url": "http://www.securityfocus.com/bid/68119" + }, + { + "type": "PACKAGE", + "url": "https://github.com/simplejson/simplejson" } ], "database_specific": { "cwe_ids": [ - "CWE-119", "CWE-129" ], "severity": "MODERATE", - "github_reviewed": false + "github_reviewed": true } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json b/advisories/github-reviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json new file mode 100644 index 00000000000..53372ac0cf9 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json @@ -0,0 +1,82 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cv78-v957-jx34", + "modified": "2022-07-27T22:17:45Z", + "published": "2022-05-24T17:12:57Z", + "aliases": [ + "CVE-2020-7599" + ], + "summary": "Exposure of Sensitive Information in Gradle publish plugin", + "details": "All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this build log is publicly visible (as it is in many popular public CI systems like TravisCI) this AWS pre-signed URL would allow a malicious actor to replace a recently uploaded plugin with their own.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.gradle.publish:plugin-publish-plugin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7599" + }, + { + "type": "WEB", + "url": "https://blog.gradle.org/plugin-portal-update" + }, + { + "type": "WEB", + "url": "https://plugins.gradle.org/plugin/com.gradle.plugin-publish" + }, + { + "type": "WEB", + "url": "https://snyk.io/vuln/SNYK-JAVA-COMGRADLEPLUGINPUBLISH-559866" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json b/advisories/github-reviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json new file mode 100644 index 00000000000..d9ba293e1d8 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json @@ -0,0 +1,74 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-gwf7-vfjf-wf6x", + "modified": "2022-07-27T21:34:46Z", + "published": "2022-05-24T16:45:24Z", + "aliases": [ + "CVE-2019-11842" + ], + "summary": "matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG", + "details": "An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "matrix-sydent" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "matrix-synapse" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.99.3.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11842" + }, + { + "type": "WEB", + "url": "https://matrix.org/blog/2019/05/03/security-updates-sydent-1-0-3-synapse-0-99-3-1-and-riot-android-0-9-0-0-8-99-0-8-28-a/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "HIGH", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json b/advisories/github-reviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json similarity index 69% rename from advisories/unreviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json rename to advisories/github-reviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json index 985225d0264..55d70a4207a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json +++ b/advisories/github-reviewed/2022/05/GHSA-qh9x-mc42-vg4g/GHSA-qh9x-mc42-vg4g.json @@ -1,11 +1,12 @@ { "schema_version": "1.2.0", "id": "GHSA-qh9x-mc42-vg4g", - "modified": "2022-05-14T03:32:28Z", + "modified": "2022-07-27T21:33:52Z", "published": "2022-05-14T03:32:28Z", "aliases": [ "CVE-2018-1000089" ], + "summary": "django-anymail Includes Sensitive Information in Log Files", "details": "Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "django-anymail" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.2" + }, + { + "fixed": "1.4" + } + ] + } + ] + } ], "references": [ { @@ -28,6 +47,10 @@ { "type": "WEB", "url": "https://github.com/anymail/django-anymail/releases/tag/v1.4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/anymail/django-anymail" } ], "database_specific": { @@ -35,6 +58,6 @@ "CWE-532" ], "severity": "HIGH", - "github_reviewed": false + "github_reviewed": true } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json b/advisories/github-reviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json rename to advisories/github-reviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json index 2b7c94126ab..01e780e6923 100644 --- a/advisories/unreviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json +++ b/advisories/github-reviewed/2022/05/GHSA-v64w-96p6-fx7w/GHSA-v64w-96p6-fx7w.json @@ -1,17 +1,36 @@ { "schema_version": "1.2.0", "id": "GHSA-v64w-96p6-fx7w", - "modified": "2022-05-17T04:48:11Z", + "modified": "2022-07-27T21:38:21Z", "published": "2022-05-17T04:48:11Z", "aliases": [ "CVE-2013-1777" ], + "summary": "Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1", "details": "The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.geronimo.framework:geronimo-jmx-remoting" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0-beta-1" + }, + { + "fixed": "3.0.1" + } + ] + } + ] + } ], "references": [ { @@ -30,6 +49,14 @@ "type": "WEB", "url": "http://geronimo.apache.org/30x-security-report.html" }, + { + "type": "WEB", + "url": "http://svn.apache.org/viewvc/geronimo/server/trunk" + }, + { + "type": "WEB", + "url": "http://svn.apache.org/viewvc?view=revision&revision=1458113" + }, { "type": "WEB", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21643282" @@ -40,6 +67,6 @@ "CWE-94" ], "severity": "HIGH", - "github_reviewed": false + "github_reviewed": true } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json b/advisories/github-reviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json new file mode 100644 index 00000000000..35f4e293825 --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5469-c5p2-xv5g", + "modified": "2022-07-27T22:10:26Z", + "published": "2022-07-23T00:00:15Z", + "aliases": [ + "CVE-2022-34113" + ], + "summary": "Dataease before 1.11.2 allows arbitrary code execution via crafter plugin", + "details": "An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. Version 1.11.2 contains a patch for the problem.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "io.dataease:dataease-plugin-common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.11.2" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.11.1" + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34113" + }, + { + "type": "WEB", + "url": "https://github.com/dataease/dataease/issues/2431" + }, + { + "type": "WEB", + "url": "https://github.com/dataease/dataease/releases/tag/v1.11.2" + }, + { + "type": "PACKAGE", + "url": "https://github.com/dataease/dataease" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-5834-xv5q-cgfw/GHSA-5834-xv5q-cgfw.json b/advisories/github-reviewed/2022/07/GHSA-5834-xv5q-cgfw/GHSA-5834-xv5q-cgfw.json new file mode 100644 index 00000000000..7b71dc5df02 --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-5834-xv5q-cgfw/GHSA-5834-xv5q-cgfw.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5834-xv5q-cgfw", + "modified": "2022-07-27T22:06:09Z", + "published": "2022-07-27T22:06:09Z", + "aliases": [ + "CVE-2022-31148" + ], + "summary": "Shopware vulnerable to persistent XSS in customer module", + "details": "### Impact\nPersistent XSS in customer module\n\n### Patches\n\nWe recommend updating to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview.\n\nFor older versions you can use the Security Plugin:\nhttps://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html\n\n### References\nhttps://docs.shopware.com/en/shopware-5-en/security-updates/security-update-07-2022", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "shopware/shopware" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.7.0" + }, + { + "fixed": "5.7.14" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 5.7.13" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/shopware/shopware/security/advisories/GHSA-5834-xv5q-cgfw" + }, + { + "type": "WEB", + "url": "https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-07-2022" + }, + { + "type": "WEB", + "url": "https://www.shopware.com/en/changelog-sw5/#5-7-14" + }, + { + "type": "PACKAGE", + "url": "https://github.com/shopware/shopware" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-8274-h5jp-97vr/GHSA-8274-h5jp-97vr.json b/advisories/github-reviewed/2022/07/GHSA-8274-h5jp-97vr/GHSA-8274-h5jp-97vr.json new file mode 100644 index 00000000000..01aba02d6af --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-8274-h5jp-97vr/GHSA-8274-h5jp-97vr.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8274-h5jp-97vr", + "modified": "2022-07-27T22:05:18Z", + "published": "2022-07-27T22:05:18Z", + "aliases": [ + "CVE-2022-31109" + ], + "summary": "Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack", + "details": "### Impact\n\nApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\\Diactoros\\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning.\n\n### Patches\n\nAny version after 2.11.0.\n\nStarting in laminas/laminas-diactoros 2.11.1, we have added `Laminas\\Diactoros\\ServerRequestFilter\\FilterServerRequestInterface`, which defines the single method `__invoke(Psr\\Http\\Message\\ServerRequestInterface $request): Psr\\Http\\Message\\ServerRequestInterface`. Filters implementing this interface allow modifying and returning a generated `ServerRequest`.\n\nThe primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as `X-Forwarded-Host`. When operating behind a reverse proxy, the `Host` header is often rewritten to the name of the node to which the request is being forwarded, and an `X-Forwarded-Host` header is generated with the original `Host` value to allow the server to determine the original host the request was intended for. (We have always examined the `X-Forwarded-Proto` header; as of Diactoros 2.11.1, we also examine the `X-Forwarded-Port` header.) To accommodate this use case, we created Laminas\\Diactoros\\ServerRequestFilter\\FilterUsingXForwardedHeaders.\n\nDue to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.\n(This value is found in `$_SERVER['REMOTE_ADDR']`, which is present as `$request->getServerParams()['REMOTE_ADDR']` within PSR-7 implementations.) `FilterUsingXForwardedHeaders` provides named constructors to allow you to trust these headers from any source (which has been the default behavior of Diactoros since the beginning), or to specify specific IP addresses or CIDR subnets to trust, along with which headers are trusted.\n\n`Laminas\\Diactoros\\ServerRequestFactory::fromGlobals()` was updated to accept a `FilterServerRequestInterface` as an additional, optional argument. Since the `X-Forwarded-*` headers do have valid use cases, particularly in clustered environments using a load balancer, to prevent backwards compatibility breaks, if no filter is provided, we generate an instance via `FilterUsingXForwardedHeaders::trustReservedSubnets()`, which generates an instance marked to trust only proxies on private subnets.\n\n### Workarounds\n\nInfrastructure or DevOps can configure web servers to reject `X-Forwarded-*` headers at the web server level.\n\nUsers of laminas/laminas-diactoros can make use of the `Laminas\\Diactoros\\RequestFilter\\RequestFilterInterface` functionality in order to either (a) disable usage of the `X-Forwarded-*` headers entirely, (b) opt-in to it, or (c) opt-in to the usage for configured proxy servers.\n\n### References\n\n- [HTTP Host Header Attacks](https://portswigger.net/web-security/host-header)\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [laminas/laminas-diactoros](https://github.com/laminas/laminas-diactoros/)\n- [Email us](mailto:security@getlaminas.org)", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "laminas/laminas-diactoros" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/laminas/laminas-diactoros/security/advisories/GHSA-8274-h5jp-97vr" + }, + { + "type": "WEB", + "url": "https://github.com/laminas/laminas-diactoros/commit/25b11d422c2e5dad868f68619888763b30f91e2d" + }, + { + "type": "WEB", + "url": "https://github.com/laminas/laminas-diactoros/releases/tag/2.11.1" + }, + { + "type": "PACKAGE", + "url": "https://github.com/laminas/laminas-diactoros" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json b/advisories/github-reviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json new file mode 100644 index 00000000000..c12b03db17a --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c2pj-rr68-pw94", + "modified": "2022-07-27T22:10:40Z", + "published": "2022-07-23T00:00:15Z", + "aliases": [ + "CVE-2022-34112" + ], + "summary": "Dataease before 1.11.2 access control issue allows attackers to arbitrarily uninstall plugin", + "details": "An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator. Version 1.11.2 contains a patch for this issue.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "io.dataease:dataease-plugin-common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.11.2" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.11.1" + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34112" + }, + { + "type": "WEB", + "url": "https://github.com/dataease/dataease/issues/2429" + }, + { + "type": "WEB", + "url": "https://github.com/dataease/dataease/commit/5f611d3e3934816e9ad34e3d21807978001e2c8b" + }, + { + "type": "WEB", + "url": "https://github.com/dataease/dataease/releases/tag/v1.11.2" + }, + { + "type": "PACKAGE", + "url": "https://github.com/dataease/dataease" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json b/advisories/github-reviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json new file mode 100644 index 00000000000..3f87e2e2ee4 --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cfcg-2qgr-v243", + "modified": "2022-07-27T22:11:04Z", + "published": "2022-07-23T00:00:22Z", + "aliases": [ + "CVE-2022-2470" + ], + "summary": "Microweber before 1.2.21 vulnerable to reflected XSS", + "details": "Microweber prior to 1.2.21 is vulnerable to reflected cross-site scripting (XSS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "microweber/microweber" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.21" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2470" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/commit/d28655183800b833abb20ccd55e1628f16ff65e4" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/3f1f679c-c243-431c-8ed0-e61543b9921b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/microweber/microweber" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json b/advisories/github-reviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json new file mode 100644 index 00000000000..99fd2c40d52 --- /dev/null +++ b/advisories/github-reviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m7gr-5w5g-36jf", + "modified": "2022-07-27T22:12:07Z", + "published": "2022-07-23T00:00:22Z", + "aliases": [ + "CVE-2022-34037" + ], + "summary": "Out-of-bounds Read can lead to client side denial of service", + "details": "An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) on the client side via a crafted URI.\n\nAccording to the maintainer, the bug only affects the client side of the request and cannot cause a denial of service on the server.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/caddyserver/caddy" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34037" + }, + { + "type": "WEB", + "url": "https://github.com/caddyserver/caddy/issues/4775" + }, + { + "type": "WEB", + "url": "https://github.com/caddyserver/caddy/commit/693e9b5283e675b56084ecc83d73176cab0ee27c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/caddyserver/caddy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json b/advisories/unreviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json deleted file mode 100644 index 891497f0e21..00000000000 --- a/advisories/unreviewed/2022/01/GHSA-9wxh-jjj5-67cv/GHSA-9wxh-jjj5-67cv.json +++ /dev/null @@ -1,37 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-9wxh-jjj5-67cv", - "modified": "2022-01-19T00:01:36Z", - "published": "2022-01-13T00:00:58Z", - "aliases": [ - "CVE-2022-20620" - ], - "details": "Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20620" - }, - { - "type": "WEB", - "url": "https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2189" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2022/01/12/6" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-668" - ], - "severity": "MODERATE", - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json b/advisories/unreviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json deleted file mode 100644 index ebfe7cf007c..00000000000 --- a/advisories/unreviewed/2022/02/GHSA-5m8f-v3gw-h94w/GHSA-5m8f-v3gw-h94w.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-5m8f-v3gw-h94w", - "modified": "2022-02-24T00:01:05Z", - "published": "2022-02-16T00:01:28Z", - "aliases": [ - "CVE-2022-25187" - ], - "details": "Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25187" - }, - { - "type": "WEB", - "url": "https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2186" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-522" - ], - "severity": "MODERATE", - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/02/GHSA-mcpv-3q7c-v7rr/GHSA-mcpv-3q7c-v7rr.json b/advisories/unreviewed/2022/02/GHSA-mcpv-3q7c-v7rr/GHSA-mcpv-3q7c-v7rr.json index a5d73178a62..2bc497bb87d 100644 --- a/advisories/unreviewed/2022/02/GHSA-mcpv-3q7c-v7rr/GHSA-mcpv-3q7c-v7rr.json +++ b/advisories/unreviewed/2022/02/GHSA-mcpv-3q7c-v7rr/GHSA-mcpv-3q7c-v7rr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mcpv-3q7c-v7rr", - "modified": "2022-02-11T00:01:09Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-02-08T00:00:30Z", "aliases": [ "CVE-2022-23184" ], "details": "In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/04/GHSA-g969-j9qm-fx8r/GHSA-g969-j9qm-fx8r.json b/advisories/unreviewed/2022/04/GHSA-g969-j9qm-fx8r/GHSA-g969-j9qm-fx8r.json index 7365bf3151b..d81ff126588 100644 --- a/advisories/unreviewed/2022/04/GHSA-g969-j9qm-fx8r/GHSA-g969-j9qm-fx8r.json +++ b/advisories/unreviewed/2022/04/GHSA-g969-j9qm-fx8r/GHSA-g969-j9qm-fx8r.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1512" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1512" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-48rh-rw8j-qvqv/GHSA-48rh-rw8j-qvqv.json b/advisories/unreviewed/2022/05/GHSA-48rh-rw8j-qvqv/GHSA-48rh-rw8j-qvqv.json index e3b7ffc6c33..2b0cb8dd705 100644 --- a/advisories/unreviewed/2022/05/GHSA-48rh-rw8j-qvqv/GHSA-48rh-rw8j-qvqv.json +++ b/advisories/unreviewed/2022/05/GHSA-48rh-rw8j-qvqv/GHSA-48rh-rw8j-qvqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-48rh-rw8j-qvqv", - "modified": "2022-05-24T16:54:40Z", + "modified": "2022-07-28T00:00:46Z", "published": "2022-05-24T16:54:40Z", "aliases": [ "CVE-2019-15507" ], "details": "In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.7. The fix was back-ported to LTS 2019.6.7 as well as LTS 2019.3.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-5fjw-573q-gg89/GHSA-5fjw-573q-gg89.json b/advisories/unreviewed/2022/05/GHSA-5fjw-573q-gg89/GHSA-5fjw-573q-gg89.json index c068eb964af..95d42595b82 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fjw-573q-gg89/GHSA-5fjw-573q-gg89.json +++ b/advisories/unreviewed/2022/05/GHSA-5fjw-573q-gg89/GHSA-5fjw-573q-gg89.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5fjw-573q-gg89", - "modified": "2022-05-24T16:54:40Z", + "modified": "2022-07-28T00:00:46Z", "published": "2022-05-24T16:54:40Z", "aliases": [ "CVE-2019-15508" ], "details": "In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 5.0.1. The fix was back-ported to 4.0.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-5m64-chxv-wxq3/GHSA-5m64-chxv-wxq3.json b/advisories/unreviewed/2022/05/GHSA-5m64-chxv-wxq3/GHSA-5m64-chxv-wxq3.json index 79fff0c5c5a..ffa80045c2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m64-chxv-wxq3/GHSA-5m64-chxv-wxq3.json +++ b/advisories/unreviewed/2022/05/GHSA-5m64-chxv-wxq3/GHSA-5m64-chxv-wxq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5m64-chxv-wxq3", - "modified": "2022-05-24T17:39:28Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-05-24T17:39:28Z", "aliases": [ "CVE-2020-29450" ], "details": "Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6cff-mj8v-fvr9/GHSA-6cff-mj8v-fvr9.json b/advisories/unreviewed/2022/05/GHSA-6cff-mj8v-fvr9/GHSA-6cff-mj8v-fvr9.json index 7570599529b..535d0e171ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cff-mj8v-fvr9/GHSA-6cff-mj8v-fvr9.json +++ b/advisories/unreviewed/2022/05/GHSA-6cff-mj8v-fvr9/GHSA-6cff-mj8v-fvr9.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-668" ], "severity": "MODERATE", "github_reviewed": false diff --git a/advisories/unreviewed/2022/05/GHSA-6jqc-mwfj-6xjc/GHSA-6jqc-mwfj-6xjc.json b/advisories/unreviewed/2022/05/GHSA-6jqc-mwfj-6xjc/GHSA-6jqc-mwfj-6xjc.json index ba7b599df4e..e67cc25988d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jqc-mwfj-6xjc/GHSA-6jqc-mwfj-6xjc.json +++ b/advisories/unreviewed/2022/05/GHSA-6jqc-mwfj-6xjc/GHSA-6jqc-mwfj-6xjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-6jqc-mwfj-6xjc", - "modified": "2022-05-24T22:28:19Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-05-24T22:28:19Z", "aliases": [ "CVE-2021-31818" ], "details": "Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-7w22-h336-hrv9/GHSA-7w22-h336-hrv9.json b/advisories/unreviewed/2022/05/GHSA-7w22-h336-hrv9/GHSA-7w22-h336-hrv9.json index 329ac730475..984ae7de039 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w22-h336-hrv9/GHSA-7w22-h336-hrv9.json +++ b/advisories/unreviewed/2022/05/GHSA-7w22-h336-hrv9/GHSA-7w22-h336-hrv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7w22-h336-hrv9", - "modified": "2022-05-24T19:07:18Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-05-24T19:07:18Z", "aliases": [ "CVE-2021-31816" ], "details": "When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-889g-gr2g-424w/GHSA-889g-gr2g-424w.json b/advisories/unreviewed/2022/05/GHSA-889g-gr2g-424w/GHSA-889g-gr2g-424w.json index 6c47ca7a70c..ebc11a2c430 100644 --- a/advisories/unreviewed/2022/05/GHSA-889g-gr2g-424w/GHSA-889g-gr2g-424w.json +++ b/advisories/unreviewed/2022/05/GHSA-889g-gr2g-424w/GHSA-889g-gr2g-424w.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-889g-gr2g-424w", - "modified": "2022-05-24T17:46:04Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-05-24T17:46:04Z", "aliases": [ "CVE-2021-26072" ], "details": "The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8xgg-pj9m-c8xj/GHSA-8xgg-pj9m-c8xj.json b/advisories/unreviewed/2022/05/GHSA-8xgg-pj9m-c8xj/GHSA-8xgg-pj9m-c8xj.json index 1db3067685d..cddb7021ec3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xgg-pj9m-c8xj/GHSA-8xgg-pj9m-c8xj.json +++ b/advisories/unreviewed/2022/05/GHSA-8xgg-pj9m-c8xj/GHSA-8xgg-pj9m-c8xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8xgg-pj9m-c8xj", - "modified": "2022-05-24T16:54:58Z", + "modified": "2022-07-28T00:00:47Z", "published": "2022-05-24T16:54:58Z", "aliases": [ "CVE-2019-15698" ], "details": "In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-98cv-g579-8fm6/GHSA-98cv-g579-8fm6.json b/advisories/unreviewed/2022/05/GHSA-98cv-g579-8fm6/GHSA-98cv-g579-8fm6.json index de6e20bf866..76da2b509e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-98cv-g579-8fm6/GHSA-98cv-g579-8fm6.json +++ b/advisories/unreviewed/2022/05/GHSA-98cv-g579-8fm6/GHSA-98cv-g579-8fm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-98cv-g579-8fm6", - "modified": "2022-05-24T17:42:50Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-05-24T17:42:50Z", "aliases": [ "CVE-2020-29448" ], "details": "The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cg8q-mvmc-qr6h/GHSA-cg8q-mvmc-qr6h.json b/advisories/unreviewed/2022/05/GHSA-cg8q-mvmc-qr6h/GHSA-cg8q-mvmc-qr6h.json index fee6e2cf968..bdbb70dff76 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg8q-mvmc-qr6h/GHSA-cg8q-mvmc-qr6h.json +++ b/advisories/unreviewed/2022/05/GHSA-cg8q-mvmc-qr6h/GHSA-cg8q-mvmc-qr6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-cg8q-mvmc-qr6h", - "modified": "2022-05-24T19:07:18Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-05-24T19:07:18Z", "aliases": [ "CVE-2021-31817" ], "details": "When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cpf5-2wrr-hcvc/GHSA-cpf5-2wrr-hcvc.json b/advisories/unreviewed/2022/05/GHSA-cpf5-2wrr-hcvc/GHSA-cpf5-2wrr-hcvc.json index 20d3859b619..3e4c92d7c43 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpf5-2wrr-hcvc/GHSA-cpf5-2wrr-hcvc.json +++ b/advisories/unreviewed/2022/05/GHSA-cpf5-2wrr-hcvc/GHSA-cpf5-2wrr-hcvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-cpf5-2wrr-hcvc", - "modified": "2022-05-24T19:16:59Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-05-24T19:16:59Z", "aliases": [ "CVE-2021-26556" ], "details": "When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json b/advisories/unreviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json deleted file mode 100644 index 59623382ad8..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-cv78-v957-jx34/GHSA-cv78-v957-jx34.json +++ /dev/null @@ -1,37 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-cv78-v957-jx34", - "modified": "2022-05-24T17:12:57Z", - "published": "2022-05-24T17:12:57Z", - "aliases": [ - "CVE-2020-7599" - ], - "details": "All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this build log is publicly visible (as it is in many popular public CI systems like TravisCI) this AWS pre-signed URL would allow a malicious actor to replace a recently uploaded plugin with their own.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7599" - }, - { - "type": "WEB", - "url": "https://blog.gradle.org/plugin-portal-update" - }, - { - "type": "WEB", - "url": "https://snyk.io/vuln/SNYK-JAVA-COMGRADLEPLUGINPUBLISH-559866" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "LOW", - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-gj89-qmxj-q494/GHSA-gj89-qmxj-q494.json b/advisories/unreviewed/2022/05/GHSA-gj89-qmxj-q494/GHSA-gj89-qmxj-q494.json index 4f1ca331023..8a553d050f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj89-qmxj-q494/GHSA-gj89-qmxj-q494.json +++ b/advisories/unreviewed/2022/05/GHSA-gj89-qmxj-q494/GHSA-gj89-qmxj-q494.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gj89-qmxj-q494", - "modified": "2022-05-24T17:31:33Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-05-24T17:31:33Z", "aliases": [ "CVE-2020-14830" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json b/advisories/unreviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json deleted file mode 100644 index a95b09f3e95..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-gwf7-vfjf-wf6x/GHSA-gwf7-vfjf-wf6x.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-gwf7-vfjf-wf6x", - "modified": "2022-05-24T16:45:24Z", - "published": "2022-05-24T16:45:24Z", - "aliases": [ - "CVE-2019-11842" - ], - "details": "An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11842" - }, - { - "type": "WEB", - "url": "https://matrix.org/blog/2019/05/03/security-updates-sydent-1-0-3-synapse-0-99-3-1-and-riot-android-0-9-0-0-8-99-0-8-28-a/" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-h289-298g-xpjw/GHSA-h289-298g-xpjw.json b/advisories/unreviewed/2022/05/GHSA-h289-298g-xpjw/GHSA-h289-298g-xpjw.json index 0d071fc1bf1..37850680afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-h289-298g-xpjw/GHSA-h289-298g-xpjw.json +++ b/advisories/unreviewed/2022/05/GHSA-h289-298g-xpjw/GHSA-h289-298g-xpjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h289-298g-xpjw", - "modified": "2022-05-24T16:45:01Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-05-24T16:45:01Z", "aliases": [ "CVE-2019-11632" ], "details": "In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped variables from a different project. (These permissions are only used in custom User Roles and do not affect built in User Roles.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false diff --git a/advisories/unreviewed/2022/05/GHSA-p57w-vp74-84r6/GHSA-p57w-vp74-84r6.json b/advisories/unreviewed/2022/05/GHSA-p57w-vp74-84r6/GHSA-p57w-vp74-84r6.json index 11d44419499..87f80446483 100644 --- a/advisories/unreviewed/2022/05/GHSA-p57w-vp74-84r6/GHSA-p57w-vp74-84r6.json +++ b/advisories/unreviewed/2022/05/GHSA-p57w-vp74-84r6/GHSA-p57w-vp74-84r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p57w-vp74-84r6", - "modified": "2022-05-24T16:52:32Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-05-24T16:52:32Z", "aliases": [ "CVE-2019-14525" ], "details": "In Octopus Deploy 2019.4.0 through 2019.6.6 and 2019.7.0 through 2019.7.7, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-pc5m-rr8v-2phw/GHSA-pc5m-rr8v-2phw.json b/advisories/unreviewed/2022/05/GHSA-pc5m-rr8v-2phw/GHSA-pc5m-rr8v-2phw.json index ef26c081067..019806a19f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc5m-rr8v-2phw/GHSA-pc5m-rr8v-2phw.json +++ b/advisories/unreviewed/2022/05/GHSA-pc5m-rr8v-2phw/GHSA-pc5m-rr8v-2phw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pc5m-rr8v-2phw", - "modified": "2022-05-24T17:31:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-05-24T17:31:34Z", "aliases": [ "CVE-2020-14836" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-w4vm-8m9w-5qwm/GHSA-w4vm-8m9w-5qwm.json b/advisories/unreviewed/2022/05/GHSA-w4vm-8m9w-5qwm/GHSA-w4vm-8m9w-5qwm.json index 0c1ce1cc63b..8adc67af6d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4vm-8m9w-5qwm/GHSA-w4vm-8m9w-5qwm.json +++ b/advisories/unreviewed/2022/05/GHSA-w4vm-8m9w-5qwm/GHSA-w4vm-8m9w-5qwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w4vm-8m9w-5qwm", - "modified": "2022-05-24T17:26:30Z", + "modified": "2022-07-28T00:00:47Z", "published": "2022-05-24T17:26:30Z", "aliases": [ "CVE-2020-16197" ], "details": "An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false diff --git a/advisories/unreviewed/2022/05/GHSA-wj9v-cg6p-qc9f/GHSA-wj9v-cg6p-qc9f.json b/advisories/unreviewed/2022/05/GHSA-wj9v-cg6p-qc9f/GHSA-wj9v-cg6p-qc9f.json index a507db4ad1e..d7468b07ed9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj9v-cg6p-qc9f/GHSA-wj9v-cg6p-qc9f.json +++ b/advisories/unreviewed/2022/05/GHSA-wj9v-cg6p-qc9f/GHSA-wj9v-cg6p-qc9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wj9v-cg6p-qc9f", - "modified": "2022-05-24T17:01:34Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-05-24T17:01:34Z", "aliases": [ "CVE-2019-19085" ], "details": "A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "LOW", "github_reviewed": false diff --git a/advisories/unreviewed/2022/05/GHSA-x7v8-768q-2m8h/GHSA-x7v8-768q-2m8h.json b/advisories/unreviewed/2022/05/GHSA-x7v8-768q-2m8h/GHSA-x7v8-768q-2m8h.json index bcd8e47ecc8..9bf674b3e52 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7v8-768q-2m8h/GHSA-x7v8-768q-2m8h.json +++ b/advisories/unreviewed/2022/05/GHSA-x7v8-768q-2m8h/GHSA-x7v8-768q-2m8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-x7v8-768q-2m8h", - "modified": "2022-05-24T19:02:30Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-05-24T19:02:30Z", "aliases": [ "CVE-2021-30183" ], "details": "Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-xvv9-f9hm-rghr/GHSA-xvv9-f9hm-rghr.json b/advisories/unreviewed/2022/05/GHSA-xvv9-f9hm-rghr/GHSA-xvv9-f9hm-rghr.json index 4404dba1f0b..2db771f49e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvv9-f9hm-rghr/GHSA-xvv9-f9hm-rghr.json +++ b/advisories/unreviewed/2022/05/GHSA-xvv9-f9hm-rghr/GHSA-xvv9-f9hm-rghr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xvv9-f9hm-rghr", - "modified": "2022-05-24T19:01:50Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-05-24T19:01:50Z", "aliases": [ "CVE-2020-29444" ], "details": "Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/07/GHSA-22hp-fm45-6q7j/GHSA-22hp-fm45-6q7j.json b/advisories/unreviewed/2022/07/GHSA-22hp-fm45-6q7j/GHSA-22hp-fm45-6q7j.json new file mode 100644 index 00000000000..dad3f2f83c6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-22hp-fm45-6q7j/GHSA-22hp-fm45-6q7j.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-22hp-fm45-6q7j", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-35911" + ], + "details": "On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35911" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/167797/Patlite-1.46-Buffer-Overflow.html" + }, + { + "type": "WEB", + "url": "https://www.patlite.co.jp/product/detail0000021462.html" + }, + { + "type": "WEB", + "url": "https://www.patlite.com/network-products/lineup/nh-fb.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2352-4x78-8g6v/GHSA-2352-4x78-8g6v.json b/advisories/unreviewed/2022/07/GHSA-2352-4x78-8g6v/GHSA-2352-4x78-8g6v.json new file mode 100644 index 00000000000..60d33448aa8 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-2352-4x78-8g6v/GHSA-2352-4x78-8g6v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-2352-4x78-8g6v", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1873" + ], + "details": "Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1873" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1305394" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-243v-5pff-qqfj/GHSA-243v-5pff-qqfj.json b/advisories/unreviewed/2022/07/GHSA-243v-5pff-qqfj/GHSA-243v-5pff-qqfj.json index 8e23d6e5947..fd14c340f3b 100644 --- a/advisories/unreviewed/2022/07/GHSA-243v-5pff-qqfj/GHSA-243v-5pff-qqfj.json +++ b/advisories/unreviewed/2022/07/GHSA-243v-5pff-qqfj/GHSA-243v-5pff-qqfj.json @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106276" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=436459" diff --git a/advisories/unreviewed/2022/07/GHSA-256m-rvq9-56mx/GHSA-256m-rvq9-56mx.json b/advisories/unreviewed/2022/07/GHSA-256m-rvq9-56mx/GHSA-256m-rvq9-56mx.json index 3153037a5f7..c2ad694ec0d 100644 --- a/advisories/unreviewed/2022/07/GHSA-256m-rvq9-56mx/GHSA-256m-rvq9-56mx.json +++ b/advisories/unreviewed/2022/07/GHSA-256m-rvq9-56mx/GHSA-256m-rvq9-56mx.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33744" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-406.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-268h-h8j2-2m45/GHSA-268h-h8j2-2m45.json b/advisories/unreviewed/2022/07/GHSA-268h-h8j2-2m45/GHSA-268h-h8j2-2m45.json index c7f404b8e44..a829f83b0fa 100644 --- a/advisories/unreviewed/2022/07/GHSA-268h-h8j2-2m45/GHSA-268h-h8j2-2m45.json +++ b/advisories/unreviewed/2022/07/GHSA-268h-h8j2-2m45/GHSA-268h-h8j2-2m45.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-268h-h8j2-2m45", - "modified": "2022-07-19T00:00:28Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:28Z", "aliases": [ "CVE-2022-24691" ], "details": "An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-28gc-xw7v-735w/GHSA-28gc-xw7v-735w.json b/advisories/unreviewed/2022/07/GHSA-28gc-xw7v-735w/GHSA-28gc-xw7v-735w.json index a7a97f5ff3f..f42597fe17e 100644 --- a/advisories/unreviewed/2022/07/GHSA-28gc-xw7v-735w/GHSA-28gc-xw7v-735w.json +++ b/advisories/unreviewed/2022/07/GHSA-28gc-xw7v-735w/GHSA-28gc-xw7v-735w.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-28gc-xw7v-735w", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1125" ], "details": "Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-29rh-32p4-4934/GHSA-29rh-32p4-4934.json b/advisories/unreviewed/2022/07/GHSA-29rh-32p4-4934/GHSA-29rh-32p4-4934.json index eb476676ab4..f7c86670df4 100644 --- a/advisories/unreviewed/2022/07/GHSA-29rh-32p4-4934/GHSA-29rh-32p4-4934.json +++ b/advisories/unreviewed/2022/07/GHSA-29rh-32p4-4934/GHSA-29rh-32p4-4934.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-29rh-32p4-4934", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-30301" ], "details": "A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2ccx-rp57-fp56/GHSA-2ccx-rp57-fp56.json b/advisories/unreviewed/2022/07/GHSA-2ccx-rp57-fp56/GHSA-2ccx-rp57-fp56.json new file mode 100644 index 00000000000..a71aaab3220 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-2ccx-rp57-fp56/GHSA-2ccx-rp57-fp56.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-2ccx-rp57-fp56", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1869" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1869" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1309467" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2j4w-p7qh-8g4g/GHSA-2j4w-p7qh-8g4g.json b/advisories/unreviewed/2022/07/GHSA-2j4w-p7qh-8g4g/GHSA-2j4w-p7qh-8g4g.json new file mode 100644 index 00000000000..00adbdecba4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-2j4w-p7qh-8g4g/GHSA-2j4w-p7qh-8g4g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-2j4w-p7qh-8g4g", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1866" + ], + "details": "Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1866" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1292264" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2jg4-f9f6-jf7m/GHSA-2jg4-f9f6-jf7m.json b/advisories/unreviewed/2022/07/GHSA-2jg4-f9f6-jf7m/GHSA-2jg4-f9f6-jf7m.json index eeded5f4e4b..c837f858205 100644 --- a/advisories/unreviewed/2022/07/GHSA-2jg4-f9f6-jf7m/GHSA-2jg4-f9f6-jf7m.json +++ b/advisories/unreviewed/2022/07/GHSA-2jg4-f9f6-jf7m/GHSA-2jg4-f9f6-jf7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2jg4-f9f6-jf7m", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1146" ], "details": "Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2qh6-hhvv-m2ww/GHSA-2qh6-hhvv-m2ww.json b/advisories/unreviewed/2022/07/GHSA-2qh6-hhvv-m2ww/GHSA-2qh6-hhvv-m2ww.json new file mode 100644 index 00000000000..58e989120ab --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-2qh6-hhvv-m2ww/GHSA-2qh6-hhvv-m2ww.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-2qh6-hhvv-m2ww", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36901" + ], + "details": "Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36901" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2053" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2v3j-gjfq-5ccx/GHSA-2v3j-gjfq-5ccx.json b/advisories/unreviewed/2022/07/GHSA-2v3j-gjfq-5ccx/GHSA-2v3j-gjfq-5ccx.json index 7bf8417db24..6d83dc33911 100644 --- a/advisories/unreviewed/2022/07/GHSA-2v3j-gjfq-5ccx/GHSA-2v3j-gjfq-5ccx.json +++ b/advisories/unreviewed/2022/07/GHSA-2v3j-gjfq-5ccx/GHSA-2v3j-gjfq-5ccx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2v3j-gjfq-5ccx", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:45Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1312" ], "details": "Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json b/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json new file mode 100644 index 00000000000..bd75441f4f5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-33vj-x2w7-j3gv", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-23100" + ], + "details": "OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23100" + }, + { + "type": "WEB", + "url": "https://open-xchange.com" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2022/Jul/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json b/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json new file mode 100644 index 00000000000..4f417b48ca4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-359g-8g36-v6qg", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-2313" + ], + "details": "A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2313" + }, + { + "type": "WEB", + "url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10385&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-37rh-j9cp-x58f/GHSA-37rh-j9cp-x58f.json b/advisories/unreviewed/2022/07/GHSA-37rh-j9cp-x58f/GHSA-37rh-j9cp-x58f.json index f8cb5d9c1cb..8caf7d89a0d 100644 --- a/advisories/unreviewed/2022/07/GHSA-37rh-j9cp-x58f/GHSA-37rh-j9cp-x58f.json +++ b/advisories/unreviewed/2022/07/GHSA-37rh-j9cp-x58f/GHSA-37rh-j9cp-x58f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-37rh-j9cp-x58f", - "modified": "2022-07-14T00:00:15Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:15Z", "aliases": [ "CVE-2022-34763" ], "details": "A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-345" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3c2j-x8m7-hrhp/GHSA-3c2j-x8m7-hrhp.json b/advisories/unreviewed/2022/07/GHSA-3c2j-x8m7-hrhp/GHSA-3c2j-x8m7-hrhp.json index 6c3258137be..9c87147a6a3 100644 --- a/advisories/unreviewed/2022/07/GHSA-3c2j-x8m7-hrhp/GHSA-3c2j-x8m7-hrhp.json +++ b/advisories/unreviewed/2022/07/GHSA-3c2j-x8m7-hrhp/GHSA-3c2j-x8m7-hrhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3c2j-x8m7-hrhp", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-2522" ], "details": "Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0060.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3crj-j3hg-7v57/GHSA-3crj-j3hg-7v57.json b/advisories/unreviewed/2022/07/GHSA-3crj-j3hg-7v57/GHSA-3crj-j3hg-7v57.json index 82e6281d9c1..cb4b3fbf515 100644 --- a/advisories/unreviewed/2022/07/GHSA-3crj-j3hg-7v57/GHSA-3crj-j3hg-7v57.json +++ b/advisories/unreviewed/2022/07/GHSA-3crj-j3hg-7v57/GHSA-3crj-j3hg-7v57.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3crj-j3hg-7v57", - "modified": "2022-07-20T00:00:22Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:22Z", "aliases": [ "CVE-2022-24082" ], "details": "If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3fjx-v9x2-fjp6/GHSA-3fjx-v9x2-fjp6.json b/advisories/unreviewed/2022/07/GHSA-3fjx-v9x2-fjp6/GHSA-3fjx-v9x2-fjp6.json new file mode 100644 index 00000000000..08f430d190b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3fjx-v9x2-fjp6/GHSA-3fjx-v9x2-fjp6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3fjx-v9x2-fjp6", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1854" + ], + "details": "Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1854" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1320024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3gw8-89v6-jfv4/GHSA-3gw8-89v6-jfv4.json b/advisories/unreviewed/2022/07/GHSA-3gw8-89v6-jfv4/GHSA-3gw8-89v6-jfv4.json index bcc1ffe856e..be7b6f027af 100644 --- a/advisories/unreviewed/2022/07/GHSA-3gw8-89v6-jfv4/GHSA-3gw8-89v6-jfv4.json +++ b/advisories/unreviewed/2022/07/GHSA-3gw8-89v6-jfv4/GHSA-3gw8-89v6-jfv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3gw8-89v6-jfv4", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-24659" ], "details": "Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3h4v-m4g6-c2v8/GHSA-3h4v-m4g6-c2v8.json b/advisories/unreviewed/2022/07/GHSA-3h4v-m4g6-c2v8/GHSA-3h4v-m4g6-c2v8.json index b42c64d5bf0..e6999b4c85a 100644 --- a/advisories/unreviewed/2022/07/GHSA-3h4v-m4g6-c2v8/GHSA-3h4v-m4g6-c2v8.json +++ b/advisories/unreviewed/2022/07/GHSA-3h4v-m4g6-c2v8/GHSA-3h4v-m4g6-c2v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3h4v-m4g6-c2v8", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1143" ], "details": "Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3jhc-73h5-x7fx/GHSA-3jhc-73h5-x7fx.json b/advisories/unreviewed/2022/07/GHSA-3jhc-73h5-x7fx/GHSA-3jhc-73h5-x7fx.json index 9ca1e6eaea7..341036b425b 100644 --- a/advisories/unreviewed/2022/07/GHSA-3jhc-73h5-x7fx/GHSA-3jhc-73h5-x7fx.json +++ b/advisories/unreviewed/2022/07/GHSA-3jhc-73h5-x7fx/GHSA-3jhc-73h5-x7fx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3jhc-73h5-x7fx", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:42Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-33318" ], "details": "Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to execute an arbitrary malicious code by sending specially crafted packets to the GENESIS64 server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3qv5-4cw7-x42h/GHSA-3qv5-4cw7-x42h.json b/advisories/unreviewed/2022/07/GHSA-3qv5-4cw7-x42h/GHSA-3qv5-4cw7-x42h.json index 22d868e562b..9803e5d2e47 100644 --- a/advisories/unreviewed/2022/07/GHSA-3qv5-4cw7-x42h/GHSA-3qv5-4cw7-x42h.json +++ b/advisories/unreviewed/2022/07/GHSA-3qv5-4cw7-x42h/GHSA-3qv5-4cw7-x42h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3qv5-4cw7-x42h", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-2199" ], "details": "The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3vvp-qmqj-rgmg/GHSA-3vvp-qmqj-rgmg.json b/advisories/unreviewed/2022/07/GHSA-3vvp-qmqj-rgmg/GHSA-3vvp-qmqj-rgmg.json index 795e9c1a895..ab23efab108 100644 --- a/advisories/unreviewed/2022/07/GHSA-3vvp-qmqj-rgmg/GHSA-3vvp-qmqj-rgmg.json +++ b/advisories/unreviewed/2022/07/GHSA-3vvp-qmqj-rgmg/GHSA-3vvp-qmqj-rgmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3vvp-qmqj-rgmg", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34033" ], "details": "HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3wmv-phhj-q327/GHSA-3wmv-phhj-q327.json b/advisories/unreviewed/2022/07/GHSA-3wmv-phhj-q327/GHSA-3wmv-phhj-q327.json index 92c1d4148ac..f84c8722ec3 100644 --- a/advisories/unreviewed/2022/07/GHSA-3wmv-phhj-q327/GHSA-3wmv-phhj-q327.json +++ b/advisories/unreviewed/2022/07/GHSA-3wmv-phhj-q327/GHSA-3wmv-phhj-q327.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3wmv-phhj-q327", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-34759" ], "details": "A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3wr4-g3xj-q452/GHSA-3wr4-g3xj-q452.json b/advisories/unreviewed/2022/07/GHSA-3wr4-g3xj-q452/GHSA-3wr4-g3xj-q452.json index 4e51b97e5d9..47273828513 100644 --- a/advisories/unreviewed/2022/07/GHSA-3wr4-g3xj-q452/GHSA-3wr4-g3xj-q452.json +++ b/advisories/unreviewed/2022/07/GHSA-3wr4-g3xj-q452/GHSA-3wr4-g3xj-q452.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3wr4-g3xj-q452", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1141" ], "details": "Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-429h-8m2j-j6cx/GHSA-429h-8m2j-j6cx.json b/advisories/unreviewed/2022/07/GHSA-429h-8m2j-j6cx/GHSA-429h-8m2j-j6cx.json index 462adfd9e84..22403f4ec10 100644 --- a/advisories/unreviewed/2022/07/GHSA-429h-8m2j-j6cx/GHSA-429h-8m2j-j6cx.json +++ b/advisories/unreviewed/2022/07/GHSA-429h-8m2j-j6cx/GHSA-429h-8m2j-j6cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-429h-8m2j-j6cx", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-33320" ], "details": "Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a project configuration file including malicious XML codes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-449w-c77c-vmf6/GHSA-449w-c77c-vmf6.json b/advisories/unreviewed/2022/07/GHSA-449w-c77c-vmf6/GHSA-449w-c77c-vmf6.json new file mode 100644 index 00000000000..4ae0ef5de7c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-449w-c77c-vmf6/GHSA-449w-c77c-vmf6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-449w-c77c-vmf6", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36884" + ], + "details": "The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36884" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-44mg-h4h9-jj38/GHSA-44mg-h4h9-jj38.json b/advisories/unreviewed/2022/07/GHSA-44mg-h4h9-jj38/GHSA-44mg-h4h9-jj38.json index 4b04653206f..3e4278c60f0 100644 --- a/advisories/unreviewed/2022/07/GHSA-44mg-h4h9-jj38/GHSA-44mg-h4h9-jj38.json +++ b/advisories/unreviewed/2022/07/GHSA-44mg-h4h9-jj38/GHSA-44mg-h4h9-jj38.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-44mg-h4h9-jj38", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-26113" ], "details": "An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-45rr-gg9f-wfcm/GHSA-45rr-gg9f-wfcm.json b/advisories/unreviewed/2022/07/GHSA-45rr-gg9f-wfcm/GHSA-45rr-gg9f-wfcm.json new file mode 100644 index 00000000000..681289f5f64 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-45rr-gg9f-wfcm/GHSA-45rr-gg9f-wfcm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-45rr-gg9f-wfcm", + "modified": "2022-07-28T00:00:48Z", + "published": "2022-07-28T00:00:48Z", + "aliases": [ + "CVE-2022-2310" + ], + "details": "An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2310" + }, + { + "type": "WEB", + "url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-476r-vp22-v7c4/GHSA-476r-vp22-v7c4.json b/advisories/unreviewed/2022/07/GHSA-476r-vp22-v7c4/GHSA-476r-vp22-v7c4.json index 7a80963d961..a051cac8810 100644 --- a/advisories/unreviewed/2022/07/GHSA-476r-vp22-v7c4/GHSA-476r-vp22-v7c4.json +++ b/advisories/unreviewed/2022/07/GHSA-476r-vp22-v7c4/GHSA-476r-vp22-v7c4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-476r-vp22-v7c4", - "modified": "2022-07-26T00:01:07Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:07Z", "aliases": [ "CVE-2022-1232" ], "details": "Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4f96-mfg4-qx5f/GHSA-4f96-mfg4-qx5f.json b/advisories/unreviewed/2022/07/GHSA-4f96-mfg4-qx5f/GHSA-4f96-mfg4-qx5f.json index e7547f8e799..39e97fb6999 100644 --- a/advisories/unreviewed/2022/07/GHSA-4f96-mfg4-qx5f/GHSA-4f96-mfg4-qx5f.json +++ b/advisories/unreviewed/2022/07/GHSA-4f96-mfg4-qx5f/GHSA-4f96-mfg4-qx5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4f96-mfg4-qx5f", - "modified": "2022-07-23T00:00:25Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-23T00:00:25Z", "aliases": [ "CVE-2022-2493" ], "details": "Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-1083" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4h8q-jm55-4xg5/GHSA-4h8q-jm55-4xg5.json b/advisories/unreviewed/2022/07/GHSA-4h8q-jm55-4xg5/GHSA-4h8q-jm55-4xg5.json index 493a509f3f9..153a6442653 100644 --- a/advisories/unreviewed/2022/07/GHSA-4h8q-jm55-4xg5/GHSA-4h8q-jm55-4xg5.json +++ b/advisories/unreviewed/2022/07/GHSA-4h8q-jm55-4xg5/GHSA-4h8q-jm55-4xg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4h8q-jm55-4xg5", - "modified": "2022-07-20T00:00:20Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:20Z", "aliases": [ "CVE-2022-27545" ], "details": "BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4pgr-vxfc-4wm7/GHSA-4pgr-vxfc-4wm7.json b/advisories/unreviewed/2022/07/GHSA-4pgr-vxfc-4wm7/GHSA-4pgr-vxfc-4wm7.json index 4ab7ee93b9f..b3c3f0fa38a 100644 --- a/advisories/unreviewed/2022/07/GHSA-4pgr-vxfc-4wm7/GHSA-4pgr-vxfc-4wm7.json +++ b/advisories/unreviewed/2022/07/GHSA-4pgr-vxfc-4wm7/GHSA-4pgr-vxfc-4wm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4pgr-vxfc-4wm7", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34045" ], "details": "Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json b/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json new file mode 100644 index 00000000000..ab75c45533a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-4pqq-wq2g-6rcm", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-34121" + ], + "details": "Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34121" + }, + { + "type": "WEB", + "url": "https://github.com/CuppaCMS/CuppaCMS/issues/18" + }, + { + "type": "WEB", + "url": "https://github.com/hansmach1ne/MyExploits/tree/main/LFI_in_CuppaCMS_templates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4pr4-pf4q-cm77/GHSA-4pr4-pf4q-cm77.json b/advisories/unreviewed/2022/07/GHSA-4pr4-pf4q-cm77/GHSA-4pr4-pf4q-cm77.json index 5cd0ecaac27..0924044d039 100644 --- a/advisories/unreviewed/2022/07/GHSA-4pr4-pf4q-cm77/GHSA-4pr4-pf4q-cm77.json +++ b/advisories/unreviewed/2022/07/GHSA-4pr4-pf4q-cm77/GHSA-4pr4-pf4q-cm77.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4pr4-pf4q-cm77", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-22360" ], "details": "IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4r8m-m7vp-cj97/GHSA-4r8m-m7vp-cj97.json b/advisories/unreviewed/2022/07/GHSA-4r8m-m7vp-cj97/GHSA-4r8m-m7vp-cj97.json index 924693e6a89..86cf151b0fb 100644 --- a/advisories/unreviewed/2022/07/GHSA-4r8m-m7vp-cj97/GHSA-4r8m-m7vp-cj97.json +++ b/advisories/unreviewed/2022/07/GHSA-4r8m-m7vp-cj97/GHSA-4r8m-m7vp-cj97.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4r8m-m7vp-cj97", - "modified": "2022-07-26T00:00:28Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-26T00:00:28Z", "aliases": [ "CVE-2022-34570" ], "details": "WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4rx6-p6gq-rm2v/GHSA-4rx6-p6gq-rm2v.json b/advisories/unreviewed/2022/07/GHSA-4rx6-p6gq-rm2v/GHSA-4rx6-p6gq-rm2v.json index 352b05d5135..aad4ca4c0e8 100644 --- a/advisories/unreviewed/2022/07/GHSA-4rx6-p6gq-rm2v/GHSA-4rx6-p6gq-rm2v.json +++ b/advisories/unreviewed/2022/07/GHSA-4rx6-p6gq-rm2v/GHSA-4rx6-p6gq-rm2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4rx6-p6gq-rm2v", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1310" ], "details": "Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4v86-x4wc-r83p/GHSA-4v86-x4wc-r83p.json b/advisories/unreviewed/2022/07/GHSA-4v86-x4wc-r83p/GHSA-4v86-x4wc-r83p.json index ad6e2e5f546..761191a3dfc 100644 --- a/advisories/unreviewed/2022/07/GHSA-4v86-x4wc-r83p/GHSA-4v86-x4wc-r83p.json +++ b/advisories/unreviewed/2022/07/GHSA-4v86-x4wc-r83p/GHSA-4v86-x4wc-r83p.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-403.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-4vqc-4jrp-pwj7/GHSA-4vqc-4jrp-pwj7.json b/advisories/unreviewed/2022/07/GHSA-4vqc-4jrp-pwj7/GHSA-4vqc-4jrp-pwj7.json index 91244f1b2b4..f30e3830c56 100644 --- a/advisories/unreviewed/2022/07/GHSA-4vqc-4jrp-pwj7/GHSA-4vqc-4jrp-pwj7.json +++ b/advisories/unreviewed/2022/07/GHSA-4vqc-4jrp-pwj7/GHSA-4vqc-4jrp-pwj7.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4vqc-4jrp-pwj7", - "modified": "2022-07-14T00:00:15Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:15Z", "aliases": [ "CVE-2022-34762" ], "details": "A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4wpp-r5j6-h3hv/GHSA-4wpp-r5j6-h3hv.json b/advisories/unreviewed/2022/07/GHSA-4wpp-r5j6-h3hv/GHSA-4wpp-r5j6-h3hv.json new file mode 100644 index 00000000000..9f8016f7dac --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-4wpp-r5j6-h3hv/GHSA-4wpp-r5j6-h3hv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-4wpp-r5j6-h3hv", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36956" + ], + "details": "In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36956" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-008#Issue1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-545j-89fj-cfc3/GHSA-545j-89fj-cfc3.json b/advisories/unreviewed/2022/07/GHSA-545j-89fj-cfc3/GHSA-545j-89fj-cfc3.json index e9f1f79a5ce..b589ee4669d 100644 --- a/advisories/unreviewed/2022/07/GHSA-545j-89fj-cfc3/GHSA-545j-89fj-cfc3.json +++ b/advisories/unreviewed/2022/07/GHSA-545j-89fj-cfc3/GHSA-545j-89fj-cfc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-545j-89fj-cfc3", - "modified": "2022-07-22T00:00:37Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:37Z", "aliases": [ "CVE-2022-32556" ], "details": "An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json b/advisories/unreviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json deleted file mode 100644 index 2a8594ed42f..00000000000 --- a/advisories/unreviewed/2022/07/GHSA-5469-c5p2-xv5g/GHSA-5469-c5p2-xv5g.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-5469-c5p2-xv5g", - "modified": "2022-07-23T00:00:15Z", - "published": "2022-07-23T00:00:15Z", - "aliases": [ - "CVE-2022-34113" - ], - "details": "An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34113" - }, - { - "type": "WEB", - "url": "https://github.com/dataease/dataease/issues/2431" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-54c2-vr3w-mp8p/GHSA-54c2-vr3w-mp8p.json b/advisories/unreviewed/2022/07/GHSA-54c2-vr3w-mp8p/GHSA-54c2-vr3w-mp8p.json new file mode 100644 index 00000000000..5526c6a0d9c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-54c2-vr3w-mp8p/GHSA-54c2-vr3w-mp8p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-54c2-vr3w-mp8p", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-2550" + ], + "details": "OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2550" + }, + { + "type": "WEB", + "url": "https://github.com/hestiacp/hestiacp/commit/3d4c309cf138943cfd1e71ae51556406987aa4bf" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/6ab4384d-bcbe-4d98-bf67-35c3535fc5c7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-55c8-6r36-9g85/GHSA-55c8-6r36-9g85.json b/advisories/unreviewed/2022/07/GHSA-55c8-6r36-9g85/GHSA-55c8-6r36-9g85.json index 8a7acb55865..dada24052f3 100644 --- a/advisories/unreviewed/2022/07/GHSA-55c8-6r36-9g85/GHSA-55c8-6r36-9g85.json +++ b/advisories/unreviewed/2022/07/GHSA-55c8-6r36-9g85/GHSA-55c8-6r36-9g85.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-55c8-6r36-9g85", - "modified": "2022-07-13T00:00:41Z", + "modified": "2022-07-28T00:00:44Z", "published": "2022-07-13T00:00:41Z", "aliases": [ "CVE-2022-29901" ], "details": "Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-568h-6mc5-cxwg/GHSA-568h-6mc5-cxwg.json b/advisories/unreviewed/2022/07/GHSA-568h-6mc5-cxwg/GHSA-568h-6mc5-cxwg.json new file mode 100644 index 00000000000..475e33c2da6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-568h-6mc5-cxwg/GHSA-568h-6mc5-cxwg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-568h-6mc5-cxwg", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1856" + ], + "details": "Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension or specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1856" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1323239" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-57f2-52wj-7vj6/GHSA-57f2-52wj-7vj6.json b/advisories/unreviewed/2022/07/GHSA-57f2-52wj-7vj6/GHSA-57f2-52wj-7vj6.json new file mode 100644 index 00000000000..f7ed2a504e9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-57f2-52wj-7vj6/GHSA-57f2-52wj-7vj6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-57f2-52wj-7vj6", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36899" + ], + "details": "Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36899" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2629" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-57f2-pm75-ff3p/GHSA-57f2-pm75-ff3p.json b/advisories/unreviewed/2022/07/GHSA-57f2-pm75-ff3p/GHSA-57f2-pm75-ff3p.json index c5801d1ae00..59ef4368a35 100644 --- a/advisories/unreviewed/2022/07/GHSA-57f2-pm75-ff3p/GHSA-57f2-pm75-ff3p.json +++ b/advisories/unreviewed/2022/07/GHSA-57f2-pm75-ff3p/GHSA-57f2-pm75-ff3p.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-57f2-pm75-ff3p", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-36322" ], "details": "In JetBrains TeamCity before 2022.04.2 build parameter injection was possible", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json b/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json index 30eed721d0f..2059ca7e9a1 100644 --- a/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json +++ b/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-59rr-qhh3-g554", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-2141" ], "details": "SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5c97-346q-77p9/GHSA-5c97-346q-77p9.json b/advisories/unreviewed/2022/07/GHSA-5c97-346q-77p9/GHSA-5c97-346q-77p9.json index baa5071a7b1..4fe44eab96e 100644 --- a/advisories/unreviewed/2022/07/GHSA-5c97-346q-77p9/GHSA-5c97-346q-77p9.json +++ b/advisories/unreviewed/2022/07/GHSA-5c97-346q-77p9/GHSA-5c97-346q-77p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5c97-346q-77p9", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-29834" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS GENESIS64 versions 10.97 to 10.97.1 allows a remote unauthenticated attacker to access to arbitrary files in the GENESIS64 server and disclose information stored in the files by embedding a malicious URL parameter in the URL of the monitoring screen delivered to the GENESIS64 mobile monitoring application and accessing the monitoring screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5cvc-6x68-h8qf/GHSA-5cvc-6x68-h8qf.json b/advisories/unreviewed/2022/07/GHSA-5cvc-6x68-h8qf/GHSA-5cvc-6x68-h8qf.json new file mode 100644 index 00000000000..f1bdb9fa28b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5cvc-6x68-h8qf/GHSA-5cvc-6x68-h8qf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5cvc-6x68-h8qf", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-33970" + ], + "details": "Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33970" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-addons/wordpress-shortcode-addons-plugin-3-1-2-authenticated-wordpress-options-change-vulnerability" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/shortcode-addons/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5frp-v5h8-3hgc/GHSA-5frp-v5h8-3hgc.json b/advisories/unreviewed/2022/07/GHSA-5frp-v5h8-3hgc/GHSA-5frp-v5h8-3hgc.json new file mode 100644 index 00000000000..16548cdbbbe --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5frp-v5h8-3hgc/GHSA-5frp-v5h8-3hgc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5frp-v5h8-3hgc", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1875" + ], + "details": "Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1875" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1306443" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json b/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json new file mode 100644 index 00000000000..6054ec5b3a6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5fwv-7q7m-cgxq", + "modified": "2022-07-28T00:00:48Z", + "published": "2022-07-28T00:00:48Z", + "aliases": [ + "CVE-2022-23099" + ], + "details": "OX App Suite through 7.10.6 allows XSS by forcing block-wise read.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23099" + }, + { + "type": "WEB", + "url": "https://open-xchange.com" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2022/Jul/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5mhw-r3wg-5qv3/GHSA-5mhw-r3wg-5qv3.json b/advisories/unreviewed/2022/07/GHSA-5mhw-r3wg-5qv3/GHSA-5mhw-r3wg-5qv3.json index ee4493a8cd8..2fe22ed2762 100644 --- a/advisories/unreviewed/2022/07/GHSA-5mhw-r3wg-5qv3/GHSA-5mhw-r3wg-5qv3.json +++ b/advisories/unreviewed/2022/07/GHSA-5mhw-r3wg-5qv3/GHSA-5mhw-r3wg-5qv3.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-403.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-5mv2-vqq7-mq5h/GHSA-5mv2-vqq7-mq5h.json b/advisories/unreviewed/2022/07/GHSA-5mv2-vqq7-mq5h/GHSA-5mv2-vqq7-mq5h.json new file mode 100644 index 00000000000..76979e211b6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5mv2-vqq7-mq5h/GHSA-5mv2-vqq7-mq5h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5mv2-vqq7-mq5h", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36908" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36908" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1375%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5vgw-67rj-9pxh/GHSA-5vgw-67rj-9pxh.json b/advisories/unreviewed/2022/07/GHSA-5vgw-67rj-9pxh/GHSA-5vgw-67rj-9pxh.json new file mode 100644 index 00000000000..3a1c2c72256 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5vgw-67rj-9pxh/GHSA-5vgw-67rj-9pxh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5vgw-67rj-9pxh", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1858" + ], + "details": "Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1858" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1314310" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5wmq-43vh-pf8j/GHSA-5wmq-43vh-pf8j.json b/advisories/unreviewed/2022/07/GHSA-5wmq-43vh-pf8j/GHSA-5wmq-43vh-pf8j.json index 159cd8c7ab0..da71cac5fa0 100644 --- a/advisories/unreviewed/2022/07/GHSA-5wmq-43vh-pf8j/GHSA-5wmq-43vh-pf8j.json +++ b/advisories/unreviewed/2022/07/GHSA-5wmq-43vh-pf8j/GHSA-5wmq-43vh-pf8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5wmq-43vh-pf8j", - "modified": "2022-07-19T00:00:28Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-19T00:00:28Z", "aliases": [ "CVE-2022-24692" ], "details": "An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the final goal of achieving client-side code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5x3f-7m52-9cgf/GHSA-5x3f-7m52-9cgf.json b/advisories/unreviewed/2022/07/GHSA-5x3f-7m52-9cgf/GHSA-5x3f-7m52-9cgf.json new file mode 100644 index 00000000000..9c362aa4f99 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5x3f-7m52-9cgf/GHSA-5x3f-7m52-9cgf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5x3f-7m52-9cgf", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36920" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36920" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2790%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5xh5-qvf5-xpvp/GHSA-5xh5-qvf5-xpvp.json b/advisories/unreviewed/2022/07/GHSA-5xh5-qvf5-xpvp/GHSA-5xh5-qvf5-xpvp.json index 8e9948b754a..ba726fa421c 100644 --- a/advisories/unreviewed/2022/07/GHSA-5xh5-qvf5-xpvp/GHSA-5xh5-qvf5-xpvp.json +++ b/advisories/unreviewed/2022/07/GHSA-5xh5-qvf5-xpvp/GHSA-5xh5-qvf5-xpvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5xh5-qvf5-xpvp", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34048" ], "details": "Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5xp2-7qfc-fwgc/GHSA-5xp2-7qfc-fwgc.json b/advisories/unreviewed/2022/07/GHSA-5xp2-7qfc-fwgc/GHSA-5xp2-7qfc-fwgc.json new file mode 100644 index 00000000000..766c8484b80 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5xp2-7qfc-fwgc/GHSA-5xp2-7qfc-fwgc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5xp2-7qfc-fwgc", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36900" + ], + "details": "Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36900" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2630" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-62wh-m4jr-233r/GHSA-62wh-m4jr-233r.json b/advisories/unreviewed/2022/07/GHSA-62wh-m4jr-233r/GHSA-62wh-m4jr-233r.json index ecb877a27d5..08a2ba89a99 100644 --- a/advisories/unreviewed/2022/07/GHSA-62wh-m4jr-233r/GHSA-62wh-m4jr-233r.json +++ b/advisories/unreviewed/2022/07/GHSA-62wh-m4jr-233r/GHSA-62wh-m4jr-233r.json @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106277" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=436460" diff --git a/advisories/unreviewed/2022/07/GHSA-637x-cm53-gcgj/GHSA-637x-cm53-gcgj.json b/advisories/unreviewed/2022/07/GHSA-637x-cm53-gcgj/GHSA-637x-cm53-gcgj.json index 0ca693201f8..130f718a4b4 100644 --- a/advisories/unreviewed/2022/07/GHSA-637x-cm53-gcgj/GHSA-637x-cm53-gcgj.json +++ b/advisories/unreviewed/2022/07/GHSA-637x-cm53-gcgj/GHSA-637x-cm53-gcgj.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-403.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-63px-7j2g-6pfw/GHSA-63px-7j2g-6pfw.json b/advisories/unreviewed/2022/07/GHSA-63px-7j2g-6pfw/GHSA-63px-7j2g-6pfw.json new file mode 100644 index 00000000000..4bb1390cd23 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-63px-7j2g-6pfw/GHSA-63px-7j2g-6pfw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-63px-7j2g-6pfw", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1874" + ], + "details": "Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1874" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1251588" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-64g8-mc22-c972/GHSA-64g8-mc22-c972.json b/advisories/unreviewed/2022/07/GHSA-64g8-mc22-c972/GHSA-64g8-mc22-c972.json index 14f65b86c4c..4755d2d7062 100644 --- a/advisories/unreviewed/2022/07/GHSA-64g8-mc22-c972/GHSA-64g8-mc22-c972.json +++ b/advisories/unreviewed/2022/07/GHSA-64g8-mc22-c972/GHSA-64g8-mc22-c972.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-64g8-mc22-c972", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:46Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2020-21405" ], "details": "An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-67gr-jwjp-pv3x/GHSA-67gr-jwjp-pv3x.json b/advisories/unreviewed/2022/07/GHSA-67gr-jwjp-pv3x/GHSA-67gr-jwjp-pv3x.json index 67b948f0788..e8ed6b9b370 100644 --- a/advisories/unreviewed/2022/07/GHSA-67gr-jwjp-pv3x/GHSA-67gr-jwjp-pv3x.json +++ b/advisories/unreviewed/2022/07/GHSA-67gr-jwjp-pv3x/GHSA-67gr-jwjp-pv3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-67gr-jwjp-pv3x", - "modified": "2022-07-19T00:00:27Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:27Z", "aliases": [ "CVE-2022-34902" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Desktop Control Agent service. The service loads Qt plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-15787.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6954-h5c8-m29f/GHSA-6954-h5c8-m29f.json b/advisories/unreviewed/2022/07/GHSA-6954-h5c8-m29f/GHSA-6954-h5c8-m29f.json new file mode 100644 index 00000000000..29fcf6f2123 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6954-h5c8-m29f/GHSA-6954-h5c8-m29f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6954-h5c8-m29f", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36922" + ], + "details": "Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36922" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2812" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6ghr-92ff-p76m/GHSA-6ghr-92ff-p76m.json b/advisories/unreviewed/2022/07/GHSA-6ghr-92ff-p76m/GHSA-6ghr-92ff-p76m.json index a7fc8b6b25b..7ae120fe362 100644 --- a/advisories/unreviewed/2022/07/GHSA-6ghr-92ff-p76m/GHSA-6ghr-92ff-p76m.json +++ b/advisories/unreviewed/2022/07/GHSA-6ghr-92ff-p76m/GHSA-6ghr-92ff-p76m.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=086ff84617185393a0bbf25830c4f36412a7d3f4" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/07/19/2" diff --git a/advisories/unreviewed/2022/07/GHSA-6x2v-hvx7-m5x7/GHSA-6x2v-hvx7-m5x7.json b/advisories/unreviewed/2022/07/GHSA-6x2v-hvx7-m5x7/GHSA-6x2v-hvx7-m5x7.json index 7d33eb78fe3..b32d1e1a69e 100644 --- a/advisories/unreviewed/2022/07/GHSA-6x2v-hvx7-m5x7/GHSA-6x2v-hvx7-m5x7.json +++ b/advisories/unreviewed/2022/07/GHSA-6x2v-hvx7-m5x7/GHSA-6x2v-hvx7-m5x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-6x2v-hvx7-m5x7", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1137" ], "details": "Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6x63-hrxg-2hjx/GHSA-6x63-hrxg-2hjx.json b/advisories/unreviewed/2022/07/GHSA-6x63-hrxg-2hjx/GHSA-6x63-hrxg-2hjx.json new file mode 100644 index 00000000000..4b32a4a00a2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6x63-hrxg-2hjx/GHSA-6x63-hrxg-2hjx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6x63-hrxg-2hjx", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36886" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36886" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2762" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6xf5-c3cx-67pv/GHSA-6xf5-c3cx-67pv.json b/advisories/unreviewed/2022/07/GHSA-6xf5-c3cx-67pv/GHSA-6xf5-c3cx-67pv.json new file mode 100644 index 00000000000..6cfa10ce8e1 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6xf5-c3cx-67pv/GHSA-6xf5-c3cx-67pv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6xf5-c3cx-67pv", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36894" + ], + "details": "An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36894" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2413" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7425-c3x3-hhjq/GHSA-7425-c3x3-hhjq.json b/advisories/unreviewed/2022/07/GHSA-7425-c3x3-hhjq/GHSA-7425-c3x3-hhjq.json index 1c2e58ade28..f6a5115e085 100644 --- a/advisories/unreviewed/2022/07/GHSA-7425-c3x3-hhjq/GHSA-7425-c3x3-hhjq.json +++ b/advisories/unreviewed/2022/07/GHSA-7425-c3x3-hhjq/GHSA-7425-c3x3-hhjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7425-c3x3-hhjq", - "modified": "2022-07-14T00:00:15Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:15Z", "aliases": [ "CVE-2022-34760" ], "details": "A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-75fc-fv3p-xh82/GHSA-75fc-fv3p-xh82.json b/advisories/unreviewed/2022/07/GHSA-75fc-fv3p-xh82/GHSA-75fc-fv3p-xh82.json new file mode 100644 index 00000000000..039b316ec58 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-75fc-fv3p-xh82/GHSA-75fc-fv3p-xh82.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-75fc-fv3p-xh82", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36896" + ], + "details": "A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36896" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2621" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-76pg-mr9v-5vwc/GHSA-76pg-mr9v-5vwc.json b/advisories/unreviewed/2022/07/GHSA-76pg-mr9v-5vwc/GHSA-76pg-mr9v-5vwc.json new file mode 100644 index 00000000000..560e7d65d34 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-76pg-mr9v-5vwc/GHSA-76pg-mr9v-5vwc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-76pg-mr9v-5vwc", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36903" + ], + "details": "A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36903" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2665%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-78fg-pvgg-6g3r/GHSA-78fg-pvgg-6g3r.json b/advisories/unreviewed/2022/07/GHSA-78fg-pvgg-6g3r/GHSA-78fg-pvgg-6g3r.json new file mode 100644 index 00000000000..6d9fc2f46b4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-78fg-pvgg-6g3r/GHSA-78fg-pvgg-6g3r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-78fg-pvgg-6g3r", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36909" + ], + "details": "A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36909" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1375%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-79x9-477g-w256/GHSA-79x9-477g-w256.json b/advisories/unreviewed/2022/07/GHSA-79x9-477g-w256/GHSA-79x9-477g-w256.json new file mode 100644 index 00000000000..4ebaf052986 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-79x9-477g-w256/GHSA-79x9-477g-w256.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-79x9-477g-w256", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36918" + ], + "details": "Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36918" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2747" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7f66-v639-c98w/GHSA-7f66-v639-c98w.json b/advisories/unreviewed/2022/07/GHSA-7f66-v639-c98w/GHSA-7f66-v639-c98w.json new file mode 100644 index 00000000000..1f671207b77 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-7f66-v639-c98w/GHSA-7f66-v639-c98w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-7f66-v639-c98w", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1863" + ], + "details": "Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1863" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1292870" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7ghq-6v49-v396/GHSA-7ghq-6v49-v396.json b/advisories/unreviewed/2022/07/GHSA-7ghq-6v49-v396/GHSA-7ghq-6v49-v396.json index c96a86791a2..b66a6e502c7 100644 --- a/advisories/unreviewed/2022/07/GHSA-7ghq-6v49-v396/GHSA-7ghq-6v49-v396.json +++ b/advisories/unreviewed/2022/07/GHSA-7ghq-6v49-v396/GHSA-7ghq-6v49-v396.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7ghq-6v49-v396", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-27483" ], "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose system` CLI commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7j35-6pjq-q8rw/GHSA-7j35-6pjq-q8rw.json b/advisories/unreviewed/2022/07/GHSA-7j35-6pjq-q8rw/GHSA-7j35-6pjq-q8rw.json index ad453450f2c..b09af179f63 100644 --- a/advisories/unreviewed/2022/07/GHSA-7j35-6pjq-q8rw/GHSA-7j35-6pjq-q8rw.json +++ b/advisories/unreviewed/2022/07/GHSA-7j35-6pjq-q8rw/GHSA-7j35-6pjq-q8rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7j35-6pjq-q8rw", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-33319" ], "details": "Out-of-bounds Read vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64 server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7jfp-3xr4-m7m9/GHSA-7jfp-3xr4-m7m9.json b/advisories/unreviewed/2022/07/GHSA-7jfp-3xr4-m7m9/GHSA-7jfp-3xr4-m7m9.json index 1c88708b1b3..3d8ce45fea9 100644 --- a/advisories/unreviewed/2022/07/GHSA-7jfp-3xr4-m7m9/GHSA-7jfp-3xr4-m7m9.json +++ b/advisories/unreviewed/2022/07/GHSA-7jfp-3xr4-m7m9/GHSA-7jfp-3xr4-m7m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7jfp-3xr4-m7m9", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:44Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1309" ], "details": "Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7mhv-mcwq-rh85/GHSA-7mhv-mcwq-rh85.json b/advisories/unreviewed/2022/07/GHSA-7mhv-mcwq-rh85/GHSA-7mhv-mcwq-rh85.json index ca2f4d95e20..d212b274afc 100644 --- a/advisories/unreviewed/2022/07/GHSA-7mhv-mcwq-rh85/GHSA-7mhv-mcwq-rh85.json +++ b/advisories/unreviewed/2022/07/GHSA-7mhv-mcwq-rh85/GHSA-7mhv-mcwq-rh85.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7mhv-mcwq-rh85", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34150" ], "details": "The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7ppp-q5f6-j96f/GHSA-7ppp-q5f6-j96f.json b/advisories/unreviewed/2022/07/GHSA-7ppp-q5f6-j96f/GHSA-7ppp-q5f6-j96f.json index 355b3bc3796..a5106e650ba 100644 --- a/advisories/unreviewed/2022/07/GHSA-7ppp-q5f6-j96f/GHSA-7ppp-q5f6-j96f.json +++ b/advisories/unreviewed/2022/07/GHSA-7ppp-q5f6-j96f/GHSA-7ppp-q5f6-j96f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7ppp-q5f6-j96f", - "modified": "2022-07-14T00:00:17Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-14T00:00:17Z", "aliases": [ "CVE-2022-34358" ], "details": "IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8294-mv9c-7m5h/GHSA-8294-mv9c-7m5h.json b/advisories/unreviewed/2022/07/GHSA-8294-mv9c-7m5h/GHSA-8294-mv9c-7m5h.json new file mode 100644 index 00000000000..e000c2371a2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8294-mv9c-7m5h/GHSA-8294-mv9c-7m5h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8294-mv9c-7m5h", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36905" + ], + "details": "Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36905" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2686" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8528-c6m6-gppm/GHSA-8528-c6m6-gppm.json b/advisories/unreviewed/2022/07/GHSA-8528-c6m6-gppm/GHSA-8528-c6m6-gppm.json new file mode 100644 index 00000000000..6a817367e89 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8528-c6m6-gppm/GHSA-8528-c6m6-gppm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8528-c6m6-gppm", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36906" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36906" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1375%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-87cc-pvcr-mp5p/GHSA-87cc-pvcr-mp5p.json b/advisories/unreviewed/2022/07/GHSA-87cc-pvcr-mp5p/GHSA-87cc-pvcr-mp5p.json index 5f9b44a0ef0..2afa6a9ab4f 100644 --- a/advisories/unreviewed/2022/07/GHSA-87cc-pvcr-mp5p/GHSA-87cc-pvcr-mp5p.json +++ b/advisories/unreviewed/2022/07/GHSA-87cc-pvcr-mp5p/GHSA-87cc-pvcr-mp5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-87cc-pvcr-mp5p", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-29057" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json b/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json new file mode 100644 index 00000000000..1a6c8173adb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-87p7-px4m-hqv2", + "modified": "2022-07-28T00:00:53Z", + "published": "2022-07-28T00:00:53Z", + "aliases": [ + "CVE-2022-36880" + ], + "details": "The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36880" + }, + { + "type": "WEB", + "url": "https://www.webmin.com/security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json b/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json new file mode 100644 index 00000000000..003ec692a33 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-88wm-pv8r-fc9q", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-35672" + ], + "details": "Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35672" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb22-16.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-897m-9wc9-hrr8/GHSA-897m-9wc9-hrr8.json b/advisories/unreviewed/2022/07/GHSA-897m-9wc9-hrr8/GHSA-897m-9wc9-hrr8.json index 1ea7801d8c2..44def8667ef 100644 --- a/advisories/unreviewed/2022/07/GHSA-897m-9wc9-hrr8/GHSA-897m-9wc9-hrr8.json +++ b/advisories/unreviewed/2022/07/GHSA-897m-9wc9-hrr8/GHSA-897m-9wc9-hrr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-897m-9wc9-hrr8", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1127" ], "details": "Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8995-37xw-9hjj/GHSA-8995-37xw-9hjj.json b/advisories/unreviewed/2022/07/GHSA-8995-37xw-9hjj/GHSA-8995-37xw-9hjj.json index c67c569e1a2..8758ff4bfbe 100644 --- a/advisories/unreviewed/2022/07/GHSA-8995-37xw-9hjj/GHSA-8995-37xw-9hjj.json +++ b/advisories/unreviewed/2022/07/GHSA-8995-37xw-9hjj/GHSA-8995-37xw-9hjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8995-37xw-9hjj", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-34756" ], "details": "A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json b/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json new file mode 100644 index 00000000000..90e0ec4c5bb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8fqx-rxr6-9fxc", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-33943" + ], + "details": "Authenticated (contributor or higher user role) Cross-Site Scripting (XSS) vulnerability in Nico Amarilla's BxSlider WP plugin <= 2.0.0 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33943" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bxslider-wp/wordpress-bxslider-wp-plugin-2-0-0-authenticated-cross-site-scripting-xss-vulnerability" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bxslider-wp/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8g36-x4m7-xxrc/GHSA-8g36-x4m7-xxrc.json b/advisories/unreviewed/2022/07/GHSA-8g36-x4m7-xxrc/GHSA-8g36-x4m7-xxrc.json new file mode 100644 index 00000000000..9dd741c83c4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8g36-x4m7-xxrc/GHSA-8g36-x4m7-xxrc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8g36-x4m7-xxrc", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1862" + ], + "details": "Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1862" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1236325" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8g4c-686x-3qcc/GHSA-8g4c-686x-3qcc.json b/advisories/unreviewed/2022/07/GHSA-8g4c-686x-3qcc/GHSA-8g4c-686x-3qcc.json index 9965255a0e2..1b9a3d263a4 100644 --- a/advisories/unreviewed/2022/07/GHSA-8g4c-686x-3qcc/GHSA-8g4c-686x-3qcc.json +++ b/advisories/unreviewed/2022/07/GHSA-8g4c-686x-3qcc/GHSA-8g4c-686x-3qcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8g4c-686x-3qcc", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-34757" ], "details": "A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between Easergy Pro software and the device, which may allow an attacker to observe protected communication details. Affected Products: Easergy P5 (V01.401.102 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-327" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8gxf-mfg7-c3xr/GHSA-8gxf-mfg7-c3xr.json b/advisories/unreviewed/2022/07/GHSA-8gxf-mfg7-c3xr/GHSA-8gxf-mfg7-c3xr.json index 1b100d21a98..ebab84d57f3 100644 --- a/advisories/unreviewed/2022/07/GHSA-8gxf-mfg7-c3xr/GHSA-8gxf-mfg7-c3xr.json +++ b/advisories/unreviewed/2022/07/GHSA-8gxf-mfg7-c3xr/GHSA-8gxf-mfg7-c3xr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8gxf-mfg7-c3xr", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1308" ], "details": "Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json b/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json new file mode 100644 index 00000000000..4d2c0714b6d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8hmj-5292-j8w9", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-34551" + ], + "details": "Sims v1.0 was discovered to allow path traversal when downloading attachments.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34551" + }, + { + "type": "WEB", + "url": "https://github.com/rawchen/sims/issues/7" + }, + { + "type": "WEB", + "url": "http://cwe.mitre.org/data/definitions/23.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8qg3-pfc8-ph4h/GHSA-8qg3-pfc8-ph4h.json b/advisories/unreviewed/2022/07/GHSA-8qg3-pfc8-ph4h/GHSA-8qg3-pfc8-ph4h.json index 9a502c64f39..a87bd9ea383 100644 --- a/advisories/unreviewed/2022/07/GHSA-8qg3-pfc8-ph4h/GHSA-8qg3-pfc8-ph4h.json +++ b/advisories/unreviewed/2022/07/GHSA-8qg3-pfc8-ph4h/GHSA-8qg3-pfc8-ph4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8qg3-pfc8-ph4h", - "modified": "2022-07-21T00:00:30Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:30Z", "aliases": [ "CVE-2022-22202" ], "details": "An Improper Handling of Exceptional Conditions vulnerability on specific PTX Series devices, including the PTX1000, PTX3000 (NextGen), PTX5000, PTX10002-60C, PTX10008, and PTX10016 Series, in Juniper Networks Junos OS allows an unauthenticated MPLS-based attacker to cause a Denial of Service (DoS) by triggering the dcpfe process to crash and FPC to restart. On affected PTX Series devices, processing specific MPLS packets received on an interface with multiple units configured may cause FPC to restart unexpectedly. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects PTX Series devices utilizing specific FPCs found on PTX1000, PTX3000 (NextGen), PTX5000, PTX10002-60C, PTX10008, and PTX10016 Series devices, only if multiple units are configured on the ingress interface, and at least one unit has 'family mpls' *not* configured. See the configuration sample below for more information. No other platforms are affected by this vulnerability. This issue affects: Juniper Networks Junos OS on PTX Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R3-S8; 20.1 versions prior to 20.1R3-S4; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S4; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8qp3-mmfx-p4h5/GHSA-8qp3-mmfx-p4h5.json b/advisories/unreviewed/2022/07/GHSA-8qp3-mmfx-p4h5/GHSA-8qp3-mmfx-p4h5.json new file mode 100644 index 00000000000..cddbb9a16d0 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8qp3-mmfx-p4h5/GHSA-8qp3-mmfx-p4h5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8qp3-mmfx-p4h5", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1872" + ], + "details": "Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1872" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1310461" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json b/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json new file mode 100644 index 00000000000..7b85baf9b07 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8vjc-vph9-rg4j", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2021-42535" + ], + "details": "VISAM VBASE version 11.6.0.6 does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42535" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8xwj-2wgh-gprh/GHSA-8xwj-2wgh-gprh.json b/advisories/unreviewed/2022/07/GHSA-8xwj-2wgh-gprh/GHSA-8xwj-2wgh-gprh.json new file mode 100644 index 00000000000..8f33a0be695 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8xwj-2wgh-gprh/GHSA-8xwj-2wgh-gprh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8xwj-2wgh-gprh", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36882" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36882" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-93f5-xcv7-w96r/GHSA-93f5-xcv7-w96r.json b/advisories/unreviewed/2022/07/GHSA-93f5-xcv7-w96r/GHSA-93f5-xcv7-w96r.json index 0009e694213..a9b1b9df236 100644 --- a/advisories/unreviewed/2022/07/GHSA-93f5-xcv7-w96r/GHSA-93f5-xcv7-w96r.json +++ b/advisories/unreviewed/2022/07/GHSA-93f5-xcv7-w96r/GHSA-93f5-xcv7-w96r.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-93f5-xcv7-w96r", - "modified": "2022-07-13T00:01:56Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-13T00:01:56Z", "aliases": [ "CVE-2022-30938" ], "details": "A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). Affected applications contains a memory corruption vulnerability while parsing specially crafted HTTP packets to /txtrace endpoint manupulating a specific argument. This could allow an attacker to crash the affected application leading to a denial of service condition", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-93rr-jgp3-wcw3/GHSA-93rr-jgp3-wcw3.json b/advisories/unreviewed/2022/07/GHSA-93rr-jgp3-wcw3/GHSA-93rr-jgp3-wcw3.json index 6d01975aa70..71d3a6ca96b 100644 --- a/advisories/unreviewed/2022/07/GHSA-93rr-jgp3-wcw3/GHSA-93rr-jgp3-wcw3.json +++ b/advisories/unreviewed/2022/07/GHSA-93rr-jgp3-wcw3/GHSA-93rr-jgp3-wcw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-93rr-jgp3-wcw3", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-33315" ], "details": "Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-96p9-4wxh-2hwm/GHSA-96p9-4wxh-2hwm.json b/advisories/unreviewed/2022/07/GHSA-96p9-4wxh-2hwm/GHSA-96p9-4wxh-2hwm.json index 691df4013ff..7242715b31b 100644 --- a/advisories/unreviewed/2022/07/GHSA-96p9-4wxh-2hwm/GHSA-96p9-4wxh-2hwm.json +++ b/advisories/unreviewed/2022/07/GHSA-96p9-4wxh-2hwm/GHSA-96p9-4wxh-2hwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-96p9-4wxh-2hwm", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1134" ], "details": "Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-975q-8v3h-8j23/GHSA-975q-8v3h-8j23.json b/advisories/unreviewed/2022/07/GHSA-975q-8v3h-8j23/GHSA-975q-8v3h-8j23.json index f3695a88d74..5881b2ab4d6 100644 --- a/advisories/unreviewed/2022/07/GHSA-975q-8v3h-8j23/GHSA-975q-8v3h-8j23.json +++ b/advisories/unreviewed/2022/07/GHSA-975q-8v3h-8j23/GHSA-975q-8v3h-8j23.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5188" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5192" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2022.html" diff --git a/advisories/unreviewed/2022/07/GHSA-99mq-hw5m-gwjj/GHSA-99mq-hw5m-gwjj.json b/advisories/unreviewed/2022/07/GHSA-99mq-hw5m-gwjj/GHSA-99mq-hw5m-gwjj.json new file mode 100644 index 00000000000..9e4a94ecd08 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-99mq-hw5m-gwjj/GHSA-99mq-hw5m-gwjj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-99mq-hw5m-gwjj", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36921" + ], + "details": "A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36921" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2790%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9cvx-cr48-6ghq/GHSA-9cvx-cr48-6ghq.json b/advisories/unreviewed/2022/07/GHSA-9cvx-cr48-6ghq/GHSA-9cvx-cr48-6ghq.json index c803e9baf54..66c4ac79e10 100644 --- a/advisories/unreviewed/2022/07/GHSA-9cvx-cr48-6ghq/GHSA-9cvx-cr48-6ghq.json +++ b/advisories/unreviewed/2022/07/GHSA-9cvx-cr48-6ghq/GHSA-9cvx-cr48-6ghq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9cvx-cr48-6ghq", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-2179" ], "details": "The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9ggc-7v6w-qg26/GHSA-9ggc-7v6w-qg26.json b/advisories/unreviewed/2022/07/GHSA-9ggc-7v6w-qg26/GHSA-9ggc-7v6w-qg26.json new file mode 100644 index 00000000000..65d7886dc29 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9ggc-7v6w-qg26/GHSA-9ggc-7v6w-qg26.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9ggc-7v6w-qg26", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36952" + ], + "details": "In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36952" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9hx4-8365-w7gm/GHSA-9hx4-8365-w7gm.json b/advisories/unreviewed/2022/07/GHSA-9hx4-8365-w7gm/GHSA-9hx4-8365-w7gm.json new file mode 100644 index 00000000000..06694d8607b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9hx4-8365-w7gm/GHSA-9hx4-8365-w7gm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9hx4-8365-w7gm", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1867" + ], + "details": "Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1867" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1315563" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9jvf-2hr4-2rrp/GHSA-9jvf-2hr4-2rrp.json b/advisories/unreviewed/2022/07/GHSA-9jvf-2hr4-2rrp/GHSA-9jvf-2hr4-2rrp.json index 0f99763ed0d..1ca3ce73ff5 100644 --- a/advisories/unreviewed/2022/07/GHSA-9jvf-2hr4-2rrp/GHSA-9jvf-2hr4-2rrp.json +++ b/advisories/unreviewed/2022/07/GHSA-9jvf-2hr4-2rrp/GHSA-9jvf-2hr4-2rrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9jvf-2hr4-2rrp", - "modified": "2022-07-21T00:00:30Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:30Z", "aliases": [ "CVE-2022-22203" ], "details": "An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc process will crash followed by the FPC reboot upon receipt of a specific hostbound packet. Continued receipt of these specific packets will create a sustained Denial of Service (DoS) condition. This issue only affects Juniper Networks Junos OS 19.4 version 19.4R3-S4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-697" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json b/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json new file mode 100644 index 00000000000..c43b8ceba44 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9r87-pc5m-9w97", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2020-6998" + ], + "details": "The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-6998" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9v26-h3ph-p8v7/GHSA-9v26-h3ph-p8v7.json b/advisories/unreviewed/2022/07/GHSA-9v26-h3ph-p8v7/GHSA-9v26-h3ph-p8v7.json index cc5c8c1b79d..e13c957a3cb 100644 --- a/advisories/unreviewed/2022/07/GHSA-9v26-h3ph-p8v7/GHSA-9v26-h3ph-p8v7.json +++ b/advisories/unreviewed/2022/07/GHSA-9v26-h3ph-p8v7/GHSA-9v26-h3ph-p8v7.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lore.kernel.org/netfilter-devel/cd9428b6-7ffb-dd22-d949-d86f4869f452@randorisec.fr/T/#u" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2022/07/02/3" diff --git a/advisories/unreviewed/2022/07/GHSA-9wq5-2p9c-q5w5/GHSA-9wq5-2p9c-q5w5.json b/advisories/unreviewed/2022/07/GHSA-9wq5-2p9c-q5w5/GHSA-9wq5-2p9c-q5w5.json index 0c210a4b9f1..6210b2fd6ce 100644 --- a/advisories/unreviewed/2022/07/GHSA-9wq5-2p9c-q5w5/GHSA-9wq5-2p9c-q5w5.json +++ b/advisories/unreviewed/2022/07/GHSA-9wq5-2p9c-q5w5/GHSA-9wq5-2p9c-q5w5.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9wq5-2p9c-q5w5", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1130" ], "details": "Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9xhm-6w5p-335v/GHSA-9xhm-6w5p-335v.json b/advisories/unreviewed/2022/07/GHSA-9xhm-6w5p-335v/GHSA-9xhm-6w5p-335v.json new file mode 100644 index 00000000000..c91f6e8679b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9xhm-6w5p-335v/GHSA-9xhm-6w5p-335v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9xhm-6w5p-335v", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36917" + ], + "details": "A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36917" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2656" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json b/advisories/unreviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json deleted file mode 100644 index dff5be4a69a..00000000000 --- a/advisories/unreviewed/2022/07/GHSA-c2pj-rr68-pw94/GHSA-c2pj-rr68-pw94.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-c2pj-rr68-pw94", - "modified": "2022-07-23T00:00:15Z", - "published": "2022-07-23T00:00:15Z", - "aliases": [ - "CVE-2022-34112" - ], - "details": "An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34112" - }, - { - "type": "WEB", - "url": "https://github.com/dataease/dataease/issues/2429" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c49c-362q-5gfw/GHSA-c49c-362q-5gfw.json b/advisories/unreviewed/2022/07/GHSA-c49c-362q-5gfw/GHSA-c49c-362q-5gfw.json index 8138fe49e22..0eb524e641c 100644 --- a/advisories/unreviewed/2022/07/GHSA-c49c-362q-5gfw/GHSA-c49c-362q-5gfw.json +++ b/advisories/unreviewed/2022/07/GHSA-c49c-362q-5gfw/GHSA-c49c-362q-5gfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-c49c-362q-5gfw", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1313" ], "details": "Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json b/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json new file mode 100644 index 00000000000..ff4ad5a306b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c4wx-gc8f-7fj9", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-27610" + ], + "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27610" + }, + { + "type": "WEB", + "url": "https://www.synology.com/security/advisory/Synology_SA_20_06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c786-7jf2-46w9/GHSA-c786-7jf2-46w9.json b/advisories/unreviewed/2022/07/GHSA-c786-7jf2-46w9/GHSA-c786-7jf2-46w9.json index a89beb06feb..c212ec27e17 100644 --- a/advisories/unreviewed/2022/07/GHSA-c786-7jf2-46w9/GHSA-c786-7jf2-46w9.json +++ b/advisories/unreviewed/2022/07/GHSA-c786-7jf2-46w9/GHSA-c786-7jf2-46w9.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-21549" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5192" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2022.html" diff --git a/advisories/unreviewed/2022/07/GHSA-c873-6fqc-4wg3/GHSA-c873-6fqc-4wg3.json b/advisories/unreviewed/2022/07/GHSA-c873-6fqc-4wg3/GHSA-c873-6fqc-4wg3.json index 0902aafa1d0..9ae016b568a 100644 --- a/advisories/unreviewed/2022/07/GHSA-c873-6fqc-4wg3/GHSA-c873-6fqc-4wg3.json +++ b/advisories/unreviewed/2022/07/GHSA-c873-6fqc-4wg3/GHSA-c873-6fqc-4wg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-c873-6fqc-4wg3", - "modified": "2022-07-22T00:00:38Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-22T00:00:38Z", "aliases": [ "CVE-2022-34767" ], "details": "Web page which \"wizardpwd.asp\" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at \"admin\" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cc4m-5453-r7jw/GHSA-cc4m-5453-r7jw.json b/advisories/unreviewed/2022/07/GHSA-cc4m-5453-r7jw/GHSA-cc4m-5453-r7jw.json index 1bae0ca3c28..569a34bdaf3 100644 --- a/advisories/unreviewed/2022/07/GHSA-cc4m-5453-r7jw/GHSA-cc4m-5453-r7jw.json +++ b/advisories/unreviewed/2022/07/GHSA-cc4m-5453-r7jw/GHSA-cc4m-5453-r7jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-cc4m-5453-r7jw", - "modified": "2022-07-22T00:00:36Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-22T00:00:36Z", "aliases": [ "CVE-2022-28877" ], "details": "This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution rights on the victim machine prior to successful exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json b/advisories/unreviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json deleted file mode 100644 index 4221ff33ed5..00000000000 --- a/advisories/unreviewed/2022/07/GHSA-cfcg-2qgr-v243/GHSA-cfcg-2qgr-v243.json +++ /dev/null @@ -1,37 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-cfcg-2qgr-v243", - "modified": "2022-07-23T00:00:22Z", - "published": "2022-07-23T00:00:22Z", - "aliases": [ - "CVE-2022-2470" - ], - "details": "Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2470" - }, - { - "type": "WEB", - "url": "https://github.com/microweber/microweber/commit/d28655183800b833abb20ccd55e1628f16ff65e4" - }, - { - "type": "WEB", - "url": "https://huntr.dev/bounties/3f1f679c-c243-431c-8ed0-e61543b9921b" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": null, - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cjgm-9qhj-94wr/GHSA-cjgm-9qhj-94wr.json b/advisories/unreviewed/2022/07/GHSA-cjgm-9qhj-94wr/GHSA-cjgm-9qhj-94wr.json index 338d460dd88..eb0b7d887af 100644 --- a/advisories/unreviewed/2022/07/GHSA-cjgm-9qhj-94wr/GHSA-cjgm-9qhj-94wr.json +++ b/advisories/unreviewed/2022/07/GHSA-cjgm-9qhj-94wr/GHSA-cjgm-9qhj-94wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-cjgm-9qhj-94wr", - "modified": "2022-07-20T00:00:25Z", + "modified": "2022-07-28T00:00:50Z", "published": "2022-07-20T00:00:25Z", "aliases": [ "CVE-2022-2468" ], "details": "A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cm5q-x57v-2v56/GHSA-cm5q-x57v-2v56.json b/advisories/unreviewed/2022/07/GHSA-cm5q-x57v-2v56/GHSA-cm5q-x57v-2v56.json new file mode 100644 index 00000000000..9b2a406a1fc --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cm5q-x57v-2v56/GHSA-cm5q-x57v-2v56.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cm5q-x57v-2v56", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1861" + ], + "details": "Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1861" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1316846" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cm7j-p8hc-97vj/GHSA-cm7j-p8hc-97vj.json b/advisories/unreviewed/2022/07/GHSA-cm7j-p8hc-97vj/GHSA-cm7j-p8hc-97vj.json new file mode 100644 index 00000000000..a96fe47d9eb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cm7j-p8hc-97vj/GHSA-cm7j-p8hc-97vj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cm7j-p8hc-97vj", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36881" + ], + "details": "Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36881" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1468" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-322" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cp5r-xqjr-84gm/GHSA-cp5r-xqjr-84gm.json b/advisories/unreviewed/2022/07/GHSA-cp5r-xqjr-84gm/GHSA-cp5r-xqjr-84gm.json new file mode 100644 index 00000000000..265a608b7f9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cp5r-xqjr-84gm/GHSA-cp5r-xqjr-84gm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cp5r-xqjr-84gm", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36898" + ], + "details": "A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36898" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2628" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cpgc-248w-frqc/GHSA-cpgc-248w-frqc.json b/advisories/unreviewed/2022/07/GHSA-cpgc-248w-frqc/GHSA-cpgc-248w-frqc.json new file mode 100644 index 00000000000..3ebcf49b171 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cpgc-248w-frqc/GHSA-cpgc-248w-frqc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cpgc-248w-frqc", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1868" + ], + "details": "Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1868" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1301203" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f956-64gx-m8ww/GHSA-f956-64gx-m8ww.json b/advisories/unreviewed/2022/07/GHSA-f956-64gx-m8ww/GHSA-f956-64gx-m8ww.json new file mode 100644 index 00000000000..241998b0093 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f956-64gx-m8ww/GHSA-f956-64gx-m8ww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f956-64gx-m8ww", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36949" + ], + "details": "In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36949" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fc76-hxx9-92hh/GHSA-fc76-hxx9-92hh.json b/advisories/unreviewed/2022/07/GHSA-fc76-hxx9-92hh/GHSA-fc76-hxx9-92hh.json index a63a7e39e27..80c08c4e854 100644 --- a/advisories/unreviewed/2022/07/GHSA-fc76-hxx9-92hh/GHSA-fc76-hxx9-92hh.json +++ b/advisories/unreviewed/2022/07/GHSA-fc76-hxx9-92hh/GHSA-fc76-hxx9-92hh.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-fc76-hxx9-92hh", - "modified": "2022-07-20T00:00:20Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:20Z", "aliases": [ "CVE-2022-27544" ], "details": "BigFix Web Reports authorized users may see SMTP credentials in clear text.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fcpx-28g7-cmwg/GHSA-fcpx-28g7-cmwg.json b/advisories/unreviewed/2022/07/GHSA-fcpx-28g7-cmwg/GHSA-fcpx-28g7-cmwg.json new file mode 100644 index 00000000000..622e6c4fbc5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fcpx-28g7-cmwg/GHSA-fcpx-28g7-cmwg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fcpx-28g7-cmwg", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1876" + ], + "details": "Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1876" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1313600" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fg3r-9xrh-gr48/GHSA-fg3r-9xrh-gr48.json b/advisories/unreviewed/2022/07/GHSA-fg3r-9xrh-gr48/GHSA-fg3r-9xrh-gr48.json index 08c051a9c8a..11a05144212 100644 --- a/advisories/unreviewed/2022/07/GHSA-fg3r-9xrh-gr48/GHSA-fg3r-9xrh-gr48.json +++ b/advisories/unreviewed/2022/07/GHSA-fg3r-9xrh-gr48/GHSA-fg3r-9xrh-gr48.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-fg3r-9xrh-gr48", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:46Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-35569" ], "details": "Blogifier v3.0 was discovered to contain an arbitrary file upload vulnerability at /api/storage/upload/PostImage. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fgqr-h6m4-c3j9/GHSA-fgqr-h6m4-c3j9.json b/advisories/unreviewed/2022/07/GHSA-fgqr-h6m4-c3j9/GHSA-fgqr-h6m4-c3j9.json index 4eff4c8c7e2..deb87118950 100644 --- a/advisories/unreviewed/2022/07/GHSA-fgqr-h6m4-c3j9/GHSA-fgqr-h6m4-c3j9.json +++ b/advisories/unreviewed/2022/07/GHSA-fgqr-h6m4-c3j9/GHSA-fgqr-h6m4-c3j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-fgqr-h6m4-c3j9", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34047" ], "details": "An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fjpq-f574-jc45/GHSA-fjpq-f574-jc45.json b/advisories/unreviewed/2022/07/GHSA-fjpq-f574-jc45/GHSA-fjpq-f574-jc45.json new file mode 100644 index 00000000000..0199c5a26db --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fjpq-f574-jc45/GHSA-fjpq-f574-jc45.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fjpq-f574-jc45", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36904" + ], + "details": "Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36904" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2665%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fmmm-5p9f-xm6r/GHSA-fmmm-5p9f-xm6r.json b/advisories/unreviewed/2022/07/GHSA-fmmm-5p9f-xm6r/GHSA-fmmm-5p9f-xm6r.json index 6374c6e5365..1890b3e3ebd 100644 --- a/advisories/unreviewed/2022/07/GHSA-fmmm-5p9f-xm6r/GHSA-fmmm-5p9f-xm6r.json +++ b/advisories/unreviewed/2022/07/GHSA-fmmm-5p9f-xm6r/GHSA-fmmm-5p9f-xm6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-fmmm-5p9f-xm6r", - "modified": "2022-07-20T00:00:20Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:20Z", "aliases": [ "CVE-2022-27579" ], "details": "A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Flexi Soft Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fqhm-fjjv-7q8x/GHSA-fqhm-fjjv-7q8x.json b/advisories/unreviewed/2022/07/GHSA-fqhm-fjjv-7q8x/GHSA-fqhm-fjjv-7q8x.json new file mode 100644 index 00000000000..26a6d197157 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fqhm-fjjv-7q8x/GHSA-fqhm-fjjv-7q8x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fqhm-fjjv-7q8x", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36911" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36911" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2105%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g33g-qhjr-v6fq/GHSA-g33g-qhjr-v6fq.json b/advisories/unreviewed/2022/07/GHSA-g33g-qhjr-v6fq/GHSA-g33g-qhjr-v6fq.json index 3b80546fd85..493fe5bdf8b 100644 --- a/advisories/unreviewed/2022/07/GHSA-g33g-qhjr-v6fq/GHSA-g33g-qhjr-v6fq.json +++ b/advisories/unreviewed/2022/07/GHSA-g33g-qhjr-v6fq/GHSA-g33g-qhjr-v6fq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-g33g-qhjr-v6fq", - "modified": "2022-07-22T00:00:32Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-22T00:00:32Z", "aliases": [ "CVE-2022-28666" ], "details": "Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g5mr-95rv-q4hc/GHSA-g5mr-95rv-q4hc.json b/advisories/unreviewed/2022/07/GHSA-g5mr-95rv-q4hc/GHSA-g5mr-95rv-q4hc.json index 1437a2fbf84..0881aebc873 100644 --- a/advisories/unreviewed/2022/07/GHSA-g5mr-95rv-q4hc/GHSA-g5mr-95rv-q4hc.json +++ b/advisories/unreviewed/2022/07/GHSA-g5mr-95rv-q4hc/GHSA-g5mr-95rv-q4hc.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://ceph.io/en/news/blog/2022/v17-2-2-quincy-released/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5O3XMDFZWA2FWU6GAYOVSFJPOUTXN42N/" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-g78q-fxv7-624v/GHSA-g78q-fxv7-624v.json b/advisories/unreviewed/2022/07/GHSA-g78q-fxv7-624v/GHSA-g78q-fxv7-624v.json new file mode 100644 index 00000000000..70998dea280 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-g78q-fxv7-624v/GHSA-g78q-fxv7-624v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-g78q-fxv7-624v", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1864" + ], + "details": "Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1864" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1320624" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gjp8-5x9w-ghxm/GHSA-gjp8-5x9w-ghxm.json b/advisories/unreviewed/2022/07/GHSA-gjp8-5x9w-ghxm/GHSA-gjp8-5x9w-ghxm.json index 08249c0c832..b88016aad1b 100644 --- a/advisories/unreviewed/2022/07/GHSA-gjp8-5x9w-ghxm/GHSA-gjp8-5x9w-ghxm.json +++ b/advisories/unreviewed/2022/07/GHSA-gjp8-5x9w-ghxm/GHSA-gjp8-5x9w-ghxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gjp8-5x9w-ghxm", - "modified": "2022-07-19T00:00:28Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:28Z", "aliases": [ "CVE-2022-24690" ], "details": "An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the endpoint by abusing a Broken Access Control issue with further SQL injection attacks to gather all user's badge numbers and PIN codes.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gm25-rhmw-47gf/GHSA-gm25-rhmw-47gf.json b/advisories/unreviewed/2022/07/GHSA-gm25-rhmw-47gf/GHSA-gm25-rhmw-47gf.json index c3c1eba4b07..f9af4f9ff19 100644 --- a/advisories/unreviewed/2022/07/GHSA-gm25-rhmw-47gf/GHSA-gm25-rhmw-47gf.json +++ b/advisories/unreviewed/2022/07/GHSA-gm25-rhmw-47gf/GHSA-gm25-rhmw-47gf.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gm25-rhmw-47gf", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-28T00:00:54Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-22358" ], "details": "IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gmwx-qv5p-38rc/GHSA-gmwx-qv5p-38rc.json b/advisories/unreviewed/2022/07/GHSA-gmwx-qv5p-38rc/GHSA-gmwx-qv5p-38rc.json index 97cce374fa0..abab5e51706 100644 --- a/advisories/unreviewed/2022/07/GHSA-gmwx-qv5p-38rc/GHSA-gmwx-qv5p-38rc.json +++ b/advisories/unreviewed/2022/07/GHSA-gmwx-qv5p-38rc/GHSA-gmwx-qv5p-38rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gmwx-qv5p-38rc", - "modified": "2022-07-21T00:00:30Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:30Z", "aliases": [ "CVE-2022-22204" ], "details": "An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service (DoS). On all MX and SRX platforms, if the SIP ALG is enabled, receipt of a specific SIP packet will create a stale SIP entry. Sustained receipt of such packets will cause the SIP call table to eventually fill up and cause a DoS for all SIP traffic. The SIP call usage can be monitored by \"show security alg sip calls\". To be affected the SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify on SRX with: user@host> show security alg status | match sip SIP : Enabled Please verify on MX whether the following is configured: [ services ... rule (term ) from/match application/application-set ] where either a. name = junos-sip or an application or application-set refers to SIP: b. [ applications application application-protocol sip ] or c. [ applications application-set application junos-sip ] This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R2-S2; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2; 21.4 versions prior to 21.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1. Juniper SIRT is not aware of any malicious exploitation of this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gq4p-4hxv-5rg9/GHSA-gq4p-4hxv-5rg9.json b/advisories/unreviewed/2022/07/GHSA-gq4p-4hxv-5rg9/GHSA-gq4p-4hxv-5rg9.json new file mode 100644 index 00000000000..d381ec64616 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-gq4p-4hxv-5rg9/GHSA-gq4p-4hxv-5rg9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-gq4p-4hxv-5rg9", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-34529" + ], + "details": "WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34529" + }, + { + "type": "WEB", + "url": "https://github.com/wasm3/wasm3/issues/337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-grg9-xmwf-c24g/GHSA-grg9-xmwf-c24g.json b/advisories/unreviewed/2022/07/GHSA-grg9-xmwf-c24g/GHSA-grg9-xmwf-c24g.json index deb4939b977..07b253b2971 100644 --- a/advisories/unreviewed/2022/07/GHSA-grg9-xmwf-c24g/GHSA-grg9-xmwf-c24g.json +++ b/advisories/unreviewed/2022/07/GHSA-grg9-xmwf-c24g/GHSA-grg9-xmwf-c24g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-grg9-xmwf-c24g", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1144" ], "details": "Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h5rj-r648-659m/GHSA-h5rj-r648-659m.json b/advisories/unreviewed/2022/07/GHSA-h5rj-r648-659m/GHSA-h5rj-r648-659m.json new file mode 100644 index 00000000000..6314cd7f467 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-h5rj-r648-659m/GHSA-h5rj-r648-659m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-h5rj-r648-659m", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36950" + ], + "details": "In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36950" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h89v-75wm-frq9/GHSA-h89v-75wm-frq9.json b/advisories/unreviewed/2022/07/GHSA-h89v-75wm-frq9/GHSA-h89v-75wm-frq9.json index 3d83e968590..7a1adda3bc5 100644 --- a/advisories/unreviewed/2022/07/GHSA-h89v-75wm-frq9/GHSA-h89v-75wm-frq9.json +++ b/advisories/unreviewed/2022/07/GHSA-h89v-75wm-frq9/GHSA-h89v-75wm-frq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h89v-75wm-frq9", - "modified": "2022-07-19T00:00:27Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:27Z", "aliases": [ "CVE-2022-34900" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Dispatcher service. The service loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-15213.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h8vm-cr7c-cgqx/GHSA-h8vm-cr7c-cgqx.json b/advisories/unreviewed/2022/07/GHSA-h8vm-cr7c-cgqx/GHSA-h8vm-cr7c-cgqx.json index f6e5e032365..427d3715275 100644 --- a/advisories/unreviewed/2022/07/GHSA-h8vm-cr7c-cgqx/GHSA-h8vm-cr7c-cgqx.json +++ b/advisories/unreviewed/2022/07/GHSA-h8vm-cr7c-cgqx/GHSA-h8vm-cr7c-cgqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h8vm-cr7c-cgqx", - "modified": "2022-07-20T00:00:20Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:20Z", "aliases": [ "CVE-2022-27580" ], "details": "A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Safety Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json b/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json new file mode 100644 index 00000000000..d6dc6a71b63 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hffq-2fq2-hfh5", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-36948" + ], + "details": "In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36948" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hgp9-2c4w-x9mh/GHSA-hgp9-2c4w-x9mh.json b/advisories/unreviewed/2022/07/GHSA-hgp9-2c4w-x9mh/GHSA-hgp9-2c4w-x9mh.json new file mode 100644 index 00000000000..b55fae995f4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hgp9-2c4w-x9mh/GHSA-hgp9-2c4w-x9mh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hgp9-2c4w-x9mh", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36890" + ], + "details": "Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36890" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2206" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hgqp-g8j9-8x49/GHSA-hgqp-g8j9-8x49.json b/advisories/unreviewed/2022/07/GHSA-hgqp-g8j9-8x49/GHSA-hgqp-g8j9-8x49.json index fc486dac24e..17750975331 100644 --- a/advisories/unreviewed/2022/07/GHSA-hgqp-g8j9-8x49/GHSA-hgqp-g8j9-8x49.json +++ b/advisories/unreviewed/2022/07/GHSA-hgqp-g8j9-8x49/GHSA-hgqp-g8j9-8x49.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hgqp-g8j9-8x49", - "modified": "2022-07-19T00:00:27Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:27Z", "aliases": [ "CVE-2022-34889" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the ACPI virtual device. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-16554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hh5c-64r3-fc9p/GHSA-hh5c-64r3-fc9p.json b/advisories/unreviewed/2022/07/GHSA-hh5c-64r3-fc9p/GHSA-hh5c-64r3-fc9p.json new file mode 100644 index 00000000000..3a74e1e94dc --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hh5c-64r3-fc9p/GHSA-hh5c-64r3-fc9p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hh5c-64r3-fc9p", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1860" + ], + "details": "Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1860" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1297209" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json new file mode 100644 index 00000000000..9ed1a7a8143 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hjmg-3wv2-r885", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2021-38417" + ], + "details": "VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38417" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hm53-hrhh-gwfq/GHSA-hm53-hrhh-gwfq.json b/advisories/unreviewed/2022/07/GHSA-hm53-hrhh-gwfq/GHSA-hm53-hrhh-gwfq.json new file mode 100644 index 00000000000..7314bd8253d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hm53-hrhh-gwfq/GHSA-hm53-hrhh-gwfq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hm53-hrhh-gwfq", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36912" + ], + "details": "A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36912" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2105%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hp4v-g8mj-wr2f/GHSA-hp4v-g8mj-wr2f.json b/advisories/unreviewed/2022/07/GHSA-hp4v-g8mj-wr2f/GHSA-hp4v-g8mj-wr2f.json new file mode 100644 index 00000000000..1845921ca82 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hp4v-g8mj-wr2f/GHSA-hp4v-g8mj-wr2f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hp4v-g8mj-wr2f", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1870" + ], + "details": "Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1870" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1323236" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hp8r-2g6p-8j5q/GHSA-hp8r-2g6p-8j5q.json b/advisories/unreviewed/2022/07/GHSA-hp8r-2g6p-8j5q/GHSA-hp8r-2g6p-8j5q.json new file mode 100644 index 00000000000..217294b7043 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hp8r-2g6p-8j5q/GHSA-hp8r-2g6p-8j5q.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hp8r-2g6p-8j5q", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1855" + ], + "details": "Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1855" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1228661" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hq75-6wcm-hc6g/GHSA-hq75-6wcm-hc6g.json b/advisories/unreviewed/2022/07/GHSA-hq75-6wcm-hc6g/GHSA-hq75-6wcm-hc6g.json index ef15d43bfa2..affc86f50b1 100644 --- a/advisories/unreviewed/2022/07/GHSA-hq75-6wcm-hc6g/GHSA-hq75-6wcm-hc6g.json +++ b/advisories/unreviewed/2022/07/GHSA-hq75-6wcm-hc6g/GHSA-hq75-6wcm-hc6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hq75-6wcm-hc6g", - "modified": "2022-07-18T00:00:32Z", + "modified": "2022-07-28T00:00:44Z", "published": "2022-07-18T00:00:32Z", "aliases": [ "CVE-2021-40149" ], "details": "The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hqjf-3fq8-46pg/GHSA-hqjf-3fq8-46pg.json b/advisories/unreviewed/2022/07/GHSA-hqjf-3fq8-46pg/GHSA-hqjf-3fq8-46pg.json index e3e8a2eda39..679209251eb 100644 --- a/advisories/unreviewed/2022/07/GHSA-hqjf-3fq8-46pg/GHSA-hqjf-3fq8-46pg.json +++ b/advisories/unreviewed/2022/07/GHSA-hqjf-3fq8-46pg/GHSA-hqjf-3fq8-46pg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hqjf-3fq8-46pg", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1306" ], "details": "Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hqrp-2gvr-75v6/GHSA-hqrp-2gvr-75v6.json b/advisories/unreviewed/2022/07/GHSA-hqrp-2gvr-75v6/GHSA-hqrp-2gvr-75v6.json index a15db5df878..725c2f063cd 100644 --- a/advisories/unreviewed/2022/07/GHSA-hqrp-2gvr-75v6/GHSA-hqrp-2gvr-75v6.json +++ b/advisories/unreviewed/2022/07/GHSA-hqrp-2gvr-75v6/GHSA-hqrp-2gvr-75v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hqrp-2gvr-75v6", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1136" ], "details": "Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json b/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json new file mode 100644 index 00000000000..9e59e6c3db8 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hrq4-ppwc-8jwx", + "modified": "2022-07-28T00:00:52Z", + "published": "2022-07-28T00:00:52Z", + "aliases": [ + "CVE-2022-34594" + ], + "details": "Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34594" + }, + { + "type": "WEB", + "url": "https://github.com/gitgeniuss/bug_report/blob/master/vendors/itsourcecode.com/advanced-school-management-system/XSS-1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hvpp-g2cx-76qq/GHSA-hvpp-g2cx-76qq.json b/advisories/unreviewed/2022/07/GHSA-hvpp-g2cx-76qq/GHSA-hvpp-g2cx-76qq.json new file mode 100644 index 00000000000..9a7ee696fda --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hvpp-g2cx-76qq/GHSA-hvpp-g2cx-76qq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hvpp-g2cx-76qq", + "modified": "2022-07-28T00:00:52Z", + "published": "2022-07-28T00:00:52Z", + "aliases": [ + "CVE-2022-34612" + ], + "details": "Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34612" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/issues/2738" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/pull/2739" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hxf7-9rv9-88v6/GHSA-hxf7-9rv9-88v6.json b/advisories/unreviewed/2022/07/GHSA-hxf7-9rv9-88v6/GHSA-hxf7-9rv9-88v6.json new file mode 100644 index 00000000000..1fcc1ed2f2f --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hxf7-9rv9-88v6/GHSA-hxf7-9rv9-88v6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hxf7-9rv9-88v6", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36897" + ], + "details": "A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36897" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2626" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j5qq-6rpm-qjgh/GHSA-j5qq-6rpm-qjgh.json b/advisories/unreviewed/2022/07/GHSA-j5qq-6rpm-qjgh/GHSA-j5qq-6rpm-qjgh.json new file mode 100644 index 00000000000..8651a11396a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-j5qq-6rpm-qjgh/GHSA-j5qq-6rpm-qjgh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-j5qq-6rpm-qjgh", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36889" + ], + "details": "Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36889" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2764" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j896-j72w-cr32/GHSA-j896-j72w-cr32.json b/advisories/unreviewed/2022/07/GHSA-j896-j72w-cr32/GHSA-j896-j72w-cr32.json new file mode 100644 index 00000000000..111ba9253e7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-j896-j72w-cr32/GHSA-j896-j72w-cr32.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-j896-j72w-cr32", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36887" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36887" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2766" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j9gm-f3p3-j5g3/GHSA-j9gm-f3p3-j5g3.json b/advisories/unreviewed/2022/07/GHSA-j9gm-f3p3-j5g3/GHSA-j9gm-f3p3-j5g3.json index 1a622db9f62..d93c29d6925 100644 --- a/advisories/unreviewed/2022/07/GHSA-j9gm-f3p3-j5g3/GHSA-j9gm-f3p3-j5g3.json +++ b/advisories/unreviewed/2022/07/GHSA-j9gm-f3p3-j5g3/GHSA-j9gm-f3p3-j5g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-j9gm-f3p3-j5g3", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1129" ], "details": "Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jhg9-9m4g-q544/GHSA-jhg9-9m4g-q544.json b/advisories/unreviewed/2022/07/GHSA-jhg9-9m4g-q544/GHSA-jhg9-9m4g-q544.json index cacb98d195d..f0c8a52c5f4 100644 --- a/advisories/unreviewed/2022/07/GHSA-jhg9-9m4g-q544/GHSA-jhg9-9m4g-q544.json +++ b/advisories/unreviewed/2022/07/GHSA-jhg9-9m4g-q544/GHSA-jhg9-9m4g-q544.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-jhg9-9m4g-q544", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2020-36558" ], "details": "A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json b/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json new file mode 100644 index 00000000000..7efda4dca34 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jhvv-qgrh-gc45", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36953" + ], + "details": "In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36953" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jj8j-6jq7-gmvh/GHSA-jj8j-6jq7-gmvh.json b/advisories/unreviewed/2022/07/GHSA-jj8j-6jq7-gmvh/GHSA-jj8j-6jq7-gmvh.json new file mode 100644 index 00000000000..71bdf422b03 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jj8j-6jq7-gmvh/GHSA-jj8j-6jq7-gmvh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jj8j-6jq7-gmvh", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36914" + ], + "details": "Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36914" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2210" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jj9f-2mf3-f7x2/GHSA-jj9f-2mf3-f7x2.json b/advisories/unreviewed/2022/07/GHSA-jj9f-2mf3-f7x2/GHSA-jj9f-2mf3-f7x2.json index 15ed37c527a..692e9cb68e2 100644 --- a/advisories/unreviewed/2022/07/GHSA-jj9f-2mf3-f7x2/GHSA-jj9f-2mf3-f7x2.json +++ b/advisories/unreviewed/2022/07/GHSA-jj9f-2mf3-f7x2/GHSA-jj9f-2mf3-f7x2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-jj9f-2mf3-f7x2", - "modified": "2022-07-20T00:00:21Z", + "modified": "2022-07-28T00:00:50Z", "published": "2022-07-20T00:00:21Z", "aliases": [ "CVE-2022-1984" ], "details": "This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json b/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json new file mode 100644 index 00000000000..5d0ec225572 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jjq6-7gx6-74fc", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-24405" + ], + "details": "OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24405" + }, + { + "type": "WEB", + "url": "https://open-xchange.com" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2022/Jul/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jr5r-25mv-wfhm/GHSA-jr5r-25mv-wfhm.json b/advisories/unreviewed/2022/07/GHSA-jr5r-25mv-wfhm/GHSA-jr5r-25mv-wfhm.json index 9124e12a919..1da0e130ccf 100644 --- a/advisories/unreviewed/2022/07/GHSA-jr5r-25mv-wfhm/GHSA-jr5r-25mv-wfhm.json +++ b/advisories/unreviewed/2022/07/GHSA-jr5r-25mv-wfhm/GHSA-jr5r-25mv-wfhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-jr5r-25mv-wfhm", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34046" ], "details": "An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jvjh-9r4q-8q5q/GHSA-jvjh-9r4q-8q5q.json b/advisories/unreviewed/2022/07/GHSA-jvjh-9r4q-8q5q/GHSA-jvjh-9r4q-8q5q.json new file mode 100644 index 00000000000..0310c033fe3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jvjh-9r4q-8q5q/GHSA-jvjh-9r4q-8q5q.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jvjh-9r4q-8q5q", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36907" + ], + "details": "A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36907" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1375%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jvvx-hmmr-rhgg/GHSA-jvvx-hmmr-rhgg.json b/advisories/unreviewed/2022/07/GHSA-jvvx-hmmr-rhgg/GHSA-jvvx-hmmr-rhgg.json new file mode 100644 index 00000000000..62c34d1ddf5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jvvx-hmmr-rhgg/GHSA-jvvx-hmmr-rhgg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jvvx-hmmr-rhgg", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36902" + ], + "details": "Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36902" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2682" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jxg9-2ch7-f552/GHSA-jxg9-2ch7-f552.json b/advisories/unreviewed/2022/07/GHSA-jxg9-2ch7-f552/GHSA-jxg9-2ch7-f552.json new file mode 100644 index 00000000000..27fc937b47a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jxg9-2ch7-f552/GHSA-jxg9-2ch7-f552.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jxg9-2ch7-f552", + "modified": "2022-07-28T00:00:53Z", + "published": "2022-07-28T00:00:53Z", + "aliases": [ + "CVE-2022-34971" + ], + "details": "An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34971" + }, + { + "type": "WEB", + "url": "https://github.com/liufee/cms/issues/62" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m2qh-3fm2-xvmg/GHSA-m2qh-3fm2-xvmg.json b/advisories/unreviewed/2022/07/GHSA-m2qh-3fm2-xvmg/GHSA-m2qh-3fm2-xvmg.json index 255e2de5efa..39f0ea24946 100644 --- a/advisories/unreviewed/2022/07/GHSA-m2qh-3fm2-xvmg/GHSA-m2qh-3fm2-xvmg.json +++ b/advisories/unreviewed/2022/07/GHSA-m2qh-3fm2-xvmg/GHSA-m2qh-3fm2-xvmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-m2qh-3fm2-xvmg", - "modified": "2022-07-23T00:00:22Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-23T00:00:22Z", "aliases": [ "CVE-2022-2511" ], "details": "Cross-site Scripting (XSS) vulnerability in the \"commonuserinterface\" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m2vc-45rr-qvfm/GHSA-m2vc-45rr-qvfm.json b/advisories/unreviewed/2022/07/GHSA-m2vc-45rr-qvfm/GHSA-m2vc-45rr-qvfm.json index ba0e49dfb18..1cb92148fb3 100644 --- a/advisories/unreviewed/2022/07/GHSA-m2vc-45rr-qvfm/GHSA-m2vc-45rr-qvfm.json +++ b/advisories/unreviewed/2022/07/GHSA-m2vc-45rr-qvfm/GHSA-m2vc-45rr-qvfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-m2vc-45rr-qvfm", - "modified": "2022-07-20T00:00:25Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-20T00:00:25Z", "aliases": [ "CVE-2022-2467" ], "details": "A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m485-79jq-cxx7/GHSA-m485-79jq-cxx7.json b/advisories/unreviewed/2022/07/GHSA-m485-79jq-cxx7/GHSA-m485-79jq-cxx7.json new file mode 100644 index 00000000000..a4d37b76154 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-m485-79jq-cxx7/GHSA-m485-79jq-cxx7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m485-79jq-cxx7", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36916" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36916" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2656" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m6jf-p94r-8589/GHSA-m6jf-p94r-8589.json b/advisories/unreviewed/2022/07/GHSA-m6jf-p94r-8589/GHSA-m6jf-p94r-8589.json new file mode 100644 index 00000000000..cc63bcae14c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-m6jf-p94r-8589/GHSA-m6jf-p94r-8589.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m6jf-p94r-8589", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-36946" + ], + "details": "nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36946" + }, + { + "type": "WEB", + "url": "https://marc.info/?l=netfilter-devel&m=165883202007292&w=2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m769-jr2m-2pmv/GHSA-m769-jr2m-2pmv.json b/advisories/unreviewed/2022/07/GHSA-m769-jr2m-2pmv/GHSA-m769-jr2m-2pmv.json new file mode 100644 index 00000000000..206ac921aa5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-m769-jr2m-2pmv/GHSA-m769-jr2m-2pmv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m769-jr2m-2pmv", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36955" + ], + "details": "In Veritas NetBackup, an attacker with unprivileged local access to a NetBackup Client may send specific commands to escalate their privileges. This affects 8.0 through 8.1.2, 8.2, 8.3 through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36955" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-008#Issue2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json b/advisories/unreviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json deleted file mode 100644 index 6f94d5112ef..00000000000 --- a/advisories/unreviewed/2022/07/GHSA-m7gr-5w5g-36jf/GHSA-m7gr-5w5g-36jf.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-m7gr-5w5g-36jf", - "modified": "2022-07-23T00:00:22Z", - "published": "2022-07-23T00:00:22Z", - "aliases": [ - "CVE-2022-34037" - ], - "details": "An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34037" - }, - { - "type": "WEB", - "url": "https://github.com/caddyserver/caddy/issues/4775" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m8w5-vwq3-gp8f/GHSA-m8w5-vwq3-gp8f.json b/advisories/unreviewed/2022/07/GHSA-m8w5-vwq3-gp8f/GHSA-m8w5-vwq3-gp8f.json new file mode 100644 index 00000000000..e4657838675 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-m8w5-vwq3-gp8f/GHSA-m8w5-vwq3-gp8f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m8w5-vwq3-gp8f", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36910" + ], + "details": "Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36910" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2048" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m9mx-49mx-whcc/GHSA-m9mx-49mx-whcc.json b/advisories/unreviewed/2022/07/GHSA-m9mx-49mx-whcc/GHSA-m9mx-49mx-whcc.json index d0d4dac3e6a..8166390956e 100644 --- a/advisories/unreviewed/2022/07/GHSA-m9mx-49mx-whcc/GHSA-m9mx-49mx-whcc.json +++ b/advisories/unreviewed/2022/07/GHSA-m9mx-49mx-whcc/GHSA-m9mx-49mx-whcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-m9mx-49mx-whcc", - "modified": "2022-07-14T00:00:15Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:15Z", "aliases": [ "CVE-2022-34761" ], "details": "A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mfx6-rr3j-xrqq/GHSA-mfx6-rr3j-xrqq.json b/advisories/unreviewed/2022/07/GHSA-mfx6-rr3j-xrqq/GHSA-mfx6-rr3j-xrqq.json index a85c10063cb..94be2aabac0 100644 --- a/advisories/unreviewed/2022/07/GHSA-mfx6-rr3j-xrqq/GHSA-mfx6-rr3j-xrqq.json +++ b/advisories/unreviewed/2022/07/GHSA-mfx6-rr3j-xrqq/GHSA-mfx6-rr3j-xrqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mfx6-rr3j-xrqq", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20861" ], "details": "Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json b/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json new file mode 100644 index 00000000000..ce9ab2dbbd2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mj46-hjj8-xr5c", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-35291" + ], + "details": "Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35291" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3226411" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json b/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json new file mode 100644 index 00000000000..817dd9c7424 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mpv4-p366-wr6p", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-34120" + ], + "details": "Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34120" + }, + { + "type": "WEB", + "url": "https://github.com/wangsj37/bug_report/blob/main/vendors/itsourcecode.com/barangay-management-system/RCE-1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mq7q-47xg-285x/GHSA-mq7q-47xg-285x.json b/advisories/unreviewed/2022/07/GHSA-mq7q-47xg-285x/GHSA-mq7q-47xg-285x.json index 32889c55b45..8223ae3b30c 100644 --- a/advisories/unreviewed/2022/07/GHSA-mq7q-47xg-285x/GHSA-mq7q-47xg-285x.json +++ b/advisories/unreviewed/2022/07/GHSA-mq7q-47xg-285x/GHSA-mq7q-47xg-285x.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mq7q-47xg-285x", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-22359" ], "details": "IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mqpc-v236-v2qj/GHSA-mqpc-v236-v2qj.json b/advisories/unreviewed/2022/07/GHSA-mqpc-v236-v2qj/GHSA-mqpc-v236-v2qj.json new file mode 100644 index 00000000000..2ab88a94bca --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mqpc-v236-v2qj/GHSA-mqpc-v236-v2qj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mqpc-v236-v2qj", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-24406" + ], + "details": "OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24406" + }, + { + "type": "WEB", + "url": "https://open-xchange.com" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2022/Jul/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mr38-g7q2-x79p/GHSA-mr38-g7q2-x79p.json b/advisories/unreviewed/2022/07/GHSA-mr38-g7q2-x79p/GHSA-mr38-g7q2-x79p.json new file mode 100644 index 00000000000..6a1e5e8a7e7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mr38-g7q2-x79p/GHSA-mr38-g7q2-x79p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mr38-g7q2-x79p", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36913" + ], + "details": "Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36913" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2105%20(2)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mvf8-h6gv-86gj/GHSA-mvf8-h6gv-86gj.json b/advisories/unreviewed/2022/07/GHSA-mvf8-h6gv-86gj/GHSA-mvf8-h6gv-86gj.json index 7df72fb62d7..37a4bde85c7 100644 --- a/advisories/unreviewed/2022/07/GHSA-mvf8-h6gv-86gj/GHSA-mvf8-h6gv-86gj.json +++ b/advisories/unreviewed/2022/07/GHSA-mvf8-h6gv-86gj/GHSA-mvf8-h6gv-86gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mvf8-h6gv-86gj", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-33316" ], "details": "Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mw5h-pmch-3mmm/GHSA-mw5h-pmch-3mmm.json b/advisories/unreviewed/2022/07/GHSA-mw5h-pmch-3mmm/GHSA-mw5h-pmch-3mmm.json index 7d34f7da9d1..402a2f1b55f 100644 --- a/advisories/unreviewed/2022/07/GHSA-mw5h-pmch-3mmm/GHSA-mw5h-pmch-3mmm.json +++ b/advisories/unreviewed/2022/07/GHSA-mw5h-pmch-3mmm/GHSA-mw5h-pmch-3mmm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mw5h-pmch-3mmm", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-24657" ], "details": "Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mw6m-9c66-qq3h/GHSA-mw6m-9c66-qq3h.json b/advisories/unreviewed/2022/07/GHSA-mw6m-9c66-qq3h/GHSA-mw6m-9c66-qq3h.json index 53c61283d88..f074b60155c 100644 --- a/advisories/unreviewed/2022/07/GHSA-mw6m-9c66-qq3h/GHSA-mw6m-9c66-qq3h.json +++ b/advisories/unreviewed/2022/07/GHSA-mw6m-9c66-qq3h/GHSA-mw6m-9c66-qq3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mw6m-9c66-qq3h", - "modified": "2022-07-26T00:01:07Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:07Z", "aliases": [ "CVE-2022-1307" ], "details": "Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mx84-3frj-x7gc/GHSA-mx84-3frj-x7gc.json b/advisories/unreviewed/2022/07/GHSA-mx84-3frj-x7gc/GHSA-mx84-3frj-x7gc.json index d82be5afb41..808ace60137 100644 --- a/advisories/unreviewed/2022/07/GHSA-mx84-3frj-x7gc/GHSA-mx84-3frj-x7gc.json +++ b/advisories/unreviewed/2022/07/GHSA-mx84-3frj-x7gc/GHSA-mx84-3frj-x7gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mx84-3frj-x7gc", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-34753" ], "details": "A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mxcc-7h5m-x57r/GHSA-mxcc-7h5m-x57r.json b/advisories/unreviewed/2022/07/GHSA-mxcc-7h5m-x57r/GHSA-mxcc-7h5m-x57r.json new file mode 100644 index 00000000000..8a539e2507f --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mxcc-7h5m-x57r/GHSA-mxcc-7h5m-x57r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mxcc-7h5m-x57r", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36885" + ], + "details": "Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36885" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-1849" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p289-v2gf-9g82/GHSA-p289-v2gf-9g82.json b/advisories/unreviewed/2022/07/GHSA-p289-v2gf-9g82/GHSA-p289-v2gf-9g82.json new file mode 100644 index 00000000000..9be8d1de508 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-p289-v2gf-9g82/GHSA-p289-v2gf-9g82.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-p289-v2gf-9g82", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36954" + ], + "details": "In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36954" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p3qc-mh98-4vq5/GHSA-p3qc-mh98-4vq5.json b/advisories/unreviewed/2022/07/GHSA-p3qc-mh98-4vq5/GHSA-p3qc-mh98-4vq5.json index e101496e42c..e4000abeb8a 100644 --- a/advisories/unreviewed/2022/07/GHSA-p3qc-mh98-4vq5/GHSA-p3qc-mh98-4vq5.json +++ b/advisories/unreviewed/2022/07/GHSA-p3qc-mh98-4vq5/GHSA-p3qc-mh98-4vq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p3qc-mh98-4vq5", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-22416" ], "details": "IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p45j-v622-3wj9/GHSA-p45j-v622-3wj9.json b/advisories/unreviewed/2022/07/GHSA-p45j-v622-3wj9/GHSA-p45j-v622-3wj9.json index eeb35865a37..74fd1af6ed3 100644 --- a/advisories/unreviewed/2022/07/GHSA-p45j-v622-3wj9/GHSA-p45j-v622-3wj9.json +++ b/advisories/unreviewed/2022/07/GHSA-p45j-v622-3wj9/GHSA-p45j-v622-3wj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p45j-v622-3wj9", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1138" ], "details": "Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p583-488v-vpxc/GHSA-p583-488v-vpxc.json b/advisories/unreviewed/2022/07/GHSA-p583-488v-vpxc/GHSA-p583-488v-vpxc.json index 00bfa5141f0..e60c9950c7a 100644 --- a/advisories/unreviewed/2022/07/GHSA-p583-488v-vpxc/GHSA-p583-488v-vpxc.json +++ b/advisories/unreviewed/2022/07/GHSA-p583-488v-vpxc/GHSA-p583-488v-vpxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p583-488v-vpxc", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1135" ], "details": "Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p5r5-rww2-cg87/GHSA-p5r5-rww2-cg87.json b/advisories/unreviewed/2022/07/GHSA-p5r5-rww2-cg87/GHSA-p5r5-rww2-cg87.json index 682aaf8afd0..cbded407c16 100644 --- a/advisories/unreviewed/2022/07/GHSA-p5r5-rww2-cg87/GHSA-p5r5-rww2-cg87.json +++ b/advisories/unreviewed/2022/07/GHSA-p5r5-rww2-cg87/GHSA-p5r5-rww2-cg87.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p5r5-rww2-cg87", - "modified": "2022-07-26T00:01:07Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:07Z", "aliases": [ "CVE-2022-1305" ], "details": "Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p878-qvqr-h9fp/GHSA-p878-qvqr-h9fp.json b/advisories/unreviewed/2022/07/GHSA-p878-qvqr-h9fp/GHSA-p878-qvqr-h9fp.json new file mode 100644 index 00000000000..cf1216398b3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-p878-qvqr-h9fp/GHSA-p878-qvqr-h9fp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-p878-qvqr-h9fp", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1865" + ], + "details": "Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1865" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1289192" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json b/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json new file mode 100644 index 00000000000..2311e1f45bb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-p954-47vj-3wxw", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-23101" + ], + "details": "OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23101" + }, + { + "type": "WEB", + "url": "https://open-xchange.com" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2022/Jul/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pfgj-6mxg-pmfv/GHSA-pfgj-6mxg-pmfv.json b/advisories/unreviewed/2022/07/GHSA-pfgj-6mxg-pmfv/GHSA-pfgj-6mxg-pmfv.json new file mode 100644 index 00000000000..fea149b9549 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-pfgj-6mxg-pmfv/GHSA-pfgj-6mxg-pmfv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-pfgj-6mxg-pmfv", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1853" + ], + "details": "Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1853" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1324864" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pfqj-j743-cxwm/GHSA-pfqj-j743-cxwm.json b/advisories/unreviewed/2022/07/GHSA-pfqj-j743-cxwm/GHSA-pfqj-j743-cxwm.json index a4eebd91860..af40b47b1fb 100644 --- a/advisories/unreviewed/2022/07/GHSA-pfqj-j743-cxwm/GHSA-pfqj-j743-cxwm.json +++ b/advisories/unreviewed/2022/07/GHSA-pfqj-j743-cxwm/GHSA-pfqj-j743-cxwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pfqj-j743-cxwm", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1133" ], "details": "Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pgm5-cr62-prxq/GHSA-pgm5-cr62-prxq.json b/advisories/unreviewed/2022/07/GHSA-pgm5-cr62-prxq/GHSA-pgm5-cr62-prxq.json index b537a9ffdde..e998f611d96 100644 --- a/advisories/unreviewed/2022/07/GHSA-pgm5-cr62-prxq/GHSA-pgm5-cr62-prxq.json +++ b/advisories/unreviewed/2022/07/GHSA-pgm5-cr62-prxq/GHSA-pgm5-cr62-prxq.json @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106274" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=436457" diff --git a/advisories/unreviewed/2022/07/GHSA-pqrc-qr29-pr59/GHSA-pqrc-qr29-pr59.json b/advisories/unreviewed/2022/07/GHSA-pqrc-qr29-pr59/GHSA-pqrc-qr29-pr59.json index f12c0919dc4..c6691f47c68 100644 --- a/advisories/unreviewed/2022/07/GHSA-pqrc-qr29-pr59/GHSA-pqrc-qr29-pr59.json +++ b/advisories/unreviewed/2022/07/GHSA-pqrc-qr29-pr59/GHSA-pqrc-qr29-pr59.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pqrc-qr29-pr59", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34042" ], "details": "Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-prvj-qfjv-3x3f/GHSA-prvj-qfjv-3x3f.json b/advisories/unreviewed/2022/07/GHSA-prvj-qfjv-3x3f/GHSA-prvj-qfjv-3x3f.json index b2988e98fa0..47cfb131db2 100644 --- a/advisories/unreviewed/2022/07/GHSA-prvj-qfjv-3x3f/GHSA-prvj-qfjv-3x3f.json +++ b/advisories/unreviewed/2022/07/GHSA-prvj-qfjv-3x3f/GHSA-prvj-qfjv-3x3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-prvj-qfjv-3x3f", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-2394" ], "details": "Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "LOW", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pw49-cjr4-3pqr/GHSA-pw49-cjr4-3pqr.json b/advisories/unreviewed/2022/07/GHSA-pw49-cjr4-3pqr/GHSA-pw49-cjr4-3pqr.json index 059845c1ba7..0c4ddf94785 100644 --- a/advisories/unreviewed/2022/07/GHSA-pw49-cjr4-3pqr/GHSA-pw49-cjr4-3pqr.json +++ b/advisories/unreviewed/2022/07/GHSA-pw49-cjr4-3pqr/GHSA-pw49-cjr4-3pqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pw49-cjr4-3pqr", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34035" ], "details": "HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pw4g-jcp5-63m9/GHSA-pw4g-jcp5-63m9.json b/advisories/unreviewed/2022/07/GHSA-pw4g-jcp5-63m9/GHSA-pw4g-jcp5-63m9.json new file mode 100644 index 00000000000..2235d6230fc --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-pw4g-jcp5-63m9/GHSA-pw4g-jcp5-63m9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-pw4g-jcp5-63m9", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36893" + ], + "details": "Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36893" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2403" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q2p6-q4x9-rcrf/GHSA-q2p6-q4x9-rcrf.json b/advisories/unreviewed/2022/07/GHSA-q2p6-q4x9-rcrf/GHSA-q2p6-q4x9-rcrf.json index af13e0a3c72..21207dbcebc 100644 --- a/advisories/unreviewed/2022/07/GHSA-q2p6-q4x9-rcrf/GHSA-q2p6-q4x9-rcrf.json +++ b/advisories/unreviewed/2022/07/GHSA-q2p6-q4x9-rcrf/GHSA-q2p6-q4x9-rcrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-q2p6-q4x9-rcrf", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-1264" ], "details": "The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q72p-4w56-hx7h/GHSA-q72p-4w56-hx7h.json b/advisories/unreviewed/2022/07/GHSA-q72p-4w56-hx7h/GHSA-q72p-4w56-hx7h.json index dc3455e8068..dafc6c097d6 100644 --- a/advisories/unreviewed/2022/07/GHSA-q72p-4w56-hx7h/GHSA-q72p-4w56-hx7h.json +++ b/advisories/unreviewed/2022/07/GHSA-q72p-4w56-hx7h/GHSA-q72p-4w56-hx7h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-q72p-4w56-hx7h", - "modified": "2022-07-22T00:00:37Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-22T00:00:37Z", "aliases": [ "CVE-2022-32430" ], "details": "An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qcm2-hcg7-gmv8/GHSA-qcm2-hcg7-gmv8.json b/advisories/unreviewed/2022/07/GHSA-qcm2-hcg7-gmv8/GHSA-qcm2-hcg7-gmv8.json index 0b4c46f7b46..7e94ff69351 100644 --- a/advisories/unreviewed/2022/07/GHSA-qcm2-hcg7-gmv8/GHSA-qcm2-hcg7-gmv8.json +++ b/advisories/unreviewed/2022/07/GHSA-qcm2-hcg7-gmv8/GHSA-qcm2-hcg7-gmv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-qcm2-hcg7-gmv8", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-36321" ], "details": "In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qf4p-7gqc-x6jx/GHSA-qf4p-7gqc-x6jx.json b/advisories/unreviewed/2022/07/GHSA-qf4p-7gqc-x6jx/GHSA-qf4p-7gqc-x6jx.json new file mode 100644 index 00000000000..24cc726d7b8 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-qf4p-7gqc-x6jx/GHSA-qf4p-7gqc-x6jx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-qf4p-7gqc-x6jx", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36895" + ], + "details": "A missing permission check in Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36895" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2619" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qj9f-6hqx-22hw/GHSA-qj9f-6hqx-22hw.json b/advisories/unreviewed/2022/07/GHSA-qj9f-6hqx-22hw/GHSA-qj9f-6hqx-22hw.json index dae9fa19a57..02a08004b9a 100644 --- a/advisories/unreviewed/2022/07/GHSA-qj9f-6hqx-22hw/GHSA-qj9f-6hqx-22hw.json +++ b/advisories/unreviewed/2022/07/GHSA-qj9f-6hqx-22hw/GHSA-qj9f-6hqx-22hw.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33743" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-405.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-qx37-fp3m-qw6q/GHSA-qx37-fp3m-qw6q.json b/advisories/unreviewed/2022/07/GHSA-qx37-fp3m-qw6q/GHSA-qx37-fp3m-qw6q.json index aa25f8c1127..d49cd570410 100644 --- a/advisories/unreviewed/2022/07/GHSA-qx37-fp3m-qw6q/GHSA-qx37-fp3m-qw6q.json +++ b/advisories/unreviewed/2022/07/GHSA-qx37-fp3m-qw6q/GHSA-qx37-fp3m-qw6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-qx37-fp3m-qw6q", - "modified": "2022-07-20T00:00:21Z", + "modified": "2022-07-28T00:00:53Z", "published": "2022-07-20T00:00:21Z", "aliases": [ "CVE-2022-2192" ], "details": "Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-425" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qxhq-w389-3vq5/GHSA-qxhq-w389-3vq5.json b/advisories/unreviewed/2022/07/GHSA-qxhq-w389-3vq5/GHSA-qxhq-w389-3vq5.json index 28f8f97a84d..b0e7dc57129 100644 --- a/advisories/unreviewed/2022/07/GHSA-qxhq-w389-3vq5/GHSA-qxhq-w389-3vq5.json +++ b/advisories/unreviewed/2022/07/GHSA-qxhq-w389-3vq5/GHSA-qxhq-w389-3vq5.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/torvalds/linux/commit/9cc02ede696272c5271a401e4f27c262359bc2f6" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-r9xr-xfwx-6crw/GHSA-r9xr-xfwx-6crw.json b/advisories/unreviewed/2022/07/GHSA-r9xr-xfwx-6crw/GHSA-r9xr-xfwx-6crw.json index a31c83b769c..93997526513 100644 --- a/advisories/unreviewed/2022/07/GHSA-r9xr-xfwx-6crw/GHSA-r9xr-xfwx-6crw.json +++ b/advisories/unreviewed/2022/07/GHSA-r9xr-xfwx-6crw/GHSA-r9xr-xfwx-6crw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-r9xr-xfwx-6crw", - "modified": "2022-07-20T00:00:20Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-20T00:00:20Z", "aliases": [ "CVE-2022-2469" ], "details": "GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json b/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json new file mode 100644 index 00000000000..2a53efa0ea6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-rcwq-vxfc-36p5/GHSA-rcwq-vxfc-36p5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-rcwq-vxfc-36p5", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2021-46830" + ], + "details": "A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46830" + }, + { + "type": "WEB", + "url": "https://www.goanywhere.com/support/advisory/68x" + }, + { + "type": "WEB", + "url": "https://www.goanywhere.com/support/release-notes/mft?limit=0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rjjm-wq7g-6hf4/GHSA-rjjm-wq7g-6hf4.json b/advisories/unreviewed/2022/07/GHSA-rjjm-wq7g-6hf4/GHSA-rjjm-wq7g-6hf4.json index afbeeb234f6..124711467a0 100644 --- a/advisories/unreviewed/2022/07/GHSA-rjjm-wq7g-6hf4/GHSA-rjjm-wq7g-6hf4.json +++ b/advisories/unreviewed/2022/07/GHSA-rjjm-wq7g-6hf4/GHSA-rjjm-wq7g-6hf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rjjm-wq7g-6hf4", - "modified": "2022-07-19T00:00:27Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-19T00:00:27Z", "aliases": [ "CVE-2022-34901" ], "details": "This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. The service executes files from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16137.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rjx3-h5w4-7663/GHSA-rjx3-h5w4-7663.json b/advisories/unreviewed/2022/07/GHSA-rjx3-h5w4-7663/GHSA-rjx3-h5w4-7663.json index 7ffe3bb8f49..c1da8d1cbda 100644 --- a/advisories/unreviewed/2022/07/GHSA-rjx3-h5w4-7663/GHSA-rjx3-h5w4-7663.json +++ b/advisories/unreviewed/2022/07/GHSA-rjx3-h5w4-7663/GHSA-rjx3-h5w4-7663.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rjx3-h5w4-7663", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1132" ], "details": "Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rqqx-fvqx-539g/GHSA-rqqx-fvqx-539g.json b/advisories/unreviewed/2022/07/GHSA-rqqx-fvqx-539g/GHSA-rqqx-fvqx-539g.json new file mode 100644 index 00000000000..84b32c37143 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-rqqx-fvqx-539g/GHSA-rqqx-fvqx-539g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-rqqx-fvqx-539g", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36891" + ], + "details": "A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36891" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2205" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rw6g-9gmq-76ff/GHSA-rw6g-9gmq-76ff.json b/advisories/unreviewed/2022/07/GHSA-rw6g-9gmq-76ff/GHSA-rw6g-9gmq-76ff.json index 9e28ed50984..1e1e91dca62 100644 --- a/advisories/unreviewed/2022/07/GHSA-rw6g-9gmq-76ff/GHSA-rw6g-9gmq-76ff.json +++ b/advisories/unreviewed/2022/07/GHSA-rw6g-9gmq-76ff/GHSA-rw6g-9gmq-76ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rw6g-9gmq-76ff", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-28T00:00:38Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-34758" ], "details": "A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. Affected Products: Easergy P5 (V01.401.102 and prior)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rx38-xpj5-528c/GHSA-rx38-xpj5-528c.json b/advisories/unreviewed/2022/07/GHSA-rx38-xpj5-528c/GHSA-rx38-xpj5-528c.json index 6db109dd56d..28841b8e901 100644 --- a/advisories/unreviewed/2022/07/GHSA-rx38-xpj5-528c/GHSA-rx38-xpj5-528c.json +++ b/advisories/unreviewed/2022/07/GHSA-rx38-xpj5-528c/GHSA-rx38-xpj5-528c.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rx38-xpj5-528c", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-33944" ], "details": "The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v3gw-vwrq-mq7v/GHSA-v3gw-vwrq-mq7v.json b/advisories/unreviewed/2022/07/GHSA-v3gw-vwrq-mq7v/GHSA-v3gw-vwrq-mq7v.json index 1a618e1f6dc..3374dfcf8aa 100644 --- a/advisories/unreviewed/2022/07/GHSA-v3gw-vwrq-mq7v/GHSA-v3gw-vwrq-mq7v.json +++ b/advisories/unreviewed/2022/07/GHSA-v3gw-vwrq-mq7v/GHSA-v3gw-vwrq-mq7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v3gw-vwrq-mq7v", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1139" ], "details": "Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v3hv-r2rh-g9gw/GHSA-v3hv-r2rh-g9gw.json b/advisories/unreviewed/2022/07/GHSA-v3hv-r2rh-g9gw/GHSA-v3hv-r2rh-g9gw.json index 61548053c47..a995572635c 100644 --- a/advisories/unreviewed/2022/07/GHSA-v3hv-r2rh-g9gw/GHSA-v3hv-r2rh-g9gw.json +++ b/advisories/unreviewed/2022/07/GHSA-v3hv-r2rh-g9gw/GHSA-v3hv-r2rh-g9gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v3hv-r2rh-g9gw", - "modified": "2022-07-22T00:00:37Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-22T00:00:37Z", "aliases": [ "CVE-2022-30628" ], "details": "It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v6fx-fw28-5wwr/GHSA-v6fx-fw28-5wwr.json b/advisories/unreviewed/2022/07/GHSA-v6fx-fw28-5wwr/GHSA-v6fx-fw28-5wwr.json index 0f8fffdb2ad..86d0831dac7 100644 --- a/advisories/unreviewed/2022/07/GHSA-v6fx-fw28-5wwr/GHSA-v6fx-fw28-5wwr.json +++ b/advisories/unreviewed/2022/07/GHSA-v6fx-fw28-5wwr/GHSA-v6fx-fw28-5wwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v6fx-fw28-5wwr", - "modified": "2022-07-20T00:00:21Z", + "modified": "2022-07-28T00:00:51Z", "published": "2022-07-20T00:00:21Z", "aliases": [ "CVE-2022-2193" ], "details": "Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to 6.14.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v878-67xw-grw2/GHSA-v878-67xw-grw2.json b/advisories/unreviewed/2022/07/GHSA-v878-67xw-grw2/GHSA-v878-67xw-grw2.json new file mode 100644 index 00000000000..60329efff82 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v878-67xw-grw2/GHSA-v878-67xw-grw2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v878-67xw-grw2", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36883" + ], + "details": "A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36883" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v9c7-jfxg-gf53/GHSA-v9c7-jfxg-gf53.json b/advisories/unreviewed/2022/07/GHSA-v9c7-jfxg-gf53/GHSA-v9c7-jfxg-gf53.json new file mode 100644 index 00000000000..3c392e97888 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v9c7-jfxg-gf53/GHSA-v9c7-jfxg-gf53.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v9c7-jfxg-gf53", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-34550" + ], + "details": "Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34550" + }, + { + "type": "WEB", + "url": "https://github.com/rawchen/sims/issues/8" + }, + { + "type": "WEB", + "url": "http://cwe.mitre.org/data/definitions/79.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vgp3-2wc7-6gv5/GHSA-vgp3-2wc7-6gv5.json b/advisories/unreviewed/2022/07/GHSA-vgp3-2wc7-6gv5/GHSA-vgp3-2wc7-6gv5.json new file mode 100644 index 00000000000..a8a1a03414a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vgp3-2wc7-6gv5/GHSA-vgp3-2wc7-6gv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vgp3-2wc7-6gv5", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-34549" + ], + "details": "Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34549" + }, + { + "type": "WEB", + "url": "https://github.com/rawchen/sims/issues/6" + }, + { + "type": "WEB", + "url": "http://cwe.mitre.org/data/definitions/434.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vgx6-62w9-6xwh/GHSA-vgx6-62w9-6xwh.json b/advisories/unreviewed/2022/07/GHSA-vgx6-62w9-6xwh/GHSA-vgx6-62w9-6xwh.json index 8c60084fd3a..4e194d4090e 100644 --- a/advisories/unreviewed/2022/07/GHSA-vgx6-62w9-6xwh/GHSA-vgx6-62w9-6xwh.json +++ b/advisories/unreviewed/2022/07/GHSA-vgx6-62w9-6xwh/GHSA-vgx6-62w9-6xwh.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vgx6-62w9-6xwh", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-29060" ], "details": "A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vjp2-9hqr-v334/GHSA-vjp2-9hqr-v334.json b/advisories/unreviewed/2022/07/GHSA-vjp2-9hqr-v334/GHSA-vjp2-9hqr-v334.json index 1c6dd25814e..628ad1c095e 100644 --- a/advisories/unreviewed/2022/07/GHSA-vjp2-9hqr-v334/GHSA-vjp2-9hqr-v334.json +++ b/advisories/unreviewed/2022/07/GHSA-vjp2-9hqr-v334/GHSA-vjp2-9hqr-v334.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vjp2-9hqr-v334", - "modified": "2022-07-21T00:00:26Z", + "modified": "2022-07-28T00:00:47Z", "published": "2022-07-21T00:00:26Z", "aliases": [ "CVE-2020-21406" ], "details": "An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vm7v-r6xm-652p/GHSA-vm7v-r6xm-652p.json b/advisories/unreviewed/2022/07/GHSA-vm7v-r6xm-652p/GHSA-vm7v-r6xm-652p.json index d24bd0c57ec..687a99c2b43 100644 --- a/advisories/unreviewed/2022/07/GHSA-vm7v-r6xm-652p/GHSA-vm7v-r6xm-652p.json +++ b/advisories/unreviewed/2022/07/GHSA-vm7v-r6xm-652p/GHSA-vm7v-r6xm-652p.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5191" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-403.txt" diff --git a/advisories/unreviewed/2022/07/GHSA-vp68-fm96-7v79/GHSA-vp68-fm96-7v79.json b/advisories/unreviewed/2022/07/GHSA-vp68-fm96-7v79/GHSA-vp68-fm96-7v79.json new file mode 100644 index 00000000000..55ce3761604 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vp68-fm96-7v79/GHSA-vp68-fm96-7v79.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vp68-fm96-7v79", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36915" + ], + "details": "Jenkins Android Signing Plugin 2.2.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36915" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2404" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vp6f-wfqp-3623/GHSA-vp6f-wfqp-3623.json b/advisories/unreviewed/2022/07/GHSA-vp6f-wfqp-3623/GHSA-vp6f-wfqp-3623.json index 4553078d610..c37fead3411 100644 --- a/advisories/unreviewed/2022/07/GHSA-vp6f-wfqp-3623/GHSA-vp6f-wfqp-3623.json +++ b/advisories/unreviewed/2022/07/GHSA-vp6f-wfqp-3623/GHSA-vp6f-wfqp-3623.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vp6f-wfqp-3623", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-28T00:00:50Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-30302" ], "details": "Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlying filesystem via specially crafted web requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vpf7-q2rx-26mh/GHSA-vpf7-q2rx-26mh.json b/advisories/unreviewed/2022/07/GHSA-vpf7-q2rx-26mh/GHSA-vpf7-q2rx-26mh.json new file mode 100644 index 00000000000..103b50d1417 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vpf7-q2rx-26mh/GHSA-vpf7-q2rx-26mh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vpf7-q2rx-26mh", + "modified": "2022-07-28T00:00:43Z", + "published": "2022-07-28T00:00:43Z", + "aliases": [ + "CVE-2022-36888" + ], + "details": "A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36888" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2593" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vrhf-cc97-jx2x/GHSA-vrhf-cc97-jx2x.json b/advisories/unreviewed/2022/07/GHSA-vrhf-cc97-jx2x/GHSA-vrhf-cc97-jx2x.json index 5103b978045..76d58dc0908 100644 --- a/advisories/unreviewed/2022/07/GHSA-vrhf-cc97-jx2x/GHSA-vrhf-cc97-jx2x.json +++ b/advisories/unreviewed/2022/07/GHSA-vrhf-cc97-jx2x/GHSA-vrhf-cc97-jx2x.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5188" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5192" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2022.html" diff --git a/advisories/unreviewed/2022/07/GHSA-vv62-xm44-43pw/GHSA-vv62-xm44-43pw.json b/advisories/unreviewed/2022/07/GHSA-vv62-xm44-43pw/GHSA-vv62-xm44-43pw.json index 69b0eeb0271..481e1ba44a9 100644 --- a/advisories/unreviewed/2022/07/GHSA-vv62-xm44-43pw/GHSA-vv62-xm44-43pw.json +++ b/advisories/unreviewed/2022/07/GHSA-vv62-xm44-43pw/GHSA-vv62-xm44-43pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vv62-xm44-43pw", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20858" ], "details": "Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w26q-54h4-q58c/GHSA-w26q-54h4-q58c.json b/advisories/unreviewed/2022/07/GHSA-w26q-54h4-q58c/GHSA-w26q-54h4-q58c.json index 6846e8a2c52..10ded5cde3b 100644 --- a/advisories/unreviewed/2022/07/GHSA-w26q-54h4-q58c/GHSA-w26q-54h4-q58c.json +++ b/advisories/unreviewed/2022/07/GHSA-w26q-54h4-q58c/GHSA-w26q-54h4-q58c.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w26q-54h4-q58c", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-34367" ], "details": "Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w4gp-qv48-5jc9/GHSA-w4gp-qv48-5jc9.json b/advisories/unreviewed/2022/07/GHSA-w4gp-qv48-5jc9/GHSA-w4gp-qv48-5jc9.json index cf44cc0f2e5..e79327926b5 100644 --- a/advisories/unreviewed/2022/07/GHSA-w4gp-qv48-5jc9/GHSA-w4gp-qv48-5jc9.json +++ b/advisories/unreviewed/2022/07/GHSA-w4gp-qv48-5jc9/GHSA-w4gp-qv48-5jc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w4gp-qv48-5jc9", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-33317" ], "details": "Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-829" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w4w4-8x3v-5mj3/GHSA-w4w4-8x3v-5mj3.json b/advisories/unreviewed/2022/07/GHSA-w4w4-8x3v-5mj3/GHSA-w4w4-8x3v-5mj3.json index 4c6aafa46e5..b519398ae14 100644 --- a/advisories/unreviewed/2022/07/GHSA-w4w4-8x3v-5mj3/GHSA-w4w4-8x3v-5mj3.json +++ b/advisories/unreviewed/2022/07/GHSA-w4w4-8x3v-5mj3/GHSA-w4w4-8x3v-5mj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w4w4-8x3v-5mj3", - "modified": "2022-07-20T00:00:21Z", + "modified": "2022-07-28T00:00:50Z", "published": "2022-07-20T00:00:21Z", "aliases": [ "CVE-2021-32504" ], "details": "Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w75p-6382-63hg/GHSA-w75p-6382-63hg.json b/advisories/unreviewed/2022/07/GHSA-w75p-6382-63hg/GHSA-w75p-6382-63hg.json new file mode 100644 index 00000000000..d9638fc9acc --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w75p-6382-63hg/GHSA-w75p-6382-63hg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w75p-6382-63hg", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-36951" + ], + "details": "In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36951" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-009#Issue2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w77j-2gh3-6mvp/GHSA-w77j-2gh3-6mvp.json b/advisories/unreviewed/2022/07/GHSA-w77j-2gh3-6mvp/GHSA-w77j-2gh3-6mvp.json index ee689eab789..239b2ba6589 100644 --- a/advisories/unreviewed/2022/07/GHSA-w77j-2gh3-6mvp/GHSA-w77j-2gh3-6mvp.json +++ b/advisories/unreviewed/2022/07/GHSA-w77j-2gh3-6mvp/GHSA-w77j-2gh3-6mvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w77j-2gh3-6mvp", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1145" ], "details": "Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interaction and profile destruction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json new file mode 100644 index 00000000000..dc270585624 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w785-44wh-9wr3", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2021-38410" + ], + "details": "AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38410" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/en/support-and-success/cyber-security-updates/" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w7qx-54fx-55q8/GHSA-w7qx-54fx-55q8.json b/advisories/unreviewed/2022/07/GHSA-w7qx-54fx-55q8/GHSA-w7qx-54fx-55q8.json new file mode 100644 index 00000000000..2fd60439fa1 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w7qx-54fx-55q8/GHSA-w7qx-54fx-55q8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w7qx-54fx-55q8", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1857" + ], + "details": "Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass file system restrictions via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1857" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1227995" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w8gx-4r6w-3rx9/GHSA-w8gx-4r6w-3rx9.json b/advisories/unreviewed/2022/07/GHSA-w8gx-4r6w-3rx9/GHSA-w8gx-4r6w-3rx9.json new file mode 100644 index 00000000000..572c57b030f --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w8gx-4r6w-3rx9/GHSA-w8gx-4r6w-3rx9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w8gx-4r6w-3rx9", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36892" + ], + "details": "Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36892" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2402" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json b/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json new file mode 100644 index 00000000000..0f0684cc345 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wc5v-h4fq-4g72", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2021-42537" + ], + "details": "VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42537" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wcxw-9v7x-9r9c/GHSA-wcxw-9v7x-9r9c.json b/advisories/unreviewed/2022/07/GHSA-wcxw-9v7x-9r9c/GHSA-wcxw-9v7x-9r9c.json index 56ca878ab64..18651a33ec3 100644 --- a/advisories/unreviewed/2022/07/GHSA-wcxw-9v7x-9r9c/GHSA-wcxw-9v7x-9r9c.json +++ b/advisories/unreviewed/2022/07/GHSA-wcxw-9v7x-9r9c/GHSA-wcxw-9v7x-9r9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wcxw-9v7x-9r9c", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1131" ], "details": "Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wp7f-3m97-grc2/GHSA-wp7f-3m97-grc2.json b/advisories/unreviewed/2022/07/GHSA-wp7f-3m97-grc2/GHSA-wp7f-3m97-grc2.json index ca5cd06144d..1df442a9702 100644 --- a/advisories/unreviewed/2022/07/GHSA-wp7f-3m97-grc2/GHSA-wp7f-3m97-grc2.json +++ b/advisories/unreviewed/2022/07/GHSA-wp7f-3m97-grc2/GHSA-wp7f-3m97-grc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wp7f-3m97-grc2", - "modified": "2022-07-24T00:00:34Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-24T00:00:34Z", "aliases": [ "CVE-2022-1142" ], "details": "Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wpqf-f5ff-6c5w/GHSA-wpqf-f5ff-6c5w.json b/advisories/unreviewed/2022/07/GHSA-wpqf-f5ff-6c5w/GHSA-wpqf-f5ff-6c5w.json index 21ae0267175..fcb721519a8 100644 --- a/advisories/unreviewed/2022/07/GHSA-wpqf-f5ff-6c5w/GHSA-wpqf-f5ff-6c5w.json +++ b/advisories/unreviewed/2022/07/GHSA-wpqf-f5ff-6c5w/GHSA-wpqf-f5ff-6c5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wpqf-f5ff-6c5w", - "modified": "2022-07-19T00:00:25Z", + "modified": "2022-07-28T00:00:39Z", "published": "2022-07-19T00:00:25Z", "aliases": [ "CVE-2022-22445" ], "details": "An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wrmg-wv9p-r52j/GHSA-wrmg-wv9p-r52j.json b/advisories/unreviewed/2022/07/GHSA-wrmg-wv9p-r52j/GHSA-wrmg-wv9p-r52j.json index 60179e8ad24..e174c0ebd9d 100644 --- a/advisories/unreviewed/2022/07/GHSA-wrmg-wv9p-r52j/GHSA-wrmg-wv9p-r52j.json +++ b/advisories/unreviewed/2022/07/GHSA-wrmg-wv9p-r52j/GHSA-wrmg-wv9p-r52j.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wrmg-wv9p-r52j", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:49Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1314" ], "details": "Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wwv7-h477-wrv7/GHSA-wwv7-h477-wrv7.json b/advisories/unreviewed/2022/07/GHSA-wwv7-h477-wrv7/GHSA-wwv7-h477-wrv7.json index e6dde4ae2b0..368e9cf74f9 100644 --- a/advisories/unreviewed/2022/07/GHSA-wwv7-h477-wrv7/GHSA-wwv7-h477-wrv7.json +++ b/advisories/unreviewed/2022/07/GHSA-wwv7-h477-wrv7/GHSA-wwv7-h477-wrv7.json @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106275" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=436458" diff --git a/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json b/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json new file mode 100644 index 00000000000..a0c849c2b64 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wwxv-fc92-xrw3", + "modified": "2022-07-28T00:00:53Z", + "published": "2022-07-28T00:00:53Z", + "aliases": [ + "CVE-2022-36879" + ], + "details": "An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36879" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/f85daf0e725358be78dfd208dea5fd665d8cb901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=f85daf0e725358be78dfd208dea5fd665d8cb901" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json b/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json new file mode 100644 index 00000000000..9b5cf50bea3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x2fp-wfrh-r34v", + "modified": "2022-07-28T00:00:41Z", + "published": "2022-07-28T00:00:41Z", + "aliases": [ + "CVE-2022-35669" + ], + "details": "Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35669" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb22-32.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json b/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json new file mode 100644 index 00000000000..2d415a8b0a0 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x4q2-hpmw-6w22", + "modified": "2022-07-28T00:00:52Z", + "published": "2022-07-28T00:00:52Z", + "aliases": [ + "CVE-2022-34611" + ], + "details": "A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the \"Contac #\" text field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34611" + }, + { + "type": "WEB", + "url": "https://github.com/As4ki/CVE-report/blob/main/OFRS.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/" + }, + { + "type": "WEB", + "url": "http://online.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json b/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json new file mode 100644 index 00000000000..f6465df5e7a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x5fh-pc22-3jcj", + "modified": "2022-07-28T00:00:49Z", + "published": "2022-07-28T00:00:49Z", + "aliases": [ + "CVE-2022-2549" + ], + "details": "NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2549" + }, + { + "type": "WEB", + "url": "https://github.com/gpac/gpac/commit/0102c5d4db7fdbf08b5b591b2a6264de33867a07" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/c93083dc-177c-4ba0-ba83-9d7fb29a5537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x7w4-vfrh-fc3h/GHSA-x7w4-vfrh-fc3h.json b/advisories/unreviewed/2022/07/GHSA-x7w4-vfrh-fc3h/GHSA-x7w4-vfrh-fc3h.json new file mode 100644 index 00000000000..f10886268f3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-x7w4-vfrh-fc3h/GHSA-x7w4-vfrh-fc3h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x7w4-vfrh-fc3h", + "modified": "2022-07-28T00:00:42Z", + "published": "2022-07-28T00:00:42Z", + "aliases": [ + "CVE-2022-36919" + ], + "details": "A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36919" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2790%20(1)" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/27/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x92g-6c25-c2jv/GHSA-x92g-6c25-c2jv.json b/advisories/unreviewed/2022/07/GHSA-x92g-6c25-c2jv/GHSA-x92g-6c25-c2jv.json index 1879f414ff2..fa062278a79 100644 --- a/advisories/unreviewed/2022/07/GHSA-x92g-6c25-c2jv/GHSA-x92g-6c25-c2jv.json +++ b/advisories/unreviewed/2022/07/GHSA-x92g-6c25-c2jv/GHSA-x92g-6c25-c2jv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-x92g-6c25-c2jv", - "modified": "2022-07-24T00:00:33Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-24T00:00:33Z", "aliases": [ "CVE-2022-1128" ], "details": "Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xgxg-m2p7-6pr3/GHSA-xgxg-m2p7-6pr3.json b/advisories/unreviewed/2022/07/GHSA-xgxg-m2p7-6pr3/GHSA-xgxg-m2p7-6pr3.json index 2d945a55141..a9e73be2916 100644 --- a/advisories/unreviewed/2022/07/GHSA-xgxg-m2p7-6pr3/GHSA-xgxg-m2p7-6pr3.json +++ b/advisories/unreviewed/2022/07/GHSA-xgxg-m2p7-6pr3/GHSA-xgxg-m2p7-6pr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xgxg-m2p7-6pr3", - "modified": "2022-07-21T00:00:28Z", + "modified": "2022-07-28T00:00:44Z", "published": "2022-07-21T00:00:28Z", "aliases": [ "CVE-2022-34049" ], "details": "An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xjx8-665x-j9wh/GHSA-xjx8-665x-j9wh.json b/advisories/unreviewed/2022/07/GHSA-xjx8-665x-j9wh/GHSA-xjx8-665x-j9wh.json index 00d93fd8835..520b9d9b08c 100644 --- a/advisories/unreviewed/2022/07/GHSA-xjx8-665x-j9wh/GHSA-xjx8-665x-j9wh.json +++ b/advisories/unreviewed/2022/07/GHSA-xjx8-665x-j9wh/GHSA-xjx8-665x-j9wh.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xjx8-665x-j9wh", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2020-36557" ], "details": "A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xmjp-848v-p77x/GHSA-xmjp-848v-p77x.json b/advisories/unreviewed/2022/07/GHSA-xmjp-848v-p77x/GHSA-xmjp-848v-p77x.json new file mode 100644 index 00000000000..7652cf86c57 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xmjp-848v-p77x/GHSA-xmjp-848v-p77x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xmjp-848v-p77x", + "modified": "2022-07-28T00:00:40Z", + "published": "2022-07-28T00:00:40Z", + "aliases": [ + "CVE-2022-1859" + ], + "details": "Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1859" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1322744" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xp2f-9mx3-3c6p/GHSA-xp2f-9mx3-3c6p.json b/advisories/unreviewed/2022/07/GHSA-xp2f-9mx3-3c6p/GHSA-xp2f-9mx3-3c6p.json index ffe606e5981..ef53113a387 100644 --- a/advisories/unreviewed/2022/07/GHSA-xp2f-9mx3-3c6p/GHSA-xp2f-9mx3-3c6p.json +++ b/advisories/unreviewed/2022/07/GHSA-xp2f-9mx3-3c6p/GHSA-xp2f-9mx3-3c6p.json @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106273" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=436456" diff --git a/advisories/unreviewed/2022/07/GHSA-xpxr-m6jm-3qph/GHSA-xpxr-m6jm-3qph.json b/advisories/unreviewed/2022/07/GHSA-xpxr-m6jm-3qph/GHSA-xpxr-m6jm-3qph.json new file mode 100644 index 00000000000..4ba356dfed9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xpxr-m6jm-3qph/GHSA-xpxr-m6jm-3qph.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xpxr-m6jm-3qph", + "modified": "2022-07-28T00:00:39Z", + "published": "2022-07-28T00:00:39Z", + "aliases": [ + "CVE-2022-1871" + ], + "details": "Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1871" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1308199" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xrg3-35mw-8rhg/GHSA-xrg3-35mw-8rhg.json b/advisories/unreviewed/2022/07/GHSA-xrg3-35mw-8rhg/GHSA-xrg3-35mw-8rhg.json index b897f3192cb..c45c1cc2cfc 100644 --- a/advisories/unreviewed/2022/07/GHSA-xrg3-35mw-8rhg/GHSA-xrg3-35mw-8rhg.json +++ b/advisories/unreviewed/2022/07/GHSA-xrg3-35mw-8rhg/GHSA-xrg3-35mw-8rhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xrg3-35mw-8rhg", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20860" ], "details": "A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is establishing a connection to Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud APIC, or Cisco Nexus Dashboard Fabric Controller, formerly Data Center Network Manager (DCNM) controllers. An attacker could exploit this vulnerability by using man-in-the-middle techniques to intercept the traffic between the affected device and the controllers, and then using a crafted certificate to impersonate the controllers. A successful exploit could allow the attacker to alter communications between devices or view sensitive information, including Administrator credentials for these controllers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xvm4-2pvm-hp3g/GHSA-xvm4-2pvm-hp3g.json b/advisories/unreviewed/2022/07/GHSA-xvm4-2pvm-hp3g/GHSA-xvm4-2pvm-hp3g.json index 761d489811c..8687756f8a1 100644 --- a/advisories/unreviewed/2022/07/GHSA-xvm4-2pvm-hp3g/GHSA-xvm4-2pvm-hp3g.json +++ b/advisories/unreviewed/2022/07/GHSA-xvm4-2pvm-hp3g/GHSA-xvm4-2pvm-hp3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xvm4-2pvm-hp3g", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-2107" ], "details": "The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xvv2-cw9q-2m9r/GHSA-xvv2-cw9q-2m9r.json b/advisories/unreviewed/2022/07/GHSA-xvv2-cw9q-2m9r/GHSA-xvv2-cw9q-2m9r.json index e097798d8c3..a465da9f600 100644 --- a/advisories/unreviewed/2022/07/GHSA-xvv2-cw9q-2m9r/GHSA-xvv2-cw9q-2m9r.json +++ b/advisories/unreviewed/2022/07/GHSA-xvv2-cw9q-2m9r/GHSA-xvv2-cw9q-2m9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xvv2-cw9q-2m9r", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-28T00:00:43Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-34001" ], "details": "Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xw76-qw2j-v4fp/GHSA-xw76-qw2j-v4fp.json b/advisories/unreviewed/2022/07/GHSA-xw76-qw2j-v4fp/GHSA-xw76-qw2j-v4fp.json index ab067c2430c..f4db2329d23 100644 --- a/advisories/unreviewed/2022/07/GHSA-xw76-qw2j-v4fp/GHSA-xw76-qw2j-v4fp.json +++ b/advisories/unreviewed/2022/07/GHSA-xw76-qw2j-v4fp/GHSA-xw76-qw2j-v4fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xw76-qw2j-v4fp", - "modified": "2022-07-26T00:01:08Z", + "modified": "2022-07-28T00:00:48Z", "published": "2022-07-26T00:01:08Z", "aliases": [ "CVE-2022-1311" ], "details": "Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json b/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json index d41d014db35..80ca9faf2e8 100644 --- a/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json +++ b/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xwjg-qxv6-28rv", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-28T00:00:41Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20857" ], "details": "Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xxw8-ppw6-gv4w/GHSA-xxw8-ppw6-gv4w.json b/advisories/unreviewed/2022/07/GHSA-xxw8-ppw6-gv4w/GHSA-xxw8-ppw6-gv4w.json index 30346845109..b6e461f32de 100644 --- a/advisories/unreviewed/2022/07/GHSA-xxw8-ppw6-gv4w/GHSA-xxw8-ppw6-gv4w.json +++ b/advisories/unreviewed/2022/07/GHSA-xxw8-ppw6-gv4w/GHSA-xxw8-ppw6-gv4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xxw8-ppw6-gv4w", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-28T00:00:40Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-24660" ], "details": "The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file