diff --git a/advisories/unreviewed/2022/04/GHSA-8hr8-h5jx-w7gp/GHSA-8hr8-h5jx-w7gp.json b/advisories/unreviewed/2022/04/GHSA-8hr8-h5jx-w7gp/GHSA-8hr8-h5jx-w7gp.json index a2cb0b570a2..c612c3a1c9a 100644 --- a/advisories/unreviewed/2022/04/GHSA-8hr8-h5jx-w7gp/GHSA-8hr8-h5jx-w7gp.json +++ b/advisories/unreviewed/2022/04/GHSA-8hr8-h5jx-w7gp/GHSA-8hr8-h5jx-w7gp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8hr8-h5jx-w7gp", - "modified": "2022-04-22T00:24:21Z", + "modified": "2025-02-13T18:31:20Z", "published": "2022-04-22T00:24:21Z", "aliases": [ "CVE-2011-4595" ], "details": "Pretty-Link WordPress plugin 1.5.2 has XSS", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-qgm5-3gxj-29mw/GHSA-qgm5-3gxj-29mw.json b/advisories/unreviewed/2022/12/GHSA-qgm5-3gxj-29mw/GHSA-qgm5-3gxj-29mw.json index cc8baa2f552..9bb126b3761 100644 --- a/advisories/unreviewed/2022/12/GHSA-qgm5-3gxj-29mw/GHSA-qgm5-3gxj-29mw.json +++ b/advisories/unreviewed/2022/12/GHSA-qgm5-3gxj-29mw/GHSA-qgm5-3gxj-29mw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgm5-3gxj-29mw", - "modified": "2022-12-28T21:30:22Z", + "modified": "2025-02-13T18:31:21Z", "published": "2022-12-19T09:30:22Z", "aliases": [ "CVE-2022-4427" diff --git a/advisories/unreviewed/2023/01/GHSA-5j3v-r3rh-6vh7/GHSA-5j3v-r3rh-6vh7.json b/advisories/unreviewed/2023/01/GHSA-5j3v-r3rh-6vh7/GHSA-5j3v-r3rh-6vh7.json index c173ad7a5a0..5c77112cab9 100644 --- a/advisories/unreviewed/2023/01/GHSA-5j3v-r3rh-6vh7/GHSA-5j3v-r3rh-6vh7.json +++ b/advisories/unreviewed/2023/01/GHSA-5j3v-r3rh-6vh7/GHSA-5j3v-r3rh-6vh7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5j3v-r3rh-6vh7", - "modified": "2023-01-12T21:30:29Z", + "modified": "2025-02-13T18:31:21Z", "published": "2023-01-07T00:30:23Z", "aliases": [ "CVE-2022-40201" diff --git a/advisories/unreviewed/2023/01/GHSA-mjxf-pxf8-wjmw/GHSA-mjxf-pxf8-wjmw.json b/advisories/unreviewed/2023/01/GHSA-mjxf-pxf8-wjmw/GHSA-mjxf-pxf8-wjmw.json index 6f351badd9c..f83f4abb5b0 100644 --- a/advisories/unreviewed/2023/01/GHSA-mjxf-pxf8-wjmw/GHSA-mjxf-pxf8-wjmw.json +++ b/advisories/unreviewed/2023/01/GHSA-mjxf-pxf8-wjmw/GHSA-mjxf-pxf8-wjmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjxf-pxf8-wjmw", - "modified": "2023-02-07T18:30:19Z", + "modified": "2025-02-13T18:31:22Z", "published": "2023-01-31T03:30:26Z", "aliases": [ "CVE-2022-40258" diff --git a/advisories/unreviewed/2023/01/GHSA-mqw8-q64p-6837/GHSA-mqw8-q64p-6837.json b/advisories/unreviewed/2023/01/GHSA-mqw8-q64p-6837/GHSA-mqw8-q64p-6837.json index f5a16e6c398..d5bb2f19267 100644 --- a/advisories/unreviewed/2023/01/GHSA-mqw8-q64p-6837/GHSA-mqw8-q64p-6837.json +++ b/advisories/unreviewed/2023/01/GHSA-mqw8-q64p-6837/GHSA-mqw8-q64p-6837.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqw8-q64p-6837", - "modified": "2023-01-12T21:30:29Z", + "modified": "2025-02-13T18:31:21Z", "published": "2023-01-07T00:30:23Z", "aliases": [ "CVE-2022-41613" diff --git a/advisories/unreviewed/2023/01/GHSA-p5j8-2qpf-wxr5/GHSA-p5j8-2qpf-wxr5.json b/advisories/unreviewed/2023/01/GHSA-p5j8-2qpf-wxr5/GHSA-p5j8-2qpf-wxr5.json index 75f3e920b63..b6c356d00bb 100644 --- a/advisories/unreviewed/2023/01/GHSA-p5j8-2qpf-wxr5/GHSA-p5j8-2qpf-wxr5.json +++ b/advisories/unreviewed/2023/01/GHSA-p5j8-2qpf-wxr5/GHSA-p5j8-2qpf-wxr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5j8-2qpf-wxr5", - "modified": "2023-01-25T03:30:32Z", + "modified": "2025-02-13T18:31:21Z", "published": "2023-01-17T21:30:22Z", "aliases": [ "CVE-2006-20001" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202309-01" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230316-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-r6c5-m6xc-3746/GHSA-r6c5-m6xc-3746.json b/advisories/unreviewed/2023/01/GHSA-r6c5-m6xc-3746/GHSA-r6c5-m6xc-3746.json index 2ce7ca9aee7..a3c53c9980e 100644 --- a/advisories/unreviewed/2023/01/GHSA-r6c5-m6xc-3746/GHSA-r6c5-m6xc-3746.json +++ b/advisories/unreviewed/2023/01/GHSA-r6c5-m6xc-3746/GHSA-r6c5-m6xc-3746.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6c5-m6xc-3746", - "modified": "2023-01-13T15:30:26Z", + "modified": "2025-02-13T18:31:21Z", "published": "2023-01-09T12:30:18Z", "aliases": [ "CVE-2022-2196" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230223-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-6gqv-38q3-6c47/GHSA-6gqv-38q3-6c47.json b/advisories/unreviewed/2023/02/GHSA-6gqv-38q3-6c47/GHSA-6gqv-38q3-6c47.json index 28c0c0cbb7b..32946d26e8a 100644 --- a/advisories/unreviewed/2023/02/GHSA-6gqv-38q3-6c47/GHSA-6gqv-38q3-6c47.json +++ b/advisories/unreviewed/2023/02/GHSA-6gqv-38q3-6c47/GHSA-6gqv-38q3-6c47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gqv-38q3-6c47", - "modified": "2023-02-24T18:30:26Z", + "modified": "2025-02-13T18:31:24Z", "published": "2023-02-16T09:30:29Z", "aliases": [ "CVE-2023-0568" diff --git a/advisories/unreviewed/2023/03/GHSA-r66m-27p7-w8fm/GHSA-r66m-27p7-w8fm.json b/advisories/unreviewed/2023/03/GHSA-r66m-27p7-w8fm/GHSA-r66m-27p7-w8fm.json index e483cc417c5..10816ef6458 100644 --- a/advisories/unreviewed/2023/03/GHSA-r66m-27p7-w8fm/GHSA-r66m-27p7-w8fm.json +++ b/advisories/unreviewed/2023/03/GHSA-r66m-27p7-w8fm/GHSA-r66m-27p7-w8fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r66m-27p7-w8fm", - "modified": "2023-03-24T21:30:48Z", + "modified": "2025-02-13T18:31:26Z", "published": "2023-03-22T15:30:19Z", "aliases": [ "CVE-2023-1281" diff --git a/advisories/unreviewed/2023/04/GHSA-238j-pxjv-rh2p/GHSA-238j-pxjv-rh2p.json b/advisories/unreviewed/2023/04/GHSA-238j-pxjv-rh2p/GHSA-238j-pxjv-rh2p.json index 96d1c80217e..44cf6315c52 100644 --- a/advisories/unreviewed/2023/04/GHSA-238j-pxjv-rh2p/GHSA-238j-pxjv-rh2p.json +++ b/advisories/unreviewed/2023/04/GHSA-238j-pxjv-rh2p/GHSA-238j-pxjv-rh2p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-46pm-cwjr-9r9x/GHSA-46pm-cwjr-9r9x.json b/advisories/unreviewed/2023/04/GHSA-46pm-cwjr-9r9x/GHSA-46pm-cwjr-9r9x.json index 30e5572e676..b23b714447f 100644 --- a/advisories/unreviewed/2023/04/GHSA-46pm-cwjr-9r9x/GHSA-46pm-cwjr-9r9x.json +++ b/advisories/unreviewed/2023/04/GHSA-46pm-cwjr-9r9x/GHSA-46pm-cwjr-9r9x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-426" + "CWE-426", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json b/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json index 54558a180f7..fac7a3f054a 100644 --- a/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json +++ b/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wg5-gmxh-4r2r", - "modified": "2023-04-10T21:30:23Z", + "modified": "2025-02-13T18:31:28Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2023-26437" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json index be55c2dbfe6..835bf7706ad 100644 --- a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json +++ b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x5j-gwp5-7hgh", - "modified": "2023-04-10T18:30:21Z", + "modified": "2025-02-13T18:31:32Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0486" diff --git a/advisories/unreviewed/2023/04/GHSA-c3h9-vpfv-3x4m/GHSA-c3h9-vpfv-3x4m.json b/advisories/unreviewed/2023/04/GHSA-c3h9-vpfv-3x4m/GHSA-c3h9-vpfv-3x4m.json index dde66279b87..f22347255e4 100644 --- a/advisories/unreviewed/2023/04/GHSA-c3h9-vpfv-3x4m/GHSA-c3h9-vpfv-3x4m.json +++ b/advisories/unreviewed/2023/04/GHSA-c3h9-vpfv-3x4m/GHSA-c3h9-vpfv-3x4m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c3h9-vpfv-3x4m", - "modified": "2024-04-04T03:41:38Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-04-26T15:30:21Z", "aliases": [ "CVE-2023-1387" ], - "details": "Grafana is an open-source platform for monitoring and observability. \n\nStarting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. \n\nBy enabling the \"url_login\" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana.\n\n", + "details": "Grafana is an open-source platform for monitoring and observability. \n\nStarting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. \n\nBy enabling the \"url_login\" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json index e9e6b84aa2d..2b74296ba35 100644 --- a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json +++ b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g23c-4prh-q9fg", - "modified": "2023-04-10T18:30:21Z", + "modified": "2025-02-13T18:31:30Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0357" diff --git a/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json b/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json index 985696fbeef..c7f9fcc09de 100644 --- a/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json +++ b/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jhw6-rjph-429f", - "modified": "2024-02-29T21:30:51Z", + "modified": "2025-02-13T18:31:33Z", "published": "2023-04-12T18:30:39Z", "aliases": [ "CVE-2023-1872" ], - "details": "A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation.\n\nThe io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered.\n\nWe recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.\n\n", + "details": "A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation.\n\nThe io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered.\n\nWe recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json index b421e6b01d3..4e1bfc5d82b 100644 --- a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json +++ b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv2f-j4fc-4c7g", - "modified": "2023-04-10T21:30:23Z", + "modified": "2025-02-13T18:31:28Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23257" diff --git a/advisories/unreviewed/2023/04/GHSA-r6wr-pw22-2qqc/GHSA-r6wr-pw22-2qqc.json b/advisories/unreviewed/2023/04/GHSA-r6wr-pw22-2qqc/GHSA-r6wr-pw22-2qqc.json index 5022b20d840..ae58c0fca8e 100644 --- a/advisories/unreviewed/2023/04/GHSA-r6wr-pw22-2qqc/GHSA-r6wr-pw22-2qqc.json +++ b/advisories/unreviewed/2023/04/GHSA-r6wr-pw22-2qqc/GHSA-r6wr-pw22-2qqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6wr-pw22-2qqc", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-13T18:31:33Z", "published": "2023-04-05T00:30:38Z", "aliases": [ "CVE-2023-0738" diff --git a/advisories/unreviewed/2023/04/GHSA-v2w5-mxw3-ccwc/GHSA-v2w5-mxw3-ccwc.json b/advisories/unreviewed/2023/04/GHSA-v2w5-mxw3-ccwc/GHSA-v2w5-mxw3-ccwc.json index 52d5fa7181c..61644176278 100644 --- a/advisories/unreviewed/2023/04/GHSA-v2w5-mxw3-ccwc/GHSA-v2w5-mxw3-ccwc.json +++ b/advisories/unreviewed/2023/04/GHSA-v2w5-mxw3-ccwc/GHSA-v2w5-mxw3-ccwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v2w5-mxw3-ccwc", - "modified": "2023-04-11T15:30:28Z", + "modified": "2025-02-13T18:31:29Z", "published": "2023-04-04T18:30:21Z", "aliases": [ "CVE-2023-28613" diff --git a/advisories/unreviewed/2023/04/GHSA-w4fp-2356-fr6f/GHSA-w4fp-2356-fr6f.json b/advisories/unreviewed/2023/04/GHSA-w4fp-2356-fr6f/GHSA-w4fp-2356-fr6f.json index da896770bc0..808585a4a0e 100644 --- a/advisories/unreviewed/2023/04/GHSA-w4fp-2356-fr6f/GHSA-w4fp-2356-fr6f.json +++ b/advisories/unreviewed/2023/04/GHSA-w4fp-2356-fr6f/GHSA-w4fp-2356-fr6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4fp-2356-fr6f", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-13T18:31:33Z", "published": "2023-04-06T00:30:22Z", "aliases": [ "CVE-2022-31888" diff --git a/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json b/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json index 5d0910f6efd..2018e33b72c 100644 --- a/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json +++ b/advisories/unreviewed/2023/04/GHSA-wv94-3wc8-85h3/GHSA-wv94-3wc8-85h3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv94-3wc8-85h3", - "modified": "2023-04-10T18:30:21Z", + "modified": "2025-02-13T18:31:31Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0480" diff --git a/advisories/unreviewed/2023/05/GHSA-7cqg-75m4-9cvf/GHSA-7cqg-75m4-9cvf.json b/advisories/unreviewed/2023/05/GHSA-7cqg-75m4-9cvf/GHSA-7cqg-75m4-9cvf.json index 83d05fde7c0..2073255a252 100644 --- a/advisories/unreviewed/2023/05/GHSA-7cqg-75m4-9cvf/GHSA-7cqg-75m4-9cvf.json +++ b/advisories/unreviewed/2023/05/GHSA-7cqg-75m4-9cvf/GHSA-7cqg-75m4-9cvf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7cqg-75m4-9cvf", - "modified": "2024-04-04T03:50:17Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2023-2573" ], - "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.\n\n\n\n", + "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/05/GHSA-8gvj-4m38-qf6h/GHSA-8gvj-4m38-qf6h.json b/advisories/unreviewed/2023/05/GHSA-8gvj-4m38-qf6h/GHSA-8gvj-4m38-qf6h.json index 40799effc35..773ba89ef2c 100644 --- a/advisories/unreviewed/2023/05/GHSA-8gvj-4m38-qf6h/GHSA-8gvj-4m38-qf6h.json +++ b/advisories/unreviewed/2023/05/GHSA-8gvj-4m38-qf6h/GHSA-8gvj-4m38-qf6h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8gvj-4m38-qf6h", - "modified": "2024-04-04T04:03:56Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-05-12T15:30:22Z", "aliases": [ "CVE-2023-1934" ], - "details": "\nThe PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential infrastructure data, highlighting the severity of this vulnerability.\n\n", + "details": "The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential infrastructure data, highlighting the severity of this vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/05/GHSA-x9rg-f8pv-j6rh/GHSA-x9rg-f8pv-j6rh.json b/advisories/unreviewed/2023/05/GHSA-x9rg-f8pv-j6rh/GHSA-x9rg-f8pv-j6rh.json index 2aed18360e4..4abc152c6c6 100644 --- a/advisories/unreviewed/2023/05/GHSA-x9rg-f8pv-j6rh/GHSA-x9rg-f8pv-j6rh.json +++ b/advisories/unreviewed/2023/05/GHSA-x9rg-f8pv-j6rh/GHSA-x9rg-f8pv-j6rh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x9rg-f8pv-j6rh", - "modified": "2024-04-04T03:50:19Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2023-2574" ], - "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.\n", + "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json b/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json index a1e2ce3a5c7..71da1f765bc 100644 --- a/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json +++ b/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2873-9vw6-x36q", - "modified": "2024-04-04T04:49:33Z", + "modified": "2025-02-13T18:31:37Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-33933" ], - "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n", + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json index 9424624cd68..45bc04c2318 100644 --- a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json +++ b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-295v-9m5g-79q9", - "modified": "2024-04-04T05:16:10Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-3090" ], - "details": "A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.\n\nThe out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.\n\n\nWe recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.\n\n", + "details": "A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.\n\nThe out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.\n\n\nWe recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-35c2-3gp6-2xg9/GHSA-35c2-3gp6-2xg9.json b/advisories/unreviewed/2023/06/GHSA-35c2-3gp6-2xg9/GHSA-35c2-3gp6-2xg9.json index 7bbe1834ab7..5e0c72794a6 100644 --- a/advisories/unreviewed/2023/06/GHSA-35c2-3gp6-2xg9/GHSA-35c2-3gp6-2xg9.json +++ b/advisories/unreviewed/2023/06/GHSA-35c2-3gp6-2xg9/GHSA-35c2-3gp6-2xg9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-35c2-3gp6-2xg9", - "modified": "2024-01-07T12:30:29Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-32216" ], - "details": "Memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.\n\n", + "details": "Memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-438x-9g8x-78p5/GHSA-438x-9g8x-78p5.json b/advisories/unreviewed/2023/06/GHSA-438x-9g8x-78p5/GHSA-438x-9g8x-78p5.json index ce85fee5181..24a58b4c743 100644 --- a/advisories/unreviewed/2023/06/GHSA-438x-9g8x-78p5/GHSA-438x-9g8x-78p5.json +++ b/advisories/unreviewed/2023/06/GHSA-438x-9g8x-78p5/GHSA-438x-9g8x-78p5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-438x-9g8x-78p5", - "modified": "2024-04-04T04:47:51Z", + "modified": "2025-02-13T18:31:37Z", "published": "2023-06-13T21:30:18Z", "aliases": [ "CVE-2022-43684" ], - "details": "ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.\n\n\n\nAdditional Details\n\nThis issue is present in the following supported ServiceNow releases: \n\n\n\n * Quebec prior to Patch 10 Hot Fix 8b\n * Rome prior to Patch 10 Hot Fix 1\n * San Diego prior to Patch 7\n * Tokyo prior to Tokyo Patch 1; and \n * Utah prior to Utah General Availability \n\n\n\n\nIf this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.\n\n\n\n", + "details": "ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.\n\n\n\nAdditional Details\n\nThis issue is present in the following supported ServiceNow releases: \n\n\n\n * Quebec prior to Patch 10 Hot Fix 8b\n * Rome prior to Patch 10 Hot Fix 1\n * San Diego prior to Patch 7\n * Tokyo prior to Tokyo Patch 1; and \n * Utah prior to Utah General Availability \n\n\n\n\nIf this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-5r5w-ww4m-44x3/GHSA-5r5w-ww4m-44x3.json b/advisories/unreviewed/2023/06/GHSA-5r5w-ww4m-44x3/GHSA-5r5w-ww4m-44x3.json index 10ad5a80776..41979a8dbc2 100644 --- a/advisories/unreviewed/2023/06/GHSA-5r5w-ww4m-44x3/GHSA-5r5w-ww4m-44x3.json +++ b/advisories/unreviewed/2023/06/GHSA-5r5w-ww4m-44x3/GHSA-5r5w-ww4m-44x3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5r5w-ww4m-44x3", - "modified": "2024-04-04T04:49:29Z", + "modified": "2025-02-13T18:31:37Z", "published": "2023-06-14T09:30:41Z", "aliases": [ "CVE-2022-47184" ], - "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.\n\n", + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json index 9eba2a4e031..f2d363e3f9e 100644 --- a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json +++ b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5rc2-qffv-3c8p", - "modified": "2024-02-01T15:30:24Z", + "modified": "2025-02-13T18:31:37Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-30631" ], - "details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n", + "details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-7mcc-hw35-pqwf/GHSA-7mcc-hw35-pqwf.json b/advisories/unreviewed/2023/06/GHSA-7mcc-hw35-pqwf/GHSA-7mcc-hw35-pqwf.json index 497fa48a1eb..b5571c2b905 100644 --- a/advisories/unreviewed/2023/06/GHSA-7mcc-hw35-pqwf/GHSA-7mcc-hw35-pqwf.json +++ b/advisories/unreviewed/2023/06/GHSA-7mcc-hw35-pqwf/GHSA-7mcc-hw35-pqwf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7mcc-hw35-pqwf", - "modified": "2024-04-04T04:57:02Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-3316" ], - "details": "A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.\n\n", + "details": "A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json b/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json index 87895d0a0b5..889b1bb9cf6 100644 --- a/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json +++ b/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8x9p-cw2c-6253", - "modified": "2024-04-04T04:58:18Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-06-20T12:30:16Z", "aliases": [ "CVE-2023-1999" ], - "details": "There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free. \n", + "details": "There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json b/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json index 4af735e8de1..ffcfdec1b5d 100644 --- a/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json +++ b/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-94qw-3pc5-wwcm", - "modified": "2023-12-20T09:30:26Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34416" ], - "details": "Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.\n\n", + "details": "Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/06/GHSA-9787-f568-7rr2/GHSA-9787-f568-7rr2.json b/advisories/unreviewed/2023/06/GHSA-9787-f568-7rr2/GHSA-9787-f568-7rr2.json index 57a95393da4..8c841fd2181 100644 --- a/advisories/unreviewed/2023/06/GHSA-9787-f568-7rr2/GHSA-9787-f568-7rr2.json +++ b/advisories/unreviewed/2023/06/GHSA-9787-f568-7rr2/GHSA-9787-f568-7rr2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9787-f568-7rr2", - "modified": "2024-04-04T05:16:13Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-3389" ], - "details": "A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.\n\nRacing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer.\n\nWe recommend upgrading past commit 4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable.\n\n", + "details": "A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.\n\nRacing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer.\n\nWe recommend upgrading past commit 4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-2qmp-8j6q-mcq6/GHSA-2qmp-8j6q-mcq6.json b/advisories/unreviewed/2023/07/GHSA-2qmp-8j6q-mcq6/GHSA-2qmp-8j6q-mcq6.json index 5d6fa6f4393..3924e58fe0a 100644 --- a/advisories/unreviewed/2023/07/GHSA-2qmp-8j6q-mcq6/GHSA-2qmp-8j6q-mcq6.json +++ b/advisories/unreviewed/2023/07/GHSA-2qmp-8j6q-mcq6/GHSA-2qmp-8j6q-mcq6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2qmp-8j6q-mcq6", - "modified": "2023-11-29T15:30:20Z", + "modified": "2025-02-13T18:31:41Z", "published": "2023-07-21T21:30:33Z", "aliases": [ "CVE-2023-3609" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\nIf tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.\n\nWe recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\nIf tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.\n\nWe recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json b/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json index f21fb8044a1..2439e40f4c4 100644 --- a/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json +++ b/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4x82-r4q4-7g8x", - "modified": "2024-04-04T05:36:06Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-07-06T19:24:14Z", "aliases": [ "CVE-2023-1829" ], - "details": "A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.\nWe recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.\n\n", + "details": "A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.\nWe recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-5852-j2m5-mf5f/GHSA-5852-j2m5-mf5f.json b/advisories/unreviewed/2023/07/GHSA-5852-j2m5-mf5f/GHSA-5852-j2m5-mf5f.json index 64defe05960..705cb7a0cc4 100644 --- a/advisories/unreviewed/2023/07/GHSA-5852-j2m5-mf5f/GHSA-5852-j2m5-mf5f.json +++ b/advisories/unreviewed/2023/07/GHSA-5852-j2m5-mf5f/GHSA-5852-j2m5-mf5f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5852-j2m5-mf5f", - "modified": "2023-11-02T03:30:25Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-13T00:30:32Z", "aliases": [ "CVE-2023-21255" ], - "details": "In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.\n\n", + "details": "In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json b/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json index 6efd55c6c5c..06801d6b5c2 100644 --- a/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json +++ b/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5p42-mr7p-8fjp", - "modified": "2024-04-04T05:53:09Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-10T18:30:48Z", "aliases": [ "CVE-2023-30448" ], - "details": "\nIBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.", + "details": "IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json b/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json index 41a90a6348c..f777a89e0c1 100644 --- a/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json +++ b/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-74q4-qj6q-75qm", - "modified": "2024-04-04T05:52:50Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-07-10T18:30:48Z", "aliases": [ "CVE-2023-30445" ], - "details": "\nIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.", + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-7qr2-m63g-5xr4/GHSA-7qr2-m63g-5xr4.json b/advisories/unreviewed/2023/07/GHSA-7qr2-m63g-5xr4/GHSA-7qr2-m63g-5xr4.json index 96aeb5bec9d..f48f1fa9d84 100644 --- a/advisories/unreviewed/2023/07/GHSA-7qr2-m63g-5xr4/GHSA-7qr2-m63g-5xr4.json +++ b/advisories/unreviewed/2023/07/GHSA-7qr2-m63g-5xr4/GHSA-7qr2-m63g-5xr4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7qr2-m63g-5xr4", - "modified": "2024-04-04T06:14:08Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-18T18:30:36Z", "aliases": [ "CVE-2023-34329" ], - "details": "\nAMI SPx contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.\n\n", + "details": "AMI SPx contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-9fvp-3hg9-xrcv/GHSA-9fvp-3hg9-xrcv.json b/advisories/unreviewed/2023/07/GHSA-9fvp-3hg9-xrcv/GHSA-9fvp-3hg9-xrcv.json index ec73dcfc49c..c2f5984171a 100644 --- a/advisories/unreviewed/2023/07/GHSA-9fvp-3hg9-xrcv/GHSA-9fvp-3hg9-xrcv.json +++ b/advisories/unreviewed/2023/07/GHSA-9fvp-3hg9-xrcv/GHSA-9fvp-3hg9-xrcv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9fvp-3hg9-xrcv", - "modified": "2024-04-04T06:19:35Z", + "modified": "2025-02-13T18:31:41Z", "published": "2023-07-24T09:30:21Z", "aliases": [ "CVE-2023-38060" ], - "details": "Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the attachment. \n\n\nThis issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.\n\n", + "details": "Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the attachment. \n\n\nThis issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json b/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json index b1a7ad13a09..8a1f83f1bf1 100644 --- a/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json +++ b/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9mcp-v29j-j4hp", - "modified": "2024-04-04T05:39:20Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-07-06T21:14:53Z", "aliases": [ "CVE-2023-28724" ], - "details": "\nNGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n", + "details": "NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json index d470eb656d6..7af12bbfe49 100644 --- a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json +++ b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f7p2-4f5g-hfv9", - "modified": "2024-02-13T21:30:23Z", + "modified": "2025-02-13T18:31:42Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43701" ], - "details": "When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.\n\n", + "details": "When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json b/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json index be23f8ee5a6..55d6b5bfb5c 100644 --- a/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json +++ b/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g3h3-xh77-5fcf", - "modified": "2024-02-13T21:30:23Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43702" ], - "details": "When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.\n\n", + "details": "When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-gcrv-hhf7-6qvh/GHSA-gcrv-hhf7-6qvh.json b/advisories/unreviewed/2023/07/GHSA-gcrv-hhf7-6qvh/GHSA-gcrv-hhf7-6qvh.json index 5538cf4f0dd..661ea587404 100644 --- a/advisories/unreviewed/2023/07/GHSA-gcrv-hhf7-6qvh/GHSA-gcrv-hhf7-6qvh.json +++ b/advisories/unreviewed/2023/07/GHSA-gcrv-hhf7-6qvh/GHSA-gcrv-hhf7-6qvh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gcrv-hhf7-6qvh", - "modified": "2023-12-29T18:30:28Z", + "modified": "2025-02-13T18:31:41Z", "published": "2023-07-21T21:30:33Z", "aliases": [ "CVE-2023-3610" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nFlaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET_ADMIN to be triggered.\n\nWe recommend upgrading past commit 4bedf9eee016286c835e3d8fa981ddece5338795.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nFlaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET_ADMIN to be triggered.\n\nWe recommend upgrading past commit 4bedf9eee016286c835e3d8fa981ddece5338795.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-gjg3-3x79-mxh4/GHSA-gjg3-3x79-mxh4.json b/advisories/unreviewed/2023/07/GHSA-gjg3-3x79-mxh4/GHSA-gjg3-3x79-mxh4.json index ebfc56c5591..37092e9ec24 100644 --- a/advisories/unreviewed/2023/07/GHSA-gjg3-3x79-mxh4/GHSA-gjg3-3x79-mxh4.json +++ b/advisories/unreviewed/2023/07/GHSA-gjg3-3x79-mxh4/GHSA-gjg3-3x79-mxh4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gjg3-3x79-mxh4", - "modified": "2024-04-04T05:39:22Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-07-06T21:14:53Z", "aliases": [ "CVE-2023-28656" ], - "details": "\nNGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n\n\n", + "details": "NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json index 031d68b1f4f..efa0c095d61 100644 --- a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json +++ b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hpg6-hp9w-vxqp", - "modified": "2024-02-13T21:30:23Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43703" ], - "details": "An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.\n\n", + "details": "An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json b/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json index 3fa0d7ede2f..bac707c9018 100644 --- a/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json +++ b/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j4r5-9qqm-p694", - "modified": "2024-04-04T05:38:29Z", + "modified": "2025-02-13T18:31:34Z", "published": "2023-07-06T19:24:19Z", "aliases": [ "CVE-2023-2236" ], - "details": "A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.\n\nBoth io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.\n\nWe recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.\n\n", + "details": "A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.\n\nBoth io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.\n\nWe recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-j6fc-pvcg-2p4f/GHSA-j6fc-pvcg-2p4f.json b/advisories/unreviewed/2023/07/GHSA-j6fc-pvcg-2p4f/GHSA-j6fc-pvcg-2p4f.json index b0df509ceae..fd6f1da1673 100644 --- a/advisories/unreviewed/2023/07/GHSA-j6fc-pvcg-2p4f/GHSA-j6fc-pvcg-2p4f.json +++ b/advisories/unreviewed/2023/07/GHSA-j6fc-pvcg-2p4f/GHSA-j6fc-pvcg-2p4f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6fc-pvcg-2p4f", - "modified": "2024-04-04T06:06:49Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-13T12:30:26Z", "aliases": [ "CVE-2023-29454" ], - "details": " Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.", + "details": "Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json b/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json index 33e7bda7314..1901f12ec74 100644 --- a/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json +++ b/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jjxm-6773-5xf7", - "modified": "2024-04-04T05:53:11Z", + "modified": "2025-02-13T18:31:39Z", "published": "2023-07-10T18:30:49Z", "aliases": [ "CVE-2023-30449" ], - "details": "\nIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.", + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-m4j4-rmj5-w5gp/GHSA-m4j4-rmj5-w5gp.json b/advisories/unreviewed/2023/07/GHSA-m4j4-rmj5-w5gp/GHSA-m4j4-rmj5-w5gp.json index 36c8fde1abb..835928ac688 100644 --- a/advisories/unreviewed/2023/07/GHSA-m4j4-rmj5-w5gp/GHSA-m4j4-rmj5-w5gp.json +++ b/advisories/unreviewed/2023/07/GHSA-m4j4-rmj5-w5gp/GHSA-m4j4-rmj5-w5gp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m4j4-rmj5-w5gp", - "modified": "2024-04-04T06:17:11Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-19T18:30:56Z", "aliases": [ "CVE-2023-3519" ], - "details": "Unauthenticated remote code execution\n", + "details": "Unauthenticated remote code execution", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-mmj4-xg4v-p3xp/GHSA-mmj4-xg4v-p3xp.json b/advisories/unreviewed/2023/07/GHSA-mmj4-xg4v-p3xp/GHSA-mmj4-xg4v-p3xp.json index 7c54602eade..5beaa637b77 100644 --- a/advisories/unreviewed/2023/07/GHSA-mmj4-xg4v-p3xp/GHSA-mmj4-xg4v-p3xp.json +++ b/advisories/unreviewed/2023/07/GHSA-mmj4-xg4v-p3xp/GHSA-mmj4-xg4v-p3xp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mmj4-xg4v-p3xp", - "modified": "2024-04-04T06:14:14Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-18T18:30:36Z", "aliases": [ "CVE-2023-34330" ], - "details": "\nAMI SPx contains a vulnerability in the BMC where a User may cause a improper control of generation of code by Dynamic Redfish Extension. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. ", + "details": "AMI SPx contains a vulnerability in the BMC where a User may cause a improper control of generation of code by Dynamic Redfish Extension. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-mvf6-w562-53x9/GHSA-mvf6-w562-53x9.json b/advisories/unreviewed/2023/07/GHSA-mvf6-w562-53x9/GHSA-mvf6-w562-53x9.json index 691ea3f68ce..37d9cd87a09 100644 --- a/advisories/unreviewed/2023/07/GHSA-mvf6-w562-53x9/GHSA-mvf6-w562-53x9.json +++ b/advisories/unreviewed/2023/07/GHSA-mvf6-w562-53x9/GHSA-mvf6-w562-53x9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mvf6-w562-53x9", - "modified": "2024-02-19T18:31:31Z", + "modified": "2025-02-13T18:31:42Z", "published": "2023-07-25T09:30:18Z", "aliases": [ "CVE-2023-3897" ], - "details": "User enumeration in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message.This issue affects SureMDM On-premise: 6.31 and below version \n\n", + "details": "User enumeration in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message.This issue affects SureMDM On-premise: 6.31 and below version ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json b/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json index d4317a726b0..0fdb5221ea5 100644 --- a/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json +++ b/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mxw6-c2fh-2h9w", - "modified": "2024-04-04T05:36:19Z", + "modified": "2025-02-13T18:31:33Z", "published": "2023-07-06T19:24:15Z", "aliases": [ "CVE-2022-47501" ], - "details": "Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a \npre-authentication attack.\nThis issue affects Apache OFBiz: before 18.12.07.\n\n", + "details": "Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a \npre-authentication attack.\nThis issue affects Apache OFBiz: before 18.12.07.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-q598-p9hw-59vj/GHSA-q598-p9hw-59vj.json b/advisories/unreviewed/2023/07/GHSA-q598-p9hw-59vj/GHSA-q598-p9hw-59vj.json index 51f96bd038e..63886fb6ef3 100644 --- a/advisories/unreviewed/2023/07/GHSA-q598-p9hw-59vj/GHSA-q598-p9hw-59vj.json +++ b/advisories/unreviewed/2023/07/GHSA-q598-p9hw-59vj/GHSA-q598-p9hw-59vj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q598-p9hw-59vj", - "modified": "2024-04-04T06:06:55Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-13T12:30:26Z", "aliases": [ "CVE-2023-29456" ], - "details": "URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.\n", + "details": "URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-xc4x-f462-g6p7/GHSA-xc4x-f462-g6p7.json b/advisories/unreviewed/2023/07/GHSA-xc4x-f462-g6p7/GHSA-xc4x-f462-g6p7.json index dc30db6d92e..efab4c3ea8c 100644 --- a/advisories/unreviewed/2023/07/GHSA-xc4x-f462-g6p7/GHSA-xc4x-f462-g6p7.json +++ b/advisories/unreviewed/2023/07/GHSA-xc4x-f462-g6p7/GHSA-xc4x-f462-g6p7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xc4x-f462-g6p7", - "modified": "2024-04-04T06:05:44Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-13T03:30:47Z", "aliases": [ "CVE-2023-34124" ], - "details": "The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.\n\n", + "details": "The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-xjm8-9w9g-9h2f/GHSA-xjm8-9w9g-9h2f.json b/advisories/unreviewed/2023/07/GHSA-xjm8-9w9g-9h2f/GHSA-xjm8-9w9g-9h2f.json index aa3b1142e97..bab439e1a9c 100644 --- a/advisories/unreviewed/2023/07/GHSA-xjm8-9w9g-9h2f/GHSA-xjm8-9w9g-9h2f.json +++ b/advisories/unreviewed/2023/07/GHSA-xjm8-9w9g-9h2f/GHSA-xjm8-9w9g-9h2f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xjm8-9w9g-9h2f", - "modified": "2024-01-19T18:30:22Z", + "modified": "2025-02-13T18:31:40Z", "published": "2023-07-13T00:30:33Z", "aliases": [ "CVE-2023-21400" ], - "details": "In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.\n\n", + "details": "In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-4xr4-3f5p-7cg4/GHSA-4xr4-3f5p-7cg4.json b/advisories/unreviewed/2023/08/GHSA-4xr4-3f5p-7cg4/GHSA-4xr4-3f5p-7cg4.json index 582713582bc..5d982c3ef63 100644 --- a/advisories/unreviewed/2023/08/GHSA-4xr4-3f5p-7cg4/GHSA-4xr4-3f5p-7cg4.json +++ b/advisories/unreviewed/2023/08/GHSA-4xr4-3f5p-7cg4/GHSA-4xr4-3f5p-7cg4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4xr4-3f5p-7cg4", - "modified": "2024-04-04T06:37:53Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-08T09:30:20Z", "aliases": [ "CVE-2023-4009" ], - "details": "In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.\n", + "details": "In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-5m2p-p2cf-cgcg/GHSA-5m2p-p2cf-cgcg.json b/advisories/unreviewed/2023/08/GHSA-5m2p-p2cf-cgcg/GHSA-5m2p-p2cf-cgcg.json index 12c88a8b5be..9811881587a 100644 --- a/advisories/unreviewed/2023/08/GHSA-5m2p-p2cf-cgcg/GHSA-5m2p-p2cf-cgcg.json +++ b/advisories/unreviewed/2023/08/GHSA-5m2p-p2cf-cgcg/GHSA-5m2p-p2cf-cgcg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5m2p-p2cf-cgcg", - "modified": "2023-12-21T03:30:32Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T00:30:40Z", "aliases": [ "CVE-2023-31430" ], - "details": "A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service.\n\n\n", + "details": "A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json b/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json index c9968f55013..c88ab5e25e7 100644 --- a/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json +++ b/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6672-m2hq-hwm4", - "modified": "2024-04-04T06:29:06Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-08-02T00:30:39Z", "aliases": [ "CVE-2023-3494" ], - "details": "The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer overflowing when copying this string. Malicious, privileged software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root, mitigated by the capabilities assigned through the Capsicum sandbox available to the bhyve process.\n\n\n", + "details": "The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer overflowing when copying this string. Malicious, privileged software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root, mitigated by the capabilities assigned through the Capsicum sandbox available to the bhyve process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-6vpw-gfh5-qmc3/GHSA-6vpw-gfh5-qmc3.json b/advisories/unreviewed/2023/08/GHSA-6vpw-gfh5-qmc3/GHSA-6vpw-gfh5-qmc3.json index aa9ba5688b2..a1921de35ce 100644 --- a/advisories/unreviewed/2023/08/GHSA-6vpw-gfh5-qmc3/GHSA-6vpw-gfh5-qmc3.json +++ b/advisories/unreviewed/2023/08/GHSA-6vpw-gfh5-qmc3/GHSA-6vpw-gfh5-qmc3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6vpw-gfh5-qmc3", - "modified": "2024-04-04T06:37:46Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-08T09:30:20Z", "aliases": [ "CVE-2023-37569" ], - "details": "This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.\n", + "details": "This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-7cj7-3cq3-8fhp/GHSA-7cj7-3cq3-8fhp.json b/advisories/unreviewed/2023/08/GHSA-7cj7-3cq3-8fhp/GHSA-7cj7-3cq3-8fhp.json index aad1ce786b8..35406d435db 100644 --- a/advisories/unreviewed/2023/08/GHSA-7cj7-3cq3-8fhp/GHSA-7cj7-3cq3-8fhp.json +++ b/advisories/unreviewed/2023/08/GHSA-7cj7-3cq3-8fhp/GHSA-7cj7-3cq3-8fhp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7cj7-3cq3-8fhp", - "modified": "2024-04-04T06:39:18Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-08T12:30:21Z", "aliases": [ "CVE-2023-4202" ], - "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.\n\n\n", + "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json b/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json index 33493dfbce2..5fb568b8bdf 100644 --- a/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json +++ b/advisories/unreviewed/2023/08/GHSA-7j4j-pg3j-97q6/GHSA-7j4j-pg3j-97q6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7j4j-pg3j-97q6", - "modified": "2024-03-21T03:35:41Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-08-31T03:30:36Z", "aliases": [ "CVE-2023-31424" ], - "details": "Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a\n allows remote unauthenticated users to bypass web authentication and \nauthorization.\n\n", + "details": "Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a\n allows remote unauthenticated users to bypass web authentication and \nauthorization.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-7ph4-rw5h-3cgg/GHSA-7ph4-rw5h-3cgg.json b/advisories/unreviewed/2023/08/GHSA-7ph4-rw5h-3cgg/GHSA-7ph4-rw5h-3cgg.json index 4f37a33b7fe..b4242ddf715 100644 --- a/advisories/unreviewed/2023/08/GHSA-7ph4-rw5h-3cgg/GHSA-7ph4-rw5h-3cgg.json +++ b/advisories/unreviewed/2023/08/GHSA-7ph4-rw5h-3cgg/GHSA-7ph4-rw5h-3cgg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7ph4-rw5h-3cgg", - "modified": "2024-04-04T06:29:20Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-02T03:30:20Z", "aliases": [ "CVE-2023-31927" ], - "details": "An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface.\n\n\n", + "details": "An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-8rqr-6hqg-pr9g/GHSA-8rqr-6hqg-pr9g.json b/advisories/unreviewed/2023/08/GHSA-8rqr-6hqg-pr9g/GHSA-8rqr-6hqg-pr9g.json index 24c4caf6a94..8ea6adb0010 100644 --- a/advisories/unreviewed/2023/08/GHSA-8rqr-6hqg-pr9g/GHSA-8rqr-6hqg-pr9g.json +++ b/advisories/unreviewed/2023/08/GHSA-8rqr-6hqg-pr9g/GHSA-8rqr-6hqg-pr9g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8rqr-6hqg-pr9g", - "modified": "2023-11-16T03:30:18Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T00:30:40Z", "aliases": [ "CVE-2023-31428" ], - "details": "Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.\n\n\n", + "details": "Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-995r-hfcw-r5pv/GHSA-995r-hfcw-r5pv.json b/advisories/unreviewed/2023/08/GHSA-995r-hfcw-r5pv/GHSA-995r-hfcw-r5pv.json index 6554c37ce03..6c269732590 100644 --- a/advisories/unreviewed/2023/08/GHSA-995r-hfcw-r5pv/GHSA-995r-hfcw-r5pv.json +++ b/advisories/unreviewed/2023/08/GHSA-995r-hfcw-r5pv/GHSA-995r-hfcw-r5pv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-995r-hfcw-r5pv", - "modified": "2024-02-16T18:31:04Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T00:30:40Z", "aliases": [ "CVE-2023-31928" ], - "details": "\nA reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application.\n\n", + "details": "A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-9r4h-7xv2-84wf/GHSA-9r4h-7xv2-84wf.json b/advisories/unreviewed/2023/08/GHSA-9r4h-7xv2-84wf/GHSA-9r4h-7xv2-84wf.json index 2e95ddd38a9..a850eaf1945 100644 --- a/advisories/unreviewed/2023/08/GHSA-9r4h-7xv2-84wf/GHSA-9r4h-7xv2-84wf.json +++ b/advisories/unreviewed/2023/08/GHSA-9r4h-7xv2-84wf/GHSA-9r4h-7xv2-84wf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9r4h-7xv2-84wf", - "modified": "2024-04-04T06:35:36Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-07T15:30:27Z", "aliases": [ "CVE-2023-3896" ], - "details": "Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3\n", + "details": "Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-cfpg-6fr3-9x4g/GHSA-cfpg-6fr3-9x4g.json b/advisories/unreviewed/2023/08/GHSA-cfpg-6fr3-9x4g/GHSA-cfpg-6fr3-9x4g.json index e328f2ed09c..21a742356b6 100644 --- a/advisories/unreviewed/2023/08/GHSA-cfpg-6fr3-9x4g/GHSA-cfpg-6fr3-9x4g.json +++ b/advisories/unreviewed/2023/08/GHSA-cfpg-6fr3-9x4g/GHSA-cfpg-6fr3-9x4g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cfpg-6fr3-9x4g", - "modified": "2023-12-01T00:30:58Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-08-31T03:30:36Z", "aliases": [ "CVE-2023-4163" ], - "details": "In\n Brocade Fabric OS before v9.2.0a, a local authenticated privileged user\n can trigger a buffer overflow condition, leading to a kernel panic with\n large input to buffers in the portcfgfportbuffers command.\n\n", + "details": "In\n Brocade Fabric OS before v9.2.0a, a local authenticated privileged user\n can trigger a buffer overflow condition, leading to a kernel panic with\n large input to buffers in the portcfgfportbuffers command.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-cx46-mm2w-4mwv/GHSA-cx46-mm2w-4mwv.json b/advisories/unreviewed/2023/08/GHSA-cx46-mm2w-4mwv/GHSA-cx46-mm2w-4mwv.json index 4bfe46a86eb..be6e9435d2d 100644 --- a/advisories/unreviewed/2023/08/GHSA-cx46-mm2w-4mwv/GHSA-cx46-mm2w-4mwv.json +++ b/advisories/unreviewed/2023/08/GHSA-cx46-mm2w-4mwv/GHSA-cx46-mm2w-4mwv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cx46-mm2w-4mwv", - "modified": "2024-04-04T06:29:04Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-08-02T00:30:39Z", "aliases": [ "CVE-2023-3107" ], - "details": "A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.\n", + "details": "A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-f2v8-3pfh-v3xm/GHSA-f2v8-3pfh-v3xm.json b/advisories/unreviewed/2023/08/GHSA-f2v8-3pfh-v3xm/GHSA-f2v8-3pfh-v3xm.json index e2980f3fbcf..ccf99516409 100644 --- a/advisories/unreviewed/2023/08/GHSA-f2v8-3pfh-v3xm/GHSA-f2v8-3pfh-v3xm.json +++ b/advisories/unreviewed/2023/08/GHSA-f2v8-3pfh-v3xm/GHSA-f2v8-3pfh-v3xm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f2v8-3pfh-v3xm", - "modified": "2024-04-04T07:02:19Z", + "modified": "2025-02-13T18:31:46Z", "published": "2023-08-17T21:30:53Z", "aliases": [ "CVE-2023-36844" ], - "details": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables.\n\nUtilizing a crafted request an attacker is able to modify \n\ncertain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities.\nThis issue affects Juniper Networks Junos OS on EX Series:\n\n\n\n * All versions prior to 20.4R3-S9;\n * 21.2 versions prior to 21.2R3-S6;\n * 21.3 versions \n\nprior to \n\n 21.3R3-S5;\n * 21.4 versions \n\nprior to \n\n21.4R3-S5;\n * 22.1 versions \n\nprior to \n\n22.1R3-S4;\n * 22.2 versions \n\nprior to \n\n22.2R3-S2;\n * 22.3 versions \n\nprior to 22.3R3-S1;\n * 22.4 versions \n\nprior to \n\n22.4R2-S2, 22.4R3.\n\n\n\n\n", + "details": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables.\n\nUtilizing a crafted request an attacker is able to modify \n\ncertain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities.\nThis issue affects Juniper Networks Junos OS on EX Series:\n\n\n\n * All versions prior to 20.4R3-S9;\n * 21.2 versions prior to 21.2R3-S6;\n * 21.3 versions \n\nprior to \n\n 21.3R3-S5;\n * 21.4 versions \n\nprior to \n\n21.4R3-S5;\n * 22.1 versions \n\nprior to \n\n22.1R3-S4;\n * 22.2 versions \n\nprior to \n\n22.2R3-S2;\n * 22.3 versions \n\nprior to 22.3R3-S1;\n * 22.4 versions \n\nprior to \n\n22.4R2-S2, 22.4R3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-fhpg-j54r-7h8v/GHSA-fhpg-j54r-7h8v.json b/advisories/unreviewed/2023/08/GHSA-fhpg-j54r-7h8v/GHSA-fhpg-j54r-7h8v.json index c9cf16e3126..d3bd8a62553 100644 --- a/advisories/unreviewed/2023/08/GHSA-fhpg-j54r-7h8v/GHSA-fhpg-j54r-7h8v.json +++ b/advisories/unreviewed/2023/08/GHSA-fhpg-j54r-7h8v/GHSA-fhpg-j54r-7h8v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fhpg-j54r-7h8v", - "modified": "2024-02-16T18:31:04Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-08-02T00:30:39Z", "aliases": [ "CVE-2023-31427" ], - "details": "\n\n\nBrocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.\n\n\n\n\n\n\n", + "details": "Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-fqh6-rrfj-3w82/GHSA-fqh6-rrfj-3w82.json b/advisories/unreviewed/2023/08/GHSA-fqh6-rrfj-3w82/GHSA-fqh6-rrfj-3w82.json index 1e451dde349..957efc679c1 100644 --- a/advisories/unreviewed/2023/08/GHSA-fqh6-rrfj-3w82/GHSA-fqh6-rrfj-3w82.json +++ b/advisories/unreviewed/2023/08/GHSA-fqh6-rrfj-3w82/GHSA-fqh6-rrfj-3w82.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fqh6-rrfj-3w82", - "modified": "2023-12-21T03:30:32Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T00:30:40Z", "aliases": [ "CVE-2023-31431" ], - "details": "A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.\n\n\n", + "details": "A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-hhx4-xmf9-97g5/GHSA-hhx4-xmf9-97g5.json b/advisories/unreviewed/2023/08/GHSA-hhx4-xmf9-97g5/GHSA-hhx4-xmf9-97g5.json index 8730c382c37..eeeb6816460 100644 --- a/advisories/unreviewed/2023/08/GHSA-hhx4-xmf9-97g5/GHSA-hhx4-xmf9-97g5.json +++ b/advisories/unreviewed/2023/08/GHSA-hhx4-xmf9-97g5/GHSA-hhx4-xmf9-97g5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hhx4-xmf9-97g5", - "modified": "2024-04-04T07:13:22Z", + "modified": "2025-02-13T18:31:50Z", "published": "2023-08-25T21:30:48Z", "aliases": [ "CVE-2023-2906" ], - "details": "Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.\n", + "details": "Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-jfm4-3vv3-fm4v/GHSA-jfm4-3vv3-fm4v.json b/advisories/unreviewed/2023/08/GHSA-jfm4-3vv3-fm4v/GHSA-jfm4-3vv3-fm4v.json index a1fc4786b19..4967a8762aa 100644 --- a/advisories/unreviewed/2023/08/GHSA-jfm4-3vv3-fm4v/GHSA-jfm4-3vv3-fm4v.json +++ b/advisories/unreviewed/2023/08/GHSA-jfm4-3vv3-fm4v/GHSA-jfm4-3vv3-fm4v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jfm4-3vv3-fm4v", - "modified": "2024-04-04T06:31:49Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-4136" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-mfq6-hv3w-q46x/GHSA-mfq6-hv3w-q46x.json b/advisories/unreviewed/2023/08/GHSA-mfq6-hv3w-q46x/GHSA-mfq6-hv3w-q46x.json index 02d530bee42..5a3faa9c020 100644 --- a/advisories/unreviewed/2023/08/GHSA-mfq6-hv3w-q46x/GHSA-mfq6-hv3w-q46x.json +++ b/advisories/unreviewed/2023/08/GHSA-mfq6-hv3w-q46x/GHSA-mfq6-hv3w-q46x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mfq6-hv3w-q46x", - "modified": "2024-04-04T06:39:24Z", + "modified": "2025-02-13T18:31:45Z", "published": "2023-08-08T12:30:21Z", "aliases": [ "CVE-2023-4203" ], - "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.\n", + "details": "Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-pjfq-h6gx-wrcf/GHSA-pjfq-h6gx-wrcf.json b/advisories/unreviewed/2023/08/GHSA-pjfq-h6gx-wrcf/GHSA-pjfq-h6gx-wrcf.json index 7a83ffac601..32f9a115e62 100644 --- a/advisories/unreviewed/2023/08/GHSA-pjfq-h6gx-wrcf/GHSA-pjfq-h6gx-wrcf.json +++ b/advisories/unreviewed/2023/08/GHSA-pjfq-h6gx-wrcf/GHSA-pjfq-h6gx-wrcf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pjfq-h6gx-wrcf", - "modified": "2024-04-04T07:09:56Z", + "modified": "2025-02-13T18:31:49Z", "published": "2023-08-23T18:30:34Z", "aliases": [ "CVE-2023-1409" ], - "details": "If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in effect, potentially allowing client to establish a TLS connection with the server that supplies any certificate.\n\nThis issue affect all MongoDB Server v6.3 versions, MongoDB Server v5.0 versions v5.0.0 to v5.0.14 and all MongoDB Server v4.4 versions.\n\n", + "details": "If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in effect, potentially allowing client to establish a TLS connection with the server that supplies any certificate.\n\nThis issue affect all MongoDB Server v6.3 versions, MongoDB Server v5.0 versions v5.0.0 to v5.0.14 and all MongoDB Server v4.4 versions.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-q587-8249-rxpr/GHSA-q587-8249-rxpr.json b/advisories/unreviewed/2023/08/GHSA-q587-8249-rxpr/GHSA-q587-8249-rxpr.json index 28b87baeec0..5224c5a4b22 100644 --- a/advisories/unreviewed/2023/08/GHSA-q587-8249-rxpr/GHSA-q587-8249-rxpr.json +++ b/advisories/unreviewed/2023/08/GHSA-q587-8249-rxpr/GHSA-q587-8249-rxpr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q587-8249-rxpr", - "modified": "2023-11-02T03:30:25Z", + "modified": "2025-02-13T18:31:43Z", "published": "2023-08-01T21:30:43Z", "aliases": [ "CVE-2023-31425" ], - "details": "\nA vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled.\n\n", + "details": "A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-qj2q-gqrj-fh7g/GHSA-qj2q-gqrj-fh7g.json b/advisories/unreviewed/2023/08/GHSA-qj2q-gqrj-fh7g/GHSA-qj2q-gqrj-fh7g.json index 6df8e551341..9dbb99e45ff 100644 --- a/advisories/unreviewed/2023/08/GHSA-qj2q-gqrj-fh7g/GHSA-qj2q-gqrj-fh7g.json +++ b/advisories/unreviewed/2023/08/GHSA-qj2q-gqrj-fh7g/GHSA-qj2q-gqrj-fh7g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qj2q-gqrj-fh7g", - "modified": "2024-04-04T07:15:56Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-08-30T00:30:48Z", "aliases": [ "CVE-2023-4296" ], - "details": "\n?If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.\n\n", + "details": "?If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-qw3m-jfhw-49pg/GHSA-qw3m-jfhw-49pg.json b/advisories/unreviewed/2023/08/GHSA-qw3m-jfhw-49pg/GHSA-qw3m-jfhw-49pg.json index 2b0f4a79967..250672528cf 100644 --- a/advisories/unreviewed/2023/08/GHSA-qw3m-jfhw-49pg/GHSA-qw3m-jfhw-49pg.json +++ b/advisories/unreviewed/2023/08/GHSA-qw3m-jfhw-49pg/GHSA-qw3m-jfhw-49pg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qw3m-jfhw-49pg", - "modified": "2023-11-24T09:30:27Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-08-31T00:30:17Z", "aliases": [ "CVE-2023-3489" ], - "details": "The \nfirmwaredownload command on Brocade Fabric OS v9.2.0 could log the \nFTP/SFTP/SCP server password in clear text in the SupportSave file when \nperforming a downgrade from Fabric OS v9.2.0 to any earlier version of \nFabric OS.\n\n", + "details": "The \nfirmwaredownload command on Brocade Fabric OS v9.2.0 could log the \nFTP/SFTP/SCP server password in clear text in the SupportSave file when \nperforming a downgrade from Fabric OS v9.2.0 to any earlier version of \nFabric OS.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-rc2q-3pmv-73vx/GHSA-rc2q-3pmv-73vx.json b/advisories/unreviewed/2023/08/GHSA-rc2q-3pmv-73vx/GHSA-rc2q-3pmv-73vx.json index a2d62591959..8c5b99aefc8 100644 --- a/advisories/unreviewed/2023/08/GHSA-rc2q-3pmv-73vx/GHSA-rc2q-3pmv-73vx.json +++ b/advisories/unreviewed/2023/08/GHSA-rc2q-3pmv-73vx/GHSA-rc2q-3pmv-73vx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rc2q-3pmv-73vx", - "modified": "2024-02-16T18:31:04Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T03:30:20Z", "aliases": [ "CVE-2023-31926" ], - "details": "System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.\n\n\n", + "details": "System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-w5cc-3g2v-73pr/GHSA-w5cc-3g2v-73pr.json b/advisories/unreviewed/2023/08/GHSA-w5cc-3g2v-73pr/GHSA-w5cc-3g2v-73pr.json index 5c8ece2bc40..1c0b230fb74 100644 --- a/advisories/unreviewed/2023/08/GHSA-w5cc-3g2v-73pr/GHSA-w5cc-3g2v-73pr.json +++ b/advisories/unreviewed/2023/08/GHSA-w5cc-3g2v-73pr/GHSA-w5cc-3g2v-73pr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w5cc-3g2v-73pr", - "modified": "2024-02-16T18:31:04Z", + "modified": "2025-02-13T18:31:44Z", "published": "2023-08-02T00:30:40Z", "aliases": [ "CVE-2023-31432" ], - "details": "Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0.\n\n\n", + "details": "Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json b/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json index 19209db9d45..76b209f8992 100644 --- a/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json +++ b/advisories/unreviewed/2023/08/GHSA-x6g3-wgpm-qhcq/GHSA-x6g3-wgpm-qhcq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x6g3-wgpm-qhcq", - "modified": "2024-03-21T03:35:41Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-08-31T03:30:36Z", "aliases": [ "CVE-2023-31423" ], - "details": "Possible\n information exposure through log file vulnerability where sensitive \nfields are recorded in the configuration log without masking on Brocade \nSANnav before v2.3.0 and 2.2.2a. Notes:\n To access the logs, the local attacker must have access to an already collected Brocade SANnav \"supportsave\" \noutputs.\n\n", + "details": "Possible\n information exposure through log file vulnerability where sensitive \nfields are recorded in the configuration log without masking on Brocade \nSANnav before v2.3.0 and 2.2.2a. Notes:\n To access the logs, the local attacker must have access to an already collected Brocade SANnav \"supportsave\" \noutputs.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-29vf-j74g-gmfc/GHSA-29vf-j74g-gmfc.json b/advisories/unreviewed/2023/09/GHSA-29vf-j74g-gmfc/GHSA-29vf-j74g-gmfc.json index e9a88134063..3a24ad04b93 100644 --- a/advisories/unreviewed/2023/09/GHSA-29vf-j74g-gmfc/GHSA-29vf-j74g-gmfc.json +++ b/advisories/unreviewed/2023/09/GHSA-29vf-j74g-gmfc/GHSA-29vf-j74g-gmfc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-29vf-j74g-gmfc", - "modified": "2024-04-04T07:52:06Z", + "modified": "2025-02-13T18:31:52Z", "published": "2023-09-27T15:30:35Z", "aliases": [ "CVE-2023-40044" ], - "details": "In WS_FTP Server version 8.7.0 prior to 8.7.4 and\n\n version 8.8.0 prior to 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.  \n\n", + "details": "In WS_FTP Server version 8.7.0 prior to 8.7.4 and\n\n version 8.8.0 prior to 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.  ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-396p-373f-r9vm/GHSA-396p-373f-r9vm.json b/advisories/unreviewed/2023/09/GHSA-396p-373f-r9vm/GHSA-396p-373f-r9vm.json index f4307efdad7..b7648d8068b 100644 --- a/advisories/unreviewed/2023/09/GHSA-396p-373f-r9vm/GHSA-396p-373f-r9vm.json +++ b/advisories/unreviewed/2023/09/GHSA-396p-373f-r9vm/GHSA-396p-373f-r9vm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-396p-373f-r9vm", - "modified": "2024-01-11T21:31:15Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4244" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nDue to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.\n\nWe recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nDue to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.\n\nWe recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-3v7f-rjgx-9grq/GHSA-3v7f-rjgx-9grq.json b/advisories/unreviewed/2023/09/GHSA-3v7f-rjgx-9grq/GHSA-3v7f-rjgx-9grq.json index 8eeb1c8a2cc..f97d87fd7c2 100644 --- a/advisories/unreviewed/2023/09/GHSA-3v7f-rjgx-9grq/GHSA-3v7f-rjgx-9grq.json +++ b/advisories/unreviewed/2023/09/GHSA-3v7f-rjgx-9grq/GHSA-3v7f-rjgx-9grq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3v7f-rjgx-9grq", - "modified": "2023-11-29T15:30:20Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-3777" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nWhen nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances.\n\nWe recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nWhen nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances.\n\nWe recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-4fhg-56x9-rf4r/GHSA-4fhg-56x9-rf4r.json b/advisories/unreviewed/2023/09/GHSA-4fhg-56x9-rf4r/GHSA-4fhg-56x9-rf4r.json index a65fcc48409..2fe994ed2cc 100644 --- a/advisories/unreviewed/2023/09/GHSA-4fhg-56x9-rf4r/GHSA-4fhg-56x9-rf4r.json +++ b/advisories/unreviewed/2023/09/GHSA-4fhg-56x9-rf4r/GHSA-4fhg-56x9-rf4r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4fhg-56x9-rf4r", - "modified": "2024-01-11T21:31:15Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4207" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.\n\nWhen fw_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit 76e42ae831991c828cffa8c37736ebfb831ad5ec.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.\n\nWhen fw_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit 76e42ae831991c828cffa8c37736ebfb831ad5ec.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-5m5v-w78j-286f/GHSA-5m5v-w78j-286f.json b/advisories/unreviewed/2023/09/GHSA-5m5v-w78j-286f/GHSA-5m5v-w78j-286f.json index 919136efbb1..5cda2514e95 100644 --- a/advisories/unreviewed/2023/09/GHSA-5m5v-w78j-286f/GHSA-5m5v-w78j-286f.json +++ b/advisories/unreviewed/2023/09/GHSA-5m5v-w78j-286f/GHSA-5m5v-w78j-286f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5m5v-w78j-286f", - "modified": "2023-12-12T15:30:58Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4015" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nOn an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead unbinding the chain and objects be deactivated but later used.\n\nWe recommend upgrading past commit 0a771f7b266b02d262900c75f1e175c7fe76fec2.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nOn an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead unbinding the chain and objects be deactivated but later used.\n\nWe recommend upgrading past commit 0a771f7b266b02d262900c75f1e175c7fe76fec2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-5xr7-jj63-cqf7/GHSA-5xr7-jj63-cqf7.json b/advisories/unreviewed/2023/09/GHSA-5xr7-jj63-cqf7/GHSA-5xr7-jj63-cqf7.json index 2379dfadfef..af93d6a50a9 100644 --- a/advisories/unreviewed/2023/09/GHSA-5xr7-jj63-cqf7/GHSA-5xr7-jj63-cqf7.json +++ b/advisories/unreviewed/2023/09/GHSA-5xr7-jj63-cqf7/GHSA-5xr7-jj63-cqf7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5xr7-jj63-cqf7", - "modified": "2023-11-29T15:30:20Z", + "modified": "2025-02-13T18:31:53Z", "published": "2023-09-27T15:30:40Z", "aliases": [ "CVE-2023-5197" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nAddition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.\n\nWe recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nAddition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.\n\nWe recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json b/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json index bbf04e38a5b..3cbafab427c 100644 --- a/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json +++ b/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g6hh-x63c-83gf", - "modified": "2023-12-22T00:30:20Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T21:32:50Z", "aliases": [ "CVE-2023-4809" ], - "details": "In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.\n\n\n\n\nAs a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.\n\n", + "details": "In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.\n\n\n\n\nAs a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-hxpr-87wq-jwf8/GHSA-hxpr-87wq-jwf8.json b/advisories/unreviewed/2023/09/GHSA-hxpr-87wq-jwf8/GHSA-hxpr-87wq-jwf8.json index c33c80b3a07..1b314320200 100644 --- a/advisories/unreviewed/2023/09/GHSA-hxpr-87wq-jwf8/GHSA-hxpr-87wq-jwf8.json +++ b/advisories/unreviewed/2023/09/GHSA-hxpr-87wq-jwf8/GHSA-hxpr-87wq-jwf8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hxpr-87wq-jwf8", - "modified": "2023-11-29T15:30:20Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4622" ], - "details": "A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.\n\nThe unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.\n\nWe recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.\n\nThe unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.\n\nWe recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-j8c5-g64v-xj97/GHSA-j8c5-g64v-xj97.json b/advisories/unreviewed/2023/09/GHSA-j8c5-g64v-xj97/GHSA-j8c5-g64v-xj97.json index 9ce179998f8..0f9591b7fe5 100644 --- a/advisories/unreviewed/2023/09/GHSA-j8c5-g64v-xj97/GHSA-j8c5-g64v-xj97.json +++ b/advisories/unreviewed/2023/09/GHSA-j8c5-g64v-xj97/GHSA-j8c5-g64v-xj97.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j8c5-g64v-xj97", - "modified": "2023-11-29T15:30:20Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4623" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be exploited to achieve local privilege escalation.\n\nIf a class with a link-sharing curve (i.e. with the HFSC_FSC flag set) has a parent without a link-sharing curve, then init_vf() will call vttree_insert() on the parent, but vttree_remove() will be skipped in update_vf(). This leaves a dangling pointer that can cause a use-after-free.\n\nWe recommend upgrading past commit b3d26c5702c7d6c45456326e56d2ccf3f103e60f.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be exploited to achieve local privilege escalation.\n\nIf a class with a link-sharing curve (i.e. with the HFSC_FSC flag set) has a parent without a link-sharing curve, then init_vf() will call vttree_insert() on the parent, but vttree_remove() will be skipped in update_vf(). This leaves a dangling pointer that can cause a use-after-free.\n\nWe recommend upgrading past commit b3d26c5702c7d6c45456326e56d2ccf3f103e60f.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-ph8p-rrmj-8gf2/GHSA-ph8p-rrmj-8gf2.json b/advisories/unreviewed/2023/09/GHSA-ph8p-rrmj-8gf2/GHSA-ph8p-rrmj-8gf2.json index fc3a9768de7..a63714a9cea 100644 --- a/advisories/unreviewed/2023/09/GHSA-ph8p-rrmj-8gf2/GHSA-ph8p-rrmj-8gf2.json +++ b/advisories/unreviewed/2023/09/GHSA-ph8p-rrmj-8gf2/GHSA-ph8p-rrmj-8gf2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ph8p-rrmj-8gf2", - "modified": "2024-01-11T21:31:15Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4208" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\nWhen u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit 3044b16e7c6fe5d24b1cdbcf1bd0a9d92d1ebd81.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\nWhen u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit 3044b16e7c6fe5d24b1cdbcf1bd0a9d92d1ebd81.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-qw4m-2pv2-7r5f/GHSA-qw4m-2pv2-7r5f.json b/advisories/unreviewed/2023/09/GHSA-qw4m-2pv2-7r5f/GHSA-qw4m-2pv2-7r5f.json index d38bd4ca18a..e82d3bec8c9 100644 --- a/advisories/unreviewed/2023/09/GHSA-qw4m-2pv2-7r5f/GHSA-qw4m-2pv2-7r5f.json +++ b/advisories/unreviewed/2023/09/GHSA-qw4m-2pv2-7r5f/GHSA-qw4m-2pv2-7r5f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qw4m-2pv2-7r5f", - "modified": "2024-01-11T21:31:15Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-12T21:30:17Z", "aliases": [ "CVE-2023-4921" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation.\n\nWhen the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue().\n\nWe recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation.\n\nWhen the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue().\n\nWe recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/09/GHSA-r8pm-459q-x6hw/GHSA-r8pm-459q-x6hw.json b/advisories/unreviewed/2023/09/GHSA-r8pm-459q-x6hw/GHSA-r8pm-459q-x6hw.json index 193e526d1e5..e5546778a67 100644 --- a/advisories/unreviewed/2023/09/GHSA-r8pm-459q-x6hw/GHSA-r8pm-459q-x6hw.json +++ b/advisories/unreviewed/2023/09/GHSA-r8pm-459q-x6hw/GHSA-r8pm-459q-x6hw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-r8pm-459q-x6hw", - "modified": "2024-01-11T21:31:15Z", + "modified": "2025-02-13T18:31:51Z", "published": "2023-09-06T15:30:27Z", "aliases": [ "CVE-2023-4206" ], - "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local privilege escalation.\n\nWhen route4_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit b80b829e9e2c1b3f7aae34855e04d8f6ecaf13c8.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local privilege escalation.\n\nWhen route4_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.\n\nWe recommend upgrading past commit b80b829e9e2c1b3f7aae34855e04d8f6ecaf13c8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json b/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json index 56d00f0039f..c246d4c912a 100644 --- a/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json +++ b/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3vrx-27jg-h7pf", - "modified": "2023-11-03T21:30:22Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-17T09:30:22Z", "aliases": [ "CVE-2023-41752" ], - "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.\n\nUsers are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.\n\n", + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.\n\nUsers are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json b/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json index 9ea3ad430ae..4ba24cb5406 100644 --- a/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json +++ b/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5vw8-jcpr-5wmv", - "modified": "2024-05-03T15:30:35Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-25T18:32:22Z", "aliases": [ "CVE-2023-3010" ], - "details": "Grafana is an open-source platform for monitoring and observability. \n\nThe WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.\n\n", + "details": "Grafana is an open-source platform for monitoring and observability. \n\nThe WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-6676-9pqr-4cw3/GHSA-6676-9pqr-4cw3.json b/advisories/unreviewed/2023/10/GHSA-6676-9pqr-4cw3/GHSA-6676-9pqr-4cw3.json index 00ffe028b6d..81902fd16c3 100644 --- a/advisories/unreviewed/2023/10/GHSA-6676-9pqr-4cw3/GHSA-6676-9pqr-4cw3.json +++ b/advisories/unreviewed/2023/10/GHSA-6676-9pqr-4cw3/GHSA-6676-9pqr-4cw3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6676-9pqr-4cw3", - "modified": "2023-12-08T21:30:29Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-17T09:30:23Z", "aliases": [ "CVE-2023-4399" ], - "details": "Grafana is an open-source platform for monitoring and observability. \n\nIn Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.\n\nHowever, the restriction can be bypassed used punycode encoding of the characters in the request address.\n\n", + "details": "Grafana is an open-source platform for monitoring and observability. \n\nIn Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.\n\nHowever, the restriction can be bypassed used punycode encoding of the characters in the request address.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json b/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json index 9f79004b6fb..6b341f82166 100644 --- a/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json +++ b/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7xw9-w465-6x42", - "modified": "2024-07-09T15:30:52Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-18T06:30:30Z", "aliases": [ "CVE-2023-38545" ], - "details": "This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \"let the host resolve the name\" could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.\n", + "details": "This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \"let the host resolve the name\" could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.", "severity": [ { "type": "CVSS_V3", @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868" }, + { + "type": "WEB", + "url": "https://github.com/UTsweetyfish/CVE-2023-38545" + }, + { + "type": "WEB", + "url": "https://github.com/bcdannyboy/CVE-2023-38545" + }, + { + "type": "WEB", + "url": "https://github.com/dbrugman/CVE-2023-38545-POC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ" diff --git a/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json b/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json index 3fb4d9ba6f7..29be9e2c4a6 100644 --- a/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json +++ b/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c3xg-7w53-6ghf", - "modified": "2024-04-04T08:36:23Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-13T00:30:18Z", "aliases": [ "CVE-2023-27316" ], - "details": "SnapCenter versions 4.8 through 4.9 are susceptible to a \nvulnerability which may allow an authenticated SnapCenter Server user to\n become an admin user on a remote system where a SnapCenter plug-in has \nbeen installed. \n\n", + "details": "SnapCenter versions 4.8 through 4.9 are susceptible to a \nvulnerability which may allow an authenticated SnapCenter Server user to\n become an admin user on a remote system where a SnapCenter plug-in has \nbeen installed.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-fr7h-j3xj-fvvv/GHSA-fr7h-j3xj-fvvv.json b/advisories/unreviewed/2023/10/GHSA-fr7h-j3xj-fvvv/GHSA-fr7h-j3xj-fvvv.json index abea8124624..35808407d4d 100644 --- a/advisories/unreviewed/2023/10/GHSA-fr7h-j3xj-fvvv/GHSA-fr7h-j3xj-fvvv.json +++ b/advisories/unreviewed/2023/10/GHSA-fr7h-j3xj-fvvv/GHSA-fr7h-j3xj-fvvv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fr7h-j3xj-fvvv", - "modified": "2023-11-03T21:30:22Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-17T09:30:22Z", "aliases": [ "CVE-2023-39456" ], - "details": "Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.\n\nUsers are recommended to upgrade to version 9.2.3, which fixes the issue.\n\n", + "details": "Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.\n\nUsers are recommended to upgrade to version 9.2.3, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-gv6g-gf42-rjg7/GHSA-gv6g-gf42-rjg7.json b/advisories/unreviewed/2023/10/GHSA-gv6g-gf42-rjg7/GHSA-gv6g-gf42-rjg7.json index 26e8292b82e..67c0e9673d7 100644 --- a/advisories/unreviewed/2023/10/GHSA-gv6g-gf42-rjg7/GHSA-gv6g-gf42-rjg7.json +++ b/advisories/unreviewed/2023/10/GHSA-gv6g-gf42-rjg7/GHSA-gv6g-gf42-rjg7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gv6g-gf42-rjg7", - "modified": "2023-11-04T03:30:19Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-25T18:32:26Z", "aliases": [ "CVE-2023-5717" ], - "details": "A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation.\n\nIf perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.\n\nWe recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.\n\n", + "details": "A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation.\n\nIf perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.\n\nWe recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-p7q8-377q-px25/GHSA-p7q8-377q-px25.json b/advisories/unreviewed/2023/10/GHSA-p7q8-377q-px25/GHSA-p7q8-377q-px25.json index 85b5415acc3..9c6ac87089f 100644 --- a/advisories/unreviewed/2023/10/GHSA-p7q8-377q-px25/GHSA-p7q8-377q-px25.json +++ b/advisories/unreviewed/2023/10/GHSA-p7q8-377q-px25/GHSA-p7q8-377q-px25.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p7q8-377q-px25", - "modified": "2024-01-07T12:30:30Z", + "modified": "2025-02-13T18:31:54Z", "published": "2023-10-02T21:30:17Z", "aliases": [ "CVE-2023-3592" ], - "details": "In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.\n", + "details": "In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json b/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json index 26836d4ebaa..d0cc6616d97 100644 --- a/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json +++ b/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq6p-fc96-wc5w", - "modified": "2025-01-28T00:32:08Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-10-26T21:30:22Z", "aliases": [ "CVE-2023-46747" diff --git a/advisories/unreviewed/2023/10/GHSA-vchq-5hmx-6hmp/GHSA-vchq-5hmx-6hmp.json b/advisories/unreviewed/2023/10/GHSA-vchq-5hmx-6hmp/GHSA-vchq-5hmx-6hmp.json index 31dfaee9a8e..d872cf31759 100644 --- a/advisories/unreviewed/2023/10/GHSA-vchq-5hmx-6hmp/GHSA-vchq-5hmx-6hmp.json +++ b/advisories/unreviewed/2023/10/GHSA-vchq-5hmx-6hmp/GHSA-vchq-5hmx-6hmp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vchq-5hmx-6hmp", - "modified": "2023-11-30T06:33:22Z", + "modified": "2025-02-13T18:31:55Z", "published": "2023-10-10T15:30:51Z", "aliases": [ "CVE-2023-30801" ], - "details": "All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the \"external program\" feature in the web user interface. This was reportedly exploited in the wild in March 2023.\n", + "details": "All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the \"external program\" feature in the web user interface. This was reportedly exploited in the wild in March 2023.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json b/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json index 205de11022b..0014d1ca81e 100644 --- a/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json +++ b/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w2qc-22jv-44g8", - "modified": "2023-11-01T18:30:30Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-23T09:30:18Z", "aliases": [ "CVE-2023-43622" ], - "details": "An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known \"slow loris\" attack pattern.\nThis has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.\n\nUsers are recommended to upgrade to version 2.4.58, which fixes the issue.\n\n", + "details": "An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known \"slow loris\" attack pattern.\nThis has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.\n\nUsers are recommended to upgrade to version 2.4.58, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json b/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json index c78445eb075..efa6cc3c02c 100644 --- a/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json +++ b/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xw7g-pw64-xph3", - "modified": "2024-06-10T18:30:50Z", + "modified": "2025-02-13T18:31:57Z", "published": "2023-10-23T09:30:18Z", "aliases": [ "CVE-2023-31122" ], - "details": "Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.\n\n", + "details": "Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-2w4h-75hc-2jv2/GHSA-2w4h-75hc-2jv2.json b/advisories/unreviewed/2023/11/GHSA-2w4h-75hc-2jv2/GHSA-2w4h-75hc-2jv2.json index c36af016c2b..5a3d47f16b4 100644 --- a/advisories/unreviewed/2023/11/GHSA-2w4h-75hc-2jv2/GHSA-2w4h-75hc-2jv2.json +++ b/advisories/unreviewed/2023/11/GHSA-2w4h-75hc-2jv2/GHSA-2w4h-75hc-2jv2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2w4h-75hc-2jv2", - "modified": "2023-11-30T06:33:23Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-22T12:30:26Z", "aliases": [ "CVE-2023-6253" ], - "details": "A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.\n", + "details": "A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json b/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json index c178070c1c0..2605025d0a6 100644 --- a/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json +++ b/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5w5f-g3w4-p65h", - "modified": "2023-11-14T21:30:54Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-14T21:30:54Z", "aliases": [ "CVE-2023-4295" ], - "details": "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. \n\n", + "details": "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json b/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json index dfec3d0b364..5c835551529 100644 --- a/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json +++ b/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cqgf-g3qq-hhxw", - "modified": "2023-11-27T21:30:55Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20568" ], - "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json b/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json index eeb241cd4de..0d79d32e6af 100644 --- a/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json +++ b/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p483-8797-gq74", - "modified": "2023-11-27T21:30:53Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2021-46748" ], - "details": "Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "details": "Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-qgj5-fp5w-7cxr/GHSA-qgj5-fp5w-7cxr.json b/advisories/unreviewed/2023/11/GHSA-qgj5-fp5w-7cxr/GHSA-qgj5-fp5w-7cxr.json index 2175c67041c..963d577b7de 100644 --- a/advisories/unreviewed/2023/11/GHSA-qgj5-fp5w-7cxr/GHSA-qgj5-fp5w-7cxr.json +++ b/advisories/unreviewed/2023/11/GHSA-qgj5-fp5w-7cxr/GHSA-qgj5-fp5w-7cxr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qgj5-fp5w-7cxr", - "modified": "2023-11-09T21:30:37Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-04T00:30:23Z", "aliases": [ "CVE-2023-32741" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-r6fg-prgw-3ff5/GHSA-r6fg-prgw-3ff5.json b/advisories/unreviewed/2023/11/GHSA-r6fg-prgw-3ff5/GHSA-r6fg-prgw-3ff5.json index c9a36ce7770..130ac044a9b 100644 --- a/advisories/unreviewed/2023/11/GHSA-r6fg-prgw-3ff5/GHSA-r6fg-prgw-3ff5.json +++ b/advisories/unreviewed/2023/11/GHSA-r6fg-prgw-3ff5/GHSA-r6fg-prgw-3ff5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-r6fg-prgw-3ff5", - "modified": "2024-03-21T03:35:58Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-15T09:30:57Z", "aliases": [ "CVE-2023-46672" ], - "details": "An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.\n\nThe prerequisites for the manifestation of this issue are:\n\n * Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format.\n\n\n * Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.\n\n\n\n\n\n\n", + "details": "An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.\n\nThe prerequisites for the manifestation of this issue are:\n\n * Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format.\n\n\n * Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json b/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json index cc9c203cacc..ad7484f7a50 100644 --- a/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json +++ b/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x8xw-jc3c-cx53", - "modified": "2023-11-27T21:30:54Z", + "modified": "2025-02-13T18:32:03Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20567" ], - "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-2fh4-45ph-7q27/GHSA-2fh4-45ph-7q27.json b/advisories/unreviewed/2023/12/GHSA-2fh4-45ph-7q27/GHSA-2fh4-45ph-7q27.json index 70c25a9b12b..d07118468b6 100644 --- a/advisories/unreviewed/2023/12/GHSA-2fh4-45ph-7q27/GHSA-2fh4-45ph-7q27.json +++ b/advisories/unreviewed/2023/12/GHSA-2fh4-45ph-7q27/GHSA-2fh4-45ph-7q27.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2fh4-45ph-7q27", - "modified": "2023-12-05T00:31:08Z", + "modified": "2025-02-13T18:32:04Z", "published": "2023-12-05T00:31:08Z", "aliases": [ "CVE-2023-40462" ], - "details": "\n\n\n\n\n\n\n\n\n\nThe ACEManager\ncomponent of ALEOS 4.16 and earlier does not\n\n\n\nperform input\nsanitization during authentication, which could\n\n\n\npotentially result\nin a Denial of Service (DoS) condition for\n\n\n\nACEManager without\nimpairing other router functions. ACEManager\n\n\n\nrecovers from the\nDoS condition by restarting within ten seconds of\n\n\n\nbecoming\nunavailable.\n\n\n\n\n\n\n\n", + "details": "The ACEManager\ncomponent of ALEOS 4.16 and earlier does not\n\n\n\nperform input\nsanitization during authentication, which could\n\n\n\npotentially result\nin a Denial of Service (DoS) condition for\n\n\n\nACEManager without\nimpairing other router functions. ACEManager\n\n\n\nrecovers from the\nDoS condition by restarting within ten seconds of\n\n\n\nbecoming\nunavailable.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json index a4e0016e591..b64e494a990 100644 --- a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json +++ b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3c85-mx4x-435c", - "modified": "2025-01-28T00:32:12Z", + "modified": "2025-02-13T18:32:07Z", "published": "2023-12-25T00:30:17Z", "aliases": [ "CVE-2023-7101" diff --git a/advisories/unreviewed/2023/12/GHSA-58qf-gq3r-xwgx/GHSA-58qf-gq3r-xwgx.json b/advisories/unreviewed/2023/12/GHSA-58qf-gq3r-xwgx/GHSA-58qf-gq3r-xwgx.json index b13913d7ac4..fd7f554e2d2 100644 --- a/advisories/unreviewed/2023/12/GHSA-58qf-gq3r-xwgx/GHSA-58qf-gq3r-xwgx.json +++ b/advisories/unreviewed/2023/12/GHSA-58qf-gq3r-xwgx/GHSA-58qf-gq3r-xwgx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-58qf-gq3r-xwgx", - "modified": "2023-12-11T12:30:34Z", + "modified": "2025-02-13T18:32:05Z", "published": "2023-12-11T12:30:34Z", "aliases": [ "CVE-2023-6185" ], - "details": "Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.\n\nIn affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.\n\n", + "details": "Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.\n\nIn affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-59mm-6rr4-j9p2/GHSA-59mm-6rr4-j9p2.json b/advisories/unreviewed/2023/12/GHSA-59mm-6rr4-j9p2/GHSA-59mm-6rr4-j9p2.json index 15674cd02d6..f3a2242ee25 100644 --- a/advisories/unreviewed/2023/12/GHSA-59mm-6rr4-j9p2/GHSA-59mm-6rr4-j9p2.json +++ b/advisories/unreviewed/2023/12/GHSA-59mm-6rr4-j9p2/GHSA-59mm-6rr4-j9p2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-59mm-6rr4-j9p2", - "modified": "2023-12-12T18:31:32Z", + "modified": "2025-02-13T18:32:04Z", "published": "2023-12-07T03:30:32Z", "aliases": [ "CVE-2023-46218" ], - "details": "This flaw allows a malicious HTTP server to set \"super cookies\" in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl's function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.\n", + "details": "This flaw allows a malicious HTTP server to set \"super cookies\" in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl's function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-9rm6-p86c-42xm/GHSA-9rm6-p86c-42xm.json b/advisories/unreviewed/2023/12/GHSA-9rm6-p86c-42xm/GHSA-9rm6-p86c-42xm.json index 01d90fcf6a2..bfd80c99339 100644 --- a/advisories/unreviewed/2023/12/GHSA-9rm6-p86c-42xm/GHSA-9rm6-p86c-42xm.json +++ b/advisories/unreviewed/2023/12/GHSA-9rm6-p86c-42xm/GHSA-9rm6-p86c-42xm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9rm6-p86c-42xm", - "modified": "2023-12-29T18:30:28Z", + "modified": "2025-02-13T18:32:04Z", "published": "2023-12-05T09:33:26Z", "aliases": [ "CVE-2023-49070" ], - "details": "\nPre-auth RCE in Apache Ofbiz 18.12.09.\n\nIt's due to XML-RPC no longer maintained still present.\nThis issue affects Apache OFBiz: before 18.12.10. \nUsers are recommended to upgrade to version 18.12.10\n\n", + "details": "Pre-auth RCE in Apache Ofbiz 18.12.09.\n\nIt's due to XML-RPC no longer maintained still present.\nThis issue affects Apache OFBiz: before 18.12.10. \nUsers are recommended to upgrade to version 18.12.10", "severity": [ { "type": "CVSS_V3", @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://ofbiz.apache.org/security.html" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.html" diff --git a/advisories/unreviewed/2023/12/GHSA-cmm4-pc7p-g834/GHSA-cmm4-pc7p-g834.json b/advisories/unreviewed/2023/12/GHSA-cmm4-pc7p-g834/GHSA-cmm4-pc7p-g834.json index 457727139b2..cfe039426dd 100644 --- a/advisories/unreviewed/2023/12/GHSA-cmm4-pc7p-g834/GHSA-cmm4-pc7p-g834.json +++ b/advisories/unreviewed/2023/12/GHSA-cmm4-pc7p-g834/GHSA-cmm4-pc7p-g834.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cmm4-pc7p-g834", - "modified": "2024-01-08T21:30:26Z", + "modified": "2025-02-13T18:32:07Z", "published": "2023-12-29T15:30:37Z", "aliases": [ "CVE-2023-47804" ], - "details": "Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.\n\nLinks can be activated by clicks, or by automatic document events.\n\nThe execution of such links must be subject to user approval.\n\nIn the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.\n\nThis is a corner case of CVE-2022-47502.\n\n", + "details": "Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.\n\nLinks can be activated by clicks, or by automatic document events.\n\nThe execution of such links must be subject to user approval.\n\nIn the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.\n\nThis is a corner case of CVE-2022-47502.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-fj44-3xpp-9cx2/GHSA-fj44-3xpp-9cx2.json b/advisories/unreviewed/2023/12/GHSA-fj44-3xpp-9cx2/GHSA-fj44-3xpp-9cx2.json index c28dde72e4b..146367bf4c6 100644 --- a/advisories/unreviewed/2023/12/GHSA-fj44-3xpp-9cx2/GHSA-fj44-3xpp-9cx2.json +++ b/advisories/unreviewed/2023/12/GHSA-fj44-3xpp-9cx2/GHSA-fj44-3xpp-9cx2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fj44-3xpp-9cx2", - "modified": "2023-12-15T15:30:20Z", + "modified": "2025-02-13T18:32:05Z", "published": "2023-12-12T03:31:45Z", "aliases": [ "CVE-2023-46219" ], - "details": "When saving HSTS data to an excessively long file name, curl could end up\nremoving all contents, making subsequent requests using that file unaware of\nthe HSTS status they should otherwise use.\n", + "details": "When saving HSTS data to an excessively long file name, curl could end up\nremoving all contents, making subsequent requests using that file unaware of\nthe HSTS status they should otherwise use.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json b/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json index a3aa7419706..2910f9e066c 100644 --- a/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json +++ b/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fvcr-3mhq-rw2x", - "modified": "2023-12-28T00:30:20Z", + "modified": "2025-02-13T18:32:07Z", "published": "2023-12-28T00:30:20Z", "aliases": [ "CVE-2023-6879" ], - "details": "Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().\n\n", + "details": "Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json b/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json index 6490966d8d1..23d2a2c7362 100644 --- a/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json +++ b/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j5r4-2mjg-6xcc", - "modified": "2024-02-08T18:30:38Z", + "modified": "2025-02-13T18:32:05Z", "published": "2023-12-18T18:30:21Z", "aliases": [ "CVE-2023-6817" ], - "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nThe function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free.\n\nWe recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nThe function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free.\n\nWe recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-m2ff-6895-cr34/GHSA-m2ff-6895-cr34.json b/advisories/unreviewed/2023/12/GHSA-m2ff-6895-cr34/GHSA-m2ff-6895-cr34.json index 73b91c8d259..b06734f22a5 100644 --- a/advisories/unreviewed/2023/12/GHSA-m2ff-6895-cr34/GHSA-m2ff-6895-cr34.json +++ b/advisories/unreviewed/2023/12/GHSA-m2ff-6895-cr34/GHSA-m2ff-6895-cr34.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m2ff-6895-cr34", - "modified": "2024-02-08T18:30:38Z", + "modified": "2025-02-13T18:32:06Z", "published": "2023-12-19T15:30:30Z", "aliases": [ "CVE-2023-6932" ], - "details": "A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation.\n\nA race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.\n\nWe recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.\n\n", + "details": "A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation.\n\nA race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.\n\nWe recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-q565-g228-cgg3/GHSA-q565-g228-cgg3.json b/advisories/unreviewed/2023/12/GHSA-q565-g228-cgg3/GHSA-q565-g228-cgg3.json index 50a3c6c180c..aabaa49af66 100644 --- a/advisories/unreviewed/2023/12/GHSA-q565-g228-cgg3/GHSA-q565-g228-cgg3.json +++ b/advisories/unreviewed/2023/12/GHSA-q565-g228-cgg3/GHSA-q565-g228-cgg3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q565-g228-cgg3", - "modified": "2023-12-11T12:30:34Z", + "modified": "2025-02-13T18:32:05Z", "published": "2023-12-11T12:30:34Z", "aliases": [ "CVE-2023-6186" ], - "details": "Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.\n\nIn affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.\n\n\n", + "details": "Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.\n\nIn affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-xv88-q3gm-mmjp/GHSA-xv88-q3gm-mmjp.json b/advisories/unreviewed/2023/12/GHSA-xv88-q3gm-mmjp/GHSA-xv88-q3gm-mmjp.json index 865fa688751..1931132c19b 100644 --- a/advisories/unreviewed/2023/12/GHSA-xv88-q3gm-mmjp/GHSA-xv88-q3gm-mmjp.json +++ b/advisories/unreviewed/2023/12/GHSA-xv88-q3gm-mmjp/GHSA-xv88-q3gm-mmjp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xv88-q3gm-mmjp", - "modified": "2023-12-19T15:30:30Z", + "modified": "2025-02-13T18:32:06Z", "published": "2023-12-19T15:30:30Z", "aliases": [ "CVE-2023-6931" ], - "details": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.\n\n", + "details": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-3r3p-444m-2g4p/GHSA-3r3p-444m-2g4p.json b/advisories/unreviewed/2024/01/GHSA-3r3p-444m-2g4p/GHSA-3r3p-444m-2g4p.json index 5171c9219d8..1458cb7e514 100644 --- a/advisories/unreviewed/2024/01/GHSA-3r3p-444m-2g4p/GHSA-3r3p-444m-2g4p.json +++ b/advisories/unreviewed/2024/01/GHSA-3r3p-444m-2g4p/GHSA-3r3p-444m-2g4p.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3r3p-444m-2g4p", - "modified": "2024-03-13T03:31:06Z", + "modified": "2025-02-13T18:32:08Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45232" ], - "details": " EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.\n\n", + "details": "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json b/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json index b72eeabb9e8..f7a78c71982 100644 --- a/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json +++ b/advisories/unreviewed/2024/01/GHSA-8549-4c5j-x7g2/GHSA-8549-4c5j-x7g2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8549-4c5j-x7g2", - "modified": "2024-01-24T03:31:25Z", + "modified": "2025-02-13T18:32:08Z", "published": "2024-01-12T15:30:31Z", "aliases": [ "CVE-2023-0437" ], - "details": "When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.\n\n", + "details": "When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json index f8c8c6bd3c4..9c9de1fa2ee 100644 --- a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json +++ b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ff22-5jp8-224r", - "modified": "2024-01-18T15:30:39Z", + "modified": "2025-02-13T18:32:10Z", "published": "2024-01-18T15:30:39Z", "aliases": [ "CVE-2021-33631" ], - "details": "Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.\n\n", + "details": "Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json b/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json index 18fb5350324..2853e42de04 100644 --- a/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json +++ b/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fqc4-ffq5-4r98", - "modified": "2024-03-07T18:30:27Z", + "modified": "2025-02-13T18:32:09Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-45236" ], - "details": " \nEDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality.\n\n\n\n", + "details": "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-fxqf-p2p3-gxvr/GHSA-fxqf-p2p3-gxvr.json b/advisories/unreviewed/2024/01/GHSA-fxqf-p2p3-gxvr/GHSA-fxqf-p2p3-gxvr.json index a80ad7aa0b6..253c74ff394 100644 --- a/advisories/unreviewed/2024/01/GHSA-fxqf-p2p3-gxvr/GHSA-fxqf-p2p3-gxvr.json +++ b/advisories/unreviewed/2024/01/GHSA-fxqf-p2p3-gxvr/GHSA-fxqf-p2p3-gxvr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fxqf-p2p3-gxvr", - "modified": "2024-03-07T18:30:26Z", + "modified": "2025-02-13T18:32:09Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-45237" ], - "details": " \nEDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality.\n\n\n\n", + "details": "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-h9v6-q439-p7j2/GHSA-h9v6-q439-p7j2.json b/advisories/unreviewed/2024/01/GHSA-h9v6-q439-p7j2/GHSA-h9v6-q439-p7j2.json index d9380acf571..b9f87279f71 100644 --- a/advisories/unreviewed/2024/01/GHSA-h9v6-q439-p7j2/GHSA-h9v6-q439-p7j2.json +++ b/advisories/unreviewed/2024/01/GHSA-h9v6-q439-p7j2/GHSA-h9v6-q439-p7j2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h9v6-q439-p7j2", - "modified": "2024-03-13T03:31:06Z", + "modified": "2025-02-13T18:32:09Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45235" ], - "details": " EDK2's Network Package is susceptible to a buffer overflow vulnerability when\n\n\n\n\n\nhandling Server ID option \n\n\n\n from a DHCPv6 proxy Advertise message. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.\n\n", + "details": "EDK2's Network Package is susceptible to a buffer overflow vulnerability when\n\n\n\n\n\nhandling Server ID option \n\n\n\n from a DHCPv6 proxy Advertise message. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-mrjv-p9q7-rxgr/GHSA-mrjv-p9q7-rxgr.json b/advisories/unreviewed/2024/01/GHSA-mrjv-p9q7-rxgr/GHSA-mrjv-p9q7-rxgr.json index b381fef970d..4cea0d70f6b 100644 --- a/advisories/unreviewed/2024/01/GHSA-mrjv-p9q7-rxgr/GHSA-mrjv-p9q7-rxgr.json +++ b/advisories/unreviewed/2024/01/GHSA-mrjv-p9q7-rxgr/GHSA-mrjv-p9q7-rxgr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mrjv-p9q7-rxgr", - "modified": "2024-03-13T03:31:06Z", + "modified": "2025-02-13T18:32:09Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45234" ], - "details": " EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.\n\n", + "details": "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-p9h6-p7cr-7842/GHSA-p9h6-p7cr-7842.json b/advisories/unreviewed/2024/01/GHSA-p9h6-p7cr-7842/GHSA-p9h6-p7cr-7842.json index 4955cc9fdd8..a22218d058b 100644 --- a/advisories/unreviewed/2024/01/GHSA-p9h6-p7cr-7842/GHSA-p9h6-p7cr-7842.json +++ b/advisories/unreviewed/2024/01/GHSA-p9h6-p7cr-7842/GHSA-p9h6-p7cr-7842.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p9h6-p7cr-7842", - "modified": "2024-03-13T03:31:06Z", + "modified": "2025-02-13T18:32:09Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45233" ], - "details": " EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.\n\n", + "details": "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json index b5a6e66dcbf..575fbf21c48 100644 --- a/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json +++ b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v75r-qqcp-59c7", - "modified": "2024-02-15T03:30:19Z", + "modified": "2025-02-13T18:32:07Z", "published": "2024-01-05T18:30:26Z", "aliases": [ "CVE-2023-46837" ], - "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n\nThis undefined behavior was meant to be addressed by XSA-437, but the\napproach was not sufficient.\n", + "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n\nThis undefined behavior was meant to be addressed by XSA-437, but the\napproach was not sufficient.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json b/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json index 5db18c4ccea..4dc77a6286c 100644 --- a/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json +++ b/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w56r-g989-xqw3", - "modified": "2024-02-20T03:30:56Z", + "modified": "2025-02-13T18:32:10Z", "published": "2024-01-30T18:30:20Z", "aliases": [ "CVE-2024-1019" ], - "details": "ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.\n", + "details": "ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json index e535da56466..ad6d77852dc 100644 --- a/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json +++ b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wqmr-cp8m-946m", - "modified": "2024-01-11T00:30:23Z", + "modified": "2025-02-13T18:32:07Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-48418" ], - "details": " In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a\n    possible way to access adb before SUW completion due to an insecure default\n    value. This could lead to local escalation of privilege with no additional\n    execution privileges needed. User interaction is not needed for\n    exploitation\n", + "details": " In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a\n    possible way to access adb before SUW completion due to an insecure default\n    value. This could lead to local escalation of privilege with no additional\n    execution privileges needed. User interaction is not needed for\n    exploitation", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-2862-59r4-c989/GHSA-2862-59r4-c989.json b/advisories/unreviewed/2024/02/GHSA-2862-59r4-c989/GHSA-2862-59r4-c989.json index ae07b62d33c..e26e44c3d8c 100644 --- a/advisories/unreviewed/2024/02/GHSA-2862-59r4-c989/GHSA-2862-59r4-c989.json +++ b/advisories/unreviewed/2024/02/GHSA-2862-59r4-c989/GHSA-2862-59r4-c989.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2862-59r4-c989", - "modified": "2024-02-15T06:31:34Z", + "modified": "2025-02-13T18:32:13Z", "published": "2024-02-08T09:30:40Z", "aliases": [ "CVE-2024-23452" ], - "details": "Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request.\n\nVulnerability Cause Description:\n\nThe http_parser does not comply with the RFC-7230 HTTP 1.1 specification.\n\nAttack scenario:\nIf a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting.\nOne particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server. \n\nSolution:\nYou can choose one solution from below:\n1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0\n 2. Apply this patch:  https://github.com/apache/brpc/pull/2518 \n\n", + "details": "Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request.\n\nVulnerability Cause Description:\n\nThe http_parser does not comply with the RFC-7230 HTTP 1.1 specification.\n\nAttack scenario:\nIf a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting.\nOne particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server. \n\nSolution:\nYou can choose one solution from below:\n1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0\n 2. Apply this patch:  https://github.com/apache/brpc/pull/2518", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-5f6g-f3pq-385m/GHSA-5f6g-f3pq-385m.json b/advisories/unreviewed/2024/02/GHSA-5f6g-f3pq-385m/GHSA-5f6g-f3pq-385m.json index 2873eeade5d..9c01e42975a 100644 --- a/advisories/unreviewed/2024/02/GHSA-5f6g-f3pq-385m/GHSA-5f6g-f3pq-385m.json +++ b/advisories/unreviewed/2024/02/GHSA-5f6g-f3pq-385m/GHSA-5f6g-f3pq-385m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f6g-f3pq-385m", - "modified": "2024-02-29T03:33:15Z", + "modified": "2025-02-13T18:32:20Z", "published": "2024-02-29T03:33:15Z", "aliases": [ "CVE-2024-0604" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-975j-m6j8-qh4v/GHSA-975j-m6j8-qh4v.json b/advisories/unreviewed/2024/02/GHSA-975j-m6j8-qh4v/GHSA-975j-m6j8-qh4v.json index af391e45f4d..8bc4823bba2 100644 --- a/advisories/unreviewed/2024/02/GHSA-975j-m6j8-qh4v/GHSA-975j-m6j8-qh4v.json +++ b/advisories/unreviewed/2024/02/GHSA-975j-m6j8-qh4v/GHSA-975j-m6j8-qh4v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-975j-m6j8-qh4v", - "modified": "2024-02-15T06:31:35Z", + "modified": "2025-02-13T18:32:13Z", "published": "2024-02-13T03:30:21Z", "aliases": [ "CVE-2023-50358" ], - "details": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.5.2645 build 20240116 and later\nQTS 4.5.4.2627 build 20231225 and later\nQTS 4.3.6.2665 build 20240131 and later\nQTS 4.3.4.2675 build 20240131 and later\nQTS 4.3.3.2644 build 20240131 and later\nQTS 4.2.6 build 20240131 and later\nQuTS hero h5.1.5.2647 build 20240118 and later\nQuTS hero h4.5.4.2626 build 20231225 and later\nQuTScloud c5.1.5.2651 and later\n", + "details": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.5.2645 build 20240116 and later\nQTS 4.5.4.2627 build 20231225 and later\nQTS 4.3.6.2665 build 20240131 and later\nQTS 4.3.4.2675 build 20240131 and later\nQTS 4.3.3.2644 build 20240131 and later\nQTS 4.2.6 build 20240131 and later\nQuTS hero h5.1.5.2647 build 20240118 and later\nQuTS hero h4.5.4.2626 build 20231225 and later\nQuTScloud c5.1.5.2651 and later", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-f4jc-jxp8-5pv7/GHSA-f4jc-jxp8-5pv7.json b/advisories/unreviewed/2024/02/GHSA-f4jc-jxp8-5pv7/GHSA-f4jc-jxp8-5pv7.json index b46be1c4bed..0cc7398c130 100644 --- a/advisories/unreviewed/2024/02/GHSA-f4jc-jxp8-5pv7/GHSA-f4jc-jxp8-5pv7.json +++ b/advisories/unreviewed/2024/02/GHSA-f4jc-jxp8-5pv7/GHSA-f4jc-jxp8-5pv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4jc-jxp8-5pv7", - "modified": "2024-02-17T03:30:30Z", + "modified": "2025-02-13T18:32:14Z", "published": "2024-02-17T03:30:30Z", "aliases": [ "CVE-2024-20953" @@ -22,10 +22,16 @@ { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2024.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-096" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-ggv5-38c7-p4jr/GHSA-ggv5-38c7-p4jr.json b/advisories/unreviewed/2024/02/GHSA-ggv5-38c7-p4jr/GHSA-ggv5-38c7-p4jr.json index 0f4cf2b5e72..36affe254e2 100644 --- a/advisories/unreviewed/2024/02/GHSA-ggv5-38c7-p4jr/GHSA-ggv5-38c7-p4jr.json +++ b/advisories/unreviewed/2024/02/GHSA-ggv5-38c7-p4jr/GHSA-ggv5-38c7-p4jr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ggv5-38c7-p4jr", - "modified": "2024-06-10T18:30:52Z", + "modified": "2025-02-13T18:32:14Z", "published": "2024-02-13T03:30:22Z", "aliases": [ "CVE-2024-25642" ], - "details": "Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.\n\n", + "details": "Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json b/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json index c1fd6cf3e54..b7b278ff7a3 100644 --- a/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json +++ b/advisories/unreviewed/2024/02/GHSA-gxmr-rxpv-c8fq/GHSA-gxmr-rxpv-c8fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxmr-rxpv-c8fq", - "modified": "2024-02-26T18:30:27Z", + "modified": "2025-02-13T18:32:11Z", "published": "2024-02-01T21:30:31Z", "aliases": [ "CVE-2023-5841" diff --git a/advisories/unreviewed/2024/02/GHSA-j269-5p85-wxpq/GHSA-j269-5p85-wxpq.json b/advisories/unreviewed/2024/02/GHSA-j269-5p85-wxpq/GHSA-j269-5p85-wxpq.json index 3d6172ccd6f..cc0450a0c4f 100644 --- a/advisories/unreviewed/2024/02/GHSA-j269-5p85-wxpq/GHSA-j269-5p85-wxpq.json +++ b/advisories/unreviewed/2024/02/GHSA-j269-5p85-wxpq/GHSA-j269-5p85-wxpq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j269-5p85-wxpq", - "modified": "2024-02-15T06:31:35Z", + "modified": "2025-02-13T18:32:13Z", "published": "2024-02-13T03:30:20Z", "aliases": [ "CVE-2023-47218" ], - "details": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.5.2645 build 20240116 and later\nQuTS hero h5.1.5.2647 build 20240118 and later\nQuTScloud c5.1.5.2651 and later\n", + "details": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.5.2645 build 20240116 and later\nQuTS hero h5.1.5.2647 build 20240118 and later\nQuTScloud c5.1.5.2651 and later", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json index 55d393f4e0f..811454a5fc9 100644 --- a/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json +++ b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3q9-44rg-xw34", - "modified": "2024-08-14T18:32:36Z", + "modified": "2025-02-13T18:32:19Z", "published": "2024-02-26T18:30:28Z", "aliases": [ "CVE-2023-49114" diff --git a/advisories/unreviewed/2024/02/GHSA-xf62-wwm9-m968/GHSA-xf62-wwm9-m968.json b/advisories/unreviewed/2024/02/GHSA-xf62-wwm9-m968/GHSA-xf62-wwm9-m968.json index f1f945f8c5d..6c707ac62ed 100644 --- a/advisories/unreviewed/2024/02/GHSA-xf62-wwm9-m968/GHSA-xf62-wwm9-m968.json +++ b/advisories/unreviewed/2024/02/GHSA-xf62-wwm9-m968/GHSA-xf62-wwm9-m968.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2qrg-pqh4-8gj9/GHSA-2qrg-pqh4-8gj9.json b/advisories/unreviewed/2024/03/GHSA-2qrg-pqh4-8gj9/GHSA-2qrg-pqh4-8gj9.json index b6abd529769..7d642a2520d 100644 --- a/advisories/unreviewed/2024/03/GHSA-2qrg-pqh4-8gj9/GHSA-2qrg-pqh4-8gj9.json +++ b/advisories/unreviewed/2024/03/GHSA-2qrg-pqh4-8gj9/GHSA-2qrg-pqh4-8gj9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2qrg-pqh4-8gj9", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-02-13T18:32:21Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2024-29137" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Reflected XSS.This issue affects Tourfic: from n/a through 2.11.7.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Reflected XSS.This issue affects Tourfic: from n/a through 2.11.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-825c-4w2m-h7fv/GHSA-825c-4w2m-h7fv.json b/advisories/unreviewed/2024/03/GHSA-825c-4w2m-h7fv/GHSA-825c-4w2m-h7fv.json index 0165ec0cb47..feed04b8e77 100644 --- a/advisories/unreviewed/2024/03/GHSA-825c-4w2m-h7fv/GHSA-825c-4w2m-h7fv.json +++ b/advisories/unreviewed/2024/03/GHSA-825c-4w2m-h7fv/GHSA-825c-4w2m-h7fv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-825c-4w2m-h7fv", - "modified": "2024-06-10T18:30:52Z", + "modified": "2025-02-13T18:32:20Z", "published": "2024-03-07T18:30:28Z", "aliases": [ "CVE-2024-1351" ], - "details": "Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\n\nRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.\n\n", + "details": "Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\n\nRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.", "severity": [ { "type": "CVSS_V3",