diff --git a/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json b/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json index 4bd934c7f69..57386406b99 100644 --- a/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json +++ b/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json b/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json index fc5cb454def..add18884c8b 100644 --- a/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json +++ b/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json @@ -80,6 +80,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Jul/9" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/20" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json b/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json index 944b51e385a..9c6d320b10c 100644 --- a/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json +++ b/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json @@ -64,6 +64,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json b/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json index 325f5647be4..ca23e59a573 100644 --- a/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json +++ b/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json b/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json index 6b0b9e6dc1d..f5a57cbba31 100644 --- a/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json +++ b/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json @@ -48,6 +48,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json index 793b258beb3..5b278aeed3a 100644 --- a/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json +++ b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json b/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json index 59dda886920..a6d27df4ba9 100644 --- a/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json +++ b/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json b/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json index ee533f018ca..9c89a567ec7 100644 --- a/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json +++ b/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json b/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json index 6f31c2ae071..119bf2e7ee6 100644 --- a/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json +++ b/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json b/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json index 1da1cc15ce6..756aaaf233e 100644 --- a/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json +++ b/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json index e28c6ca2fab..89b8a247df4 100644 --- a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json +++ b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5534" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json b/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json index 3100a22eaa9..942671f0a5e 100644 --- a/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json +++ b/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json b/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json index 60fa1dc7a52..7bba950a875 100644 --- a/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json +++ b/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json b/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json index 667605a3e12..3bf55894b68 100644 --- a/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json +++ b/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json @@ -65,6 +65,30 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json b/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json index a60af58a565..313a337e2a4 100644 --- a/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json +++ b/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json b/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json new file mode 100644 index 00000000000..b2d61c5ebbe --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59qp-8h5f-h6h4", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46668" + ], + "details": "If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46668" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/endpoint-v8-10-4-security-update/345203" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json index c4dec92a043..ea829564644 100644 --- a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json +++ b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json b/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json index fbd1000a3b2..9e86c657c1f 100644 --- a/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json +++ b/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json b/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json index ca39b3669f2..2816ded2079 100644 --- a/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json +++ b/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json b/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json index 7a63af0526d..2b413c4d673 100644 --- a/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json +++ b/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json b/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json index 4e28df980ef..1cdc466b596 100644 --- a/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json +++ b/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json b/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json index dd90caf3fbc..c2efd01bc08 100644 --- a/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json +++ b/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json b/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json new file mode 100644 index 00000000000..39ca63bf26e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7frm-v438-mwmg", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-30967" + ], + "details": "Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30967" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=8fd5809f-26f8-406e-b36f-4a6596a19d79" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json b/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json index 0b8047fcb90..4fc33064efb 100644 --- a/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json +++ b/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json @@ -65,6 +65,30 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json b/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json index 8735edb18fa..7e370e8c49a 100644 --- a/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json +++ b/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json b/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json index 0e51778c303..dd5752e47ca 100644 --- a/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json +++ b/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json b/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json index 8b4e920d7f8..dadfec525dc 100644 --- a/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json +++ b/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json index 40838428365..ec3891e7fac 100644 --- a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json +++ b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json new file mode 100644 index 00000000000..4b1043e6cac --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94rj-cjmj-fm26", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38849" + ], + "details": "An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38849" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38849.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657203739-yvGg5PjN" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json b/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json index c52a3c9d229..70b68ed2dda 100644 --- a/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json +++ b/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json b/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json index 109337af7a5..9e629dec041 100644 --- a/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json +++ b/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json b/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json index 5329387b224..89c88f6c802 100644 --- a/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json +++ b/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json index 6b846d545a7..f99bbe16998 100644 --- a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json +++ b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213986" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json b/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json new file mode 100644 index 00000000000..01a2f1a5e1d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crff-6xx5-6mj3", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46583" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) \" Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46583" + }, + { + "type": "WEB", + "url": "https://github.com/rumble773/sec-research/blob/main/NiV/CVE-2023-46583.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json b/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json new file mode 100644 index 00000000000..b282c3ae178 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f257-8wpr-74j7", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-30969" + ], + "details": "The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30969" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=afcbc9b2-de62-44b9-b28b-2ebf0684fbf7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json b/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json new file mode 100644 index 00000000000..7d343b71380 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm32-j6m7-4pp6", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46584" + ], + "details": "SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) \" Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46584" + }, + { + "type": "WEB", + "url": "https://github.com/rumble773/sec-research/blob/main/NiV/CVE-2023-46584.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json b/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json index 4c694356c30..dcb683c1625 100644 --- a/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json +++ b/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json b/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json index abc269744c2..4a4cba701dc 100644 --- a/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json +++ b/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json index 65852e83ae4..9203a610894 100644 --- a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json +++ b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213983" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json b/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json index 8c08cafb3b2..395f06d61ae 100644 --- a/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json +++ b/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json b/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json new file mode 100644 index 00000000000..7853ee7026a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh6q-p4vm-gvm8", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-43906" + ], + "details": "Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43906" + }, + { + "type": "WEB", + "url": "https://github.com/Playful-CR/CVE-paddle-/blob/main/CVE-2023-43906" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json b/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json index f0acaa23013..71c0a9c431a 100644 --- a/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json +++ b/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json b/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json index 0b8dd2d65c9..f234d19e655 100644 --- a/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json +++ b/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json b/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json index ac369ca9a3f..ebeb6147d66 100644 --- a/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json +++ b/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json b/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json index 9cd88980c1a..5603968828b 100644 --- a/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json +++ b/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json index 75784f2678c..4e355c2eea0 100644 --- a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json +++ b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json b/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json new file mode 100644 index 00000000000..b44b697031a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpwj-x7jq-jhc6", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38848" + ], + "details": "An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38848" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38848.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657640647-Wk2xYj38" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json index 0812c2bd0ee..73408cd888e 100644 --- a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json +++ b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json b/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json index b3d91ea26e8..db017900e7a 100644 --- a/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json +++ b/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json b/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json new file mode 100644 index 00000000000..96890894ccf --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfgv-5fc9-mh6x", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38847" + ], + "details": "An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38847" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38847.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657631315-oX5J26Ak" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 1b0bf4e7e14..19c7f3496c4 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5534" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json b/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json new file mode 100644 index 00000000000..68dd1969bd0 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp9j-3hxc-wm7p", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46345" + ], + "details": "Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46345" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rycbar77/d747b2c37b544ece30b2353a65ab41f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json b/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json index 34f8f1554e1..1f90fa44fa0 100644 --- a/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json +++ b/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json b/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json new file mode 100644 index 00000000000..2f4edf7fc9f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v24w-vwv8-8qjf", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38845" + ], + "details": "An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38845" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38845.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657030660-8nDEQNbe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json b/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json new file mode 100644 index 00000000000..9047feda283 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5r3-qxfr-w8w4", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38846" + ], + "details": "An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38846" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38846.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657925980-KmmGkje5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json index dccaad6c786..895ae4b48d5 100644 --- a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json +++ b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json b/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json index 3223b5852af..b020375f34b 100644 --- a/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json +++ b/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json b/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json index c80056e72ad..f5b7cf25956 100644 --- a/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json +++ b/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json index b88e701355a..28452a3b60a 100644 --- a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json +++ b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213982" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json b/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json index bbdbb0e53d0..2e13bf4978b 100644 --- a/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json +++ b/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json b/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json index 2dfb3bc5751..b66cb7ba36f 100644 --- a/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json +++ b/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json b/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json new file mode 100644 index 00000000000..426c1299ade --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqr2-f99c-rcpq", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-43905" + ], + "details": "Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43905" + }, + { + "type": "WEB", + "url": "https://github.com/Playful-CR/CVE-paddle-/blob/main/CVE-2023-43905..md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json index 9fd64df8720..93da10964f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json +++ b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": {