From 82c0747436a57518aaaf193a1413fe6b2442d3bf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 26 Oct 2023 00:31:51 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3rqj-8cc4-p9rh.json | 4 ++ .../GHSA-4pvh-jrgh-mpvj.json | 4 ++ .../GHSA-hgwq-wchh-f9vv.json | 8 ++++ .../GHSA-2rh9-r44r-2xv6.json | 4 ++ .../GHSA-5pgr-2gf9-wh94.json | 4 ++ .../GHSA-hvfg-rr99-vxgg.json | 4 ++ .../GHSA-mfhq-77wv-g7gh.json | 4 ++ .../GHSA-ph6h-mvrc-7rq5.json | 4 ++ .../GHSA-x7vr-7frv-2rrh.json | 4 ++ .../GHSA-22x6-c42f-8q7h.json | 20 +++++++++ .../GHSA-294c-hpxh-5qrx.json | 4 ++ .../GHSA-2jcp-64q4-69c4.json | 12 ++++++ .../GHSA-468w-3r6j-mchw.json | 4 ++ .../GHSA-4fc2-j39p-mv7v.json | 24 +++++++++++ .../GHSA-4j7x-78x6-53cx.json | 24 +++++++++++ .../GHSA-59qp-8h5f-h6h4.json | 42 +++++++++++++++++++ .../GHSA-5p7g-qx77-8f6h.json | 4 ++ .../GHSA-5vg3-8c2w-qh9w.json | 8 ++++ .../GHSA-6r68-v3jx-h6qg.json | 24 +++++++++++ .../GHSA-6w99-p6vc-wh73.json | 12 ++++++ .../GHSA-6x9f-qr8v-5wfw.json | 4 ++ .../GHSA-7379-vgf5-fcwc.json | 12 ++++++ .../GHSA-7frm-v438-mwmg.json | 38 +++++++++++++++++ .../GHSA-7j5q-8x2v-mrhw.json | 24 +++++++++++ .../GHSA-83px-x9cj-8f5g.json | 8 ++++ .../GHSA-88c9-3488-gx4h.json | 8 ++++ .../GHSA-8q5r-gmrx-88jx.json | 4 ++ .../GHSA-8xq6-frf7-63cg.json | 16 +++++++ .../GHSA-94rj-cjmj-fm26.json | 39 +++++++++++++++++ .../GHSA-9mh4-4vr9-p4jq.json | 16 +++++++ .../GHSA-c483-xw4j-pmcm.json | 20 +++++++++ .../GHSA-ccvf-q4m9-xf67.json | 16 +++++++ .../GHSA-ch8m-5863-fcr7.json | 16 +++++++ .../GHSA-crff-6xx5-6mj3.json | 35 ++++++++++++++++ .../GHSA-f257-8wpr-74j7.json | 38 +++++++++++++++++ .../GHSA-fm32-j6m7-4pp6.json | 35 ++++++++++++++++ .../GHSA-fr42-p77x-54x8.json | 8 ++++ .../GHSA-fwv4-p95x-f2mc.json | 8 ++++ .../GHSA-g5vf-92m7-vh6w.json | 4 ++ .../GHSA-gmf5-xh65-wv9w.json | 4 ++ .../GHSA-hh6q-p4vm-gvm8.json | 35 ++++++++++++++++ .../GHSA-hhcv-5r95-mwmc.json | 4 ++ .../GHSA-hp7g-968m-74c4.json | 20 +++++++++ .../GHSA-hvm3-h7gj-pmfc.json | 4 ++ .../GHSA-j755-pf65-mmrq.json | 4 ++ .../GHSA-jmh8-4h3g-x5g5.json | 24 +++++++++++ .../GHSA-jpwj-x7jq-jhc6.json | 39 +++++++++++++++++ .../GHSA-m58q-xcxc-4q6h.json | 4 ++ .../GHSA-mxqf-9j3w-rv3f.json | 20 +++++++++ .../GHSA-pfgv-5fc9-mh6x.json | 39 +++++++++++++++++ .../GHSA-q38f-wwqq-rr3v.json | 4 ++ .../GHSA-qp9j-3hxc-wm7p.json | 35 ++++++++++++++++ .../GHSA-qw77-8mx5-p223.json | 16 +++++++ .../GHSA-v24w-vwv8-8qjf.json | 39 +++++++++++++++++ .../GHSA-v5r3-qxfr-w8w4.json | 39 +++++++++++++++++ .../GHSA-w3ff-vvc7-jg8f.json | 16 +++++++ .../GHSA-w4xv-vxw5-h385.json | 4 ++ .../GHSA-w8f8-j2jj-6qwh.json | 4 ++ .../GHSA-wmqw-xg54-ch38.json | 4 ++ .../GHSA-wp7x-2348-v58r.json | 12 ++++++ .../GHSA-x9v9-7hfr-q9g4.json | 12 ++++++ .../GHSA-xqr2-f99c-rcpq.json | 35 ++++++++++++++++ .../GHSA-xr44-9893-8w63.json | 12 ++++++ 63 files changed, 996 insertions(+) create mode 100644 advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json create mode 100644 advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json create mode 100644 advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json create mode 100644 advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json create mode 100644 advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json create mode 100644 advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json create mode 100644 advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json create mode 100644 advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json create mode 100644 advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json create mode 100644 advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json create mode 100644 advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json create mode 100644 advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json create mode 100644 advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json diff --git a/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json b/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json index 4bd934c7f69..57386406b99 100644 --- a/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json +++ b/advisories/unreviewed/2023/05/GHSA-3rqj-8cc4-p9rh/GHSA-3rqj-8cc4-p9rh.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json b/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json index fc5cb454def..add18884c8b 100644 --- a/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json +++ b/advisories/unreviewed/2023/06/GHSA-4pvh-jrgh-mpvj/GHSA-4pvh-jrgh-mpvj.json @@ -80,6 +80,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Jul/9" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/20" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json b/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json index 944b51e385a..9c6d320b10c 100644 --- a/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json +++ b/advisories/unreviewed/2023/07/GHSA-hgwq-wchh-f9vv/GHSA-hgwq-wchh-f9vv.json @@ -64,6 +64,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json b/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json index 325f5647be4..ca23e59a573 100644 --- a/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json +++ b/advisories/unreviewed/2023/09/GHSA-2rh9-r44r-2xv6/GHSA-2rh9-r44r-2xv6.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json b/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json index 6b0b9e6dc1d..f5a57cbba31 100644 --- a/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json +++ b/advisories/unreviewed/2023/09/GHSA-5pgr-2gf9-wh94/GHSA-5pgr-2gf9-wh94.json @@ -48,6 +48,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json index 793b258beb3..5b278aeed3a 100644 --- a/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json +++ b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json b/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json index 59dda886920..a6d27df4ba9 100644 --- a/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json +++ b/advisories/unreviewed/2023/09/GHSA-mfhq-77wv-g7gh/GHSA-mfhq-77wv-g7gh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json b/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json index ee533f018ca..9c89a567ec7 100644 --- a/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json +++ b/advisories/unreviewed/2023/09/GHSA-ph6h-mvrc-7rq5/GHSA-ph6h-mvrc-7rq5.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json b/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json index 6f31c2ae071..119bf2e7ee6 100644 --- a/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json +++ b/advisories/unreviewed/2023/09/GHSA-x7vr-7frv-2rrh/GHSA-x7vr-7frv-2rrh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json b/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json index 1da1cc15ce6..756aaaf233e 100644 --- a/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json +++ b/advisories/unreviewed/2023/10/GHSA-22x6-c42f-8q7h/GHSA-22x6-c42f-8q7h.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json index e28c6ca2fab..89b8a247df4 100644 --- a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json +++ b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5534" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json b/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json index 3100a22eaa9..942671f0a5e 100644 --- a/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json +++ b/advisories/unreviewed/2023/10/GHSA-2jcp-64q4-69c4/GHSA-2jcp-64q4-69c4.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json b/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json index 60fa1dc7a52..7bba950a875 100644 --- a/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json +++ b/advisories/unreviewed/2023/10/GHSA-468w-3r6j-mchw/GHSA-468w-3r6j-mchw.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json b/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json index 667605a3e12..3bf55894b68 100644 --- a/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json +++ b/advisories/unreviewed/2023/10/GHSA-4fc2-j39p-mv7v/GHSA-4fc2-j39p-mv7v.json @@ -65,6 +65,30 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json b/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json index a60af58a565..313a337e2a4 100644 --- a/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json +++ b/advisories/unreviewed/2023/10/GHSA-4j7x-78x6-53cx/GHSA-4j7x-78x6-53cx.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json b/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json new file mode 100644 index 00000000000..b2d61c5ebbe --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-59qp-8h5f-h6h4/GHSA-59qp-8h5f-h6h4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59qp-8h5f-h6h4", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46668" + ], + "details": "If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46668" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/endpoint-v8-10-4-security-update/345203" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json index c4dec92a043..ea829564644 100644 --- a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json +++ b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json b/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json index fbd1000a3b2..9e86c657c1f 100644 --- a/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json +++ b/advisories/unreviewed/2023/10/GHSA-5vg3-8c2w-qh9w/GHSA-5vg3-8c2w-qh9w.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json b/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json index ca39b3669f2..2816ded2079 100644 --- a/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json +++ b/advisories/unreviewed/2023/10/GHSA-6r68-v3jx-h6qg/GHSA-6r68-v3jx-h6qg.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json b/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json index 7a63af0526d..2b413c4d673 100644 --- a/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json +++ b/advisories/unreviewed/2023/10/GHSA-6w99-p6vc-wh73/GHSA-6w99-p6vc-wh73.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json b/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json index 4e28df980ef..1cdc466b596 100644 --- a/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json +++ b/advisories/unreviewed/2023/10/GHSA-6x9f-qr8v-5wfw/GHSA-6x9f-qr8v-5wfw.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json b/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json index dd90caf3fbc..c2efd01bc08 100644 --- a/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json +++ b/advisories/unreviewed/2023/10/GHSA-7379-vgf5-fcwc/GHSA-7379-vgf5-fcwc.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json b/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json new file mode 100644 index 00000000000..39ca63bf26e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7frm-v438-mwmg/GHSA-7frm-v438-mwmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7frm-v438-mwmg", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-30967" + ], + "details": "Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30967" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=8fd5809f-26f8-406e-b36f-4a6596a19d79" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json b/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json index 0b8047fcb90..4fc33064efb 100644 --- a/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json +++ b/advisories/unreviewed/2023/10/GHSA-7j5q-8x2v-mrhw/GHSA-7j5q-8x2v-mrhw.json @@ -65,6 +65,30 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json b/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json index 8735edb18fa..7e370e8c49a 100644 --- a/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json +++ b/advisories/unreviewed/2023/10/GHSA-83px-x9cj-8f5g/GHSA-83px-x9cj-8f5g.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json b/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json index 0e51778c303..dd5752e47ca 100644 --- a/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json +++ b/advisories/unreviewed/2023/10/GHSA-88c9-3488-gx4h/GHSA-88c9-3488-gx4h.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json b/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json index 8b4e920d7f8..dadfec525dc 100644 --- a/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json +++ b/advisories/unreviewed/2023/10/GHSA-8q5r-gmrx-88jx/GHSA-8q5r-gmrx-88jx.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json index 40838428365..ec3891e7fac 100644 --- a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json +++ b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json new file mode 100644 index 00000000000..4b1043e6cac --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-94rj-cjmj-fm26/GHSA-94rj-cjmj-fm26.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94rj-cjmj-fm26", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38849" + ], + "details": "An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38849" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38849.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657203739-yvGg5PjN" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json b/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json index c52a3c9d229..70b68ed2dda 100644 --- a/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json +++ b/advisories/unreviewed/2023/10/GHSA-9mh4-4vr9-p4jq/GHSA-9mh4-4vr9-p4jq.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json b/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json index 109337af7a5..9e629dec041 100644 --- a/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json +++ b/advisories/unreviewed/2023/10/GHSA-c483-xw4j-pmcm/GHSA-c483-xw4j-pmcm.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json b/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json index 5329387b224..89c88f6c802 100644 --- a/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json +++ b/advisories/unreviewed/2023/10/GHSA-ccvf-q4m9-xf67/GHSA-ccvf-q4m9-xf67.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json index 6b846d545a7..f99bbe16998 100644 --- a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json +++ b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213986" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json b/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json new file mode 100644 index 00000000000..01a2f1a5e1d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-crff-6xx5-6mj3/GHSA-crff-6xx5-6mj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crff-6xx5-6mj3", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46583" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) \" Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46583" + }, + { + "type": "WEB", + "url": "https://github.com/rumble773/sec-research/blob/main/NiV/CVE-2023-46583.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json b/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json new file mode 100644 index 00000000000..b282c3ae178 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-f257-8wpr-74j7/GHSA-f257-8wpr-74j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f257-8wpr-74j7", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-30969" + ], + "details": "The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30969" + }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=afcbc9b2-de62-44b9-b28b-2ebf0684fbf7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json b/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json new file mode 100644 index 00000000000..7d343b71380 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fm32-j6m7-4pp6/GHSA-fm32-j6m7-4pp6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm32-j6m7-4pp6", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46584" + ], + "details": "SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) \" Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46584" + }, + { + "type": "WEB", + "url": "https://github.com/rumble773/sec-research/blob/main/NiV/CVE-2023-46584.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json b/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json index 4c694356c30..dcb683c1625 100644 --- a/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json +++ b/advisories/unreviewed/2023/10/GHSA-fr42-p77x-54x8/GHSA-fr42-p77x-54x8.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json b/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json index abc269744c2..4a4cba701dc 100644 --- a/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json +++ b/advisories/unreviewed/2023/10/GHSA-fwv4-p95x-f2mc/GHSA-fwv4-p95x-f2mc.json @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json index 65852e83ae4..9203a610894 100644 --- a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json +++ b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213983" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json b/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json index 8c08cafb3b2..395f06d61ae 100644 --- a/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json +++ b/advisories/unreviewed/2023/10/GHSA-gmf5-xh65-wv9w/GHSA-gmf5-xh65-wv9w.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json b/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json new file mode 100644 index 00000000000..7853ee7026a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-hh6q-p4vm-gvm8/GHSA-hh6q-p4vm-gvm8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh6q-p4vm-gvm8", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-43906" + ], + "details": "Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43906" + }, + { + "type": "WEB", + "url": "https://github.com/Playful-CR/CVE-paddle-/blob/main/CVE-2023-43906" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json b/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json index f0acaa23013..71c0a9c431a 100644 --- a/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json +++ b/advisories/unreviewed/2023/10/GHSA-hhcv-5r95-mwmc/GHSA-hhcv-5r95-mwmc.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json b/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json index 0b8dd2d65c9..f234d19e655 100644 --- a/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json +++ b/advisories/unreviewed/2023/10/GHSA-hp7g-968m-74c4/GHSA-hp7g-968m-74c4.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json b/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json index ac369ca9a3f..ebeb6147d66 100644 --- a/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json +++ b/advisories/unreviewed/2023/10/GHSA-hvm3-h7gj-pmfc/GHSA-hvm3-h7gj-pmfc.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json b/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json index 9cd88980c1a..5603968828b 100644 --- a/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json +++ b/advisories/unreviewed/2023/10/GHSA-j755-pf65-mmrq/GHSA-j755-pf65-mmrq.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json index 75784f2678c..4e355c2eea0 100644 --- a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json +++ b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/22" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json b/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json new file mode 100644 index 00000000000..b44b697031a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jpwj-x7jq-jhc6/GHSA-jpwj-x7jq-jhc6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpwj-x7jq-jhc6", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38848" + ], + "details": "An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38848" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38848.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657640647-Wk2xYj38" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json index 0812c2bd0ee..73408cd888e 100644 --- a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json +++ b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json b/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json index b3d91ea26e8..db017900e7a 100644 --- a/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json +++ b/advisories/unreviewed/2023/10/GHSA-mxqf-9j3w-rv3f/GHSA-mxqf-9j3w-rv3f.json @@ -57,6 +57,26 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json b/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json new file mode 100644 index 00000000000..96890894ccf --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pfgv-5fc9-mh6x/GHSA-pfgv-5fc9-mh6x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfgv-5fc9-mh6x", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38847" + ], + "details": "An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38847" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38847.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657631315-oX5J26Ak" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 1b0bf4e7e14..19c7f3496c4 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5534" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json b/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json new file mode 100644 index 00000000000..68dd1969bd0 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-qp9j-3hxc-wm7p/GHSA-qp9j-3hxc-wm7p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp9j-3hxc-wm7p", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-46345" + ], + "details": "Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46345" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rycbar77/d747b2c37b544ece30b2353a65ab41f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json b/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json index 34f8f1554e1..1f90fa44fa0 100644 --- a/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json +++ b/advisories/unreviewed/2023/10/GHSA-qw77-8mx5-p223/GHSA-qw77-8mx5-p223.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json b/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json new file mode 100644 index 00000000000..2f4edf7fc9f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v24w-vwv8-8qjf/GHSA-v24w-vwv8-8qjf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v24w-vwv8-8qjf", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38845" + ], + "details": "An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38845" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38845.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657030660-8nDEQNbe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json b/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json new file mode 100644 index 00000000000..9047feda283 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v5r3-qxfr-w8w4/GHSA-v5r3-qxfr-w8w4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5r3-qxfr-w8w4", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-38846" + ], + "details": "An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38846" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-38846.md" + }, + { + "type": "WEB", + "url": "https://liff.line.me/1657925980-KmmGkje5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json index dccaad6c786..895ae4b48d5 100644 --- a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json +++ b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json @@ -49,6 +49,22 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json b/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json index 3223b5852af..b020375f34b 100644 --- a/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json +++ b/advisories/unreviewed/2023/10/GHSA-w4xv-vxw5-h385/GHSA-w4xv-vxw5-h385.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json b/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json index c80056e72ad..f5b7cf25956 100644 --- a/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json +++ b/advisories/unreviewed/2023/10/GHSA-w8f8-j2jj-6qwh/GHSA-w8f8-j2jj-6qwh.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json index b88e701355a..28452a3b60a 100644 --- a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json +++ b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213982" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json b/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json index bbdbb0e53d0..2e13bf4978b 100644 --- a/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json +++ b/advisories/unreviewed/2023/10/GHSA-wp7x-2348-v58r/GHSA-wp7x-2348-v58r.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json b/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json index 2dfb3bc5751..b66cb7ba36f 100644 --- a/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json +++ b/advisories/unreviewed/2023/10/GHSA-x9v9-7hfr-q9g4/GHSA-x9v9-7hfr-q9g4.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213985" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/26" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json b/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json new file mode 100644 index 00000000000..426c1299ade --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-xqr2-f99c-rcpq/GHSA-xqr2-f99c-rcpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqr2-f99c-rcpq", + "modified": "2023-10-26T00:30:37Z", + "published": "2023-10-26T00:30:37Z", + "aliases": [ + "CVE-2023-43905" + ], + "details": "Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43905" + }, + { + "type": "WEB", + "url": "https://github.com/Playful-CR/CVE-paddle-/blob/main/CVE-2023-43905..md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json index 9fd64df8720..93da10964f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json +++ b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json @@ -41,6 +41,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213988" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/19" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/24" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/25" } ], "database_specific": {