mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-cv2w-q8c3-xjv7 GHSA-cfh5-3ghh-wfjx GHSA-c945-cqj5-wfv6 GHSA-h3j8-wx8r-29j6 GHSA-m653-m4xm-rxrr GHSA-6rx2-vgf2-fwv2 GHSA-9cmp-2g73-ff98 GHSA-wm25-c777-f2h3 GHSA-65h2-wf7m-q2v8 GHSA-3gm2-5hwv-5pp2 GHSA-45rg-4qh3-jxp9 GHSA-56p2-xp5h-2cf3 GHSA-9gwj-43rx-hrvq GHSA-9qf7-53rf-5jg7 GHSA-crg9-44h2-xw35 GHSA-m4mp-v249-x3mh GHSA-vhh4-xqj8-87v3 GHSA-w2qc-22jv-44g8 GHSA-wv72-9v4w-73w6 GHSA-x93f-pq85-wxcw GHSA-xw78-pcr6-wrg8 GHSA-xw7g-pw64-xph3
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cv2w-q8c3-xjv7",
|
||||
"modified": "2022-12-16T20:45:28Z",
|
||||
"modified": "2023-10-27T15:29:59Z",
|
||||
"published": "2022-05-24T19:19:43Z",
|
||||
"aliases": [
|
||||
"CVE-2021-21697"
|
||||
@@ -11,7 +11,7 @@
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
@@ -82,7 +82,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-184"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2022-06-23T06:46:48Z",
|
||||
"nvd_published_at": "2021-11-04T17:15:00Z"
|
||||
|
||||
+6
-2
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cfh5-3ghh-wfjx",
|
||||
"modified": "2020-06-16T21:31:17Z",
|
||||
"modified": "2023-10-27T15:30:16Z",
|
||||
"published": "2018-10-17T00:05:06Z",
|
||||
"aliases": [
|
||||
"CVE-2014-3577"
|
||||
@@ -93,6 +93,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0003/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.html"
|
||||
@@ -231,7 +235,7 @@
|
||||
"CWE-347"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": "2020-06-16T21:31:17Z",
|
||||
"nvd_published_at": "2014-08-21T14:55:00Z"
|
||||
}
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20230818-0014/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0008/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openssl.org/news/secadv/20230731.txt"
|
||||
|
||||
@@ -81,6 +81,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230719190824.21196-1-fw@strlen.de/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0001/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m653-m4xm-rxrr",
|
||||
"modified": "2023-10-04T18:30:24Z",
|
||||
"modified": "2023-10-27T15:30:16Z",
|
||||
"published": "2023-07-06T21:15:06Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32707"
|
||||
@@ -32,6 +32,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://packetstormsecurity.com/files/174602/Splunk-Enterprise-Account-Takeover.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://packetstormsecurity.com/files/175386/Splunk-edit_user-Capability-Privilege-Escalation.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -97,6 +97,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/netdev/193d6cdf-d6c9-f9be-c36a-b2a7551d5fb6@mojatatu.com/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -53,6 +53,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/all/20230731164237.48365-3-lersek@redhat.com/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5480"
|
||||
|
||||
+6
-2
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-65h2-wf7m-q2v8",
|
||||
"modified": "2023-09-27T20:16:42Z",
|
||||
"modified": "2023-10-27T15:30:17Z",
|
||||
"published": "2023-09-27T15:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3223"
|
||||
@@ -87,6 +87,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/undertow-io/undertow"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0004/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
@@ -94,7 +98,7 @@
|
||||
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": "2023-09-27T20:16:42Z",
|
||||
"nvd_published_at": null
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3gm2-5hwv-5pp2",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5443"
|
||||
],
|
||||
"details": "Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting.This issue affects E-invoice: before 2.1.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5443"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.usom.gov.tr/bildirim/tr-23-0610"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-1320"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-45rg-4qh3-jxp9",
|
||||
"modified": "2023-10-20T09:30:27Z",
|
||||
"modified": "2023-10-27T15:30:18Z",
|
||||
"published": "2023-10-20T09:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4271"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-56p2-xp5h-2cf3",
|
||||
"modified": "2023-10-20T00:30:25Z",
|
||||
"modified": "2023-10-27T15:30:18Z",
|
||||
"published": "2023-10-20T00:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-43345"
|
||||
],
|
||||
"details": "Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9gwj-43rx-hrvq",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46393"
|
||||
],
|
||||
"details": "gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46393"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitee.com/gouguopen/gougucms/issues/I88TKH"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9qf7-53rf-5jg7",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5807"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection.This issue affects Education Portal: before 3.2023.29.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5807"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.usom.gov.tr/bildirim/tr-23-0608"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-crg9-44h2-xw35",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46604"
|
||||
],
|
||||
"details": "Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. \n\nUsers are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46604"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-502"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m4mp-v249-x3mh",
|
||||
"modified": "2023-10-25T18:32:20Z",
|
||||
"modified": "2023-10-27T15:30:18Z",
|
||||
"published": "2023-10-23T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45802"
|
||||
@@ -25,6 +25,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0011/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vhh4-xqj8-87v3",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44376"
|
||||
],
|
||||
"details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add2' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44376"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://fluidattacks.com/advisories/ono"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://https://projectworlds.in/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -21,6 +21,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231027-0011/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wv72-9v4w-73w6",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46394"
|
||||
],
|
||||
"details": "A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46394"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitee.com/gouguopen/gougucms/issues/I88TC0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x93f-pq85-wxcw",
|
||||
"modified": "2023-10-27T15:30:20Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44377"
|
||||
],
|
||||
"details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add3' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44377"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://fluidattacks.com/advisories/ono"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://https://projectworlds.in/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user