Publish Advisories

GHSA-cv2w-q8c3-xjv7
GHSA-cfh5-3ghh-wfjx
GHSA-c945-cqj5-wfv6
GHSA-h3j8-wx8r-29j6
GHSA-m653-m4xm-rxrr
GHSA-6rx2-vgf2-fwv2
GHSA-9cmp-2g73-ff98
GHSA-wm25-c777-f2h3
GHSA-65h2-wf7m-q2v8
GHSA-3gm2-5hwv-5pp2
GHSA-45rg-4qh3-jxp9
GHSA-56p2-xp5h-2cf3
GHSA-9gwj-43rx-hrvq
GHSA-9qf7-53rf-5jg7
GHSA-crg9-44h2-xw35
GHSA-m4mp-v249-x3mh
GHSA-vhh4-xqj8-87v3
GHSA-w2qc-22jv-44g8
GHSA-wv72-9v4w-73w6
GHSA-x93f-pq85-wxcw
GHSA-xw78-pcr6-wrg8
GHSA-xw7g-pw64-xph3
This commit is contained in:
advisory-database[bot]
2023-10-27 15:32:09 +00:00
parent 9b3fb5eab2
commit 8515342961
22 changed files with 332 additions and 13 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv2w-q8c3-xjv7",
"modified": "2022-12-16T20:45:28Z",
"modified": "2023-10-27T15:29:59Z",
"published": "2022-05-24T19:19:43Z",
"aliases": [
"CVE-2021-21697"
@@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -82,7 +82,7 @@
"cwe_ids": [
"CWE-184"
],
"severity": "HIGH",
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-06-23T06:46:48Z",
"nvd_published_at": "2021-11-04T17:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfh5-3ghh-wfjx",
"modified": "2020-06-16T21:31:17Z",
"modified": "2023-10-27T15:30:16Z",
"published": "2018-10-17T00:05:06Z",
"aliases": [
"CVE-2014-3577"
@@ -93,6 +93,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0003/"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.html"
@@ -231,7 +235,7 @@
"CWE-347"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed": false,
"github_reviewed_at": "2020-06-16T21:31:17Z",
"nvd_published_at": "2014-08-21T14:55:00Z"
}
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230818-0014/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0008/"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20230731.txt"
@@ -81,6 +81,10 @@
"type": "WEB",
"url": "https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230719190824.21196-1-fw@strlen.de/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0001/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m653-m4xm-rxrr",
"modified": "2023-10-04T18:30:24Z",
"modified": "2023-10-27T15:30:16Z",
"published": "2023-07-06T21:15:06Z",
"aliases": [
"CVE-2023-32707"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/174602/Splunk-Enterprise-Account-Takeover.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175386/Splunk-edit_user-Capability-Privilege-Escalation.html"
}
],
"database_specific": {
@@ -97,6 +97,10 @@
"type": "WEB",
"url": "https://lore.kernel.org/netdev/193d6cdf-d6c9-f9be-c36a-b2a7551d5fb6@mojatatu.com/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -53,6 +53,10 @@
"type": "WEB",
"url": "https://lore.kernel.org/all/20230731164237.48365-3-lersek@redhat.com/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0002/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5480"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65h2-wf7m-q2v8",
"modified": "2023-09-27T20:16:42Z",
"modified": "2023-10-27T15:30:17Z",
"published": "2023-09-27T15:30:35Z",
"aliases": [
"CVE-2023-3223"
@@ -87,6 +87,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/undertow-io/undertow"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0004/"
}
],
"database_specific": {
@@ -94,7 +98,7 @@
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed": false,
"github_reviewed_at": "2023-09-27T20:16:42Z",
"nvd_published_at": null
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3gm2-5hwv-5pp2",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-5443"
],
"details": "Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting.This issue affects E-invoice: before 2.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5443"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-23-0610"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1320"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45rg-4qh3-jxp9",
"modified": "2023-10-20T09:30:27Z",
"modified": "2023-10-27T15:30:18Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4271"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56p2-xp5h-2cf3",
"modified": "2023-10-20T00:30:25Z",
"modified": "2023-10-27T15:30:18Z",
"published": "2023-10-20T00:30:25Z",
"aliases": [
"CVE-2023-43345"
],
"details": "Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gwj-43rx-hrvq",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-46393"
],
"details": "gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46393"
},
{
"type": "WEB",
"url": "https://gitee.com/gouguopen/gougucms/issues/I88TKH"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qf7-53rf-5jg7",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-5807"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection.This issue affects Education Portal: before 3.2023.29.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5807"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-23-0608"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crg9-44h2-xw35",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-46604"
],
"details": "Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. \n\nUsers are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46604"
},
{
"type": "WEB",
"url": "https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4mp-v249-x3mh",
"modified": "2023-10-25T18:32:20Z",
"modified": "2023-10-27T15:30:18Z",
"published": "2023-10-23T09:30:18Z",
"aliases": [
"CVE-2023-45802"
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0011/"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhh4-xqj8-87v3",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-44376"
],
"details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add2' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44376"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/ono"
},
{
"type": "WEB",
"url": "https://https://projectworlds.in/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0011/"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv72-9v4w-73w6",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-46394"
],
"details": "A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46394"
},
{
"type": "WEB",
"url": "https://gitee.com/gouguopen/gougucms/issues/I88TC0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x93f-pq85-wxcw",
"modified": "2023-10-27T15:30:20Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-44377"
],
"details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add3' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44377"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/ono"
},
{
"type": "WEB",
"url": "https://https://projectworlds.in/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}

Some files were not shown because too many files have changed in this diff Show More