diff --git a/advisories/github-reviewed/2022/05/GHSA-cv2w-q8c3-xjv7/GHSA-cv2w-q8c3-xjv7.json b/advisories/github-reviewed/2022/05/GHSA-cv2w-q8c3-xjv7/GHSA-cv2w-q8c3-xjv7.json index cafaa2dd477..9cb8892d638 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cv2w-q8c3-xjv7/GHSA-cv2w-q8c3-xjv7.json +++ b/advisories/github-reviewed/2022/05/GHSA-cv2w-q8c3-xjv7/GHSA-cv2w-q8c3-xjv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv2w-q8c3-xjv7", - "modified": "2022-12-16T20:45:28Z", + "modified": "2023-10-27T15:29:59Z", "published": "2022-05-24T19:19:43Z", "aliases": [ "CVE-2021-21697" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], "affected": [ @@ -82,7 +82,7 @@ "cwe_ids": [ "CWE-184" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-06-23T06:46:48Z", "nvd_published_at": "2021-11-04T17:15:00Z" diff --git a/advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json b/advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json similarity index 97% rename from advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json rename to advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json index c9c85da7640..493cd20afdf 100644 --- a/advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json +++ b/advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfh5-3ghh-wfjx", - "modified": "2020-06-16T21:31:17Z", + "modified": "2023-10-27T15:30:16Z", "published": "2018-10-17T00:05:06Z", "aliases": [ "CVE-2014-3577" @@ -93,6 +93,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0003/" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.html" @@ -231,7 +235,7 @@ "CWE-347" ], "severity": "MODERATE", - "github_reviewed": true, + "github_reviewed": false, "github_reviewed_at": "2020-06-16T21:31:17Z", "nvd_published_at": "2014-08-21T14:55:00Z" } diff --git a/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json b/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json index f86f157285a..0468fdc19e9 100644 --- a/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json +++ b/advisories/unreviewed/2023/07/GHSA-c945-cqj5-wfv6/GHSA-c945-cqj5-wfv6.json @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230818-0014/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0008/" + }, { "type": "WEB", "url": "https://www.openssl.org/news/secadv/20230731.txt" diff --git a/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json b/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json index b319dc1b3ce..f6d7bb9d202 100644 --- a/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json +++ b/advisories/unreviewed/2023/07/GHSA-h3j8-wx8r-29j6/GHSA-h3j8-wx8r-29j6.json @@ -81,6 +81,10 @@ "type": "WEB", "url": "https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230719190824.21196-1-fw@strlen.de/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0001/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/07/GHSA-m653-m4xm-rxrr/GHSA-m653-m4xm-rxrr.json b/advisories/unreviewed/2023/07/GHSA-m653-m4xm-rxrr/GHSA-m653-m4xm-rxrr.json index 979fed497fa..1b2f2566aa2 100644 --- a/advisories/unreviewed/2023/07/GHSA-m653-m4xm-rxrr/GHSA-m653-m4xm-rxrr.json +++ b/advisories/unreviewed/2023/07/GHSA-m653-m4xm-rxrr/GHSA-m653-m4xm-rxrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m653-m4xm-rxrr", - "modified": "2023-10-04T18:30:24Z", + "modified": "2023-10-27T15:30:16Z", "published": "2023-07-06T21:15:06Z", "aliases": [ "CVE-2023-32707" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/174602/Splunk-Enterprise-Account-Takeover.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/175386/Splunk-edit_user-Capability-Privilege-Escalation.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-6rx2-vgf2-fwv2/GHSA-6rx2-vgf2-fwv2.json b/advisories/unreviewed/2023/08/GHSA-6rx2-vgf2-fwv2/GHSA-6rx2-vgf2-fwv2.json index 32648d9071f..fd0eff0bd40 100644 --- a/advisories/unreviewed/2023/08/GHSA-6rx2-vgf2-fwv2/GHSA-6rx2-vgf2-fwv2.json +++ b/advisories/unreviewed/2023/08/GHSA-6rx2-vgf2-fwv2/GHSA-6rx2-vgf2-fwv2.json @@ -97,6 +97,10 @@ "type": "WEB", "url": "https://lore.kernel.org/netdev/193d6cdf-d6c9-f9be-c36a-b2a7551d5fb6@mojatatu.com/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0002/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/08/GHSA-9cmp-2g73-ff98/GHSA-9cmp-2g73-ff98.json b/advisories/unreviewed/2023/08/GHSA-9cmp-2g73-ff98/GHSA-9cmp-2g73-ff98.json index 89c9ea336ef..54525870a76 100644 --- a/advisories/unreviewed/2023/08/GHSA-9cmp-2g73-ff98/GHSA-9cmp-2g73-ff98.json +++ b/advisories/unreviewed/2023/08/GHSA-9cmp-2g73-ff98/GHSA-9cmp-2g73-ff98.json @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://lore.kernel.org/all/20230731164237.48365-3-lersek@redhat.com/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0002/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/08/GHSA-wm25-c777-f2h3/GHSA-wm25-c777-f2h3.json b/advisories/unreviewed/2023/08/GHSA-wm25-c777-f2h3/GHSA-wm25-c777-f2h3.json index d004818c336..c09b31ec7c9 100644 --- a/advisories/unreviewed/2023/08/GHSA-wm25-c777-f2h3/GHSA-wm25-c777-f2h3.json +++ b/advisories/unreviewed/2023/08/GHSA-wm25-c777-f2h3/GHSA-wm25-c777-f2h3.json @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0002/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/github-reviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json b/advisories/unreviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json similarity index 93% rename from advisories/github-reviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json rename to advisories/unreviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json index ba37f7e4b7e..b5af6d47b15 100644 --- a/advisories/github-reviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json +++ b/advisories/unreviewed/2023/09/GHSA-65h2-wf7m-q2v8/GHSA-65h2-wf7m-q2v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65h2-wf7m-q2v8", - "modified": "2023-09-27T20:16:42Z", + "modified": "2023-10-27T15:30:17Z", "published": "2023-09-27T15:30:35Z", "aliases": [ "CVE-2023-3223" @@ -87,6 +87,10 @@ { "type": "PACKAGE", "url": "https://github.com/undertow-io/undertow" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0004/" } ], "database_specific": { @@ -94,7 +98,7 @@ ], "severity": "HIGH", - "github_reviewed": true, + "github_reviewed": false, "github_reviewed_at": "2023-09-27T20:16:42Z", "nvd_published_at": null } diff --git a/advisories/unreviewed/2023/10/GHSA-3gm2-5hwv-5pp2/GHSA-3gm2-5hwv-5pp2.json b/advisories/unreviewed/2023/10/GHSA-3gm2-5hwv-5pp2/GHSA-3gm2-5hwv-5pp2.json new file mode 100644 index 00000000000..b70d3bf902b --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3gm2-5hwv-5pp2/GHSA-3gm2-5hwv-5pp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gm2-5hwv-5pp2", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-5443" + ], + "details": "Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting.This issue affects E-invoice: before 2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5443" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0610" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1320" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json b/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json index ede266e4f88..ad6017d0bee 100644 --- a/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json +++ b/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45rg-4qh3-jxp9", - "modified": "2023-10-20T09:30:27Z", + "modified": "2023-10-27T15:30:18Z", "published": "2023-10-20T09:30:27Z", "aliases": [ "CVE-2023-4271" diff --git a/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json b/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json index 45581b41845..893750ba4b0 100644 --- a/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json +++ b/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56p2-xp5h-2cf3", - "modified": "2023-10-20T00:30:25Z", + "modified": "2023-10-27T15:30:18Z", "published": "2023-10-20T00:30:25Z", "aliases": [ "CVE-2023-43345" ], "details": "Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9gwj-43rx-hrvq/GHSA-9gwj-43rx-hrvq.json b/advisories/unreviewed/2023/10/GHSA-9gwj-43rx-hrvq/GHSA-9gwj-43rx-hrvq.json new file mode 100644 index 00000000000..7816c7b91d8 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9gwj-43rx-hrvq/GHSA-9gwj-43rx-hrvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gwj-43rx-hrvq", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-46393" + ], + "details": "gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46393" + }, + { + "type": "WEB", + "url": "https://gitee.com/gouguopen/gougucms/issues/I88TKH" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9qf7-53rf-5jg7/GHSA-9qf7-53rf-5jg7.json b/advisories/unreviewed/2023/10/GHSA-9qf7-53rf-5jg7/GHSA-9qf7-53rf-5jg7.json new file mode 100644 index 00000000000..5b3d5199c7d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9qf7-53rf-5jg7/GHSA-9qf7-53rf-5jg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qf7-53rf-5jg7", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-5807" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection.This issue affects Education Portal: before 3.2023.29.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5807" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0608" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json b/advisories/unreviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json new file mode 100644 index 00000000000..3d796a36bdb --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crg9-44h2-xw35", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-46604" + ], + "details": "Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. \n\nUsers are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46604" + }, + { + "type": "WEB", + "url": "https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json b/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json index 252b32e8002..f924376c148 100644 --- a/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json +++ b/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4mp-v249-x3mh", - "modified": "2023-10-25T18:32:20Z", + "modified": "2023-10-27T15:30:18Z", "published": "2023-10-23T09:30:18Z", "aliases": [ "CVE-2023-45802" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0011/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-vhh4-xqj8-87v3/GHSA-vhh4-xqj8-87v3.json b/advisories/unreviewed/2023/10/GHSA-vhh4-xqj8-87v3/GHSA-vhh4-xqj8-87v3.json new file mode 100644 index 00000000000..60f95e1ab7c --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-vhh4-xqj8-87v3/GHSA-vhh4-xqj8-87v3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhh4-xqj8-87v3", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-44376" + ], + "details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add2' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44376" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/ono" + }, + { + "type": "WEB", + "url": "https://https://projectworlds.in/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json b/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json index bf97bcbc239..f0ba317e092 100644 --- a/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json +++ b/advisories/unreviewed/2023/10/GHSA-w2qc-22jv-44g8/GHSA-w2qc-22jv-44g8.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0011/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wv72-9v4w-73w6/GHSA-wv72-9v4w-73w6.json b/advisories/unreviewed/2023/10/GHSA-wv72-9v4w-73w6/GHSA-wv72-9v4w-73w6.json new file mode 100644 index 00000000000..bdded5af207 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-wv72-9v4w-73w6/GHSA-wv72-9v4w-73w6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv72-9v4w-73w6", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-46394" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46394" + }, + { + "type": "WEB", + "url": "https://gitee.com/gouguopen/gougucms/issues/I88TC0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-x93f-pq85-wxcw/GHSA-x93f-pq85-wxcw.json b/advisories/unreviewed/2023/10/GHSA-x93f-pq85-wxcw/GHSA-x93f-pq85-wxcw.json new file mode 100644 index 00000000000..271e2c396f4 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-x93f-pq85-wxcw/GHSA-x93f-pq85-wxcw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x93f-pq85-wxcw", + "modified": "2023-10-27T15:30:20Z", + "published": "2023-10-27T15:30:20Z", + "aliases": [ + "CVE-2023-44377" + ], + "details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add3' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44377" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/ono" + }, + { + "type": "WEB", + "url": "https://https://projectworlds.in/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json b/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json index 201a6935779..0918afef0ab 100644 --- a/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json +++ b/advisories/unreviewed/2023/10/GHSA-xw78-pcr6-wrg8/GHSA-xw78-pcr6-wrg8.json @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=5f69f5c65e483928c4b28ed16af6e5742929f1ee" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0010/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5532" diff --git a/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json b/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json index dbb8471e8f2..0f4a2965cb7 100644 --- a/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json +++ b/advisories/unreviewed/2023/10/GHSA-xw7g-pw64-xph3/GHSA-xw7g-pw64-xph3.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0011/" } ], "database_specific": {