Publish Advisories

GHSA-25x7-989g-366h
GHSA-2873-9vw6-x36q
GHSA-39h7-cq3m-g3fv
GHSA-4gff-fjgq-76g6
GHSA-5rc2-qffv-3c8p
GHSA-75cg-g4f4-h9c2
GHSA-7693-rm3h-988x
GHSA-8c88-9jmc-phqr
GHSA-9qvp-qqr3-gfx3
GHSA-fqhp-rhm6-8rrj
GHSA-gmvw-h9hf-3rxv
GHSA-h3v4-g87v-9f8x
GHSA-h9x5-2vrm-ww3f
GHSA-pq98-r2rc-hr54
GHSA-qwvc-xxgc-r8jq
GHSA-r33p-xcv8-c582
GHSA-r4jh-xqh3-r437
GHSA-r6x9-4x42-c57h
GHSA-rrr5-v5h9-fpwp
GHSA-v668-ccv8-m5gx
GHSA-wp54-pwvg-rqq5
GHSA-xc2q-prrj-8cp6
This commit is contained in:
advisory-database[bot]
2023-06-21 21:31:36 +00:00
parent a363618be1
commit 87fc9aa873
22 changed files with 421 additions and 16 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25x7-989g-366h",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-21T21:30:24Z",
"aliases": [
"CVE-2023-0971"
],
"details": "A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0971"
},
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2873-9vw6-x36q",
"modified": "2023-06-14T09:30:42Z",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-14T09:30:42Z",
"aliases": [
"CVE-2023-33933"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39h7-cq3m-g3fv",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:25Z",
"aliases": [
"CVE-2023-24261"
],
"details": "A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24261"
},
{
"type": "WEB",
"url": "https://justinapplegate.me/2023/glinet-CVE-2023-24261/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gff-fjgq-76g6",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:25Z",
"aliases": [
"CVE-2023-33591"
],
"details": "User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33591"
},
{
"type": "WEB",
"url": "https://github.com/DARSHANAGUPTA10/CVE/blob/main/CVE%202023-33591"
},
{
"type": "WEB",
"url": "https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rc2-qffv-3c8p",
"modified": "2023-06-14T09:30:42Z",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-14T09:30:42Z",
"aliases": [
"CVE-2023-30631"
],
"details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7693-rm3h-988x",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:24Z",
"aliases": [
"CVE-2023-25435"
],
"details": "libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25435"
},
{
"type": "WEB",
"url": "https://gitlab.com/libtiff/libtiff/-/issues/518"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c88-9jmc-phqr",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-21T21:30:24Z",
"aliases": [
"CVE-2023-0970"
],
"details": "Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0970"
},
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qvp-qqr3-gfx3",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:25Z",
"aliases": [
"CVE-2023-33405"
],
"details": "Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33405"
},
{
"type": "WEB",
"url": "https://github.com/hacip/CVE-2023-33405"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqhp-rhm6-8rrj",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:25Z",
"aliases": [
"CVE-2023-33289"
],
"details": "The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33289"
},
{
"type": "WEB",
"url": "https://gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611"
},
{
"type": "WEB",
"url": "https://github.com/progscrape/urlnorm"
},
{
"type": "WEB",
"url": "https://lib.rs/crates/urlnorm"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmvw-h9hf-3rxv",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-21T21:30:24Z",
"aliases": [
"CVE-2023-0969"
],
"details": "A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0969"
},
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3v4-g87v-9f8x",
"modified": "2023-06-13T21:30:18Z",
"modified": "2023-06-21T21:30:22Z",
"published": "2023-06-13T21:30:18Z",
"aliases": [
"CVE-2023-27836"
],
"details": "TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9x5-2vrm-ww3f",
"modified": "2023-06-21T21:30:24Z",
"published": "2023-06-21T21:30:24Z",
"aliases": [
"CVE-2023-0972"
],
"details": "Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0972"
},
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq98-r2rc-hr54",
"modified": "2023-06-21T21:30:25Z",
"published": "2023-06-21T21:30:25Z",
"aliases": [
"CVE-2023-3110"
],
"details": "Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3110"
},
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r33p-xcv8-c582",
"modified": "2023-06-13T12:30:16Z",
"modified": "2023-06-21T21:30:22Z",
"published": "2023-06-13T12:30:16Z",
"aliases": [
"CVE-2023-29160"
],
"details": "Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": null,
"github_reviewed": false,
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30082"
},
{
"type": "WEB",
"url": "https://blog.manavparekh.com/2023/06/cve-2023-30082.html"
},
{
"type": "WEB",
"url": "https://github.com/manavparekh/CVEs/blob/main/CVE-2023-30082/Steps%20to%20reproduce.txt"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://kb.isc.org/docs/cve-2023-2911"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/06/21/6"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://kb.isc.org/docs/cve-2023-2828"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/06/21/6"
}
],
"database_specific": {

Some files were not shown because too many files have changed in this diff Show More