diff --git a/advisories/unreviewed/2023/12/GHSA-2255-f3p6-4fv3/GHSA-2255-f3p6-4fv3.json b/advisories/unreviewed/2023/12/GHSA-2255-f3p6-4fv3/GHSA-2255-f3p6-4fv3.json index b6e9d96b04f..ea6790220b2 100644 --- a/advisories/unreviewed/2023/12/GHSA-2255-f3p6-4fv3/GHSA-2255-f3p6-4fv3.json +++ b/advisories/unreviewed/2023/12/GHSA-2255-f3p6-4fv3/GHSA-2255-f3p6-4fv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2255-f3p6-4fv3", - "modified": "2023-12-14T00:30:26Z", + "modified": "2023-12-18T21:30:22Z", "published": "2023-12-14T00:30:26Z", "aliases": [ "CVE-2023-41621" ], "details": "A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-24r5-xw2j-9h9x/GHSA-24r5-xw2j-9h9x.json b/advisories/unreviewed/2023/12/GHSA-24r5-xw2j-9h9x/GHSA-24r5-xw2j-9h9x.json index 5eb79bea356..e85677f6bbb 100644 --- a/advisories/unreviewed/2023/12/GHSA-24r5-xw2j-9h9x/GHSA-24r5-xw2j-9h9x.json +++ b/advisories/unreviewed/2023/12/GHSA-24r5-xw2j-9h9x/GHSA-24r5-xw2j-9h9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24r5-xw2j-9h9x", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40628" ], "details": "A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-2m47-7r27-xh85/GHSA-2m47-7r27-xh85.json b/advisories/unreviewed/2023/12/GHSA-2m47-7r27-xh85/GHSA-2m47-7r27-xh85.json index 83f659fba4c..c1304652116 100644 --- a/advisories/unreviewed/2023/12/GHSA-2m47-7r27-xh85/GHSA-2m47-7r27-xh85.json +++ b/advisories/unreviewed/2023/12/GHSA-2m47-7r27-xh85/GHSA-2m47-7r27-xh85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m47-7r27-xh85", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-25644" diff --git a/advisories/unreviewed/2023/12/GHSA-2q88-68x3-v4pp/GHSA-2q88-68x3-v4pp.json b/advisories/unreviewed/2023/12/GHSA-2q88-68x3-v4pp/GHSA-2q88-68x3-v4pp.json new file mode 100644 index 00000000000..6c5af47b260 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2q88-68x3-v4pp/GHSA-2q88-68x3-v4pp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q88-68x3-v4pp", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-6203" + ], + "details": "The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6203" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/229273e6-e849-447f-a95a-0730969ecdae" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json b/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json new file mode 100644 index 00000000000..cce576be48e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44xq-r8h3-q4q6", + "modified": "2023-12-18T21:30:26Z", + "published": "2023-12-18T21:30:26Z", + "aliases": [ + "CVE-2023-51384" + ], + "details": "In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51384" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-9.6" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/12/18/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json b/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json new file mode 100644 index 00000000000..2b569423314 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c5v-86xf-p6j6", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-47741" + ], + "details": "\nIBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47741" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7097785" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7097801" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4ppj-757r-h8qc/GHSA-4ppj-757r-h8qc.json b/advisories/unreviewed/2023/12/GHSA-4ppj-757r-h8qc/GHSA-4ppj-757r-h8qc.json index d8d43e371be..d7d52491183 100644 --- a/advisories/unreviewed/2023/12/GHSA-4ppj-757r-h8qc/GHSA-4ppj-757r-h8qc.json +++ b/advisories/unreviewed/2023/12/GHSA-4ppj-757r-h8qc/GHSA-4ppj-757r-h8qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4ppj-757r-h8qc", - "modified": "2023-12-14T03:30:53Z", + "modified": "2023-12-18T21:30:22Z", "published": "2023-12-14T03:30:53Z", "aliases": [ "CVE-2023-31546" ], "details": "Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T01:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-52q9-9jfh-88p5/GHSA-52q9-9jfh-88p5.json b/advisories/unreviewed/2023/12/GHSA-52q9-9jfh-88p5/GHSA-52q9-9jfh-88p5.json index cf54c49e103..5b481f0a71c 100644 --- a/advisories/unreviewed/2023/12/GHSA-52q9-9jfh-88p5/GHSA-52q9-9jfh-88p5.json +++ b/advisories/unreviewed/2023/12/GHSA-52q9-9jfh-88p5/GHSA-52q9-9jfh-88p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52q9-9jfh-88p5", - "modified": "2023-12-14T00:30:26Z", + "modified": "2023-12-18T21:30:22Z", "published": "2023-12-14T00:30:26Z", "aliases": [ "CVE-2023-40921" ], "details": "SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T00:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json new file mode 100644 index 00000000000..95b53911e6a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mq4-x9g5-4vc4", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-51385" + ], + "details": "In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51385" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-9.6" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/12/18/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-65mr-mxqp-9fgc/GHSA-65mr-mxqp-9fgc.json b/advisories/unreviewed/2023/12/GHSA-65mr-mxqp-9fgc/GHSA-65mr-mxqp-9fgc.json index 041c90f08ad..2fe50567cc4 100644 --- a/advisories/unreviewed/2023/12/GHSA-65mr-mxqp-9fgc/GHSA-65mr-mxqp-9fgc.json +++ b/advisories/unreviewed/2023/12/GHSA-65mr-mxqp-9fgc/GHSA-65mr-mxqp-9fgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65mr-mxqp-9fgc", - "modified": "2023-12-14T18:30:20Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T18:30:20Z", "aliases": [ "CVE-2023-49172" diff --git a/advisories/unreviewed/2023/12/GHSA-67qp-jc76-wwrg/GHSA-67qp-jc76-wwrg.json b/advisories/unreviewed/2023/12/GHSA-67qp-jc76-wwrg/GHSA-67qp-jc76-wwrg.json index 0eef5c3b681..c28914b5b70 100644 --- a/advisories/unreviewed/2023/12/GHSA-67qp-jc76-wwrg/GHSA-67qp-jc76-wwrg.json +++ b/advisories/unreviewed/2023/12/GHSA-67qp-jc76-wwrg/GHSA-67qp-jc76-wwrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67qp-jc76-wwrg", - "modified": "2023-12-12T21:31:12Z", + "modified": "2023-12-18T21:30:21Z", "published": "2023-12-12T21:31:12Z", "aliases": [ "CVE-2023-34064" ], "details": "Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T20:15:06Z" diff --git a/advisories/unreviewed/2023/12/GHSA-73xg-5xg9-crjv/GHSA-73xg-5xg9-crjv.json b/advisories/unreviewed/2023/12/GHSA-73xg-5xg9-crjv/GHSA-73xg-5xg9-crjv.json new file mode 100644 index 00000000000..c3dd74a1dc2 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-73xg-5xg9-crjv/GHSA-73xg-5xg9-crjv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73xg-5xg9-crjv", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-6077" + ], + "details": "The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6077" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1afc0e4a-f712-47d4-bf29-7719ccbbbb1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-77gw-gm6r-6m2p/GHSA-77gw-gm6r-6m2p.json b/advisories/unreviewed/2023/12/GHSA-77gw-gm6r-6m2p/GHSA-77gw-gm6r-6m2p.json index 59ee9935cbc..cec879e2bc3 100644 --- a/advisories/unreviewed/2023/12/GHSA-77gw-gm6r-6m2p/GHSA-77gw-gm6r-6m2p.json +++ b/advisories/unreviewed/2023/12/GHSA-77gw-gm6r-6m2p/GHSA-77gw-gm6r-6m2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77gw-gm6r-6m2p", - "modified": "2023-12-15T12:30:29Z", + "modified": "2023-12-18T21:30:26Z", "published": "2023-12-15T12:30:29Z", "aliases": [ "CVE-2023-48530" diff --git a/advisories/unreviewed/2023/12/GHSA-7cr4-32jg-hwx2/GHSA-7cr4-32jg-hwx2.json b/advisories/unreviewed/2023/12/GHSA-7cr4-32jg-hwx2/GHSA-7cr4-32jg-hwx2.json new file mode 100644 index 00000000000..bb758bde61d --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7cr4-32jg-hwx2/GHSA-7cr4-32jg-hwx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cr4-32jg-hwx2", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-5005" + ], + "details": "The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5005" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bfb174d4-7658-4883-a682-d06bda89ec44" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7j57-9v54-xwjr/GHSA-7j57-9v54-xwjr.json b/advisories/unreviewed/2023/12/GHSA-7j57-9v54-xwjr/GHSA-7j57-9v54-xwjr.json index 0a879353997..0325efe652e 100644 --- a/advisories/unreviewed/2023/12/GHSA-7j57-9v54-xwjr/GHSA-7j57-9v54-xwjr.json +++ b/advisories/unreviewed/2023/12/GHSA-7j57-9v54-xwjr/GHSA-7j57-9v54-xwjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j57-9v54-xwjr", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-48925" ], "details": "SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:42Z" diff --git a/advisories/unreviewed/2023/12/GHSA-7w5c-q3c8-5c62/GHSA-7w5c-q3c8-5c62.json b/advisories/unreviewed/2023/12/GHSA-7w5c-q3c8-5c62/GHSA-7w5c-q3c8-5c62.json index 1e72348c3a5..e0f0c3b4d67 100644 --- a/advisories/unreviewed/2023/12/GHSA-7w5c-q3c8-5c62/GHSA-7w5c-q3c8-5c62.json +++ b/advisories/unreviewed/2023/12/GHSA-7w5c-q3c8-5c62/GHSA-7w5c-q3c8-5c62.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-7x7j-52gx-4h55/GHSA-7x7j-52gx-4h55.json b/advisories/unreviewed/2023/12/GHSA-7x7j-52gx-4h55/GHSA-7x7j-52gx-4h55.json new file mode 100644 index 00000000000..99012474c5e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7x7j-52gx-4h55/GHSA-7x7j-52gx-4h55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x7j-52gx-4h55", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-4311" + ], + "details": "The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4311" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/21950116-1a69-4848-9da0-e912096c0fce" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7xp2-7hw7-rv8q/GHSA-7xp2-7hw7-rv8q.json b/advisories/unreviewed/2023/12/GHSA-7xp2-7hw7-rv8q/GHSA-7xp2-7hw7-rv8q.json new file mode 100644 index 00000000000..f367b003684 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7xp2-7hw7-rv8q/GHSA-7xp2-7hw7-rv8q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xp2-7hw7-rv8q", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-5882" + ], + "details": "The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5882" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/72be4b5c-21be-46af-a3f4-08b4c190a7e2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8f5w-6f56-pffq/GHSA-8f5w-6f56-pffq.json b/advisories/unreviewed/2023/12/GHSA-8f5w-6f56-pffq/GHSA-8f5w-6f56-pffq.json index 42110a7fbc4..ff6706a355c 100644 --- a/advisories/unreviewed/2023/12/GHSA-8f5w-6f56-pffq/GHSA-8f5w-6f56-pffq.json +++ b/advisories/unreviewed/2023/12/GHSA-8f5w-6f56-pffq/GHSA-8f5w-6f56-pffq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f5w-6f56-pffq", - "modified": "2023-12-14T15:30:22Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T15:30:22Z", "aliases": [ "CVE-2023-50369" diff --git a/advisories/unreviewed/2023/12/GHSA-8r5w-j8rm-886w/GHSA-8r5w-j8rm-886w.json b/advisories/unreviewed/2023/12/GHSA-8r5w-j8rm-886w/GHSA-8r5w-j8rm-886w.json index 93a67488d28..c257ccb248e 100644 --- a/advisories/unreviewed/2023/12/GHSA-8r5w-j8rm-886w/GHSA-8r5w-j8rm-886w.json +++ b/advisories/unreviewed/2023/12/GHSA-8r5w-j8rm-886w/GHSA-8r5w-j8rm-886w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8r5w-j8rm-886w", - "modified": "2023-12-13T21:30:31Z", + "modified": "2023-12-18T21:30:22Z", "published": "2023-12-13T21:30:31Z", "aliases": [ "CVE-2023-6790" diff --git a/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json b/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json index 097d004542a..73f93b103a2 100644 --- a/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json +++ b/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xqf-3483-8954", - "modified": "2023-12-14T21:31:16Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T21:31:16Z", "aliases": [ "CVE-2023-4694" ], "details": "Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T19:15:16Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9277-mg3f-fmc2/GHSA-9277-mg3f-fmc2.json b/advisories/unreviewed/2023/12/GHSA-9277-mg3f-fmc2/GHSA-9277-mg3f-fmc2.json index 05b3e9b3df6..7fdb40180c0 100644 --- a/advisories/unreviewed/2023/12/GHSA-9277-mg3f-fmc2/GHSA-9277-mg3f-fmc2.json +++ b/advisories/unreviewed/2023/12/GHSA-9277-mg3f-fmc2/GHSA-9277-mg3f-fmc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9277-mg3f-fmc2", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-49828" diff --git a/advisories/unreviewed/2023/12/GHSA-9xr2-xchp-c4gr/GHSA-9xr2-xchp-c4gr.json b/advisories/unreviewed/2023/12/GHSA-9xr2-xchp-c4gr/GHSA-9xr2-xchp-c4gr.json index 6fe36fbbd60..03fc2fce9ab 100644 --- a/advisories/unreviewed/2023/12/GHSA-9xr2-xchp-c4gr/GHSA-9xr2-xchp-c4gr.json +++ b/advisories/unreviewed/2023/12/GHSA-9xr2-xchp-c4gr/GHSA-9xr2-xchp-c4gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xr2-xchp-c4gr", - "modified": "2023-12-15T12:30:30Z", + "modified": "2023-12-18T21:30:26Z", "published": "2023-12-15T12:30:30Z", "aliases": [ "CVE-2023-48538" diff --git a/advisories/unreviewed/2023/12/GHSA-c3w3-6pr9-c827/GHSA-c3w3-6pr9-c827.json b/advisories/unreviewed/2023/12/GHSA-c3w3-6pr9-c827/GHSA-c3w3-6pr9-c827.json index afd442be356..99fe41c0211 100644 --- a/advisories/unreviewed/2023/12/GHSA-c3w3-6pr9-c827/GHSA-c3w3-6pr9-c827.json +++ b/advisories/unreviewed/2023/12/GHSA-c3w3-6pr9-c827/GHSA-c3w3-6pr9-c827.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3w3-6pr9-c827", - "modified": "2023-12-15T12:30:29Z", + "modified": "2023-12-18T21:30:25Z", "published": "2023-12-15T12:30:29Z", "aliases": [ "CVE-2023-48504" diff --git a/advisories/unreviewed/2023/12/GHSA-c6px-7rm7-c5xr/GHSA-c6px-7rm7-c5xr.json b/advisories/unreviewed/2023/12/GHSA-c6px-7rm7-c5xr/GHSA-c6px-7rm7-c5xr.json index 86e19be1d44..7427acafc8a 100644 --- a/advisories/unreviewed/2023/12/GHSA-c6px-7rm7-c5xr/GHSA-c6px-7rm7-c5xr.json +++ b/advisories/unreviewed/2023/12/GHSA-c6px-7rm7-c5xr/GHSA-c6px-7rm7-c5xr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6px-7rm7-c5xr", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-49833" diff --git a/advisories/unreviewed/2023/12/GHSA-fv5r-xq86-g76x/GHSA-fv5r-xq86-g76x.json b/advisories/unreviewed/2023/12/GHSA-fv5r-xq86-g76x/GHSA-fv5r-xq86-g76x.json index cc6ad0a459f..fab5676a16e 100644 --- a/advisories/unreviewed/2023/12/GHSA-fv5r-xq86-g76x/GHSA-fv5r-xq86-g76x.json +++ b/advisories/unreviewed/2023/12/GHSA-fv5r-xq86-g76x/GHSA-fv5r-xq86-g76x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv5r-xq86-g76x", - "modified": "2023-12-14T18:30:20Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T18:30:20Z", "aliases": [ "CVE-2023-49171" diff --git a/advisories/unreviewed/2023/12/GHSA-g37f-r5c6-x58f/GHSA-g37f-r5c6-x58f.json b/advisories/unreviewed/2023/12/GHSA-g37f-r5c6-x58f/GHSA-g37f-r5c6-x58f.json index bfc90df84b3..4016394ff17 100644 --- a/advisories/unreviewed/2023/12/GHSA-g37f-r5c6-x58f/GHSA-g37f-r5c6-x58f.json +++ b/advisories/unreviewed/2023/12/GHSA-g37f-r5c6-x58f/GHSA-g37f-r5c6-x58f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g37f-r5c6-x58f", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-25643" diff --git a/advisories/unreviewed/2023/12/GHSA-g9xh-cc3h-8ghx/GHSA-g9xh-cc3h-8ghx.json b/advisories/unreviewed/2023/12/GHSA-g9xh-cc3h-8ghx/GHSA-g9xh-cc3h-8ghx.json new file mode 100644 index 00000000000..3eb70fd8e31 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-g9xh-cc3h-8ghx/GHSA-g9xh-cc3h-8ghx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9xh-cc3h-8ghx", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-6065" + ], + "details": "The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6065" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1w83xWsVLS_gCpQy4LDwbjNK9JaB87EEf/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/64f2557f-c5e4-4779-9e28-911dfaf2dda5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-ghxm-9fh8-8p5g/GHSA-ghxm-9fh8-8p5g.json b/advisories/unreviewed/2023/12/GHSA-ghxm-9fh8-8p5g/GHSA-ghxm-9fh8-8p5g.json index 239a86c4134..b3e4ec6e56e 100644 --- a/advisories/unreviewed/2023/12/GHSA-ghxm-9fh8-8p5g/GHSA-ghxm-9fh8-8p5g.json +++ b/advisories/unreviewed/2023/12/GHSA-ghxm-9fh8-8p5g/GHSA-ghxm-9fh8-8p5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ghxm-9fh8-8p5g", - "modified": "2023-12-12T03:31:45Z", + "modified": "2023-12-18T21:30:21Z", "published": "2023-12-12T03:31:45Z", "aliases": [ "CVE-2023-49581" @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-gj3x-fvqg-gcjm/GHSA-gj3x-fvqg-gcjm.json b/advisories/unreviewed/2023/12/GHSA-gj3x-fvqg-gcjm/GHSA-gj3x-fvqg-gcjm.json new file mode 100644 index 00000000000..88ed37aa412 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gj3x-fvqg-gcjm/GHSA-gj3x-fvqg-gcjm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj3x-fvqg-gcjm", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-4724" + ], + "details": "The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4724" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/48820f1d-45cb-4f1f-990d-d132bfc5536f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gwvq-pm88-g84j/GHSA-gwvq-pm88-g84j.json b/advisories/unreviewed/2023/12/GHSA-gwvq-pm88-g84j/GHSA-gwvq-pm88-g84j.json new file mode 100644 index 00000000000..a7dd299af78 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gwvq-pm88-g84j/GHSA-gwvq-pm88-g84j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwvq-pm88-g84j", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-6295" + ], + "details": "The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6295" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/adc9ed9f-55b4-43a9-a79d-c7120764f47c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-h738-v27m-f6mw/GHSA-h738-v27m-f6mw.json b/advisories/unreviewed/2023/12/GHSA-h738-v27m-f6mw/GHSA-h738-v27m-f6mw.json index d107281f45a..f5d4521b7b6 100644 --- a/advisories/unreviewed/2023/12/GHSA-h738-v27m-f6mw/GHSA-h738-v27m-f6mw.json +++ b/advisories/unreviewed/2023/12/GHSA-h738-v27m-f6mw/GHSA-h738-v27m-f6mw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h738-v27m-f6mw", - "modified": "2023-12-13T15:30:57Z", + "modified": "2023-12-18T21:30:21Z", "published": "2023-12-13T15:30:57Z", "aliases": [ "CVE-2023-34194" ], "details": "StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\\0' located after whitespace.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T14:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hc3j-xxm8-9r6j/GHSA-hc3j-xxm8-9r6j.json b/advisories/unreviewed/2023/12/GHSA-hc3j-xxm8-9r6j/GHSA-hc3j-xxm8-9r6j.json index 312fa8bc239..0cf11f08bbf 100644 --- a/advisories/unreviewed/2023/12/GHSA-hc3j-xxm8-9r6j/GHSA-hc3j-xxm8-9r6j.json +++ b/advisories/unreviewed/2023/12/GHSA-hc3j-xxm8-9r6j/GHSA-hc3j-xxm8-9r6j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hc3j-xxm8-9r6j", - "modified": "2023-12-14T15:30:22Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T15:30:22Z", "aliases": [ "CVE-2023-50371" diff --git a/advisories/unreviewed/2023/12/GHSA-j6vh-6qq8-qh37/GHSA-j6vh-6qq8-qh37.json b/advisories/unreviewed/2023/12/GHSA-j6vh-6qq8-qh37/GHSA-j6vh-6qq8-qh37.json index f6b20280b24..82ba700982e 100644 --- a/advisories/unreviewed/2023/12/GHSA-j6vh-6qq8-qh37/GHSA-j6vh-6qq8-qh37.json +++ b/advisories/unreviewed/2023/12/GHSA-j6vh-6qq8-qh37/GHSA-j6vh-6qq8-qh37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6vh-6qq8-qh37", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-49820" diff --git a/advisories/unreviewed/2023/12/GHSA-jgjj-g58w-4hp3/GHSA-jgjj-g58w-4hp3.json b/advisories/unreviewed/2023/12/GHSA-jgjj-g58w-4hp3/GHSA-jgjj-g58w-4hp3.json new file mode 100644 index 00000000000..5f923724d76 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-jgjj-g58w-4hp3/GHSA-jgjj-g58w-4hp3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgjj-g58w-4hp3", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-6222" + ], + "details": "IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6222" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1krgHH2NvVFr93VpErLkOjDV3L6M5yIA1/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/df892e99-c0f6-42b8-a834-fc55d1bde130" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jpmp-7hr8-c4xp/GHSA-jpmp-7hr8-c4xp.json b/advisories/unreviewed/2023/12/GHSA-jpmp-7hr8-c4xp/GHSA-jpmp-7hr8-c4xp.json index 50d39754695..5ebe8f9292e 100644 --- a/advisories/unreviewed/2023/12/GHSA-jpmp-7hr8-c4xp/GHSA-jpmp-7hr8-c4xp.json +++ b/advisories/unreviewed/2023/12/GHSA-jpmp-7hr8-c4xp/GHSA-jpmp-7hr8-c4xp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-jpwp-h56f-5v3g/GHSA-jpwp-h56f-5v3g.json b/advisories/unreviewed/2023/12/GHSA-jpwp-h56f-5v3g/GHSA-jpwp-h56f-5v3g.json index eb4421faf15..c1888a67350 100644 --- a/advisories/unreviewed/2023/12/GHSA-jpwp-h56f-5v3g/GHSA-jpwp-h56f-5v3g.json +++ b/advisories/unreviewed/2023/12/GHSA-jpwp-h56f-5v3g/GHSA-jpwp-h56f-5v3g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-88" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-jxxf-4j56-j82w/GHSA-jxxf-4j56-j82w.json b/advisories/unreviewed/2023/12/GHSA-jxxf-4j56-j82w/GHSA-jxxf-4j56-j82w.json index 0480048e3d8..7b407d88083 100644 --- a/advisories/unreviewed/2023/12/GHSA-jxxf-4j56-j82w/GHSA-jxxf-4j56-j82w.json +++ b/advisories/unreviewed/2023/12/GHSA-jxxf-4j56-j82w/GHSA-jxxf-4j56-j82w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxxf-4j56-j82w", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-46348" ], "details": "SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:42Z" diff --git a/advisories/unreviewed/2023/12/GHSA-m4mq-h54p-47ph/GHSA-m4mq-h54p-47ph.json b/advisories/unreviewed/2023/12/GHSA-m4mq-h54p-47ph/GHSA-m4mq-h54p-47ph.json index 030365306af..3859b5bbde3 100644 --- a/advisories/unreviewed/2023/12/GHSA-m4mq-h54p-47ph/GHSA-m4mq-h54p-47ph.json +++ b/advisories/unreviewed/2023/12/GHSA-m4mq-h54p-47ph/GHSA-m4mq-h54p-47ph.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-426" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json b/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json new file mode 100644 index 00000000000..41b8da5fc1c --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6gh-58ph-rm3q", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-6272" + ], + "details": "The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6272" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a03243ea-fee7-46e4-8037-a228afc5297a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-mj7q-43fj-hgf5/GHSA-mj7q-43fj-hgf5.json b/advisories/unreviewed/2023/12/GHSA-mj7q-43fj-hgf5/GHSA-mj7q-43fj-hgf5.json index 6c1ed598d7c..a0048569546 100644 --- a/advisories/unreviewed/2023/12/GHSA-mj7q-43fj-hgf5/GHSA-mj7q-43fj-hgf5.json +++ b/advisories/unreviewed/2023/12/GHSA-mj7q-43fj-hgf5/GHSA-mj7q-43fj-hgf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mj7q-43fj-hgf5", - "modified": "2023-12-15T12:30:29Z", + "modified": "2023-12-18T21:30:26Z", "published": "2023-12-15T12:30:29Z", "aliases": [ "CVE-2023-48527" diff --git a/advisories/unreviewed/2023/12/GHSA-phw8-53h6-pq4g/GHSA-phw8-53h6-pq4g.json b/advisories/unreviewed/2023/12/GHSA-phw8-53h6-pq4g/GHSA-phw8-53h6-pq4g.json index d4a9caae3bf..eb0eb6406c1 100644 --- a/advisories/unreviewed/2023/12/GHSA-phw8-53h6-pq4g/GHSA-phw8-53h6-pq4g.json +++ b/advisories/unreviewed/2023/12/GHSA-phw8-53h6-pq4g/GHSA-phw8-53h6-pq4g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phw8-53h6-pq4g", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-50564" ], "details": "An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T15:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-pr5v-xq9x-gp8m/GHSA-pr5v-xq9x-gp8m.json b/advisories/unreviewed/2023/12/GHSA-pr5v-xq9x-gp8m/GHSA-pr5v-xq9x-gp8m.json new file mode 100644 index 00000000000..475a22b3ac8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-pr5v-xq9x-gp8m/GHSA-pr5v-xq9x-gp8m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr5v-xq9x-gp8m", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-6289" + ], + "details": "The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6289" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8c83dd57-9291-4dfc-846d-5ad47534e2ad" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q3f5-cm95-p5vp/GHSA-q3f5-cm95-p5vp.json b/advisories/unreviewed/2023/12/GHSA-q3f5-cm95-p5vp/GHSA-q3f5-cm95-p5vp.json index 968b85bc1e3..6e3acffcd02 100644 --- a/advisories/unreviewed/2023/12/GHSA-q3f5-cm95-p5vp/GHSA-q3f5-cm95-p5vp.json +++ b/advisories/unreviewed/2023/12/GHSA-q3f5-cm95-p5vp/GHSA-q3f5-cm95-p5vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3f5-cm95-p5vp", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-25642" diff --git a/advisories/unreviewed/2023/12/GHSA-q62r-62c5-h547/GHSA-q62r-62c5-h547.json b/advisories/unreviewed/2023/12/GHSA-q62r-62c5-h547/GHSA-q62r-62c5-h547.json index d504ce5856b..075d8cc17cc 100644 --- a/advisories/unreviewed/2023/12/GHSA-q62r-62c5-h547/GHSA-q62r-62c5-h547.json +++ b/advisories/unreviewed/2023/12/GHSA-q62r-62c5-h547/GHSA-q62r-62c5-h547.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q62r-62c5-h547", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-49827" diff --git a/advisories/unreviewed/2023/12/GHSA-q94h-2h95-cmhh/GHSA-q94h-2h95-cmhh.json b/advisories/unreviewed/2023/12/GHSA-q94h-2h95-cmhh/GHSA-q94h-2h95-cmhh.json index 31ed122a67c..4735b613548 100644 --- a/advisories/unreviewed/2023/12/GHSA-q94h-2h95-cmhh/GHSA-q94h-2h95-cmhh.json +++ b/advisories/unreviewed/2023/12/GHSA-q94h-2h95-cmhh/GHSA-q94h-2h95-cmhh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-qgv4-xfrj-hvp7/GHSA-qgv4-xfrj-hvp7.json b/advisories/unreviewed/2023/12/GHSA-qgv4-xfrj-hvp7/GHSA-qgv4-xfrj-hvp7.json new file mode 100644 index 00000000000..ec0085fc309 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-qgv4-xfrj-hvp7/GHSA-qgv4-xfrj-hvp7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgv4-xfrj-hvp7", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-5886" + ], + "details": "The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5886" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0a08e49d-d34e-4140-a15d-ad64444665a3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-r24w-m5xx-v22x/GHSA-r24w-m5xx-v22x.json b/advisories/unreviewed/2023/12/GHSA-r24w-m5xx-v22x/GHSA-r24w-m5xx-v22x.json index 2dc983fbd4f..a6375c2bce6 100644 --- a/advisories/unreviewed/2023/12/GHSA-r24w-m5xx-v22x/GHSA-r24w-m5xx-v22x.json +++ b/advisories/unreviewed/2023/12/GHSA-r24w-m5xx-v22x/GHSA-r24w-m5xx-v22x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r24w-m5xx-v22x", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-50565" ], "details": "A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T15:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r5pw-wrg5-wrfp/GHSA-r5pw-wrg5-wrfp.json b/advisories/unreviewed/2023/12/GHSA-r5pw-wrg5-wrfp/GHSA-r5pw-wrg5-wrfp.json index 0f27bb018bd..3ed684cdf84 100644 --- a/advisories/unreviewed/2023/12/GHSA-r5pw-wrg5-wrfp/GHSA-r5pw-wrg5-wrfp.json +++ b/advisories/unreviewed/2023/12/GHSA-r5pw-wrg5-wrfp/GHSA-r5pw-wrg5-wrfp.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-502" + "CWE-502", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rv9h-r568-vpqg/GHSA-rv9h-r568-vpqg.json b/advisories/unreviewed/2023/12/GHSA-rv9h-r568-vpqg/GHSA-rv9h-r568-vpqg.json index 88bfc75ac8d..6bffe9ac118 100644 --- a/advisories/unreviewed/2023/12/GHSA-rv9h-r568-vpqg/GHSA-rv9h-r568-vpqg.json +++ b/advisories/unreviewed/2023/12/GHSA-rv9h-r568-vpqg/GHSA-rv9h-r568-vpqg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv9h-r568-vpqg", - "modified": "2023-12-15T12:30:30Z", + "modified": "2023-12-18T21:30:26Z", "published": "2023-12-15T12:30:30Z", "aliases": [ "CVE-2023-48552" diff --git a/advisories/unreviewed/2023/12/GHSA-v2vm-8pr4-wgpw/GHSA-v2vm-8pr4-wgpw.json b/advisories/unreviewed/2023/12/GHSA-v2vm-8pr4-wgpw/GHSA-v2vm-8pr4-wgpw.json new file mode 100644 index 00000000000..a99bb22325b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v2vm-8pr4-wgpw/GHSA-v2vm-8pr4-wgpw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2vm-8pr4-wgpw", + "modified": "2023-12-18T21:30:28Z", + "published": "2023-12-18T21:30:28Z", + "aliases": [ + "CVE-2023-40691" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40691" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/264805" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7096365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-v6cw-g4v9-gjmf/GHSA-v6cw-g4v9-gjmf.json b/advisories/unreviewed/2023/12/GHSA-v6cw-g4v9-gjmf/GHSA-v6cw-g4v9-gjmf.json new file mode 100644 index 00000000000..e2026fb462f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v6cw-g4v9-gjmf/GHSA-v6cw-g4v9-gjmf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6cw-g4v9-gjmf", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-5348" + ], + "details": "The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5348" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b37b09c1-1b53-471c-9b10-7d2d05ae11f1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vcw3-69r6-3w2m/GHSA-vcw3-69r6-3w2m.json b/advisories/unreviewed/2023/12/GHSA-vcw3-69r6-3w2m/GHSA-vcw3-69r6-3w2m.json index 5f12b6e8191..d5692d9c8af 100644 --- a/advisories/unreviewed/2023/12/GHSA-vcw3-69r6-3w2m/GHSA-vcw3-69r6-3w2m.json +++ b/advisories/unreviewed/2023/12/GHSA-vcw3-69r6-3w2m/GHSA-vcw3-69r6-3w2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcw3-69r6-3w2m", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-18T21:30:23Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40627" ], "details": "A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vjmq-6c5p-f7rq/GHSA-vjmq-6c5p-f7rq.json b/advisories/unreviewed/2023/12/GHSA-vjmq-6c5p-f7rq/GHSA-vjmq-6c5p-f7rq.json index 174d0eeaeca..002608f115b 100644 --- a/advisories/unreviewed/2023/12/GHSA-vjmq-6c5p-f7rq/GHSA-vjmq-6c5p-f7rq.json +++ b/advisories/unreviewed/2023/12/GHSA-vjmq-6c5p-f7rq/GHSA-vjmq-6c5p-f7rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjmq-6c5p-f7rq", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-50563" ], "details": "Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T15:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vw2g-7q92-r8q5/GHSA-vw2g-7q92-r8q5.json b/advisories/unreviewed/2023/12/GHSA-vw2g-7q92-r8q5/GHSA-vw2g-7q92-r8q5.json index e9a593a7cb7..9d24e93d15a 100644 --- a/advisories/unreviewed/2023/12/GHSA-vw2g-7q92-r8q5/GHSA-vw2g-7q92-r8q5.json +++ b/advisories/unreviewed/2023/12/GHSA-vw2g-7q92-r8q5/GHSA-vw2g-7q92-r8q5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vw2g-7q92-r8q5", - "modified": "2023-12-14T15:30:23Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-50073" ], "details": "EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T15:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-wfp5-m787-m69h/GHSA-wfp5-m787-m69h.json b/advisories/unreviewed/2023/12/GHSA-wfp5-m787-m69h/GHSA-wfp5-m787-m69h.json index aa2a7a524ac..5759aa8e993 100644 --- a/advisories/unreviewed/2023/12/GHSA-wfp5-m787-m69h/GHSA-wfp5-m787-m69h.json +++ b/advisories/unreviewed/2023/12/GHSA-wfp5-m787-m69h/GHSA-wfp5-m787-m69h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfp5-m787-m69h", - "modified": "2023-12-15T12:30:29Z", + "modified": "2023-12-18T21:30:25Z", "published": "2023-12-15T12:30:29Z", "aliases": [ "CVE-2023-48512" diff --git a/advisories/unreviewed/2023/12/GHSA-x2v5-rr6p-h9j3/GHSA-x2v5-rr6p-h9j3.json b/advisories/unreviewed/2023/12/GHSA-x2v5-rr6p-h9j3/GHSA-x2v5-rr6p-h9j3.json index 62d00b16ac7..32abf3d2c5f 100644 --- a/advisories/unreviewed/2023/12/GHSA-x2v5-rr6p-h9j3/GHSA-x2v5-rr6p-h9j3.json +++ b/advisories/unreviewed/2023/12/GHSA-x2v5-rr6p-h9j3/GHSA-x2v5-rr6p-h9j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2v5-rr6p-h9j3", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-18T21:30:24Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-49841" diff --git a/advisories/unreviewed/2023/12/GHSA-x98r-x2vh-j7fm/GHSA-x98r-x2vh-j7fm.json b/advisories/unreviewed/2023/12/GHSA-x98r-x2vh-j7fm/GHSA-x98r-x2vh-j7fm.json new file mode 100644 index 00000000000..aefda8acd1e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-x98r-x2vh-j7fm/GHSA-x98r-x2vh-j7fm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x98r-x2vh-j7fm", + "modified": "2023-12-18T21:30:27Z", + "published": "2023-12-18T21:30:27Z", + "aliases": [ + "CVE-2023-5949" + ], + "details": "The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5949" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3cec27ca-f470-402d-ae3e-271cb59cf407" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T20:15:08Z" + } +} \ No newline at end of file