Publish Advisories

GHSA-wc8x-f5rv-3653
GHSA-2j82-v6wc-3928
GHSA-3f5j-mfg2-hxvj
GHSA-3q89-rj9x-cm52
GHSA-3x3h-vg3c-vcrx
GHSA-5whq-6jp7-w2mg
GHSA-88m5-rfvg-rhq2
GHSA-93vw-2xp9-jc53
GHSA-9jrv-g44v-qxwj
GHSA-ccvr-j87g-x67g
GHSA-f9c3-v8hj-gm62
GHSA-fqg5-7rjv-45wh
GHSA-ghvq-25qv-wp2m
GHSA-hrfw-pwjg-7prc
GHSA-j37f-j5pq-r37j
GHSA-jj5v-fhp7-pww8
GHSA-r2x8-rf8m-w2r2
GHSA-r43r-rvvf-rrh9
GHSA-xch8-frxx-v8q6
GHSA-xqmc-g86x-qfxp
This commit is contained in:
advisory-database[bot]
2024-01-05 00:31:45 +00:00
parent a9514cc6b4
commit 8ded744214
20 changed files with 71 additions and 43 deletions
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22995"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f5j-mfg2-hxvj",
"modified": "2023-12-28T21:30:39Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:39Z",
"aliases": [
"CVE-2023-50839"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q89-rj9x-cm52",
"modified": "2023-12-28T06:30:23Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T06:30:23Z",
"aliases": [
"CVE-2023-49229"
],
"details": "An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-28T04:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x3h-vg3c-vcrx",
"modified": "2023-12-28T21:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:38Z",
"aliases": [
"CVE-2023-50841"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5whq-6jp7-w2mg",
"modified": "2023-12-29T03:30:29Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T03:30:29Z",
"aliases": [
"CVE-2023-31298"
],
"details": "Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T02:15:45Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-843"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93vw-2xp9-jc53",
"modified": "2023-12-28T21:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:38Z",
"aliases": [
"CVE-2023-50838"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccvr-j87g-x67g",
"modified": "2023-12-28T21:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:38Z",
"aliases": [
"CVE-2023-50846"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f9c3-v8hj-gm62",
"modified": "2023-12-28T21:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:38Z",
"aliases": [
"CVE-2023-50845"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-843"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghvq-25qv-wp2m",
"modified": "2023-12-29T06:30:30Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T06:30:30Z",
"aliases": [
"CVE-2023-52173"
],
"details": "XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T04:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrfw-pwjg-7prc",
"modified": "2023-12-29T06:30:29Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T06:30:29Z",
"aliases": [
"CVE-2023-31296"
],
"details": "CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1236"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T04:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j37f-j5pq-r37j",
"modified": "2023-12-29T00:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-29T00:30:38Z",
"aliases": [
"CVE-2023-50104"
],
"details": "ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T00:15:50Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj5v-fhp7-pww8",
"modified": "2023-12-28T21:30:38Z",
"modified": "2024-01-05T00:30:27Z",
"published": "2023-12-28T21:30:38Z",
"aliases": [
"CVE-2023-50844"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2x8-rf8m-w2r2",
"modified": "2023-12-29T03:30:29Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T03:30:29Z",
"aliases": [
"CVE-2023-31301"
],
"details": "Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T02:15:45Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r43r-rvvf-rrh9",
"modified": "2023-12-29T06:30:30Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T06:30:30Z",
"aliases": [
"CVE-2023-52174"
],
"details": "XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T04:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xch8-frxx-v8q6",
"modified": "2023-12-29T03:30:29Z",
"modified": "2024-01-05T00:30:28Z",
"published": "2023-12-29T03:30:29Z",
"aliases": [
"CVE-2023-31292"
],
"details": "An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via \"Back Button Refresh\" attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-29T02:15:44Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,