From 8ded7442148aa2d3fdbab78fa9afad5189e95cb9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 5 Jan 2024 00:31:45 +0000 Subject: [PATCH] Publish Advisories GHSA-wc8x-f5rv-3653 GHSA-2j82-v6wc-3928 GHSA-3f5j-mfg2-hxvj GHSA-3q89-rj9x-cm52 GHSA-3x3h-vg3c-vcrx GHSA-5whq-6jp7-w2mg GHSA-88m5-rfvg-rhq2 GHSA-93vw-2xp9-jc53 GHSA-9jrv-g44v-qxwj GHSA-ccvr-j87g-x67g GHSA-f9c3-v8hj-gm62 GHSA-fqg5-7rjv-45wh GHSA-ghvq-25qv-wp2m GHSA-hrfw-pwjg-7prc GHSA-j37f-j5pq-r37j GHSA-jj5v-fhp7-pww8 GHSA-r2x8-rf8m-w2r2 GHSA-r43r-rvvf-rrh9 GHSA-xch8-frxx-v8q6 GHSA-xqmc-g86x-qfxp --- .../03/GHSA-wc8x-f5rv-3653/GHSA-wc8x-f5rv-3653.json | 4 ++++ .../12/GHSA-2j82-v6wc-3928/GHSA-2j82-v6wc-3928.json | 2 +- .../12/GHSA-3f5j-mfg2-hxvj/GHSA-3f5j-mfg2-hxvj.json | 2 +- .../12/GHSA-3q89-rj9x-cm52/GHSA-3q89-rj9x-cm52.json | 11 +++++++---- .../12/GHSA-3x3h-vg3c-vcrx/GHSA-3x3h-vg3c-vcrx.json | 2 +- .../12/GHSA-5whq-6jp7-w2mg/GHSA-5whq-6jp7-w2mg.json | 11 +++++++---- .../12/GHSA-88m5-rfvg-rhq2/GHSA-88m5-rfvg-rhq2.json | 2 +- .../12/GHSA-93vw-2xp9-jc53/GHSA-93vw-2xp9-jc53.json | 2 +- .../12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json | 2 +- .../12/GHSA-ccvr-j87g-x67g/GHSA-ccvr-j87g-x67g.json | 2 +- .../12/GHSA-f9c3-v8hj-gm62/GHSA-f9c3-v8hj-gm62.json | 2 +- .../12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json | 2 +- .../12/GHSA-ghvq-25qv-wp2m/GHSA-ghvq-25qv-wp2m.json | 11 +++++++---- .../12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json | 11 +++++++---- .../12/GHSA-j37f-j5pq-r37j/GHSA-j37f-j5pq-r37j.json | 11 +++++++---- .../12/GHSA-jj5v-fhp7-pww8/GHSA-jj5v-fhp7-pww8.json | 2 +- .../12/GHSA-r2x8-rf8m-w2r2/GHSA-r2x8-rf8m-w2r2.json | 11 +++++++---- .../12/GHSA-r43r-rvvf-rrh9/GHSA-r43r-rvvf-rrh9.json | 11 +++++++---- .../12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json | 11 +++++++---- .../12/GHSA-xqmc-g86x-qfxp/GHSA-xqmc-g86x-qfxp.json | 2 +- 20 files changed, 71 insertions(+), 43 deletions(-) diff --git a/advisories/unreviewed/2022/03/GHSA-wc8x-f5rv-3653/GHSA-wc8x-f5rv-3653.json b/advisories/unreviewed/2022/03/GHSA-wc8x-f5rv-3653/GHSA-wc8x-f5rv-3653.json index 3c221c68520..fa09f49fc2d 100644 --- a/advisories/unreviewed/2022/03/GHSA-wc8x-f5rv-3653/GHSA-wc8x-f5rv-3653.json +++ b/advisories/unreviewed/2022/03/GHSA-wc8x-f5rv-3653/GHSA-wc8x-f5rv-3653.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22995" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00000.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/" diff --git a/advisories/unreviewed/2023/12/GHSA-2j82-v6wc-3928/GHSA-2j82-v6wc-3928.json b/advisories/unreviewed/2023/12/GHSA-2j82-v6wc-3928/GHSA-2j82-v6wc-3928.json index e4a801ec33d..df224a1da35 100644 --- a/advisories/unreviewed/2023/12/GHSA-2j82-v6wc-3928/GHSA-2j82-v6wc-3928.json +++ b/advisories/unreviewed/2023/12/GHSA-2j82-v6wc-3928/GHSA-2j82-v6wc-3928.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-3f5j-mfg2-hxvj/GHSA-3f5j-mfg2-hxvj.json b/advisories/unreviewed/2023/12/GHSA-3f5j-mfg2-hxvj/GHSA-3f5j-mfg2-hxvj.json index b83a608cc3f..33ea7e4de97 100644 --- a/advisories/unreviewed/2023/12/GHSA-3f5j-mfg2-hxvj/GHSA-3f5j-mfg2-hxvj.json +++ b/advisories/unreviewed/2023/12/GHSA-3f5j-mfg2-hxvj/GHSA-3f5j-mfg2-hxvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f5j-mfg2-hxvj", - "modified": "2023-12-28T21:30:39Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:39Z", "aliases": [ "CVE-2023-50839" diff --git a/advisories/unreviewed/2023/12/GHSA-3q89-rj9x-cm52/GHSA-3q89-rj9x-cm52.json b/advisories/unreviewed/2023/12/GHSA-3q89-rj9x-cm52/GHSA-3q89-rj9x-cm52.json index 0f389ccd374..238be301565 100644 --- a/advisories/unreviewed/2023/12/GHSA-3q89-rj9x-cm52/GHSA-3q89-rj9x-cm52.json +++ b/advisories/unreviewed/2023/12/GHSA-3q89-rj9x-cm52/GHSA-3q89-rj9x-cm52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q89-rj9x-cm52", - "modified": "2023-12-28T06:30:23Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T06:30:23Z", "aliases": [ "CVE-2023-49229" ], "details": "An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T04:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-3x3h-vg3c-vcrx/GHSA-3x3h-vg3c-vcrx.json b/advisories/unreviewed/2023/12/GHSA-3x3h-vg3c-vcrx/GHSA-3x3h-vg3c-vcrx.json index 52e174b4852..1f6813f0d14 100644 --- a/advisories/unreviewed/2023/12/GHSA-3x3h-vg3c-vcrx/GHSA-3x3h-vg3c-vcrx.json +++ b/advisories/unreviewed/2023/12/GHSA-3x3h-vg3c-vcrx/GHSA-3x3h-vg3c-vcrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x3h-vg3c-vcrx", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:38Z", "aliases": [ "CVE-2023-50841" diff --git a/advisories/unreviewed/2023/12/GHSA-5whq-6jp7-w2mg/GHSA-5whq-6jp7-w2mg.json b/advisories/unreviewed/2023/12/GHSA-5whq-6jp7-w2mg/GHSA-5whq-6jp7-w2mg.json index bff27f8dff9..8a82562c1fe 100644 --- a/advisories/unreviewed/2023/12/GHSA-5whq-6jp7-w2mg/GHSA-5whq-6jp7-w2mg.json +++ b/advisories/unreviewed/2023/12/GHSA-5whq-6jp7-w2mg/GHSA-5whq-6jp7-w2mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5whq-6jp7-w2mg", - "modified": "2023-12-29T03:30:29Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T03:30:29Z", "aliases": [ "CVE-2023-31298" ], "details": "Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T02:15:45Z" diff --git a/advisories/unreviewed/2023/12/GHSA-88m5-rfvg-rhq2/GHSA-88m5-rfvg-rhq2.json b/advisories/unreviewed/2023/12/GHSA-88m5-rfvg-rhq2/GHSA-88m5-rfvg-rhq2.json index 2bc6ce34dc2..c7c68fe6ace 100644 --- a/advisories/unreviewed/2023/12/GHSA-88m5-rfvg-rhq2/GHSA-88m5-rfvg-rhq2.json +++ b/advisories/unreviewed/2023/12/GHSA-88m5-rfvg-rhq2/GHSA-88m5-rfvg-rhq2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-93vw-2xp9-jc53/GHSA-93vw-2xp9-jc53.json b/advisories/unreviewed/2023/12/GHSA-93vw-2xp9-jc53/GHSA-93vw-2xp9-jc53.json index e143626a64d..8814cc32523 100644 --- a/advisories/unreviewed/2023/12/GHSA-93vw-2xp9-jc53/GHSA-93vw-2xp9-jc53.json +++ b/advisories/unreviewed/2023/12/GHSA-93vw-2xp9-jc53/GHSA-93vw-2xp9-jc53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93vw-2xp9-jc53", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:38Z", "aliases": [ "CVE-2023-50838" diff --git a/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json b/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json index bd1ae269ed8..4c626ed2ac4 100644 --- a/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json +++ b/advisories/unreviewed/2023/12/GHSA-9jrv-g44v-qxwj/GHSA-9jrv-g44v-qxwj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-ccvr-j87g-x67g/GHSA-ccvr-j87g-x67g.json b/advisories/unreviewed/2023/12/GHSA-ccvr-j87g-x67g/GHSA-ccvr-j87g-x67g.json index b3c3a0d0ba8..d2b0debbcb2 100644 --- a/advisories/unreviewed/2023/12/GHSA-ccvr-j87g-x67g/GHSA-ccvr-j87g-x67g.json +++ b/advisories/unreviewed/2023/12/GHSA-ccvr-j87g-x67g/GHSA-ccvr-j87g-x67g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccvr-j87g-x67g", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:38Z", "aliases": [ "CVE-2023-50846" diff --git a/advisories/unreviewed/2023/12/GHSA-f9c3-v8hj-gm62/GHSA-f9c3-v8hj-gm62.json b/advisories/unreviewed/2023/12/GHSA-f9c3-v8hj-gm62/GHSA-f9c3-v8hj-gm62.json index 5fbf54d0d93..5b5ac6f640d 100644 --- a/advisories/unreviewed/2023/12/GHSA-f9c3-v8hj-gm62/GHSA-f9c3-v8hj-gm62.json +++ b/advisories/unreviewed/2023/12/GHSA-f9c3-v8hj-gm62/GHSA-f9c3-v8hj-gm62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9c3-v8hj-gm62", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:38Z", "aliases": [ "CVE-2023-50845" diff --git a/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json b/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json index bdd6fe1f805..ed2b9b575fc 100644 --- a/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json +++ b/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-ghvq-25qv-wp2m/GHSA-ghvq-25qv-wp2m.json b/advisories/unreviewed/2023/12/GHSA-ghvq-25qv-wp2m/GHSA-ghvq-25qv-wp2m.json index ee54c113f89..45e752ff57b 100644 --- a/advisories/unreviewed/2023/12/GHSA-ghvq-25qv-wp2m/GHSA-ghvq-25qv-wp2m.json +++ b/advisories/unreviewed/2023/12/GHSA-ghvq-25qv-wp2m/GHSA-ghvq-25qv-wp2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghvq-25qv-wp2m", - "modified": "2023-12-29T06:30:30Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T06:30:30Z", "aliases": [ "CVE-2023-52173" ], "details": "XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T04:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json b/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json index c583331bb8e..eec323091dd 100644 --- a/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json +++ b/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrfw-pwjg-7prc", - "modified": "2023-12-29T06:30:29Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T06:30:29Z", "aliases": [ "CVE-2023-31296" ], "details": "CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T04:15:09Z" diff --git a/advisories/unreviewed/2023/12/GHSA-j37f-j5pq-r37j/GHSA-j37f-j5pq-r37j.json b/advisories/unreviewed/2023/12/GHSA-j37f-j5pq-r37j/GHSA-j37f-j5pq-r37j.json index 079aa85d8f9..3d6c9e3a96b 100644 --- a/advisories/unreviewed/2023/12/GHSA-j37f-j5pq-r37j/GHSA-j37f-j5pq-r37j.json +++ b/advisories/unreviewed/2023/12/GHSA-j37f-j5pq-r37j/GHSA-j37f-j5pq-r37j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j37f-j5pq-r37j", - "modified": "2023-12-29T00:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-29T00:30:38Z", "aliases": [ "CVE-2023-50104" ], "details": "ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T00:15:50Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jj5v-fhp7-pww8/GHSA-jj5v-fhp7-pww8.json b/advisories/unreviewed/2023/12/GHSA-jj5v-fhp7-pww8/GHSA-jj5v-fhp7-pww8.json index bd7477939d1..a913634b620 100644 --- a/advisories/unreviewed/2023/12/GHSA-jj5v-fhp7-pww8/GHSA-jj5v-fhp7-pww8.json +++ b/advisories/unreviewed/2023/12/GHSA-jj5v-fhp7-pww8/GHSA-jj5v-fhp7-pww8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj5v-fhp7-pww8", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-05T00:30:27Z", "published": "2023-12-28T21:30:38Z", "aliases": [ "CVE-2023-50844" diff --git a/advisories/unreviewed/2023/12/GHSA-r2x8-rf8m-w2r2/GHSA-r2x8-rf8m-w2r2.json b/advisories/unreviewed/2023/12/GHSA-r2x8-rf8m-w2r2/GHSA-r2x8-rf8m-w2r2.json index 04ed8f55923..056593f431e 100644 --- a/advisories/unreviewed/2023/12/GHSA-r2x8-rf8m-w2r2/GHSA-r2x8-rf8m-w2r2.json +++ b/advisories/unreviewed/2023/12/GHSA-r2x8-rf8m-w2r2/GHSA-r2x8-rf8m-w2r2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2x8-rf8m-w2r2", - "modified": "2023-12-29T03:30:29Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T03:30:29Z", "aliases": [ "CVE-2023-31301" ], "details": "Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T02:15:45Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r43r-rvvf-rrh9/GHSA-r43r-rvvf-rrh9.json b/advisories/unreviewed/2023/12/GHSA-r43r-rvvf-rrh9/GHSA-r43r-rvvf-rrh9.json index 0fbb24f929b..5ce4e7dedd9 100644 --- a/advisories/unreviewed/2023/12/GHSA-r43r-rvvf-rrh9/GHSA-r43r-rvvf-rrh9.json +++ b/advisories/unreviewed/2023/12/GHSA-r43r-rvvf-rrh9/GHSA-r43r-rvvf-rrh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r43r-rvvf-rrh9", - "modified": "2023-12-29T06:30:30Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T06:30:30Z", "aliases": [ "CVE-2023-52174" ], "details": "XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T04:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json b/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json index 2c5e0d48445..97241eb0a92 100644 --- a/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json +++ b/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xch8-frxx-v8q6", - "modified": "2023-12-29T03:30:29Z", + "modified": "2024-01-05T00:30:28Z", "published": "2023-12-29T03:30:29Z", "aliases": [ "CVE-2023-31292" ], "details": "An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via \"Back Button Refresh\" attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-29T02:15:44Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xqmc-g86x-qfxp/GHSA-xqmc-g86x-qfxp.json b/advisories/unreviewed/2023/12/GHSA-xqmc-g86x-qfxp/GHSA-xqmc-g86x-qfxp.json index d96ea70cd1f..fef40ab581e 100644 --- a/advisories/unreviewed/2023/12/GHSA-xqmc-g86x-qfxp/GHSA-xqmc-g86x-qfxp.json +++ b/advisories/unreviewed/2023/12/GHSA-xqmc-g86x-qfxp/GHSA-xqmc-g86x-qfxp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false,