diff --git a/advisories/unreviewed/2023/06/GHSA-83p3-xf8j-2pxj/GHSA-83p3-xf8j-2pxj.json b/advisories/unreviewed/2023/06/GHSA-83p3-xf8j-2pxj/GHSA-83p3-xf8j-2pxj.json index 79639b249a3..ae73482c0d6 100644 --- a/advisories/unreviewed/2023/06/GHSA-83p3-xf8j-2pxj/GHSA-83p3-xf8j-2pxj.json +++ b/advisories/unreviewed/2023/06/GHSA-83p3-xf8j-2pxj/GHSA-83p3-xf8j-2pxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83p3-xf8j-2pxj", - "modified": "2023-06-26T21:30:59Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-26T21:30:59Z", "aliases": [ "CVE-2020-23066" ], "details": "Cross Site Scripting vulnerability in TinyMCE v.4.9.6 and before and v.5.0.0 thru v.5.1.4 allows an attacker to execute arbitrary code via the editor function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json b/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json index 716e69f8914..9e773f13115 100644 --- a/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json +++ b/advisories/unreviewed/2023/06/GHSA-8x9p-cw2c-6253/GHSA-8x9p-cw2c-6253.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x9p-cw2c-6253", - "modified": "2023-06-20T12:30:16Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-20T12:30:16Z", "aliases": [ "CVE-2023-1999" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-415", "CWE-416" ], "severity": null, diff --git a/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json b/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json index eb07905181e..12acc10e911 100644 --- a/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json +++ b/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9j35-h8v6-5943", - "modified": "2023-06-27T18:30:34Z", + "modified": "2023-07-05T15:30:24Z", "published": "2023-06-27T18:30:34Z", "aliases": [ "CVE-2023-35800" ], "details": "Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-gf4x-x9q7-jgg2/GHSA-gf4x-x9q7-jgg2.json b/advisories/unreviewed/2023/06/GHSA-gf4x-x9q7-jgg2/GHSA-gf4x-x9q7-jgg2.json index 970ee93fe46..7802c0dcc82 100644 --- a/advisories/unreviewed/2023/06/GHSA-gf4x-x9q7-jgg2/GHSA-gf4x-x9q7-jgg2.json +++ b/advisories/unreviewed/2023/06/GHSA-gf4x-x9q7-jgg2/GHSA-gf4x-x9q7-jgg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf4x-x9q7-jgg2", - "modified": "2023-06-23T21:30:30Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-23T21:30:30Z", "aliases": [ "CVE-2023-25003" ], "details": "A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-gh99-wp5q-6r8p/GHSA-gh99-wp5q-6r8p.json b/advisories/unreviewed/2023/06/GHSA-gh99-wp5q-6r8p/GHSA-gh99-wp5q-6r8p.json index b6a50f5bc4e..03db0d1daa2 100644 --- a/advisories/unreviewed/2023/06/GHSA-gh99-wp5q-6r8p/GHSA-gh99-wp5q-6r8p.json +++ b/advisories/unreviewed/2023/06/GHSA-gh99-wp5q-6r8p/GHSA-gh99-wp5q-6r8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gh99-wp5q-6r8p", - "modified": "2023-06-26T21:30:59Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-26T21:30:59Z", "aliases": [ "CVE-2023-27082" ], "details": "Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json b/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json index 0ddca5903c1..577e73dc1ac 100644 --- a/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json +++ b/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppp2-fxjc-67f9", - "modified": "2023-06-27T18:30:34Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-27T18:30:34Z", "aliases": [ "CVE-2023-35799" ], "details": "Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-v5wr-22jp-335p/GHSA-v5wr-22jp-335p.json b/advisories/unreviewed/2023/06/GHSA-v5wr-22jp-335p/GHSA-v5wr-22jp-335p.json index 5bd0284f945..8b4bdae0257 100644 --- a/advisories/unreviewed/2023/06/GHSA-v5wr-22jp-335p/GHSA-v5wr-22jp-335p.json +++ b/advisories/unreviewed/2023/06/GHSA-v5wr-22jp-335p/GHSA-v5wr-22jp-335p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5wr-22jp-335p", - "modified": "2023-06-23T12:30:18Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-23T12:30:18Z", "aliases": [ "CVE-2023-30362" ], "details": "Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-vcpw-jwjp-3c74/GHSA-vcpw-jwjp-3c74.json b/advisories/unreviewed/2023/06/GHSA-vcpw-jwjp-3c74/GHSA-vcpw-jwjp-3c74.json index 63d9b4a0a4f..eb957cdb108 100644 --- a/advisories/unreviewed/2023/06/GHSA-vcpw-jwjp-3c74/GHSA-vcpw-jwjp-3c74.json +++ b/advisories/unreviewed/2023/06/GHSA-vcpw-jwjp-3c74/GHSA-vcpw-jwjp-3c74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcpw-jwjp-3c74", - "modified": "2023-06-23T18:30:26Z", + "modified": "2023-07-05T15:30:23Z", "published": "2023-06-23T18:30:26Z", "aliases": [ "CVE-2023-3317" ], "details": "A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi mt76/mt7921 sub-component in the Linux Kernel. This flaw could allow an attacker to crash the system after 'features' memory release. This vulnerability could even lead to a kernel information leak problem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-vjwh-p6r4-4q46/GHSA-vjwh-p6r4-4q46.json b/advisories/unreviewed/2023/06/GHSA-vjwh-p6r4-4q46/GHSA-vjwh-p6r4-4q46.json index 2ace139b34d..911bf323b62 100644 --- a/advisories/unreviewed/2023/06/GHSA-vjwh-p6r4-4q46/GHSA-vjwh-p6r4-4q46.json +++ b/advisories/unreviewed/2023/06/GHSA-vjwh-p6r4-4q46/GHSA-vjwh-p6r4-4q46.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-863" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-27fj-7xp4-5c3r/GHSA-27fj-7xp4-5c3r.json b/advisories/unreviewed/2023/07/GHSA-27fj-7xp4-5c3r/GHSA-27fj-7xp4-5c3r.json new file mode 100644 index 00000000000..2b9f0e65f4b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-27fj-7xp4-5c3r/GHSA-27fj-7xp4-5c3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27fj-7xp4-5c3r", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35974" + ], + "details": "Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35974" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json b/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json new file mode 100644 index 00000000000..6284e11e7ee --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qhm-365q-v39p", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35978" + ], + "details": "A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35978" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4m78-wr94-p294/GHSA-4m78-wr94-p294.json b/advisories/unreviewed/2023/07/GHSA-4m78-wr94-p294/GHSA-4m78-wr94-p294.json new file mode 100644 index 00000000000..9b2350a86b8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4m78-wr94-p294/GHSA-4m78-wr94-p294.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m78-wr94-p294", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-2538" + ], + "details": "A CWE-552 \"Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 allows an unauthenticated remote attacker to retrieve the private key of the TLS certificate in use by the BMC via forced browsing. This can then be abused to perform Man-in-the-Middle (MitM) attacks against victims that access the web interface through HTTPS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2538" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-2538/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-58x7-6mqf-pcgw/GHSA-58x7-6mqf-pcgw.json b/advisories/unreviewed/2023/07/GHSA-58x7-6mqf-pcgw/GHSA-58x7-6mqf-pcgw.json new file mode 100644 index 00000000000..4f3f3f17374 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-58x7-6mqf-pcgw/GHSA-58x7-6mqf-pcgw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58x7-6mqf-pcgw", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2021-46893" + ], + "details": "Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46893" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2023/7/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json b/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json new file mode 100644 index 00000000000..6c2658bb588 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f43-782r-rjgv", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35973" + ], + "details": "Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35973" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json b/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json new file mode 100644 index 00000000000..9788115aa45 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c7wh-g26h-jp33/GHSA-c7wh-g26h-jp33.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7wh-g26h-jp33", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2021-46891" + ], + "details": "Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46891" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2023/7/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cf6v-9j57-v6r6/GHSA-cf6v-9j57-v6r6.json b/advisories/unreviewed/2023/07/GHSA-cf6v-9j57-v6r6/GHSA-cf6v-9j57-v6r6.json new file mode 100644 index 00000000000..f3942b880c9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cf6v-9j57-v6r6/GHSA-cf6v-9j57-v6r6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf6v-9j57-v6r6", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-3515" + ], + "details": "Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3515" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/commit/9aaaf980f0ba15611f30568bd67bce3ec12954e2" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/e335cd18-bc4d-4585-adb7-426c817ed053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g45c-4xf2-8f43/GHSA-g45c-4xf2-8f43.json b/advisories/unreviewed/2023/07/GHSA-g45c-4xf2-8f43/GHSA-g45c-4xf2-8f43.json new file mode 100644 index 00000000000..ebf644bfb0e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g45c-4xf2-8f43/GHSA-g45c-4xf2-8f43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g45c-4xf2-8f43", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35975" + ], + "details": "An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35975" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gj9h-fgq8-9cfm/GHSA-gj9h-fgq8-9cfm.json b/advisories/unreviewed/2023/07/GHSA-gj9h-fgq8-9cfm/GHSA-gj9h-fgq8-9cfm.json new file mode 100644 index 00000000000..d1bf2cdb647 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gj9h-fgq8-9cfm/GHSA-gj9h-fgq8-9cfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj9h-fgq8-9cfm", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35976" + ], + "details": "Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35976" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json b/advisories/unreviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json new file mode 100644 index 00000000000..e15503b6908 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h755-8qp9-cq85", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-36665" + ], + "details": "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty. NOTE: this CVE Record is about \"Object.constructor.prototype. = ...;\" whereas CVE-2022-25878 was about \"Object.__proto__. = ...;\" instead.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36665" + }, + { + "type": "WEB", + "url": "https://github.com/protobufjs/protobuf.js/pull/1899" + }, + { + "type": "WEB", + "url": "https://github.com/protobufjs/protobuf.js/commit/e66379f451b0393c27d87b37fa7d271619e16b0d" + }, + { + "type": "WEB", + "url": "https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.2.3...protobufjs-v7.2.4" + }, + { + "type": "WEB", + "url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4" + }, + { + "type": "WEB", + "url": "https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-2023-36665" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ppc4-8r5x-9fwf/GHSA-ppc4-8r5x-9fwf.json b/advisories/unreviewed/2023/07/GHSA-ppc4-8r5x-9fwf/GHSA-ppc4-8r5x-9fwf.json new file mode 100644 index 00000000000..ef7cbda882c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ppc4-8r5x-9fwf/GHSA-ppc4-8r5x-9fwf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppc4-8r5x-9fwf", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-3455" + ], + "details": "Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3455" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2023/7/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vqxv-crf9-843x/GHSA-vqxv-crf9-843x.json b/advisories/unreviewed/2023/07/GHSA-vqxv-crf9-843x/GHSA-vqxv-crf9-843x.json new file mode 100644 index 00000000000..08be393fa12 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vqxv-crf9-843x/GHSA-vqxv-crf9-843x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxv-crf9-843x", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35979" + ], + "details": "There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35979" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w8v4-5hx2-xq34/GHSA-w8v4-5hx2-xq34.json b/advisories/unreviewed/2023/07/GHSA-w8v4-5hx2-xq34/GHSA-w8v4-5hx2-xq34.json new file mode 100644 index 00000000000..785962a6a61 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w8v4-5hx2-xq34/GHSA-w8v4-5hx2-xq34.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8v4-5hx2-xq34", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-35971" + ], + "details": "A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35971" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json b/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json new file mode 100644 index 00000000000..26e67d32525 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w9wr-4926-mh54/GHSA-w9wr-4926-mh54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9wr-4926-mh54", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-35972" + ], + "details": "An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35972" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wj5p-x3cr-46w8/GHSA-wj5p-x3cr-46w8.json b/advisories/unreviewed/2023/07/GHSA-wj5p-x3cr-46w8/GHSA-wj5p-x3cr-46w8.json new file mode 100644 index 00000000000..4a8369a16e9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wj5p-x3cr-46w8/GHSA-wj5p-x3cr-46w8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj5p-x3cr-46w8", + "modified": "2023-07-05T15:30:24Z", + "published": "2023-07-05T15:30:24Z", + "aliases": [ + "CVE-2023-3089" + ], + "details": "A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3089" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-3089" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2212085" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x7v9-4x5r-vpv8/GHSA-x7v9-4x5r-vpv8.json b/advisories/unreviewed/2023/07/GHSA-x7v9-4x5r-vpv8/GHSA-x7v9-4x5r-vpv8.json new file mode 100644 index 00000000000..0ccc8acf4b2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x7v9-4x5r-vpv8/GHSA-x7v9-4x5r-vpv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7v9-4x5r-vpv8", + "modified": "2023-07-05T15:30:25Z", + "published": "2023-07-05T15:30:25Z", + "aliases": [ + "CVE-2023-35977" + ], + "details": "Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35977" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file