From 90cf0ad8541537fd5ea2905c2e4a501c84cfa720 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 10 Apr 2024 18:40:54 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-6xrf-q977-5vgc.json | 4 +-
.../GHSA-9jfx-84v9-2rr2.json | 6 +-
.../GHSA-rpvr-38xv-xvxq.json | 6 +-
.../GHSA-v5fm-hr72-27hx.json | 6 +-
.../GHSA-67hx-6x53-jw92.json | 21 ++-
.../GHSA-5667-3wch-7q7w.json | 12 +-
.../GHSA-27jx-ffw8-xrqv.json | 69 ++++++++
.../GHSA-2q59-h24c-w6fg.json | 8 +-
.../GHSA-4685-2x5r-65pj.json | 148 ++++++++++++++++++
.../GHSA-4v52-7q2x-v4xj.json | 65 ++++++++
.../GHSA-4v7x-pqxf-cx7m.json | 111 +++++++++++++
.../GHSA-5pgg-2g8v-p4x9.json | 69 ++++++++
.../GHSA-65pc-76pq-pvf5.json | 62 ++++++++
.../GHSA-6cf6-8hvr-r68w.json | 82 ++++++++++
.../GHSA-75hq-h6g9-h4q5.json | 8 +-
.../GHSA-9ph3-v2vh-3qx7.json | 8 +-
.../GHSA-9qxr-qj54-h672.json | 92 +++++++++++
.../GHSA-c33x-xqrf-c478.json | 13 +-
.../GHSA-c4gr-q97g-ppwc.json | 8 +-
.../GHSA-f8h5-v2vg-46rr.json | 72 +++++++++
.../GHSA-j2rp-gmqv-frhv.json | 61 ++++++++
.../GHSA-m4v8-wqvr-p9f7.json | 93 +++++++++++
.../GHSA-mcw6-3256-64gg.json | 134 ++++++++++++++++
.../GHSA-q6cp-qfwq-4gcv.json | 85 ++++++++++
.../GHSA-vc6q-ccj9-9r89.json | 69 ++++++++
.../GHSA-w5w5-8vfh-xcjq.json | 65 ++++++++
.../GHSA-w67v-ph4x-f48q.json | 134 ++++++++++++++++
.../GHSA-w7hm-hmxv-pvhf.json | 65 ++++++++
.../GHSA-wp43-vprh-c3w5.json | 118 ++++++++++++++
.../GHSA-wpff-wm84-x5cx.json | 72 +++++++++
.../GHSA-x9xc-63hg-vcfq.json | 69 ++++++++
.../GHSA-xfhw-6mc4-mgxf.json | 65 ++++++++
.../GHSA-xp9j-8p68-9q93.json | 61 ++++++++
.../GHSA-45gr-6358-jhr3.json | 10 +-
.../GHSA-cm79-jwwm-5h7h.json | 4 +-
.../GHSA-546p-cf3x-vwc8.json | 4 +-
.../GHSA-vvcp-5v5p-8jhc.json | 4 +-
.../GHSA-2228-5m6x-4rqm.json | 11 +-
.../GHSA-2256-rrc4-rg7p.json | 4 +-
.../GHSA-2377-2j75-w5v6.json | 4 +-
.../GHSA-2425-r3xx-w4v7.json | 4 +-
.../GHSA-2434-68xh-wxm6.json | 4 +-
.../GHSA-243m-j5w7-6mw6.json | 4 +-
.../GHSA-243r-m3w5-w83p.json | 4 +-
.../GHSA-244x-f55f-vxmr.json | 4 +-
.../GHSA-2456-m625-hcj6.json | 4 +-
.../GHSA-24f5-5fmf-pwmc.json | 6 +-
.../GHSA-25h8-g2f4-5mwj.json | 4 +-
.../GHSA-26rx-wm6q-f3g4.json | 4 +-
.../GHSA-272r-9398-x32j.json | 4 +-
.../GHSA-27j3-ww98-6j8q.json | 4 +-
.../GHSA-2962-mm2g-265c.json | 4 +-
.../GHSA-299r-q2gj-44gj.json | 4 +-
.../GHSA-29j4-8jcf-4q5w.json | 4 +-
.../GHSA-29m7-5q7x-g3fr.json | 4 +-
.../GHSA-2cc2-mcjj-r4mp.json | 9 +-
.../GHSA-2cgq-5ww9-3c6v.json | 11 +-
.../GHSA-2fcg-hwv9-g767.json | 4 +-
.../GHSA-2fp9-9cqm-x4p7.json | 4 +-
.../GHSA-2g3g-vvgw-mw65.json | 4 +-
.../GHSA-2gwx-jm42-4548.json | 4 +-
.../GHSA-2hcc-ww5c-44wh.json | 7 +-
.../GHSA-2hmc-82rg-26hv.json | 4 +-
.../GHSA-2mh6-g78c-5h6c.json | 4 +-
.../GHSA-2mqf-694r-32x9.json | 4 +-
.../GHSA-2mxq-q8p2-g2c8.json | 4 +-
.../GHSA-2pfh-4x3h-w3hm.json | 4 +-
.../GHSA-2q58-xp4p-xpqc.json | 4 +-
.../GHSA-2q77-j9qq-67hg.json | 4 +-
.../GHSA-2q9m-8wj3-95xg.json | 4 +-
.../GHSA-2qqg-m8pw-2q2v.json | 4 +-
.../GHSA-2rrh-8pm2-3q2c.json | 4 +-
.../GHSA-2vvx-5g27-9gvj.json | 4 +-
.../GHSA-2w9c-67cj-fxpp.json | 4 +-
.../GHSA-2w9p-mj8f-374x.json | 4 +-
.../GHSA-2w9p-mqx6-cvqc.json | 4 +-
.../GHSA-2wg8-2hgh-5f85.json | 6 +-
.../GHSA-2wq9-hq2m-2hfq.json | 4 +-
.../GHSA-2xg8-857g-4j2x.json | 4 +-
.../GHSA-2xmm-8j84-pj46.json | 4 +-
.../GHSA-32jc-368c-fvg6.json | 9 +-
.../GHSA-32qf-g28m-p524.json | 4 +-
.../GHSA-32vv-cw3x-ch8f.json | 4 +-
.../GHSA-339p-cxqq-7j6j.json | 4 +-
.../GHSA-33gx-m93p-j6wc.json | 4 +-
.../GHSA-33mh-qwc8-jxxx.json | 7 +-
.../GHSA-34fg-whr2-93rc.json | 11 +-
.../GHSA-34pm-grcc-xjrw.json | 4 +-
.../GHSA-3579-vvrm-33pp.json | 4 +-
.../GHSA-35hg-f9qq-236g.json | 7 +-
.../GHSA-364j-ch9m-hp4h.json | 4 +-
.../GHSA-3728-9cr9-4xwr.json | 4 +-
.../GHSA-3743-q7xh-2hv2.json | 9 +-
.../GHSA-377v-9whx-fp3q.json | 4 +-
.../GHSA-37gq-4hg5-cxqj.json | 4 +-
.../GHSA-37gv-9q37-8946.json | 4 +-
.../GHSA-37q7-h3xv-cfp3.json | 4 +-
.../GHSA-3856-cjch-9cv8.json | 4 +-
.../GHSA-38h4-p674-c649.json | 4 +-
.../GHSA-38rh-4m8x-2658.json | 4 +-
.../GHSA-3c2j-r5f4-2fcc.json | 4 +-
.../GHSA-3c82-4vr9-q4gw.json | 4 +-
.../GHSA-3c9r-8wrp-84w3.json | 4 +-
.../GHSA-3f75-cqgv-mw4m.json | 4 +-
.../GHSA-3g9h-f994-3h4c.json | 4 +-
.../GHSA-3h2f-562g-hqwc.json | 4 +-
.../GHSA-3h69-hjjf-qcc3.json | 4 +-
.../GHSA-3j7c-23m3-57jj.json | 11 +-
.../GHSA-3j7w-jp46-9752.json | 4 +-
.../GHSA-3j9j-5462-cpx8.json | 4 +-
.../GHSA-3jqw-qj8r-mjgp.json | 4 +-
.../GHSA-3m8h-rcx6-p525.json | 4 +-
.../GHSA-3mpm-5q2w-wr7w.json | 4 +-
.../GHSA-3pg9-8r34-25v2.json | 4 +-
.../GHSA-3ph5-58qm-r6wg.json | 4 +-
.../GHSA-3qf9-64j6-3672.json | 4 +-
.../GHSA-3qmc-vv7g-wccj.json | 4 +-
.../GHSA-3qmw-7623-hwxf.json | 4 +-
.../GHSA-3rhv-vcmv-prv6.json | 4 +-
.../GHSA-3vfv-wc96-x87r.json | 4 +-
.../GHSA-3vj4-3g37-rf7w.json | 4 +-
.../GHSA-3wm5-3g94-xp54.json | 4 +-
.../GHSA-3x3x-vjcr-56cc.json | 8 +-
.../GHSA-42hr-vjrg-wjr7.json | 4 +-
.../GHSA-42jw-237g-7j4r.json | 4 +-
.../GHSA-433v-4977-67pv.json | 11 +-
.../GHSA-43pr-r6xw-f56v.json | 9 +-
.../GHSA-4473-7649-rj9x.json | 11 +-
.../GHSA-456w-4cfv-54mf.json | 4 +-
.../GHSA-45rg-4qh3-jxp9.json | 4 +-
.../GHSA-46j9-q72c-3w95.json | 4 +-
.../GHSA-474m-7m4r-wvgh.json | 4 +-
.../GHSA-47h2-h6q2-ghrw.json | 4 +-
.../GHSA-4869-ghp2-7x5q.json | 4 +-
.../GHSA-48hc-h5m8-9fxf.json | 11 +-
.../GHSA-48r4-c3jw-rj8r.json | 4 +-
.../GHSA-49gm-5685-8fxv.json | 4 +-
.../GHSA-49j2-f7c9-w9qc.json | 4 +-
.../GHSA-4c7j-v446-xgx3.json | 4 +-
.../GHSA-4cgf-2hf9-w2rc.json | 4 +-
.../GHSA-4f7j-xf8r-8572.json | 4 +-
.../GHSA-4g94-rrhw-h5fw.json | 7 +-
.../GHSA-4g9c-4jmr-xrqp.json | 4 +-
.../GHSA-4gh5-3g83-4888.json | 11 +-
.../GHSA-4grg-q38c-r772.json | 4 +-
.../GHSA-4gxq-5q4x-qpf7.json | 4 +-
.../GHSA-4hqp-42w7-3hv5.json | 4 +-
.../GHSA-4j4f-q993-cr2r.json | 4 +-
.../GHSA-4j6r-mf7f-44jq.json | 4 +-
.../GHSA-4j8p-h8p2-rc88.json | 4 +-
.../GHSA-4j94-2784-394x.json | 15 +-
.../GHSA-4jh4-mwq8-wx24.json | 4 +-
.../GHSA-4jhw-x435-x5f7.json | 4 +-
.../GHSA-4mh7-v2h4-6vf9.json | 9 +-
.../GHSA-4mq9-mp5g-r83q.json | 9 +-
.../GHSA-4mwj-qxcc-x2p8.json | 4 +-
.../GHSA-4p2x-j6f2-872j.json | 4 +-
.../GHSA-4p52-qfg6-cwjr.json | 4 +-
.../GHSA-4pfv-vgmw-jgcr.json | 4 +-
.../GHSA-4pgc-4ghm-q2mf.json | 4 +-
.../GHSA-4pm7-5852-9cj6.json | 4 +-
.../GHSA-4pxq-qc65-2pqq.json | 4 +-
.../GHSA-4q58-qpcg-q4vf.json | 4 +-
.../GHSA-4r3r-8gr6-mjmm.json | 4 +-
.../GHSA-4r9r-cpgw-cf98.json | 4 +-
.../GHSA-4rv5-xm6p-7p7f.json | 4 +-
.../GHSA-4v9x-wfx7-57r9.json | 4 +-
.../GHSA-4vf3-57vh-hmm8.json | 4 +-
.../GHSA-4vhm-j5mp-9wcg.json | 4 +-
.../GHSA-4x43-fwgv-cq8j.json | 4 +-
.../GHSA-4xch-3w57-6pj7.json | 4 +-
.../GHSA-4xxx-xjp2-284m.json | 4 +-
.../GHSA-52hf-8hgx-m78v.json | 4 +-
.../GHSA-537g-m9mx-pvhm.json | 4 +-
.../GHSA-53p3-mj4q-6834.json | 4 +-
.../GHSA-542f-549f-58vm.json | 11 +-
.../GHSA-5488-g25c-556m.json | 4 +-
.../GHSA-548m-xpmx-h6v4.json | 4 +-
.../GHSA-549w-5fgc-66mp.json | 4 +-
.../GHSA-555p-hvwp-mh56.json | 4 +-
.../GHSA-5572-2439-pvwc.json | 4 +-
.../GHSA-559q-gjf6-hx34.json | 4 +-
.../GHSA-55h7-hprj-3g5x.json | 4 +-
.../GHSA-566r-vx98-9rr7.json | 4 +-
.../GHSA-56p2-xp5h-2cf3.json | 4 +-
.../GHSA-56qj-x9h6-9389.json | 4 +-
.../GHSA-57rr-j54c-gw9x.json | 4 +-
.../GHSA-59mr-825p-2g28.json | 4 +-
.../GHSA-5cg5-8chj-3gqc.json | 4 +-
.../GHSA-5cgm-4jc2-42h7.json | 11 +-
.../GHSA-5cq7-9mrf-9vfp.json | 4 +-
.../GHSA-5f5r-qwxj-xhxq.json | 4 +-
.../GHSA-5f6x-wr72-j225.json | 4 +-
.../GHSA-5g66-7886-w8m2.json | 4 +-
.../GHSA-5gfj-h4p7-f68x.json | 4 +-
.../GHSA-5j36-w363-p3jq.json | 4 +-
.../GHSA-5j8w-6m93-cp7q.json | 4 +-
.../GHSA-5mmq-8hjw-gc3g.json | 4 +-
.../GHSA-5pgp-q8pq-w37h.json | 4 +-
.../GHSA-5prg-5cfp-g266.json | 4 +-
.../GHSA-5q42-rqhh-m4v6.json | 4 +-
.../GHSA-5q5q-4pvv-q47c.json | 4 +-
.../GHSA-5qvw-j8jj-q3w9.json | 11 +-
.../GHSA-5rj2-m4rq-8fmp.json | 4 +-
.../GHSA-5rpw-fg4q-7wj5.json | 4 +-
.../GHSA-5rqf-6wfj-r66h.json | 4 +-
.../GHSA-5v38-92h7-3886.json | 4 +-
.../GHSA-5vgg-9h5w-h365.json | 8 +-
.../GHSA-5vgv-43pv-3r7p.json | 4 +-
.../GHSA-5vw8-jcpr-5wmv.json | 4 +-
.../GHSA-5xgm-7mgw-vcg3.json | 4 +-
.../GHSA-5xpv-3hf7-xx79.json | 4 +-
.../GHSA-624m-p552-xj26.json | 11 +-
.../GHSA-638j-4q3q-4843.json | 4 +-
.../GHSA-63h9-pmmv-4m65.json | 4 +-
.../GHSA-63rp-vfr8-4qw7.json | 4 +-
.../GHSA-63w9-q3qg-2wg7.json | 4 +-
.../GHSA-6436-gq3f-g99g.json | 4 +-
.../GHSA-644w-28vg-vrrc.json | 4 +-
.../GHSA-645x-3j3m-f2c2.json | 4 +-
.../GHSA-64ff-hjjg-hwr8.json | 9 +-
.../GHSA-64xv-qmpj-7grf.json | 4 +-
.../GHSA-652g-v3x6-f997.json | 4 +-
.../GHSA-66px-8gqr-866w.json | 11 +-
.../GHSA-66qc-5f4v-2m8h.json | 4 +-
.../GHSA-67p5-wmww-f3q5.json | 4 +-
.../GHSA-67pv-pwcc-82hx.json | 4 +-
.../GHSA-683f-hcw3-5vgr.json | 7 +-
.../GHSA-687q-46r9-m8ww.json | 9 +-
.../GHSA-68c3-2gxf-hpcv.json | 4 +-
.../GHSA-6999-r624-hg6j.json | 4 +-
.../GHSA-6cr3-pfhw-g3c7.json | 4 +-
.../GHSA-6f7x-qj2v-8rh2.json | 4 +-
.../GHSA-6gp7-g3rx-2cq6.json | 4 +-
.../GHSA-6gr4-x7gv-xwjp.json | 4 +-
.../GHSA-6gwq-qjqq-9xpv.json | 4 +-
.../GHSA-6h2p-v2jw-9mc4.json | 4 +-
.../GHSA-6j74-3j28-p2f4.json | 4 +-
.../GHSA-6jpv-f5xm-f87c.json | 4 +-
.../GHSA-6jvj-rjjj-4gfr.json | 4 +-
.../GHSA-6m4w-xmq7-g92p.json | 4 +-
.../GHSA-6q4v-gp5x-qpwg.json | 4 +-
.../GHSA-6qj5-v722-xhxc.json | 4 +-
.../GHSA-6r76-9f7g-6w9v.json | 4 +-
.../GHSA-6v6v-fgmr-w8g2.json | 4 +-
.../GHSA-6vf3-6gq2-8cgv.json | 4 +-
.../GHSA-6w2r-58cq-54q2.json | 7 +-
.../GHSA-6wc2-f8mc-76rv.json | 9 +-
.../GHSA-6wh6-h5jg-ghcx.json | 4 +-
.../GHSA-7374-hfgm-rm8v.json | 4 +-
.../GHSA-76g7-7jq2-pjg7.json | 4 +-
.../GHSA-76mp-24cw-7mwq.json | 9 +-
.../GHSA-77wr-jhhf-58xr.json | 4 +-
.../GHSA-7c2j-9gcg-5ggw.json | 4 +-
.../GHSA-7c84-qx75-c25g.json | 4 +-
.../GHSA-7c8x-vv95-q9jj.json | 11 +-
.../GHSA-7c9p-q9cx-hrg3.json | 4 +-
.../GHSA-7f74-9j92-993v.json | 4 +-
.../GHSA-7grc-fv66-9g6g.json | 4 +-
.../GHSA-7gx8-jvcv-jmvj.json | 4 +-
.../GHSA-7hch-jrf6-fjw8.json | 4 +-
.../GHSA-7hqq-m574-qjp2.json | 4 +-
.../GHSA-7jqv-m3g3-hfjh.json | 4 +-
.../GHSA-7jrw-mp94-7v28.json | 11 +-
.../GHSA-7jxg-pm47-89ph.json | 11 +-
.../GHSA-7m68-3mc5-7wwf.json | 4 +-
.../GHSA-7m88-f659-f4w6.json | 4 +-
.../GHSA-7mhw-hvfr-5wr9.json | 11 +-
.../GHSA-7mwm-qgvf-37wp.json | 4 +-
.../GHSA-7pc9-4xmj-8wv3.json | 4 +-
.../GHSA-7pfc-834q-h497.json | 4 +-
.../GHSA-7q52-xpr7-cj38.json | 4 +-
.../GHSA-7qx9-qw7h-vvwq.json | 4 +-
.../GHSA-7v28-76v4-349r.json | 4 +-
.../GHSA-7vm7-mp89-q7c7.json | 9 +-
.../GHSA-7w42-6f8j-cx26.json | 9 +-
.../GHSA-7wxc-mh8q-7484.json | 11 +-
.../GHSA-7x29-jh5v-6wwf.json | 4 +-
.../GHSA-7xp8-vhxc-29v9.json | 11 +-
.../GHSA-82hj-ghm7-6vpg.json | 4 +-
.../GHSA-834h-7mjv-2g94.json | 4 +-
.../GHSA-836w-q8xf-8mq9.json | 4 +-
.../GHSA-85q4-wfv9-wrvq.json | 4 +-
.../GHSA-865m-g6fc-h55q.json | 4 +-
.../GHSA-87j3-33px-qqww.json | 4 +-
.../GHSA-87wm-cfp5-465j.json | 4 +-
.../GHSA-886f-64fm-9xmm.json | 4 +-
.../GHSA-8992-9q7r-8chp.json | 4 +-
.../GHSA-8c9g-7c4g-j7x7.json | 11 +-
.../GHSA-8cfv-g2mq-hrpw.json | 4 +-
.../GHSA-8ch2-m9x4-vgjv.json | 4 +-
.../GHSA-8f2j-r3g9-qhmm.json | 4 +-
.../GHSA-8h3j-g9f5-qfm7.json | 4 +-
.../GHSA-8h3p-5f62-5ppm.json | 4 +-
.../GHSA-8h83-vm48-vxjm.json | 4 +-
.../GHSA-8hhq-vrcj-6mpj.json | 4 +-
.../GHSA-8j8g-9794-h995.json | 11 +-
.../GHSA-8j9h-fmv7-4h7w.json | 4 +-
.../GHSA-8jpm-94jj-mfm6.json | 4 +-
.../GHSA-8jxc-5f94-22vh.json | 4 +-
.../GHSA-8m6j-x8hv-vfpr.json | 4 +-
.../GHSA-8m87-q3vv-mcr6.json | 4 +-
.../GHSA-8p63-mwfp-hjrv.json | 9 +-
.../GHSA-8q5v-q254-rx9v.json | 4 +-
.../GHSA-8qqf-9w4f-fp2m.json | 4 +-
.../GHSA-8r46-xgxw-rm8j.json | 4 +-
.../GHSA-8rj7-wpfp-6wx5.json | 4 +-
.../GHSA-8wgv-6377-h5p6.json | 4 +-
.../GHSA-8x86-h5jc-fg6v.json | 4 +-
.../GHSA-8xrj-3qq4-m659.json | 4 +-
.../GHSA-92g2-c2g8-rfxp.json | 4 +-
.../GHSA-93hx-mh7c-w6hg.json | 4 +-
.../GHSA-93jh-7v3q-c8c6.json | 4 +-
.../GHSA-93rg-x44m-w3fg.json | 4 +-
.../GHSA-94mp-fmc5-vxqv.json | 4 +-
.../GHSA-94xm-wg2w-cvfq.json | 4 +-
.../GHSA-95pq-x7mh-2f6c.json | 4 +-
.../GHSA-95vp-23xg-jv7p.json | 4 +-
.../GHSA-96rf-64j2-34rj.json | 4 +-
.../GHSA-97hh-rrpx-8434.json | 4 +-
.../GHSA-97mp-43rr-5rcx.json | 4 +-
.../GHSA-98q6-96hr-7jxp.json | 4 +-
.../GHSA-992r-442f-c792.json | 4 +-
.../GHSA-99v8-x8w9-cmfp.json | 4 +-
.../GHSA-9c5w-974x-xjxh.json | 4 +-
.../GHSA-9f28-p89f-245f.json | 4 +-
.../GHSA-9gjr-ph32-5q54.json | 4 +-
.../GHSA-9h4p-65h5-f3vx.json | 4 +-
.../GHSA-9h5h-vqj6-gf88.json | 11 +-
.../GHSA-9j4q-chv7-qjv6.json | 4 +-
.../GHSA-9jcp-r9cp-5qwf.json | 4 +-
.../GHSA-9jhj-p8jf-q52w.json | 4 +-
.../GHSA-9jm2-h589-xc6m.json | 4 +-
.../GHSA-9jm9-9xjf-h3x2.json | 11 +-
.../GHSA-9jrm-qw53-pvvc.json | 4 +-
.../GHSA-9m58-r896-qpmc.json | 4 +-
.../GHSA-9mqf-3pqw-75gf.json | 4 +-
.../GHSA-9mvw-c7r6-xcpq.json | 4 +-
.../GHSA-9mx6-4gg4-85xj.json | 4 +-
.../GHSA-9p9h-72r2-r3gj.json | 4 +-
.../GHSA-9pvh-gq43-pqc3.json | 4 +-
.../GHSA-9q57-wj63-96j5.json | 4 +-
.../GHSA-9q93-64jr-x633.json | 6 +-
.../GHSA-9qr5-85g4-f6rq.json | 7 +-
.../GHSA-9qvm-7q24-7mg9.json | 4 +-
.../GHSA-9r4m-vc45-52hp.json | 4 +-
.../GHSA-9v76-7rmr-76cm.json | 9 +-
.../GHSA-9vf3-vw7m-x4rr.json | 4 +-
.../GHSA-9vp9-v4wh-433r.json | 4 +-
.../GHSA-9vph-3jrp-5jwh.json | 4 +-
.../GHSA-9w2j-4f43-pmmh.json | 4 +-
.../GHSA-9wx6-ggqr-p55x.json | 4 +-
.../GHSA-c2qp-qqm8-h8cw.json | 4 +-
.../GHSA-c359-g3mh-v8vw.json | 4 +-
.../GHSA-c36p-pqfp-h5j2.json | 4 +-
.../GHSA-c3v3-8wvp-5mg4.json | 5 +-
.../GHSA-c3vw-3m8x-p7qv.json | 4 +-
.../GHSA-c3xg-7w53-6ghf.json | 4 +-
.../GHSA-c55p-cv2w-vc32.json | 4 +-
.../GHSA-c5qj-vxvj-r553.json | 4 +-
.../GHSA-c752-3p6c-46qc.json | 4 +-
.../GHSA-c79c-7rg5-qq47.json | 4 +-
.../GHSA-c7fp-g3rh-mvf7.json | 11 +-
.../GHSA-c7mx-g2c4-4phj.json | 4 +-
.../GHSA-c82f-8fqm-wg4g.json | 4 +-
.../GHSA-c89h-9543-w7hx.json | 4 +-
.../GHSA-c8wx-v976-xhgj.json | 4 +-
.../GHSA-c9pj-4j3g-856x.json | 4 +-
.../GHSA-cc3f-r3m3-h7f9.json | 11 +-
.../GHSA-cc6c-373w-hg4m.json | 11 +-
.../GHSA-cc6j-mm94-2h5g.json | 4 +-
.../GHSA-cc7h-9j52-gh84.json | 4 +-
.../GHSA-cf5j-jfg7-qmqc.json | 4 +-
.../GHSA-cggm-fc75-c35c.json | 4 +-
.../GHSA-cgm3-875w-4qq8.json | 4 +-
.../GHSA-cgm3-p7mh-qpqx.json | 11 +-
.../GHSA-chgw-cwwq-79xg.json | 4 +-
.../GHSA-chwf-pr57-9wm2.json | 4 +-
.../GHSA-cj23-4vc3-qpfc.json | 4 +-
.../GHSA-cj2w-wj5h-c44x.json | 4 +-
.../GHSA-cj3f-w95j-x9xv.json | 6 +-
.../GHSA-cjff-m8pq-m7x6.json | 4 +-
.../GHSA-cjgx-jx6j-cmg7.json | 9 +-
.../GHSA-cjjx-jw4j-6587.json | 4 +-
.../GHSA-cmfg-v75g-8wm3.json | 4 +-
.../GHSA-cp3v-75fh-g783.json | 4 +-
.../GHSA-cpgw-pm36-mfq9.json | 4 +-
.../GHSA-cq8v-q3f4-9cwp.json | 4 +-
.../GHSA-cqgr-82mv-j79r.json | 4 +-
.../GHSA-cqjm-c96f-4qp5.json | 4 +-
.../GHSA-cqv4-m6cq-x9jx.json | 4 +-
.../GHSA-cr2w-gfw6-cgj8.json | 4 +-
.../GHSA-cr8h-8gv8-gxxv.json | 4 +-
.../GHSA-cv24-gm95-4rrg.json | 11 +-
.../GHSA-cv5w-p79v-vvxq.json | 4 +-
.../GHSA-cw54-cgwp-3c3v.json | 4 +-
.../GHSA-cw58-3hpw-976j.json | 5 +-
.../GHSA-cwfq-h62h-3hg5.json | 4 +-
.../GHSA-cx68-9cx9-qmrj.json | 4 +-
.../GHSA-cx9h-wv2x-v9rg.json | 9 +-
.../GHSA-f2ch-w95m-q82q.json | 4 +-
.../GHSA-f35c-gw68-7hgr.json | 4 +-
.../GHSA-f37j-rr3j-w7mq.json | 4 +-
.../GHSA-f3jw-63xv-7wfj.json | 4 +-
.../GHSA-f3v7-7g27-82qw.json | 4 +-
.../GHSA-f42h-c5pj-9hxp.json | 4 +-
.../GHSA-f43r-fv98-jc2w.json | 4 +-
.../GHSA-f464-84q7-49hm.json | 4 +-
.../GHSA-f4h9-mcvf-w57c.json | 4 +-
.../GHSA-f4vf-79gp-p96v.json | 4 +-
.../GHSA-f4x5-257x-2739.json | 6 +-
.../GHSA-f54w-qppp-5xp8.json | 4 +-
.../GHSA-f5q5-79ff-jh27.json | 11 +-
.../GHSA-f5qf-87r9-8v7q.json | 4 +-
.../GHSA-f5v4-cqgf-pfvv.json | 4 +-
.../GHSA-f5w9-q8fj-h9jj.json | 6 +-
.../GHSA-f69q-975j-f6mc.json | 4 +-
.../GHSA-f7rx-678f-vf6q.json | 4 +-
.../GHSA-f7v3-rpm4-hwv2.json | 4 +-
.../GHSA-f865-7gxm-95r4.json | 4 +-
.../GHSA-f8h4-8cx8-j35m.json | 4 +-
.../GHSA-f8xx-2rx5-fc4w.json | 4 +-
.../GHSA-f96p-9v3g-ffm4.json | 11 +-
.../GHSA-f9cg-fxjq-h54m.json | 11 +-
.../GHSA-f9vm-fr8w-hm2v.json | 4 +-
.../GHSA-fc5f-gc6j-gfhf.json | 4 +-
.../GHSA-fc94-mp7c-xmpq.json | 4 +-
.../GHSA-fcmv-m5pv-9mj4.json | 4 +-
.../GHSA-fcv4-fw97-74j9.json | 4 +-
.../GHSA-ff5g-xv9r-r383.json | 11 +-
.../GHSA-ffqm-rxh4-r75f.json | 11 +-
.../GHSA-ffxw-phw3-h58r.json | 4 +-
.../GHSA-fgvx-4256-89cx.json | 4 +-
.../GHSA-fh5x-h6r2-7rvf.json | 4 +-
.../GHSA-fhx9-p329-4x23.json | 4 +-
.../GHSA-fj34-c7pj-j8xq.json | 4 +-
.../GHSA-fj49-xvp9-p96q.json | 11 +-
.../GHSA-fjcg-2rqh-mpj3.json | 4 +-
.../GHSA-fm3x-qgq6-7xmf.json | 4 +-
.../GHSA-fm9q-gf87-g4h8.json | 4 +-
.../GHSA-fp27-qfpm-95w8.json | 4 +-
.../GHSA-fp5c-vf9m-6gv3.json | 4 +-
.../GHSA-fq23-mhmq-5hc5.json | 4 +-
.../GHSA-fq72-4xq4-w8hg.json | 4 +-
.../GHSA-fq8c-93h2-hrr9.json | 4 +-
.../GHSA-fqv5-4rc8-87p9.json | 4 +-
.../GHSA-fr4c-rcw2-hh8p.json | 11 +-
.../GHSA-fr4f-6grf-fhqw.json | 4 +-
.../GHSA-frhp-4qgh-c626.json | 11 +-
.../GHSA-fvrc-4g4c-396g.json | 4 +-
.../GHSA-fwh4-pm54-qx88.json | 4 +-
.../GHSA-fwj5-xh52-x3wv.json | 4 +-
.../GHSA-fx4r-ccm6-2q6f.json | 4 +-
.../GHSA-g28m-wpc6-78c8.json | 4 +-
.../GHSA-g3px-65r8-wfgx.json | 4 +-
.../GHSA-g47w-cvcq-qh23.json | 7 +-
.../GHSA-g49j-6p9j-4r5c.json | 4 +-
.../GHSA-g4j5-f2j8-q53j.json | 4 +-
.../GHSA-g574-v9wx-6x2q.json | 4 +-
.../GHSA-g6cq-79gq-xhxv.json | 4 +-
.../GHSA-g7rr-rj9q-jfww.json | 4 +-
.../GHSA-g8cv-hhj5-2rjx.json | 4 +-
.../GHSA-g92q-cp9m-6xg3.json | 4 +-
.../GHSA-g95v-666p-2m3x.json | 4 +-
.../GHSA-g978-26j8-v9jj.json | 4 +-
.../GHSA-g99m-655w-j95w.json | 4 +-
.../GHSA-g9fr-v3jx-9jph.json | 4 +-
.../GHSA-g9r5-p2qr-8f4f.json | 4 +-
.../GHSA-gc74-6h94-8cfj.json | 4 +-
.../GHSA-gc7q-964p-3f2q.json | 4 +-
.../GHSA-gg84-68cr-5wgm.json | 4 +-
.../GHSA-ggq5-xv35-rxhf.json | 4 +-
.../GHSA-ggr8-3hwx-4f2m.json | 4 +-
.../GHSA-ggrv-94gh-qf9g.json | 4 +-
.../GHSA-gh52-2rq4-cqx2.json | 4 +-
.../GHSA-ghc9-27wr-4w58.json | 4 +-
.../GHSA-ghvx-5v39-7hv5.json | 4 +-
.../GHSA-gj95-8384-wrh5.json | 4 +-
.../GHSA-gjv4-9pfg-rv2p.json | 11 +-
.../GHSA-gprh-65m4-pxq9.json | 4 +-
.../GHSA-gq43-3jqj-7h4q.json | 4 +-
.../GHSA-gq92-gmhv-53v8.json | 4 +-
.../GHSA-gqc6-p5c3-q963.json | 4 +-
.../GHSA-gqww-mmf9-7x23.json | 4 +-
.../GHSA-gr46-9pmg-323c.json | 4 +-
.../GHSA-grc6-r6f8-xj7c.json | 4 +-
.../GHSA-grfg-rxx4-pppc.json | 4 +-
.../GHSA-grgw-cqmv-xp2v.json | 4 +-
.../GHSA-grvj-w989-52pr.json | 4 +-
.../GHSA-gx5h-6g66-6r78.json | 4 +-
.../GHSA-gxg6-4mhh-v28x.json | 4 +-
.../GHSA-h223-ghxp-jcj3.json | 4 +-
.../GHSA-h2q7-whv7-5m3x.json | 4 +-
.../GHSA-h35v-vvv3-ww3x.json | 4 +-
.../GHSA-h3g9-cwr6-hphx.json | 4 +-
.../GHSA-h3vv-x3m8-whmj.json | 4 +-
.../GHSA-h43q-h523-j594.json | 4 +-
.../GHSA-h4vh-xjqq-7hrh.json | 4 +-
.../GHSA-h5pw-9677-4hqp.json | 4 +-
.../GHSA-h6p5-xfhf-88h8.json | 5 +-
.../GHSA-h7m2-v987-3v73.json | 4 +-
.../GHSA-h7x8-97pc-7qrv.json | 4 +-
.../GHSA-h87j-f78f-m3fm.json | 4 +-
.../GHSA-h8wx-v5rf-mxrf.json | 4 +-
.../GHSA-h9fc-752h-284m.json | 4 +-
.../GHSA-h9gw-q7wq-vrfv.json | 4 +-
.../GHSA-h9p2-g8w7-8363.json | 4 +-
.../GHSA-hch9-gprw-2g9j.json | 4 +-
.../GHSA-hcph-762f-fp48.json | 4 +-
.../GHSA-hcpj-5jqq-8232.json | 4 +-
.../GHSA-hcpq-pf4q-ppwv.json | 4 +-
.../GHSA-hf28-wjr8-2h5p.json | 4 +-
.../GHSA-hfmf-h398-rr97.json | 4 +-
.../GHSA-hfr4-7364-jv2q.json | 4 +-
.../GHSA-hg5g-m3rr-7xx2.json | 4 +-
.../GHSA-hgjj-3x23-5xv2.json | 11 +-
.../GHSA-hh2j-wjqr-83pc.json | 4 +-
.../GHSA-hhpr-xj4f-5p6q.json | 4 +-
.../GHSA-hmvm-g3wg-h58r.json | 4 +-
.../GHSA-hp8q-38h9-gmmv.json | 11 +-
.../GHSA-hqj4-p6qw-7mf2.json | 4 +-
.../GHSA-hqmv-5rff-cqrx.json | 4 +-
.../GHSA-hrf7-7wwm-qrvh.json | 4 +-
.../GHSA-hrjc-cqfh-wxgv.json | 4 +-
.../GHSA-hv42-72cg-mr2j.json | 4 +-
.../GHSA-hw85-44xg-3h9f.json | 4 +-
.../GHSA-hwcv-rwgg-wfrh.json | 4 +-
.../GHSA-hwhm-x7h4-2284.json | 4 +-
.../GHSA-hx67-h5vf-9cfq.json | 4 +-
.../GHSA-j2h9-jq5m-473h.json | 4 +-
.../GHSA-j2q7-6q2x-2q9p.json | 4 +-
.../GHSA-j38r-mq7j-wgvr.json | 4 +-
.../GHSA-j438-gf7h-pvjh.json | 11 +-
.../GHSA-j5gv-w838-mmcx.json | 4 +-
.../GHSA-j5wm-92c4-p546.json | 11 +-
.../GHSA-j5xw-gh42-g53c.json | 4 +-
.../GHSA-j62j-mjvg-xgrq.json | 4 +-
.../GHSA-j663-6jpj-xx8c.json | 4 +-
.../GHSA-j6cr-wmfq-h73p.json | 4 +-
.../GHSA-j6r3-vq2c-4ghw.json | 4 +-
.../GHSA-j6vq-hjmf-4p85.json | 9 +-
.../GHSA-j76p-cmp2-vxj3.json | 4 +-
.../GHSA-j7gf-5v9f-v496.json | 4 +-
.../GHSA-j7mh-fcjh-vp2q.json | 4 +-
.../GHSA-j7wf-qmpf-6v3c.json | 4 +-
.../GHSA-j8cp-xjh5-74x4.json | 4 +-
.../GHSA-j8g4-qgjp-w2g8.json | 4 +-
.../GHSA-j8rr-p259-7wpm.json | 4 +-
.../GHSA-j98c-6x58-jmvw.json | 4 +-
.../GHSA-jf22-c97p-4hxv.json | 4 +-
.../GHSA-jf4r-vjvc-pj36.json | 4 +-
.../GHSA-jfmm-v8pp-89h8.json | 4 +-
.../GHSA-jgfr-c5jr-627r.json | 11 +-
.../GHSA-jgpr-gfxw-cgxq.json | 4 +-
.../GHSA-jh8v-f3wq-v85p.json | 4 +-
.../GHSA-jhcx-vwjq-7w4c.json | 4 +-
.../GHSA-jhg8-2q46-wfq7.json | 4 +-
.../GHSA-jhg8-jx4g-7x8h.json | 4 +-
.../GHSA-jjxw-34h2-rrhg.json | 11 +-
.../GHSA-jm5q-9m8m-p5p5.json | 4 +-
.../GHSA-jp3p-m9qw-pgfj.json | 9 +-
.../GHSA-jp8v-q88c-wmpm.json | 4 +-
.../GHSA-jpgp-pmqh-538w.json | 9 +-
.../GHSA-jppc-gxqh-pgw5.json | 4 +-
.../GHSA-jpq4-mchv-jv8r.json | 11 +-
.../GHSA-jq2h-j9qf-53rv.json | 4 +-
.../GHSA-jqqc-vv26-h55v.json | 7 +-
.../GHSA-jqxm-w4mh-hq99.json | 4 +-
.../GHSA-jr64-37xj-g5qc.json | 4 +-
.../GHSA-jrmm-33p6-jvrr.json | 4 +-
.../GHSA-jrq4-jwcw-x9x4.json | 4 +-
.../GHSA-jrqx-4ghm-m5qq.json | 4 +-
.../GHSA-jv9m-jp3m-8vjq.json | 4 +-
.../GHSA-jvcq-3v53-v38c.json | 4 +-
.../GHSA-jx3j-p7wg-qg83.json | 4 +-
.../GHSA-jxhx-66x5-h397.json | 4 +-
.../GHSA-m276-5338-rwf8.json | 4 +-
.../GHSA-m276-v8xm-46jm.json | 4 +-
.../GHSA-m2cg-wrh8-h3xx.json | 4 +-
.../GHSA-m2g3-pg3w-frm3.json | 7 +-
.../GHSA-m37q-25f6-v3p9.json | 4 +-
.../GHSA-m3cj-392g-3vvg.json | 4 +-
.../GHSA-m3gg-5v93-qrhg.json | 11 +-
.../GHSA-m3gw-cj93-vpfv.json | 4 +-
.../GHSA-m3q4-xp7h-m6pw.json | 4 +-
.../GHSA-m3x8-pm7x-r5mj.json | 4 +-
.../GHSA-m486-7gcf-2983.json | 4 +-
.../GHSA-m4g4-hvch-vhgf.json | 11 +-
.../GHSA-m5x7-2x5r-8m3f.json | 11 +-
.../GHSA-m63v-p8hp-rg28.json | 4 +-
.../GHSA-m6cj-mh5r-8m7w.json | 7 +-
.../GHSA-m6mv-6jvc-p4xv.json | 4 +-
.../GHSA-m6vm-37g8-gqvh.json | 8 +-
.../GHSA-m6vw-rhwf-xjxq.json | 4 +-
.../GHSA-m745-jcvj-8cx6.json | 11 +-
.../GHSA-m79x-fpgm-vgr7.json | 11 +-
.../GHSA-m7jf-8pgq-2mqc.json | 4 +-
.../GHSA-m8hv-934h-rrx4.json | 4 +-
.../GHSA-m8m2-8cm8-p8jv.json | 6 +-
.../GHSA-m8qw-xmhp-rq5v.json | 4 +-
.../GHSA-m95x-53px-rf76.json | 4 +-
.../GHSA-m98r-vcx2-w27j.json | 4 +-
.../GHSA-m9mf-9j6p-6pq4.json | 11 +-
.../GHSA-m9q5-2qrh-wq37.json | 4 +-
.../GHSA-mc66-gqxj-pwmg.json | 9 +-
.../GHSA-mc6f-pv36-prr2.json | 4 +-
.../GHSA-mcm3-pfm7-4jqc.json | 4 +-
.../GHSA-mf6p-742g-5xxf.json | 4 +-
.../GHSA-mfjh-chmq-4prp.json | 9 +-
.../GHSA-mfrv-mqm7-5gq4.json | 4 +-
.../GHSA-mhh8-w4c2-86mr.json | 4 +-
.../GHSA-mj48-4fj3-6fjg.json | 4 +-
.../GHSA-mjf7-677g-49gx.json | 4 +-
.../GHSA-mjq5-3fch-g47q.json | 4 +-
.../GHSA-mm53-7fpm-65wv.json | 4 +-
.../GHSA-mm89-gccr-q279.json | 4 +-
.../GHSA-mphg-9rp5-xxj5.json | 4 +-
.../GHSA-mqx8-vg45-6p4q.json | 4 +-
.../GHSA-mrh7-ghhj-6r6w.json | 4 +-
.../GHSA-mrmx-w3x5-x556.json | 4 +-
.../GHSA-mvgw-crv9-m67p.json | 7 +-
.../GHSA-mw6g-jfc3-6x9v.json | 4 +-
.../GHSA-mwvw-6ggj-fhv5.json | 4 +-
.../GHSA-mwx4-p8m2-4p2h.json | 4 +-
.../GHSA-mx2h-qjgg-2vv4.json | 11 +-
.../GHSA-mxc9-v9vg-4xfw.json | 4 +-
.../GHSA-p28p-p2pv-wq98.json | 4 +-
.../GHSA-p32x-38hp-2r9x.json | 4 +-
.../GHSA-p3c7-jpcr-hr4q.json | 4 +-
.../GHSA-p3m2-9555-cgrw.json | 4 +-
.../GHSA-p3qx-72c8-xc9p.json | 4 +-
.../GHSA-p42g-23f7-4prj.json | 4 +-
.../GHSA-p47p-mr97-m42h.json | 4 +-
.../GHSA-p492-rhv2-844c.json | 4 +-
.../GHSA-p4f9-fq6j-5cff.json | 4 +-
.../GHSA-p54m-3wc3-2mv6.json | 4 +-
.../GHSA-p567-4mpc-fq6p.json | 4 +-
.../GHSA-p583-5mfr-xmp2.json | 4 +-
.../GHSA-p678-r7cm-66fh.json | 4 +-
.../GHSA-p6qf-pwx3-wfwf.json | 4 +-
.../GHSA-p78w-ghp7-m4p3.json | 4 +-
.../GHSA-p7g5-687r-f7jc.json | 11 +-
.../GHSA-p7jx-m4x8-cghf.json | 11 +-
.../GHSA-p7q4-fcj5-j6x7.json | 4 +-
.../GHSA-p8w3-h8rp-r2hj.json | 4 +-
.../GHSA-p96p-f58w-gwc6.json | 11 +-
.../GHSA-p9mf-x9hh-r538.json | 4 +-
.../GHSA-pc6g-crww-hwrf.json | 4 +-
.../GHSA-pfv4-p727-hwgq.json | 4 +-
.../GHSA-pfwv-624m-h3m9.json | 4 +-
.../GHSA-pg47-79wc-w499.json | 4 +-
.../GHSA-pgcm-23q3-r64w.json | 4 +-
.../GHSA-pj73-2q4q-jx35.json | 4 +-
.../GHSA-pj99-jgm5-c727.json | 11 +-
.../GHSA-pjgc-6mr2-9jx3.json | 4 +-
.../GHSA-pjgc-q78w-v6ph.json | 4 +-
.../GHSA-pjgq-qrmj-w46x.json | 4 +-
.../GHSA-pmmx-5xxg-mxh5.json | 11 +-
.../GHSA-pqgv-m3cr-37hw.json | 4 +-
.../GHSA-pr44-2445-9366.json | 4 +-
.../GHSA-prmr-w665-vw34.json | 4 +-
.../GHSA-pv22-ff8w-9h7r.json | 4 +-
.../GHSA-pv8r-9v7r-hr5c.json | 4 +-
.../GHSA-pvjf-v9wm-73fj.json | 4 +-
.../GHSA-pwfh-gp98-cccx.json | 4 +-
.../GHSA-pwfx-qrrf-76cp.json | 4 +-
.../GHSA-pxfv-24mx-mrvc.json | 4 +-
.../GHSA-q235-62fh-xp9w.json | 4 +-
.../GHSA-q2mj-6ff7-3gvh.json | 4 +-
.../GHSA-q438-9265-rccj.json | 9 +-
.../GHSA-q499-4369-cpxq.json | 4 +-
.../GHSA-q4q3-fg32-45m8.json | 4 +-
.../GHSA-q5cp-3jrf-3q9p.json | 4 +-
.../GHSA-q5mg-3r24-hvx2.json | 4 +-
.../GHSA-q5qf-qc2j-h64w.json | 4 +-
.../GHSA-q5xh-mxrq-59gx.json | 4 +-
.../GHSA-q62w-24vx-vhfg.json | 4 +-
.../GHSA-q6rf-xpm8-9wqx.json | 11 +-
.../GHSA-q775-f869-g43r.json | 4 +-
.../GHSA-q7vg-v528-qjwj.json | 4 +-
.../GHSA-q84w-p2g5-rxw9.json | 5 +-
.../GHSA-q8cx-3xf8-m9w4.json | 4 +-
.../GHSA-q8pj-w683-cp52.json | 4 +-
.../GHSA-q8w9-3c5w-2mhv.json | 4 +-
.../GHSA-q92r-cx7h-2f3j.json | 8 +-
.../GHSA-q98j-84jm-w837.json | 4 +-
.../GHSA-q9v9-cm52-vqj5.json | 4 +-
.../GHSA-qc92-q864-m3mh.json | 4 +-
.../GHSA-qfw9-g7jh-72p3.json | 4 +-
.../GHSA-qg2v-xqqh-rxvv.json | 4 +-
.../GHSA-qgg9-7g95-6v4j.json | 11 +-
.../GHSA-qgm6-p3q3-r5mp.json | 4 +-
.../GHSA-qh48-5646-82cv.json | 4 +-
.../GHSA-qhc9-rg5r-4qv3.json | 4 +-
.../GHSA-qj3c-jhpr-p28m.json | 4 +-
.../GHSA-qmhg-c8c8-6m24.json | 4 +-
.../GHSA-qmv3-76vc-754w.json | 4 +-
.../GHSA-qp4h-xpf2-fc6c.json | 4 +-
.../GHSA-qpg6-4w2g-v5f5.json | 4 +-
.../GHSA-qq98-52pp-9245.json | 4 +-
.../GHSA-qqmx-f648-jpq4.json | 4 +-
.../GHSA-qr56-4922-vccv.json | 4 +-
.../GHSA-qr8h-rg34-whwf.json | 9 +-
.../GHSA-qrhv-m52g-wcw8.json | 4 +-
.../GHSA-qrm9-mm7m-8xgw.json | 4 +-
.../GHSA-qvh2-rg4v-27xj.json | 4 +-
.../GHSA-qxjh-36c6-ww4r.json | 4 +-
.../GHSA-qxp6-m9jg-58rw.json | 4 +-
.../GHSA-qxr9-324x-2r4p.json | 4 +-
.../GHSA-r22f-cv66-85xr.json | 4 +-
.../GHSA-r2hq-xr24-chr5.json | 4 +-
.../GHSA-r2vj-428g-v68v.json | 4 +-
.../GHSA-r3c5-fgch-pmpm.json | 4 +-
.../GHSA-r3xw-5c7m-743g.json | 4 +-
.../GHSA-r45f-qh5g-8496.json | 4 +-
.../GHSA-r4fj-mm48-prvv.json | 4 +-
.../GHSA-r4g9-49vg-wwc7.json | 11 +-
.../GHSA-r4p3-fhf3-gwvv.json | 4 +-
.../GHSA-r57m-5qwg-3ccx.json | 11 +-
.../GHSA-r6cf-cv75-5928.json | 4 +-
.../GHSA-r6fm-r8h7-c67g.json | 4 +-
.../GHSA-r6j8-w974-w846.json | 9 +-
.../GHSA-r6wp-r547-f9gf.json | 4 +-
.../GHSA-r738-3h9r-fpvv.json | 4 +-
.../GHSA-r78r-gvgq-2chj.json | 4 +-
.../GHSA-r7w5-7g5j-xmxj.json | 4 +-
.../GHSA-r86r-95mc-vg6p.json | 4 +-
.../GHSA-r8wq-3m37-8m4m.json | 4 +-
.../GHSA-rcf7-xjfr-3cgc.json | 4 +-
.../GHSA-rcgg-pr6j-3pmh.json | 4 +-
.../GHSA-rcq5-59gf-jqxv.json | 4 +-
.../GHSA-rff2-w9c9-q4gc.json | 11 +-
.../GHSA-rff8-hf8p-29h7.json | 4 +-
.../GHSA-rfmr-g36p-h7hg.json | 4 +-
.../GHSA-rfrw-m2jx-m42j.json | 4 +-
.../GHSA-rg52-86vx-997f.json | 4 +-
.../GHSA-rg8p-4m72-g4mp.json | 4 +-
.../GHSA-rgg4-rgq7-84pp.json | 11 +-
.../GHSA-rggm-rhpj-48vx.json | 4 +-
.../GHSA-rgx4-jh4p-m887.json | 4 +-
.../GHSA-rjg8-3hfx-6fxx.json | 4 +-
.../GHSA-rjhv-95gq-rwv4.json | 4 +-
.../GHSA-rjj3-fg8r-3rr5.json | 4 +-
.../GHSA-rjm7-96c8-22jg.json | 4 +-
.../GHSA-rm5h-68jf-f7v7.json | 4 +-
.../GHSA-rm9j-9ph9-4h45.json | 4 +-
.../GHSA-rq36-9f5f-2gw7.json | 4 +-
.../GHSA-rq7j-h64w-rghf.json | 4 +-
.../GHSA-rq9v-22cg-86qc.json | 4 +-
.../GHSA-rqj6-qq4v-5w96.json | 4 +-
.../GHSA-rqp9-whcw-xww5.json | 4 +-
.../GHSA-rqr7-5xf4-6wh2.json | 11 +-
.../GHSA-rqrp-8f48-953h.json | 4 +-
.../GHSA-rv9v-x78f-m73w.json | 4 +-
.../GHSA-rvj7-4p84-v4cg.json | 11 +-
.../GHSA-rvw9-8m2p-4pgm.json | 4 +-
.../GHSA-rwvj-m246-jv4x.json | 4 +-
.../GHSA-v2hx-f34m-8276.json | 4 +-
.../GHSA-v38m-2fgx-2r9p.json | 4 +-
.../GHSA-v3fx-p4xm-rv4x.json | 4 +-
.../GHSA-v3qf-4pxv-m9xf.json | 4 +-
.../GHSA-v4vw-f7vp-84w3.json | 4 +-
.../GHSA-v697-7hq7-978f.json | 11 +-
.../GHSA-v725-xj67-9v99.json | 4 +-
.../GHSA-v7qj-g6j7-8wq9.json | 4 +-
.../GHSA-v85h-7j57-3529.json | 4 +-
.../GHSA-v986-xf39-cqrw.json | 11 +-
.../GHSA-v994-7f87-hh83.json | 4 +-
.../GHSA-vcf5-8489-9vj6.json | 11 +-
.../GHSA-vcrv-8fh9-j64x.json | 4 +-
.../GHSA-vfgj-vqjw-hh7g.json | 4 +-
.../GHSA-vg5x-5wm4-7r4x.json | 4 +-
.../GHSA-vj2w-frgg-mff6.json | 4 +-
.../GHSA-vm4p-cgrm-3hvm.json | 4 +-
.../GHSA-vm8f-qpq4-4vw6.json | 11 +-
.../GHSA-vmvv-5f2v-26q8.json | 4 +-
.../GHSA-vmx7-gqgq-2jhh.json | 4 +-
.../GHSA-vpx5-mhrx-64h5.json | 9 +-
.../GHSA-vr7r-prw9-wjpq.json | 4 +-
.../GHSA-vrpg-hfmh-2gwf.json | 4 +-
.../GHSA-vvc5-h94x-p72m.json | 4 +-
.../GHSA-vwm5-j2mm-8pxx.json | 4 +-
.../GHSA-vx25-5r7c-m73f.json | 4 +-
.../GHSA-vx32-2j79-22fm.json | 4 +-
.../GHSA-vx4h-jx68-6g52.json | 4 +-
.../GHSA-vx79-v9rq-vjp5.json | 4 +-
.../GHSA-vxwp-6hpw-p9g4.json | 4 +-
.../GHSA-w25r-hpmc-xhc2.json | 4 +-
.../GHSA-w25v-58xw-9xcx.json | 9 +-
.../GHSA-w279-72w5-rrq7.json | 11 +-
.../GHSA-w2g3-j73q-7qv7.json | 4 +-
.../GHSA-w2mg-g9h8-g57f.json | 4 +-
.../GHSA-w3wr-rggh-27pq.json | 4 +-
.../GHSA-w42r-qhq4-9fc9.json | 4 +-
.../GHSA-w4jx-8cv4-c4v7.json | 4 +-
.../GHSA-w5w4-gqf5-fh33.json | 4 +-
.../GHSA-w5wv-98xr-mhmx.json | 4 +-
.../GHSA-w695-r3qx-vgwq.json | 4 +-
.../GHSA-w6rw-h3mq-8rp8.json | 4 +-
.../GHSA-w72r-ch4p-xqg3.json | 4 +-
.../GHSA-w74v-6wvv-qx6w.json | 4 +-
.../GHSA-w7q5-62h8-hhmc.json | 4 +-
.../GHSA-w833-px7j-q64c.json | 7 +-
.../GHSA-wc67-fg6q-qm47.json | 4 +-
.../GHSA-wc9v-c62x-353g.json | 4 +-
.../GHSA-wcj6-qwxq-5x5h.json | 4 +-
.../GHSA-wf9m-2866-7623.json | 4 +-
.../GHSA-wfjp-4mpm-mr6x.json | 4 +-
.../GHSA-wg44-xvpw-f949.json | 4 +-
.../GHSA-whjp-vqw5-874c.json | 4 +-
.../GHSA-wj4x-x659-777v.json | 4 +-
.../GHSA-wj86-wmr8-wpx4.json | 4 +-
.../GHSA-wp7p-cgcx-mwrm.json | 4 +-
.../GHSA-wpvc-39pm-wp2r.json | 4 +-
.../GHSA-wq72-w6pg-xxqp.json | 11 +-
.../GHSA-wqrx-2j54-p3fc.json | 4 +-
.../GHSA-wqw5-fg63-857m.json | 4 +-
.../GHSA-wr6j-q48c-hx4c.json | 4 +-
.../GHSA-wrcg-8gp5-rhrm.json | 4 +-
.../GHSA-wrh7-xqxc-wghp.json | 4 +-
.../GHSA-wvm9-mq8w-wrm8.json | 4 +-
.../GHSA-wwff-qqfj-cv2g.json | 4 +-
.../GHSA-wwfp-p79h-2x5v.json | 4 +-
.../GHSA-wx55-4qhm-8qw2.json | 4 +-
.../GHSA-wxgq-cmv5-57qx.json | 4 +-
.../GHSA-wxww-3fw5-44w4.json | 4 +-
.../GHSA-x529-3p36-rxh5.json | 4 +-
.../GHSA-x578-82rc-944x.json | 4 +-
.../GHSA-x57h-259q-ggjv.json | 4 +-
.../GHSA-x63c-6jx4-44mv.json | 4 +-
.../GHSA-x7gg-f2xv-xw56.json | 4 +-
.../GHSA-x9hv-97wr-x4j8.json | 4 +-
.../GHSA-xc8p-j5f8-7w98.json | 11 +-
.../GHSA-xf6j-84wr-6vq4.json | 11 +-
.../GHSA-xfh2-4rhf-q57x.json | 4 +-
.../GHSA-xfmg-8p5c-72jm.json | 4 +-
.../GHSA-xgf4-vh79-4g7j.json | 4 +-
.../GHSA-xgm7-5784-5cxv.json | 4 +-
.../GHSA-xh9r-6fmf-q43q.json | 4 +-
.../GHSA-xhm8-r9jc-63fw.json | 4 +-
.../GHSA-xmxw-j4c5-629g.json | 4 +-
.../GHSA-xp27-gwqx-8qx4.json | 4 +-
.../GHSA-xph7-mv6p-642w.json | 11 +-
.../GHSA-xpvj-vm4g-wmjm.json | 4 +-
.../GHSA-xpvx-v3vc-27gc.json | 4 +-
.../GHSA-xq43-hwmx-8g8w.json | 4 +-
.../GHSA-xqpc-wjc5-8chx.json | 4 +-
.../GHSA-xqxc-686p-m2m3.json | 4 +-
.../GHSA-xrwj-6h7r-w997.json | 4 +-
.../GHSA-xrxc-cv69-f3fp.json | 4 +-
.../GHSA-xv96-5q4x-p79p.json | 4 +-
.../GHSA-xvwc-m4qj-9wr9.json | 4 +-
.../GHSA-xw7q-2j98-xv6p.json | 4 +-
.../GHSA-xx33-j3mf-gffc.json | 4 +-
.../GHSA-xxc8-gpg2-9w9f.json | 4 +-
.../GHSA-xxvm-h2mx-9mwj.json | 4 +-
.../GHSA-273x-mxvr-9vx2.json | 6 +-
.../GHSA-cmph-x6r4-4whr.json | 18 ++-
.../GHSA-fxmj-6xv8-f3m7.json | 6 +-
.../GHSA-g9mf-qvgg-vwxr.json | 13 +-
.../GHSA-mj54-2qgh-27pf.json | 6 +-
.../GHSA-q52q-f54c-xmvp.json | 14 +-
.../GHSA-q5mw-2cvx-mjj3.json | 6 +-
.../GHSA-w6qf-42m7-vh68.json | 18 ++-
.../GHSA-85v9-53x3-q4xp.json | 6 +-
.../GHSA-9hpm-6w4c-hxh2.json | 6 +-
.../GHSA-hv2r-vh4p-hqmp.json | 6 +-
.../GHSA-j3p2-j2wj-5w6g.json | 6 +-
.../GHSA-mfw5-pp35-j4h8.json | 18 ++-
.../GHSA-pg2q-wfgh-r323.json | 2 +-
.../GHSA-pvrq-gg3w-f695.json | 6 +-
.../GHSA-q99v-mcmh-7x5m.json | 6 +-
.../GHSA-vmqf-grh3-9rrr.json | 6 +-
.../GHSA-vww6-323c-pxr2.json | 6 +-
.../GHSA-w5g2-4rxc-h7x8.json | 6 +-
.../GHSA-x28p-h97m-3347.json | 6 +-
.../GHSA-xqf9-qrgq-fxfv.json | 6 +-
.../GHSA-2252-87pv-34g4.json | 63 ++++++++
.../GHSA-25gg-qp55-68p3.json | 39 +++++
.../GHSA-29xc-2rhm-5f2q.json | 35 +++++
.../GHSA-2pv2-gg54-r8f4.json | 43 +++++
.../GHSA-2q2v-8vjq-r8m5.json | 42 +++++
.../GHSA-2vp9-gjfg-fmgw.json | 6 +-
.../GHSA-346g-pfrw-wm3v.json | 38 +++++
.../GHSA-3fpg-5xv7-pq63.json | 35 +++++
.../GHSA-3fpg-j8cw-vcjq.json | 42 +++++
.../GHSA-3h96-p8ww-vw66.json | 42 +++++
.../GHSA-3mvj-7p7p-x4x5.json | 38 +++++
.../GHSA-3v83-crv9-cf9p.json | 63 ++++++++
.../GHSA-3xr5-7rvh-x3v2.json | 38 +++++
.../GHSA-43fc-v55w-5mx4.json | 38 +++++
.../GHSA-44wr-9xpq-76v2.json | 47 ++++++
.../GHSA-4965-8838-r53x.json | 38 +++++
.../GHSA-4cqm-42fg-6pwv.json | 38 +++++
.../GHSA-4jvv-2c5h-wr97.json | 59 +++++++
.../GHSA-4q8v-gqw7-8xpx.json | 47 ++++++
.../GHSA-4ww3-585w-6p9r.json | 38 +++++
.../GHSA-4x7j-vfwq-rj38.json | 35 +++++
.../GHSA-55vp-7jr8-5mm9.json | 38 +++++
.../GHSA-5656-3635-q384.json | 35 +++++
.../GHSA-56m7-9pwj-r76p.json | 35 +++++
.../GHSA-5g26-fc68-x9f2.json | 6 +-
.../GHSA-5h4m-75jp-hg7m.json | 35 +++++
.../GHSA-5mg2-h7qv-m552.json | 55 +++++++
.../GHSA-5qc4-82jh-h385.json | 35 +++++
.../GHSA-5rw8-2rrx-mf5m.json | 38 +++++
.../GHSA-5xrf-xvwc-pmfg.json | 38 +++++
.../GHSA-6426-p644-ffcf.json | 38 +++++
.../GHSA-69h6-fpm9-fc3r.json | 55 +++++++
.../GHSA-6gmw-8x48-q8ww.json | 35 +++++
.../GHSA-6jfg-4px6-v4c9.json | 38 +++++
.../GHSA-6jqp-mm8h-jjgv.json | 55 +++++++
.../GHSA-6x3j-xjx9-j84h.json | 35 +++++
.../GHSA-78h8-m693-fp8x.json | 38 +++++
.../GHSA-7g5r-fqfh-59j6.json | 43 +++++
.../GHSA-7hfh-vfcv-wfqp.json | 38 +++++
.../GHSA-7vqv-4gqw-665q.json | 63 ++++++++
.../GHSA-7w6v-jhvx-qx5c.json | 47 ++++++
.../GHSA-7xpv-78qx-q843.json | 63 ++++++++
.../GHSA-85q5-wrpf-m53q.json | 46 ++++++
.../GHSA-85r2-29g6-f4w7.json | 38 +++++
.../GHSA-866j-mv4h-26jh.json | 51 ++++++
.../GHSA-8f9g-693j-6rw3.json | 38 +++++
.../GHSA-8fvm-73q4-3j6f.json | 38 +++++
.../GHSA-8vf4-q8g2-79g5.json | 55 +++++++
.../GHSA-8xc6-54p8-3p65.json | 43 +++++
.../GHSA-8xr9-89pc-8wcx.json | 38 +++++
.../GHSA-9243-vfr2-5rcw.json | 38 +++++
.../GHSA-95rc-29j2-q3vr.json | 51 ++++++
.../GHSA-96rw-9jfw-gw2m.json | 54 +++++++
.../GHSA-9fvf-9v35-97qv.json | 35 +++++
.../GHSA-9m65-6pjm-r78p.json | 35 +++++
.../GHSA-9m7w-p6hr-xv2x.json | 54 +++++++
.../GHSA-9rp8-67w7-gf47.json | 55 +++++++
.../GHSA-9wj5-w226-r39m.json | 38 +++++
.../GHSA-c3rj-rhqm-q53c.json | 38 +++++
.../GHSA-c4ch-cv96-r58v.json | 35 +++++
.../GHSA-cm2m-f7gc-hv64.json | 42 +++++
.../GHSA-cq4r-22pw-4cc7.json | 46 ++++++
.../GHSA-cxc3-9vgm-w6pp.json | 38 +++++
.../GHSA-f34w-8j75-rh85.json | 55 +++++++
.../GHSA-ffgg-5wp9-rrp5.json | 38 +++++
.../GHSA-fgh4-9fc9-vxgv.json | 38 +++++
.../GHSA-fp6w-hx4c-x44g.json | 55 +++++++
.../GHSA-fpf4-cfch-367m.json | 55 +++++++
.../GHSA-frw5-678v-439g.json | 43 +++++
.../GHSA-gj3p-9jv7-cm49.json | 50 ++++++
.../GHSA-gj98-2c7c-vmc4.json | 47 ++++++
.../GHSA-gvmc-5p79-xx55.json | 35 +++++
.../GHSA-h2vw-qxx3-m3jv.json | 6 +-
.../GHSA-h88c-q974-86mm.json | 35 +++++
.../GHSA-hg8p-x2hq-57m9.json | 50 ++++++
.../GHSA-hhxq-r4w4-4f7m.json | 39 +++++
.../GHSA-j2g4-vr97-pwvm.json | 51 ++++++
.../GHSA-j4vc-q2qg-4hj8.json | 38 +++++
.../GHSA-j4x2-5qq6-fvpq.json | 38 +++++
.../GHSA-jf7f-5899-cj5x.json | 42 +++++
.../GHSA-jh5x-r89q-r9g4.json | 50 ++++++
.../GHSA-jj9v-ff2v-cgx9.json | 59 +++++++
.../GHSA-jv67-jxg9-q8v4.json | 43 +++++
.../GHSA-mcfm-cxwv-vq32.json | 35 +++++
.../GHSA-mcgw-94j6-6g4q.json | 6 +-
.../GHSA-mfj7-pc34-cqm8.json | 38 +++++
.../GHSA-mq9r-62m5-pjc2.json | 38 +++++
.../GHSA-mqqf-4p7r-rf89.json | 42 +++++
.../GHSA-p499-wvm3-j86w.json | 39 +++++
.../GHSA-p8g6-7v7w-4whg.json | 55 +++++++
.../GHSA-pfjp-fv5p-fjx7.json | 59 +++++++
.../GHSA-pjr2-pwcr-ffrh.json | 39 +++++
.../GHSA-ppf4-83qq-m3fm.json | 35 +++++
.../GHSA-q4hp-86wf-hj44.json | 47 ++++++
.../GHSA-q6w6-rjjj-5p52.json | 42 +++++
.../GHSA-qfh3-r9xh-mmwf.json | 35 +++++
.../GHSA-qgf9-6cxx-q2qv.json | 35 +++++
.../GHSA-qgpm-9vqg-rgrr.json | 39 +++++
.../GHSA-qgq8-952v-8jwq.json | 38 +++++
.../GHSA-qhq3-q3p4-4fxm.json | 38 +++++
.../GHSA-qv7c-pjpr-grqx.json | 59 +++++++
.../GHSA-r596-ggc2-8m6g.json | 38 +++++
.../GHSA-r7p6-cff4-g6q4.json | 51 ++++++
.../GHSA-rhvv-h8rg-3gxq.json | 42 +++++
.../GHSA-rj8v-47w4-c66w.json | 38 +++++
.../GHSA-rm2h-rx39-6fc3.json | 55 +++++++
.../GHSA-rmrx-q6x5-whjx.json | 50 ++++++
.../GHSA-rqhw-p5r2-7vq4.json | 6 +-
.../GHSA-rr4c-9mp9-8wp6.json | 35 +++++
.../GHSA-vm4m-6mf9-8885.json | 38 +++++
.../GHSA-vmgj-7wpp-x799.json | 38 +++++
.../GHSA-vqhg-mqww-h64x.json | 35 +++++
.../GHSA-w322-w9fv-rx3m.json | 42 +++++
.../GHSA-w59w-35q3-vcg7.json | 35 +++++
.../GHSA-w5wq-cvfc-3r8g.json | 39 +++++
.../GHSA-w68v-jm79-7cvv.json | 38 +++++
.../GHSA-w94f-xh79-q24v.json | 39 +++++
.../GHSA-w9gh-mc2w-wrg3.json | 42 +++++
.../GHSA-w9qr-vr3p-gqmx.json | 43 +++++
.../GHSA-wm99-2g28-jp5m.json | 51 ++++++
.../GHSA-wxqf-qvrv-xr8r.json | 35 +++++
.../GHSA-x4pp-356g-v2qr.json | 43 +++++
999 files changed, 9323 insertions(+), 1886 deletions(-)
create mode 100644 advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-4685-2x5r-65pj/GHSA-4685-2x5r-65pj.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-5pgg-2g8v-p4x9/GHSA-5pgg-2g8v-p4x9.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-6cf6-8hvr-r68w/GHSA-6cf6-8hvr-r68w.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-9qxr-qj54-h672/GHSA-9qxr-qj54-h672.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-j2rp-gmqv-frhv/GHSA-j2rp-gmqv-frhv.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-mcw6-3256-64gg/GHSA-mcw6-3256-64gg.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-vc6q-ccj9-9r89/GHSA-vc6q-ccj9-9r89.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-w67v-ph4x-f48q/GHSA-w67v-ph4x-f48q.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-wp43-vprh-c3w5/GHSA-wp43-vprh-c3w5.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-wpff-wm84-x5cx/GHSA-wpff-wm84-x5cx.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-x9xc-63hg-vcfq/GHSA-x9xc-63hg-vcfq.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json
create mode 100644 advisories/github-reviewed/2024/04/GHSA-xp9j-8p68-9q93/GHSA-xp9j-8p68-9q93.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-25gg-qp55-68p3/GHSA-25gg-qp55-68p3.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3fpg-5xv7-pq63/GHSA-3fpg-5xv7-pq63.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3mvj-7p7p-x4x5/GHSA-3mvj-7p7p-x4x5.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4cqm-42fg-6pwv/GHSA-4cqm-42fg-6pwv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-55vp-7jr8-5mm9/GHSA-55vp-7jr8-5mm9.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5rw8-2rrx-mf5m/GHSA-5rw8-2rrx-mf5m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-5xrf-xvwc-pmfg/GHSA-5xrf-xvwc-pmfg.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-6gmw-8x48-q8ww/GHSA-6gmw-8x48-q8ww.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-6x3j-xjx9-j84h/GHSA-6x3j-xjx9-j84h.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-78h8-m693-fp8x/GHSA-78h8-m693-fp8x.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-85r2-29g6-f4w7/GHSA-85r2-29g6-f4w7.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-8f9g-693j-6rw3/GHSA-8f9g-693j-6rw3.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-cm2m-f7gc-hv64/GHSA-cm2m-f7gc-hv64.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-ffgg-5wp9-rrp5/GHSA-ffgg-5wp9-rrp5.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-gvmc-5p79-xx55/GHSA-gvmc-5p79-xx55.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-h88c-q974-86mm/GHSA-h88c-q974-86mm.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-j4vc-q2qg-4hj8/GHSA-j4vc-q2qg-4hj8.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-j4x2-5qq6-fvpq/GHSA-j4x2-5qq6-fvpq.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-jf7f-5899-cj5x/GHSA-jf7f-5899-cj5x.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-jv67-jxg9-q8v4/GHSA-jv67-jxg9-q8v4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-mcfm-cxwv-vq32/GHSA-mcfm-cxwv-vq32.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-mfj7-pc34-cqm8/GHSA-mfj7-pc34-cqm8.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-pjr2-pwcr-ffrh/GHSA-pjr2-pwcr-ffrh.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-ppf4-83qq-m3fm/GHSA-ppf4-83qq-m3fm.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-rr4c-9mp9-8wp6/GHSA-rr4c-9mp9-8wp6.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-vmgj-7wpp-x799/GHSA-vmgj-7wpp-x799.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-vqhg-mqww-h64x/GHSA-vqhg-mqww-h64x.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-wxqf-qvrv-xr8r/GHSA-wxqf-qvrv-xr8r.json
create mode 100644 advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
diff --git a/advisories/github-reviewed/2022/12/GHSA-6xrf-q977-5vgc/GHSA-6xrf-q977-5vgc.json b/advisories/github-reviewed/2022/12/GHSA-6xrf-q977-5vgc/GHSA-6xrf-q977-5vgc.json
index 51e8c56c27c..ac2526c02f7 100644
--- a/advisories/github-reviewed/2022/12/GHSA-6xrf-q977-5vgc/GHSA-6xrf-q977-5vgc.json
+++ b/advisories/github-reviewed/2022/12/GHSA-6xrf-q977-5vgc/GHSA-6xrf-q977-5vgc.json
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xrf-q977-5vgc",
- "modified": "2023-01-06T03:21:28Z",
+ "modified": "2024-04-04T13:49:56Z",
"published": "2022-12-26T09:30:25Z",
"aliases": [
"CVE-2022-4742"
],
"summary": "json-pointer vulnerable to Prototype Pollution",
- "details": "A vulnerability, which was classified as critical, has been found in json-pointer. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The name of the patch is 859c9984b6c407fc2d5a0a7e47c7274daa681941. It is recommended to apply a patch to fix this issue. VDB-216794 is the identifier assigned to this vulnerability.",
+ "details": "A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. Upgrading to version 0.6.2 is able to address this issue. The patch is identified as 859c9984b6c407fc2d5a0a7e47c7274daa681941. It is recommended to upgrade the affected component. VDB-216794 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json b/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json
index 7eeab0642d7..c924560ec42 100644
--- a/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json
+++ b/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jfx-84v9-2rr2",
- "modified": "2024-04-01T18:30:58Z",
+ "modified": "2024-04-05T15:08:07Z",
"published": "2023-07-20T00:30:24Z",
"aliases": [
"CVE-2023-3299"
@@ -70,6 +70,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/nomad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://pkg.go.dev/vuln/GO-2024-2669"
}
],
"database_specific": {
diff --git a/advisories/github-reviewed/2023/07/GHSA-rpvr-38xv-xvxq/GHSA-rpvr-38xv-xvxq.json b/advisories/github-reviewed/2023/07/GHSA-rpvr-38xv-xvxq/GHSA-rpvr-38xv-xvxq.json
index 621d0708966..25606da6aa6 100644
--- a/advisories/github-reviewed/2023/07/GHSA-rpvr-38xv-xvxq/GHSA-rpvr-38xv-xvxq.json
+++ b/advisories/github-reviewed/2023/07/GHSA-rpvr-38xv-xvxq/GHSA-rpvr-38xv-xvxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rpvr-38xv-xvxq",
- "modified": "2024-04-01T18:33:25Z",
+ "modified": "2024-04-05T15:34:23Z",
"published": "2023-07-20T00:30:24Z",
"aliases": [
"CVE-2023-3072"
@@ -66,6 +66,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/nomad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://pkg.go.dev/vuln/GO-2024-2670"
}
],
"database_specific": {
diff --git a/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json b/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json
index 937d1203188..114002f52c9 100644
--- a/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json
+++ b/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5fm-hr72-27hx",
- "modified": "2024-04-01T19:17:38Z",
+ "modified": "2024-04-05T15:34:59Z",
"published": "2023-07-20T00:30:25Z",
"aliases": [
"CVE-2023-3300"
@@ -70,6 +70,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/nomad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://pkg.go.dev/vuln/GO-2024-2671"
}
],
"database_specific": {
diff --git a/advisories/github-reviewed/2023/10/GHSA-67hx-6x53-jw92/GHSA-67hx-6x53-jw92.json b/advisories/github-reviewed/2023/10/GHSA-67hx-6x53-jw92/GHSA-67hx-6x53-jw92.json
index 6e8fa57e853..92e56c6e2bf 100644
--- a/advisories/github-reviewed/2023/10/GHSA-67hx-6x53-jw92/GHSA-67hx-6x53-jw92.json
+++ b/advisories/github-reviewed/2023/10/GHSA-67hx-6x53-jw92/GHSA-67hx-6x53-jw92.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67hx-6x53-jw92",
- "modified": "2023-10-16T13:55:36Z",
+ "modified": "2024-04-04T14:26:10Z",
"published": "2023-10-16T13:55:36Z",
"aliases": [
"CVE-2023-45133"
@@ -52,6 +52,25 @@
]
}
]
+ },
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "babel-traverse"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "< 7.23.2"
+ }
}
],
"references": [
diff --git a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json
index 6c19c291065..f662d46c86f 100644
--- a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json
+++ b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5667-3wch-7q7w",
- "modified": "2024-04-03T15:30:41Z",
+ "modified": "2024-04-09T12:30:44Z",
"published": "2024-03-27T09:30:40Z",
"aliases": [
"CVE-2024-1023"
@@ -9,7 +9,10 @@
"summary": "Eclipse Vert.x memory leak",
"details": "A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
{
@@ -80,6 +83,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1662"
},
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1706"
+ },
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1023"
@@ -95,6 +102,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-119",
"CWE-200"
],
"severity": "MODERATE",
diff --git a/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json b/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json
new file mode 100644
index 00000000000..922e22d911b
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json
@@ -0,0 +1,69 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-27jx-ffw8-xrqv",
+ "modified": "2024-04-04T17:01:56Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-3116"
+ ],
+ "summary": "pgAdmin Remote Code Execution (RCE) vulnerability",
+ "details": "pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "PyPI",
+ "name": "pgadmin4"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "8.5"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3116"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/pgadmin-org/pgadmin4/issues/7326"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/pgadmin-org/pgadmin4/commit/fbbbfe22dd468bcfef1e1f833ec32289a6e56a8b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/aelmokhtar/689a8be7e3bd535ec01992d8ec7b2b98"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/pgadmin-org/pgadmin4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T17:01:56Z",
+ "nvd_published_at": "2024-04-04T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-2q59-h24c-w6fg/GHSA-2q59-h24c-w6fg.json b/advisories/github-reviewed/2024/04/GHSA-2q59-h24c-w6fg/GHSA-2q59-h24c-w6fg.json
index 96a72811048..7edfdc75f5f 100644
--- a/advisories/github-reviewed/2024/04/GHSA-2q59-h24c-w6fg/GHSA-2q59-h24c-w6fg.json
+++ b/advisories/github-reviewed/2024/04/GHSA-2q59-h24c-w6fg/GHSA-2q59-h24c-w6fg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q59-h24c-w6fg",
- "modified": "2024-04-03T14:13:02Z",
+ "modified": "2024-04-04T13:37:56Z",
"published": "2024-04-03T14:13:02Z",
"aliases": [
"CVE-2024-30265"
@@ -97,6 +97,10 @@
"type": "WEB",
"url": "https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30265"
+ },
{
"type": "WEB",
"url": "https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52"
@@ -129,6 +133,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-03T14:13:02Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-04-03T23:15:13Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-4685-2x5r-65pj/GHSA-4685-2x5r-65pj.json b/advisories/github-reviewed/2024/04/GHSA-4685-2x5r-65pj/GHSA-4685-2x5r-65pj.json
new file mode 100644
index 00000000000..07bc77522dd
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-4685-2x5r-65pj/GHSA-4685-2x5r-65pj.json
@@ -0,0 +1,148 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4685-2x5r-65pj",
+ "modified": "2024-04-05T15:07:16Z",
+ "published": "2024-04-05T15:03:03Z",
+ "aliases": [
+ "CVE-2024-3250"
+ ],
+ "summary": "Pebble service manager's file pull API allows access by any user",
+ "details": "### Impact\n\nNote: \"Pebble\" here refers to [Canonical's service manager](https://github.com/canonical/pebble), not the [Let's Encrypt ACME test server](https://github.com/letsencrypt/pebble).\n\nThe API behind `pebble pull`, used to read files from the workload container by Juju charms, allows access from any user, instead of just admin. In Juju Kubernetes sidecar charms, Pebble and the charm run as root, so they have full access. But if another restricted unix user gains local access to the container host, they could hit the Pebble `GET /v1/files?action=read` API and would be allowed to read any file in the workload container, for example an ssh key or database password or other sensitive information. If there are ssh keys they could then potentially ssh into the workload, or if something like a database password they could log into the database.\n\nNote that this requires local user access to the host machine. It seems unlikely that an attacker could gain this level of access in a Juju Kubernetes context, but if someone did and there's sensitive information in files accessible to Pebble, the consequences are bad.\n\nTo reproduce the issue, go back to the Pebble version in Juju 2.9 (5842ea68c9c7), do `pebble run` as root in one terminal window, then in another terminal window, as a regular user, use the `pebble pull` CLI. You will be able to pull any file as a regular user.\n\n### Patches\n\nThe original patch is commit https://github.com/canonical/pebble/commit/cd326225b9b0be067da7d8858e2c912078cbbbd5. There's also https://github.com/canonical/pebble/pull/406, which fixes this issue in more recent Pebble versions (that PR also fixes a separate issue we introduced more recently, but hasn't been released in Juju yet).\n\nWe released the fix in the following Pebble versions:\n\n- https://github.com/canonical/pebble/releases/tag/v1.1.1\n- https://github.com/canonical/pebble/releases/tag/v1.4.2\n- https://github.com/canonical/pebble/releases/tag/v1.7.4\n- https://github.com/canonical/pebble/releases/tag/v1.10.2\n\nJuju will be releasing patch versions with this fix shortly:\n\n- Juju 2.9.49 (Pebble v1.1.1)\n- Juju 3.1.8 (Pebble v1.4.2)\n- Juju 3.3.4 (Pebble v1.4.2)\n- Juju 3.4.2 (Pebble v1.7.4)\n- Juju 3.5.0 (Pebble v1.10.2)\n\n### References\n\n* https://www.cve.org/CVERecord?id=CVE-2024-3250\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/canonical/pebble"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.2.0"
+ },
+ {
+ "fixed": "1.4.2"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "< 1.4.1"
+ }
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/canonical/pebble"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.5.0"
+ },
+ {
+ "fixed": "1.7.3"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/canonical/pebble"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.8.0"
+ },
+ {
+ "fixed": "1.10.2"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "< 1.10.1"
+ }
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/canonical/pebble"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "1.1.1"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/security/advisories/GHSA-4685-2x5r-65pj"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3250"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/pull/406"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/commit/4ca343d3889533143477e21c63867f2f3c3b5645"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/commit/a5f6f062a11ea156697b854264385ff7e1985fd8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/commit/b8abd1ff0090f3e0749e81eb1fc3ea16ba95f514"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/commit/cd326225b9b0be067da7d8858e2c912078cbbbd5"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/canonical/pebble"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.cve.org/CVERecord?id=CVE-2024-3250"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:03:03Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json b/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json
new file mode 100644
index 00000000000..f9f957db008
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4v52-7q2x-v4xj",
+ "modified": "2024-04-05T15:08:53Z",
+ "published": "2024-04-05T15:08:53Z",
+ "aliases": [
+
+ ],
+ "summary": "eyre: Parts of Report are dropped as the wrong type during downcast",
+ "details": "In affected versions, after a `Report` is constructed using `wrap_err` or `wrap_err_with` to attach a message of type `D` onto an error of type `E`, then using `downcast` to recover ownership of either the value of type `D` or the value of type `E`, one of two things can go wrong:\n\n- If downcasting to `E`, there remains a value of type `D` to be dropped. It is incorrectly \"dropped\" by running `E`'s drop behavior, rather than `D`'s. For example if `D` is `&str` and `E` is `std::io::Error`, there would be a call of `std::io::Error::drop` in which the reference received by the `Drop` impl does not refer to a valid value of type `std::io::Error`, but instead to `&str`.\n\n- If downcasting to `D`, there remains a value of type `E` to be dropped. When `D` and `E` do not happen to be the same size, `E`'s drop behavior is incorrectly executed in the wrong location. The reference received by the `Drop` impl may point left or right of the real `E` value that is meant to be getting dropped.\n\nIn both cases, when the `Report` contains an error `E` that has nontrivial drop behavior, the most likely outcome is memory corruption.\n\nWhen the `Report` contains an error `E` that has trivial drop behavior (for example a `Utf8Error`) but where `D` has nontrivial drop behavior (such as `String`), the most likely outcome is that downcasting to `E` would leak `D`.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "eyre"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0.6.9"
+ },
+ {
+ "fixed": "0.6.12"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/eyre-rs/eyre/issues/141"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/eyre-rs/eyre/commit/770ac3fa1435eae3b166a4b072053360e38a0575"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/eyre-rs/eyre"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2024-0021.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-843"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:08:53Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json b/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json
new file mode 100644
index 00000000000..d4a04f27889
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json
@@ -0,0 +1,111 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4v7x-pqxf-cx7m",
+ "modified": "2024-04-04T23:02:57Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2023-45288"
+ ],
+ "summary": "net/http, x/net/http2: close connections when receiving too many headers",
+ "details": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "net/http"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "1.21.9"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "golang.org/x/net/http2"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "0.23.0"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "net/http"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.22.0-0"
+ },
+ {
+ "fixed": "1.22.2"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45288"
+ },
+ {
+ "type": "WEB",
+ "url": "https://go.dev/cl/576155"
+ },
+ {
+ "type": "WEB",
+ "url": "https://go.dev/issue/65051"
+ },
+ {
+ "type": "WEB",
+ "url": "https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M"
+ },
+ {
+ "type": "WEB",
+ "url": "https://nowotarski.info/http2-continuation-flood-technical-details"
+ },
+ {
+ "type": "WEB",
+ "url": "https://pkg.go.dev/vuln/GO-2024-2687"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T23:02:57Z",
+ "nvd_published_at": "2024-04-04T21:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-5pgg-2g8v-p4x9/GHSA-5pgg-2g8v-p4x9.json b/advisories/github-reviewed/2024/04/GHSA-5pgg-2g8v-p4x9/GHSA-5pgg-2g8v-p4x9.json
new file mode 100644
index 00000000000..9af2eeaab99
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-5pgg-2g8v-p4x9/GHSA-5pgg-2g8v-p4x9.json
@@ -0,0 +1,69 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5pgg-2g8v-p4x9",
+ "modified": "2024-04-08T13:47:03Z",
+ "published": "2024-04-05T06:30:46Z",
+ "aliases": [
+ "CVE-2024-22363"
+ ],
+ "summary": "SheetJS Regular Expression Denial of Service (ReDoS)",
+ "details": "SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "xlsx"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "0.20.2"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22363"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cdn.sheetjs.com/advisories/CVE-2024-22363"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cwe.mitre.org/data/definitions/1333.html"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://git.sheetjs.com/sheetjs/sheetjs"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.sheetjs.com/sheetjs/sheetjs/src/tag/v0.20.2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1333"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-08T13:47:03Z",
+ "nvd_published_at": "2024-04-05T06:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json b/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json
new file mode 100644
index 00000000000..a271d318fe7
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-65pc-76pq-pvf5/GHSA-65pc-76pq-pvf5.json
@@ -0,0 +1,62 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-65pc-76pq-pvf5",
+ "modified": "2024-04-05T15:06:16Z",
+ "published": "2024-04-04T15:30:34Z",
+ "withdrawn": "2024-04-05T15:06:16Z",
+ "aliases": [
+
+ ],
+ "summary": "Duplicate Advisory: Pebble service manager's file pull API allows access by any user",
+ "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4685-2x5r-65pj. This link is maintained to preserve external references.\n\n## Original Description\nIt was discovered that Pebble's read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/canonical/pebble"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "1.1.1"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/canonical/pebble/security/advisories/GHSA-4685-2x5r-65pj"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3250"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.cve.org/CVERecord?id=CVE-2024-3250"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:06:16Z",
+ "nvd_published_at": "2024-04-04T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-6cf6-8hvr-r68w/GHSA-6cf6-8hvr-r68w.json b/advisories/github-reviewed/2024/04/GHSA-6cf6-8hvr-r68w/GHSA-6cf6-8hvr-r68w.json
new file mode 100644
index 00000000000..4c99d324af0
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-6cf6-8hvr-r68w/GHSA-6cf6-8hvr-r68w.json
@@ -0,0 +1,82 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6cf6-8hvr-r68w",
+ "modified": "2024-04-05T15:44:23Z",
+ "published": "2024-04-04T14:21:19Z",
+ "aliases": [
+ "CVE-2024-31206"
+ ],
+ "summary": "dectalk-tts Uses Unencrypted HTTP Request",
+ "details": "### Impact\n\nIn `dectalk-tts@1.0.0`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified by attackers. Anyone who uses the package could be the victim of a [man-in-the-middle (MITM)](https://en.wikipedia.org/wiki/Man-in-the-middle_attack) attack.\n\nTheft\n\nBecause `dectalk-tts` is a text-to-speech package, user requests are expected to only contain natural language. The package [README](https://github.com/JstnMcBrd/dectalk-tts/blob/main/README.md) warns that user input is sent to a third-party API, so users should not send sensitive information regardless.\n\nBut if users ignore the warnings and send sensitive information anyway, that information could be stolen by attackers.\n\nModification\n\nAttackers could manipulate requests to the API. However, the worst a modified request could do is return an incorrect audio file or bad request rejection.\n\nAttackers could also manipulate responses from the API, returning malicious output to the user. Output is expected to be a wav-encoded buffer, which users will likely save to a file. This could be a dangerous entrypoint to the user's filesystem.\n\n### Patches\n\nThe network request was upgraded to HTTPS in version `1.0.1`. No other changes were made, so updating is risk-free.\n\n### Workarounds\n\nThere are no workarounds, but here are some precautions:\n\n- Do not send any sensitive information.\n\n- Carefully verify the API response before saving it.\n\n### References\n\n[Vulnerable code](https://github.com/JstnMcBrd/dectalk-tts/blob/b3e92156cbb699218ac9b9c7d8979abd0e635767/src/index.ts#L18)\n[Original report](https://github.com/JstnMcBrd/dectalk-tts/issues/3)\n[Patch pull request](https://github.com/JstnMcBrd/dectalk-tts/pull/4)\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "dectalk-tts"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.0.0"
+ },
+ {
+ "fixed": "1.0.1"
+ }
+ ]
+ }
+ ],
+ "versions": [
+ "1.0.0"
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts/security/advisories/GHSA-6cf6-8hvr-r68w"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31206"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts/issues/3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts/pull/4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts/commit/3600d8ac156f27da553ac4ead46d16989a350105"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/JstnMcBrd/dectalk-tts/blob/b3e92156cbb699218ac9b9c7d8979abd0e635767/src/index.ts#L18"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-300",
+ "CWE-319",
+ "CWE-598"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T14:21:19Z",
+ "nvd_published_at": "2024-04-04T23:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-75hq-h6g9-h4q5/GHSA-75hq-h6g9-h4q5.json b/advisories/github-reviewed/2024/04/GHSA-75hq-h6g9-h4q5/GHSA-75hq-h6g9-h4q5.json
index a1e8053b629..9bcb58d0a6c 100644
--- a/advisories/github-reviewed/2024/04/GHSA-75hq-h6g9-h4q5/GHSA-75hq-h6g9-h4q5.json
+++ b/advisories/github-reviewed/2024/04/GHSA-75hq-h6g9-h4q5/GHSA-75hq-h6g9-h4q5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75hq-h6g9-h4q5",
- "modified": "2024-04-02T21:09:24Z",
+ "modified": "2024-04-04T20:24:14Z",
"published": "2024-04-02T21:09:23Z",
"aliases": [
"CVE-2024-30266"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30266"
+ },
{
"type": "WEB",
"url": "https://github.com/bytecodealliance/wasmtime/issues/8281"
@@ -71,6 +75,6 @@
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-04-02T21:09:23Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-04-04T16:15:09Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json
index 47ac6e57467..e96af1a6378 100644
--- a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json
+++ b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ph3-v2vh-3qx7",
- "modified": "2024-04-03T15:30:41Z",
+ "modified": "2024-04-09T12:30:46Z",
"published": "2024-04-02T09:30:42Z",
"aliases": [
"CVE-2024-1300"
@@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
- "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
}
],
"affected": [
@@ -83,6 +83,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1662"
},
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1706"
+ },
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1300"
diff --git a/advisories/github-reviewed/2024/04/GHSA-9qxr-qj54-h672/GHSA-9qxr-qj54-h672.json b/advisories/github-reviewed/2024/04/GHSA-9qxr-qj54-h672/GHSA-9qxr-qj54-h672.json
new file mode 100644
index 00000000000..4b55d329047
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-9qxr-qj54-h672/GHSA-9qxr-qj54-h672.json
@@ -0,0 +1,92 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9qxr-qj54-h672",
+ "modified": "2024-04-04T16:25:33Z",
+ "published": "2024-04-04T14:20:54Z",
+ "aliases": [
+ "CVE-2024-30261"
+ ],
+ "summary": "Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect",
+ "details": "### Impact\n\nIf an attacker can alter the `integrity` option passed to `fetch()`, they can let `fetch()` accept requests as valid even if they have been tampered.\n\n### Patches\n\nFixed in https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3.\nFixes has been released in v5.28.4 and v6.11.1.\n\n\n### Workarounds\n\nEnsure that `integrity` cannot be tampered with.\n\n### References\n\nhttps://hackerone.com/reports/2377760\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "undici"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "5.28.4"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "undici"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "6.0.0"
+ },
+ {
+ "fixed": "6.11.1"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30261"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hackerone.com/reports/2377760"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/nodejs/undici"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": "LOW",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T14:20:54Z",
+ "nvd_published_at": "2024-04-04T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-c33x-xqrf-c478/GHSA-c33x-xqrf-c478.json b/advisories/github-reviewed/2024/04/GHSA-c33x-xqrf-c478/GHSA-c33x-xqrf-c478.json
index 00961c8c47e..867f56c1ced 100644
--- a/advisories/github-reviewed/2024/04/GHSA-c33x-xqrf-c478/GHSA-c33x-xqrf-c478.json
+++ b/advisories/github-reviewed/2024/04/GHSA-c33x-xqrf-c478/GHSA-c33x-xqrf-c478.json
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c33x-xqrf-c478",
- "modified": "2024-04-02T14:16:05Z",
+ "modified": "2024-04-05T18:53:25Z",
"published": "2024-04-02T14:16:05Z",
"aliases": [
"CVE-2024-22189"
],
"summary": "QUIC's Connection ID Mechanism vulnerable to Memory Exhaustion Attack",
- "details": "An attacker can cause its peer to run out of memory sending a large number of NEW_CONNECTION_ID frames that retire old connection IDs. The receiver is supposed to respond to each retirement frame with a RETIRE_CONNECTION_ID frame. The attacker can prevent the receiver from sending out (the vast majority of) these RETIRE_CONNECTION_ID frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate.\n\nI published a more detailed description of the attack and its mitigation in this blog post: https://seemann.io/posts/2024-03-19-exploiting-quics-connection-id-management/.\nI also presented this attack in the IETF QUIC working group session at IETF 119: https://youtu.be/JqXtYcZAtIA?si=nJ31QKLBSTRXY35U&t=3683\n\nThere's no way to mitigate this attack, please update quic-go to a version that contains the fix.",
+ "details": "An attacker can cause its peer to run out of memory by sending a large number of NEW_CONNECTION_ID frames that retire old connection IDs. The receiver is supposed to respond to each retirement frame with a RETIRE_CONNECTION_ID frame. The attacker can prevent the receiver from sending out (the vast majority of) these RETIRE_CONNECTION_ID frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate.\n\nI published a more detailed description of the attack and its mitigation in this blog post: https://seemann.io/posts/2024-03-19-exploiting-quics-connection-id-management/.\nI also presented this attack in the IETF QUIC working group session at IETF 119: https://youtu.be/JqXtYcZAtIA?si=nJ31QKLBSTRXY35U&t=3683\n\nThere's no way to mitigate this attack, please update quic-go to a version that contains the fix.",
"severity": [
{
"type": "CVSS_V3",
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/quic-go/quic-go/security/advisories/GHSA-c33x-xqrf-c478"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22189"
+ },
{
"type": "WEB",
"url": "https://github.com/quic-go/quic-go/commit/4a99b816ae3ab03ae5449d15aac45147c85ed47a"
@@ -59,11 +63,12 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-400"
+ "CWE-400",
+ "CWE-770"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-02T14:16:05Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-04-04T15:15:37Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-c4gr-q97g-ppwc/GHSA-c4gr-q97g-ppwc.json b/advisories/github-reviewed/2024/04/GHSA-c4gr-q97g-ppwc/GHSA-c4gr-q97g-ppwc.json
index d41cbf56be1..a8135f13c78 100644
--- a/advisories/github-reviewed/2024/04/GHSA-c4gr-q97g-ppwc/GHSA-c4gr-q97g-ppwc.json
+++ b/advisories/github-reviewed/2024/04/GHSA-c4gr-q97g-ppwc/GHSA-c4gr-q97g-ppwc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4gr-q97g-ppwc",
- "modified": "2024-04-01T20:33:53Z",
+ "modified": "2024-04-04T16:25:21Z",
"published": "2024-04-01T20:33:53Z",
"aliases": [
"CVE-2024-30250"
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/kindspells/astro-shield/security/advisories/GHSA-c4gr-q97g-ppwc"
},
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30250"
+ },
{
"type": "WEB",
"url": "https://github.com/kindspells/astro-shield/commit/1221019306f501bf5fa9bcfb5a23a2321d34ba0a"
@@ -64,6 +68,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-01T20:33:53Z",
- "nvd_published_at": null
+ "nvd_published_at": "2024-04-04T15:15:39Z"
}
}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json
new file mode 100644
index 00000000000..e8e5bd75929
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-f8h5-v2vg-46rr/GHSA-f8h5-v2vg-46rr.json
@@ -0,0 +1,72 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f8h5-v2vg-46rr",
+ "modified": "2024-04-09T21:33:27Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-2700"
+ ],
+ "summary": "quarkus-core leaks local environment variables from Quarkus namespace during application's build",
+ "details": "A vulnerability was found in the quarkus-core component. Quarkus captures the local environment variables from the Quarkus namespace during the application's build. Thus, running the resulting application inherits the values captured at build time. \n\nHowever, some local environment variables may have been set by the developer / CI environment for testing purposes, such as dropping the database during the application startup or trusting all TLS certificates to accept self-signed certificates. If these properties are configured using environment variables or the .env facility, they are captured into the built application. It leads to dangerous behavior if the application does not override these values.\n\nThis behavior only happens for configuration properties from the `quarkus.*` namespace. So, application-specific properties are not captured.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Maven",
+ "name": "io.quarkus:quarkus-core"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "3.9.2"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "<= 3.9.1"
+ }
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/quarkusio/quarkus/issues/39927"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-2700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2273281"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/quarkusio/quarkus"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-526"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T17:01:45Z",
+ "nvd_published_at": "2024-04-04T14:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-j2rp-gmqv-frhv/GHSA-j2rp-gmqv-frhv.json b/advisories/github-reviewed/2024/04/GHSA-j2rp-gmqv-frhv/GHSA-j2rp-gmqv-frhv.json
new file mode 100644
index 00000000000..a37938c009e
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-j2rp-gmqv-frhv/GHSA-j2rp-gmqv-frhv.json
@@ -0,0 +1,61 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j2rp-gmqv-frhv",
+ "modified": "2024-04-04T22:10:49Z",
+ "published": "2024-04-04T18:30:34Z",
+ "aliases": [
+ "CVE-2024-2660"
+ ],
+ "summary": "HashiCorpVault does not correctly validate OCSP responses",
+ "details": "Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/hashicorp/vault"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "1.16.0"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2660"
+ },
+ {
+ "type": "WEB",
+ "url": "https://discuss.hashicorp.com/t/hcsec-2024-07-vault-tls-cert-auth-method-did-not-correctly-validate-ocsp-responses/64573"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/hashicorp/vault"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-703"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T22:10:49Z",
+ "nvd_published_at": "2024-04-04T18:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json b/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json
new file mode 100644
index 00000000000..8b075fdfc81
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json
@@ -0,0 +1,93 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m4v8-wqvr-p9f7",
+ "modified": "2024-04-04T20:24:00Z",
+ "published": "2024-04-04T14:20:39Z",
+ "aliases": [
+ "CVE-2024-30260"
+ ],
+ "summary": "Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline",
+ "details": "### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "undici"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "5.28.4"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "undici"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "6.0.0"
+ },
+ {
+ "fixed": "6.11.1"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30260"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hackerone.com/reports/2408074"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/nodejs/undici"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200",
+ "CWE-285"
+ ],
+ "severity": "LOW",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T14:20:39Z",
+ "nvd_published_at": "2024-04-04T16:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-mcw6-3256-64gg/GHSA-mcw6-3256-64gg.json b/advisories/github-reviewed/2024/04/GHSA-mcw6-3256-64gg/GHSA-mcw6-3256-64gg.json
new file mode 100644
index 00000000000..c138a2b96bf
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-mcw6-3256-64gg/GHSA-mcw6-3256-64gg.json
@@ -0,0 +1,134 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mcw6-3256-64gg",
+ "modified": "2024-04-05T17:05:05Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-28949"
+ ],
+ "summary": "Mattermost Server doesn't limit the number of user preferences",
+ "details": "Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "8.1.0"
+ },
+ {
+ "fixed": "8.1.11"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.3.0"
+ },
+ {
+ "fixed": "9.3.3"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.4.0"
+ },
+ {
+ "fixed": "9.4.4"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.5.0"
+ },
+ {
+ "fixed": "9.5.2"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28949"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/11a21f4da352a472a09de3b8e125514750a6619a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/362b7d29d35c00fe80721d3d47442a4f3168eb2b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/5632d6b4ff6d019a21bb8ddd037d4a931cd85ae2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/88f9285173dc4cb35fa19a8b8604e098a567f704"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "mattermost/mattermost"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T17:05:05Z",
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json b/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json
new file mode 100644
index 00000000000..b6527ad1eb0
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json
@@ -0,0 +1,85 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q6cp-qfwq-4gcv",
+ "modified": "2024-04-05T15:05:32Z",
+ "published": "2024-04-05T15:05:32Z",
+ "aliases": [
+
+ ],
+ "summary": "h2 servers vulnerable to degradation of service with CONTINUATION Flood",
+ "details": "An attacker can send a flood of CONTINUATION frames, causing `h2` to process them indefinitely. This results in an increase in CPU usage.\n\nTokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency.\n\nMore details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/.\n\nPatches available for 0.4.x and 0.3.x versions.\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "h2"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "0.3.26"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "h2"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0.4.0"
+ },
+ {
+ "fixed": "0.4.4"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/hyperium/h2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2024-0332.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seanmonstar.com/blog/hyper-http2-continuation-flood"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.kb.cert.org/vuls/id/421644"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400",
+ "CWE-770"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:05:32Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-vc6q-ccj9-9r89/GHSA-vc6q-ccj9-9r89.json b/advisories/github-reviewed/2024/04/GHSA-vc6q-ccj9-9r89/GHSA-vc6q-ccj9-9r89.json
new file mode 100644
index 00000000000..9aecd8bcb82
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-vc6q-ccj9-9r89/GHSA-vc6q-ccj9-9r89.json
@@ -0,0 +1,69 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vc6q-ccj9-9r89",
+ "modified": "2024-04-05T17:03:38Z",
+ "published": "2024-04-05T06:30:46Z",
+ "aliases": [
+ "CVE-2024-27448"
+ ],
+ "summary": "MailDev Remote Code Execution",
+ "details": "MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to `lib/mailserver.js` writing arbitrary code into the `routes.js` file.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "maildev"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "2.0.0-beta1"
+ },
+ {
+ "last_affected": "2.1.0"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27448"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Tim-Hoekstra/MailDev-2.1.0-Exploit-RCE"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/maildev/maildev"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/maildev/maildev/releases"
+ },
+ {
+ "type": "WEB",
+ "url": "https://intrix.com.au/articles/exposing-major-security-flaw-in-maildev"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T17:03:37Z",
+ "nvd_published_at": "2024-04-05T06:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json b/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json
new file mode 100644
index 00000000000..a10b4bff0a0
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-w5w5-8vfh-xcjq/GHSA-w5w5-8vfh-xcjq.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w5w5-8vfh-xcjq",
+ "modified": "2024-04-05T15:39:19Z",
+ "published": "2024-04-05T15:39:19Z",
+ "aliases": [
+
+ ],
+ "summary": "whoami stack buffer overflow on several Unix platforms",
+ "details": "With versions of the whoami crate >= 0.5.3 and < 1.5.0, calling any of these functions leads to an immediate stack buffer overflow on illumos and Solaris:\n\n- `whoami::username`\n- `whoami::realname`\n- `whoami::username_os`\n- `whoami::realname_os`\n\nWith versions of the whoami crate >= 0.5.3 and < 1.0.1, calling any of the above functions also leads to a stack buffer overflow on these platforms:\n\n- Bitrig\n- DragonFlyBSD\n- FreeBSD\n- NetBSD\n- OpenBSD\n\nThis occurs because of an incorrect definition of the `passwd` struct on those platforms.\n\nAs a result of this issue, denial of service and data corruption have both been observed in the wild. The issue is possibly exploitable as well.\n\nThis vulnerability also affects other Unix platforms that aren't Linux or macOS.\n\nThis issue has been addressed in whoami 1.5.0.\n\nFor more information, see [this GitHub issue](https://github.com/ardaku/whoami/issues/91).\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "whoami"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0.5.3"
+ },
+ {
+ "fixed": "1.5.0"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/ardaku/whoami/issues/91"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ardaku/whoami/commit/d6ee13ed9e818aa51b8d86d95e8009a376289a40"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/ardaku/whoami"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2024-0020.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-121"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:39:19Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-w67v-ph4x-f48q/GHSA-w67v-ph4x-f48q.json b/advisories/github-reviewed/2024/04/GHSA-w67v-ph4x-f48q/GHSA-w67v-ph4x-f48q.json
new file mode 100644
index 00000000000..26acf1b830d
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-w67v-ph4x-f48q/GHSA-w67v-ph4x-f48q.json
@@ -0,0 +1,134 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w67v-ph4x-f48q",
+ "modified": "2024-04-05T17:04:41Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-29221"
+ ],
+ "summary": "Mattermost Server Improper Access Control ",
+ "details": "Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the \"Add Members\" permission was explicitly removed from team admins. \n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "8.1.0"
+ },
+ {
+ "fixed": "8.1.11"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.5.0"
+ },
+ {
+ "fixed": "9.5.2"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.4.0"
+ },
+ {
+ "fixed": "9.4.4"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.3.0"
+ },
+ {
+ "fixed": "9.3.3"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29221"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/0dc03fbc6e3c9afb14137e72ab3fa6f5a0125b9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/5cce9fed7363386afebd81a58fb5fab7d2729c8f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/a5784f34ba6592c6454b8742f24af9d06279e347"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mattermost/mattermost/commit/dd3fe2991a70a41790d6bef5d31afc5957525f3c"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/mattermost/mattermost"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T17:04:41Z",
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json b/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json
new file mode 100644
index 00000000000..2f3543ed255
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w7hm-hmxv-pvhf",
+ "modified": "2024-04-05T15:06:27Z",
+ "published": "2024-04-05T15:06:27Z",
+ "aliases": [
+
+ ],
+ "summary": "HPACK decoder panics on invalid input",
+ "details": "Due to insufficient checking of input data, decoding certain data sequences can lead to _Decoder::decode_ panicking rather than returning an error.\n\nExample code that triggers this vulnerability looks like this:\n\n```rust\nuse hpack::Decoder;\n\npub fn main() {\n let input = &[0x3f];\n let mut decoder = Decoder::new();\n let _ = decoder.decode(input);\n}\n```\n\nhpack is unmaintained. A crate with the panics fixed has been published as [hpack-patched](https://crates.io/crates/hpack-patched).\n\nAlso consider using [fluke-hpack](https://crates.io/crates/fluke-hpack) or [httlib-huffman](https://crates.io/crates/httlib-huffman) as an alternative.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "hpack"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "last_affected": "0.3.0"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/mlalic/hpack-rs/issues/11"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/sno2/hpack-rs-patched/commit/d669282924a95311599e9e7dd53869ee96b3a2f5"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/mlalic/hpack-rs"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2023-0085.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-754"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:06:27Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-wp43-vprh-c3w5/GHSA-wp43-vprh-c3w5.json b/advisories/github-reviewed/2024/04/GHSA-wp43-vprh-c3w5/GHSA-wp43-vprh-c3w5.json
new file mode 100644
index 00000000000..58d080888f9
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-wp43-vprh-c3w5/GHSA-wp43-vprh-c3w5.json
@@ -0,0 +1,118 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wp43-vprh-c3w5",
+ "modified": "2024-04-05T17:07:26Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-2447"
+ ],
+ "summary": "Mattermost fails to authenticate the source of certain types of post actions",
+ "details": "Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "8.1.0"
+ },
+ {
+ "fixed": "8.1.11"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.5.0"
+ },
+ {
+ "fixed": "9.5.2"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.4.0"
+ },
+ {
+ "fixed": "9.4.4"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "9.3.0"
+ },
+ {
+ "fixed": "9.3.3"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2447"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "mattermost/mattermost"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T17:07:26Z",
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-wpff-wm84-x5cx/GHSA-wpff-wm84-x5cx.json b/advisories/github-reviewed/2024/04/GHSA-wpff-wm84-x5cx/GHSA-wpff-wm84-x5cx.json
new file mode 100644
index 00000000000..3a010d13344
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-wpff-wm84-x5cx/GHSA-wpff-wm84-x5cx.json
@@ -0,0 +1,72 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wpff-wm84-x5cx",
+ "modified": "2024-04-04T20:24:59Z",
+ "published": "2024-04-04T14:39:03Z",
+ "aliases": [
+ "CVE-2024-31215"
+ ],
+ "summary": "Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check",
+ "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\nSSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When malicious app is uploaded to Static analyzer, it is possible to make internal requests.\n\nCredits: Oleg Surnin (Positive Technologies).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nv3.9.8 and above\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nCode level patch\n\n### References\n_Are there any links users can visit to find out more?_\nhttps://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/2373",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "PyPI",
+ "name": "mobsf"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "3.9.8"
+ }
+ ]
+ }
+ ],
+ "database_specific": {
+ "last_known_affected_version_range": "<= 3.9.7"
+ }
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wpff-wm84-x5cx"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31215"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/2373"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/43bb71d115d78c03faa82d75445dd908e9b32716"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/MobSF/Mobile-Security-Framework-MobSF"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-04T14:39:03Z",
+ "nvd_published_at": "2024-04-04T16:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-x9xc-63hg-vcfq/GHSA-x9xc-63hg-vcfq.json b/advisories/github-reviewed/2024/04/GHSA-x9xc-63hg-vcfq/GHSA-x9xc-63hg-vcfq.json
new file mode 100644
index 00000000000..8b57ae9289d
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-x9xc-63hg-vcfq/GHSA-x9xc-63hg-vcfq.json
@@ -0,0 +1,69 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x9xc-63hg-vcfq",
+ "modified": "2024-04-05T15:00:55Z",
+ "published": "2024-04-05T15:00:55Z",
+ "aliases": [
+ "CVE-2024-27284"
+ ],
+ "summary": "cassandra-rs's non-idiomatic use of iterators leads to use after free",
+ "details": "### Impact\nCode that attempts to use an item (e.g., a row) returned by an iterator after the iterator has advanced to the next item will be accessing freed memory and experience undefined behaviour. Code that uses the item and then advances the iterator is unaffected. This problem has always existed.\n\nThis is a use-after-free bug, so it's rated high severity. If your code uses a pre-3.0.0 version of cassandra-rs, and uses an item returned by a cassandra-rs iterator after calling `next()` on that iterator, then it is vulnerable. However, such code will almost always fail immediately - so we believe it is unlikely that any code using this pattern would have reached production. For peace of mind, we recommend you upgrade anyway.\n\n### Patches\nThe problem has been fixed in version 3.0.0. Users should upgrade to ensure their code cannot use the problematic pattern.\n\n### Workarounds\nEnsure all usage fits the expected pattern. For example, use `get_first_row()` rather than an iterator, or completely process an item before advancing the iterator with `next()`.\n\n### References\nNone.\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "cassandra-cpp"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "3.0.0"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/Metaswitch/cassandra-rs/security/advisories/GHSA-x9xc-63hg-vcfq"
+ },
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27284"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Metaswitch/cassandra-rs/commit/ae054dc8044eac9c2c7ae2b1ab154b53ca7f8df7"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/Metaswitch/cassandra-rs"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2024-0017.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:00:55Z",
+ "nvd_published_at": "2024-02-29T01:44:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json b/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json
new file mode 100644
index 00000000000..c000ef289b1
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xfhw-6mc4-mgxf",
+ "modified": "2024-04-05T15:40:40Z",
+ "published": "2024-04-05T15:40:40Z",
+ "aliases": [
+
+ ],
+ "summary": "crayon: ObjectPool creates uninitialized memory when freeing objects",
+ "details": "As of version 0.6.0, the ObjectPool explicitly creates an uninitialized instance of its type parameter when it attempts to free an object, and swaps it into the storage. This causes instant undefined behavior due to reading the uninitialized memory in order to write it to the pool storage.\n\nExtremely basic usage of the crate can trigger this issue, e.g. this code from a doctest:\n\n```rust\nuse crayon::prelude::*;\napplication::oneshot().unwrap();\n\nlet mut params = MeshParams::default();\n\nlet mesh = video::create_mesh(params, None).unwrap();\n\n// Deletes the mesh object.\nvideo::delete_mesh(mesh); // <-- UB\n```\n\nThe Clippy warning for this code was silenced in commit c2fde19caf6149d91faa504263f0bc5cafc35de5.\n\nDiscovered via https://asan.saethlin.dev/ub?crate=crayon&version=0.7.1\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "crates.io",
+ "name": "crayon"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0.6.0"
+ },
+ {
+ "last_affected": "0.7.1"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "WEB",
+ "url": "https://github.com/shawnscode/crayon/issues/109"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/shawnscode/crayon/commit/c2fde19caf6149d91faa504263f0bc5cafc35de5"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/shawnscode/crayon"
+ },
+ {
+ "type": "WEB",
+ "url": "https://rustsec.org/advisories/RUSTSEC-2024-0018.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T15:40:40Z",
+ "nvd_published_at": null
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2024/04/GHSA-xp9j-8p68-9q93/GHSA-xp9j-8p68-9q93.json b/advisories/github-reviewed/2024/04/GHSA-xp9j-8p68-9q93/GHSA-xp9j-8p68-9q93.json
new file mode 100644
index 00000000000..1f642bdf849
--- /dev/null
+++ b/advisories/github-reviewed/2024/04/GHSA-xp9j-8p68-9q93/GHSA-xp9j-8p68-9q93.json
@@ -0,0 +1,61 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xp9j-8p68-9q93",
+ "modified": "2024-04-05T17:03:58Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-21848"
+ ],
+ "summary": "Mattermost Server Improper Access Control",
+ "details": "Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Go",
+ "name": "github.com/mattermost/mattermost/server/v8"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "8.1.11"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21848"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/mattermost/mattermost"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": "LOW",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-05T17:03:58Z",
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2022/10/GHSA-45gr-6358-jhr3/GHSA-45gr-6358-jhr3.json b/advisories/unreviewed/2022/10/GHSA-45gr-6358-jhr3/GHSA-45gr-6358-jhr3.json
index 1898db771eb..bb731888f04 100644
--- a/advisories/unreviewed/2022/10/GHSA-45gr-6358-jhr3/GHSA-45gr-6358-jhr3.json
+++ b/advisories/unreviewed/2022/10/GHSA-45gr-6358-jhr3/GHSA-45gr-6358-jhr3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45gr-6358-jhr3",
- "modified": "2022-10-28T12:00:34Z",
+ "modified": "2024-04-04T18:30:33Z",
"published": "2022-10-26T19:00:38Z",
"aliases": [
"CVE-2022-3671"
@@ -29,9 +29,17 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202310-06"
},
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.212014"
+ },
{
"type": "WEB",
"url": "https://vuldb.com/?id.212014"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.49576"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2023/04/GHSA-cm79-jwwm-5h7h/GHSA-cm79-jwwm-5h7h.json b/advisories/unreviewed/2023/04/GHSA-cm79-jwwm-5h7h/GHSA-cm79-jwwm-5h7h.json
index fb2d914610b..552def37692 100644
--- a/advisories/unreviewed/2023/04/GHSA-cm79-jwwm-5h7h/GHSA-cm79-jwwm-5h7h.json
+++ b/advisories/unreviewed/2023/04/GHSA-cm79-jwwm-5h7h/GHSA-cm79-jwwm-5h7h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cm79-jwwm-5h7h",
- "modified": "2023-04-27T00:30:50Z",
+ "modified": "2024-04-04T15:14:21Z",
"published": "2023-04-18T00:31:59Z",
"aliases": [
"CVE-2021-33797"
@@ -35,7 +35,7 @@
"CWE-119",
"CWE-190"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-17T22:15:07Z"
diff --git a/advisories/unreviewed/2023/08/GHSA-546p-cf3x-vwc8/GHSA-546p-cf3x-vwc8.json b/advisories/unreviewed/2023/08/GHSA-546p-cf3x-vwc8/GHSA-546p-cf3x-vwc8.json
index 82eace55d69..0dc6fa69161 100644
--- a/advisories/unreviewed/2023/08/GHSA-546p-cf3x-vwc8/GHSA-546p-cf3x-vwc8.json
+++ b/advisories/unreviewed/2023/08/GHSA-546p-cf3x-vwc8/GHSA-546p-cf3x-vwc8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-546p-cf3x-vwc8",
- "modified": "2023-08-31T12:30:52Z",
+ "modified": "2024-04-04T15:14:24Z",
"published": "2023-08-31T12:30:52Z",
"aliases": [
"CVE-2023-41740"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-31T10:15:08Z"
diff --git a/advisories/unreviewed/2023/08/GHSA-vvcp-5v5p-8jhc/GHSA-vvcp-5v5p-8jhc.json b/advisories/unreviewed/2023/08/GHSA-vvcp-5v5p-8jhc/GHSA-vvcp-5v5p-8jhc.json
index 0cde6ad2a2d..3346941d52b 100644
--- a/advisories/unreviewed/2023/08/GHSA-vvcp-5v5p-8jhc/GHSA-vvcp-5v5p-8jhc.json
+++ b/advisories/unreviewed/2023/08/GHSA-vvcp-5v5p-8jhc/GHSA-vvcp-5v5p-8jhc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvcp-5v5p-8jhc",
- "modified": "2023-08-03T06:30:23Z",
+ "modified": "2024-04-04T15:14:22Z",
"published": "2023-08-03T06:30:23Z",
"aliases": [
"CVE-2023-3932"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-03T05:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json b/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json
index 4c704da1ab7..b6ef10830d5 100644
--- a/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json
+++ b/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2228-5m6x-4rqm",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:08Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2018-16739"
],
"details": "An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2256-rrc4-rg7p/GHSA-2256-rrc4-rg7p.json b/advisories/unreviewed/2023/10/GHSA-2256-rrc4-rg7p/GHSA-2256-rrc4-rg7p.json
index 443a0beb389..c101484b355 100644
--- a/advisories/unreviewed/2023/10/GHSA-2256-rrc4-rg7p/GHSA-2256-rrc4-rg7p.json
+++ b/advisories/unreviewed/2023/10/GHSA-2256-rrc4-rg7p/GHSA-2256-rrc4-rg7p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2256-rrc4-rg7p",
- "modified": "2023-10-20T06:30:19Z",
+ "modified": "2024-04-04T08:49:24Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-5613"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T05:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2377-2j75-w5v6/GHSA-2377-2j75-w5v6.json b/advisories/unreviewed/2023/10/GHSA-2377-2j75-w5v6/GHSA-2377-2j75-w5v6.json
index bed1cabee09..3b33ff119cf 100644
--- a/advisories/unreviewed/2023/10/GHSA-2377-2j75-w5v6/GHSA-2377-2j75-w5v6.json
+++ b/advisories/unreviewed/2023/10/GHSA-2377-2j75-w5v6/GHSA-2377-2j75-w5v6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2377-2j75-w5v6",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:19Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36751"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2425-r3xx-w4v7/GHSA-2425-r3xx-w4v7.json b/advisories/unreviewed/2023/10/GHSA-2425-r3xx-w4v7/GHSA-2425-r3xx-w4v7.json
index 1b44cf408a6..9d38bafa63a 100644
--- a/advisories/unreviewed/2023/10/GHSA-2425-r3xx-w4v7/GHSA-2425-r3xx-w4v7.json
+++ b/advisories/unreviewed/2023/10/GHSA-2425-r3xx-w4v7/GHSA-2425-r3xx-w4v7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2425-r3xx-w4v7",
- "modified": "2023-10-31T15:30:19Z",
+ "modified": "2024-04-04T08:53:42Z",
"published": "2023-10-24T00:31:07Z",
"aliases": [
"CVE-2023-33517"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-552"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T23:15:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2434-68xh-wxm6/GHSA-2434-68xh-wxm6.json b/advisories/unreviewed/2023/10/GHSA-2434-68xh-wxm6/GHSA-2434-68xh-wxm6.json
index d59297cb072..e1310e81dee 100644
--- a/advisories/unreviewed/2023/10/GHSA-2434-68xh-wxm6/GHSA-2434-68xh-wxm6.json
+++ b/advisories/unreviewed/2023/10/GHSA-2434-68xh-wxm6/GHSA-2434-68xh-wxm6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2434-68xh-wxm6",
- "modified": "2023-10-17T21:30:23Z",
+ "modified": "2024-04-04T08:43:43Z",
"published": "2023-10-17T21:30:23Z",
"aliases": [
"CVE-2023-4896"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-243m-j5w7-6mw6/GHSA-243m-j5w7-6mw6.json b/advisories/unreviewed/2023/10/GHSA-243m-j5w7-6mw6/GHSA-243m-j5w7-6mw6.json
index e8b18ec1c1f..ca6b94437a5 100644
--- a/advisories/unreviewed/2023/10/GHSA-243m-j5w7-6mw6/GHSA-243m-j5w7-6mw6.json
+++ b/advisories/unreviewed/2023/10/GHSA-243m-j5w7-6mw6/GHSA-243m-j5w7-6mw6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-243m-j5w7-6mw6",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:41:40Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4795"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-243r-m3w5-w83p/GHSA-243r-m3w5-w83p.json b/advisories/unreviewed/2023/10/GHSA-243r-m3w5-w83p/GHSA-243r-m3w5-w83p.json
index 834631c6a68..84ac63447fd 100644
--- a/advisories/unreviewed/2023/10/GHSA-243r-m3w5-w83p/GHSA-243r-m3w5-w83p.json
+++ b/advisories/unreviewed/2023/10/GHSA-243r-m3w5-w83p/GHSA-243r-m3w5-w83p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-243r-m3w5-w83p",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:08Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5231"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-244x-f55f-vxmr/GHSA-244x-f55f-vxmr.json b/advisories/unreviewed/2023/10/GHSA-244x-f55f-vxmr/GHSA-244x-f55f-vxmr.json
index 67ad5f4f03a..c6c42f7703d 100644
--- a/advisories/unreviewed/2023/10/GHSA-244x-f55f-vxmr/GHSA-244x-f55f-vxmr.json
+++ b/advisories/unreviewed/2023/10/GHSA-244x-f55f-vxmr/GHSA-244x-f55f-vxmr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-244x-f55f-vxmr",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:27Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-43891"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-209"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T03:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2456-m625-hcj6/GHSA-2456-m625-hcj6.json b/advisories/unreviewed/2023/10/GHSA-2456-m625-hcj6/GHSA-2456-m625-hcj6.json
index 21aa7140e1f..49f0a964d88 100644
--- a/advisories/unreviewed/2023/10/GHSA-2456-m625-hcj6/GHSA-2456-m625-hcj6.json
+++ b/advisories/unreviewed/2023/10/GHSA-2456-m625-hcj6/GHSA-2456-m625-hcj6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2456-m625-hcj6",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:16Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5615"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-24f5-5fmf-pwmc/GHSA-24f5-5fmf-pwmc.json b/advisories/unreviewed/2023/10/GHSA-24f5-5fmf-pwmc/GHSA-24f5-5fmf-pwmc.json
index 96b675f44ad..57bbf32b246 100644
--- a/advisories/unreviewed/2023/10/GHSA-24f5-5fmf-pwmc/GHSA-24f5-5fmf-pwmc.json
+++ b/advisories/unreviewed/2023/10/GHSA-24f5-5fmf-pwmc/GHSA-24f5-5fmf-pwmc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24f5-5fmf-pwmc",
- "modified": "2023-10-19T09:30:18Z",
+ "modified": "2024-04-04T08:47:08Z",
"published": "2023-10-19T09:30:18Z",
"aliases": [
"CVE-2023-34050"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-502"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json b/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json
index d6155638ad0..8ce023cb192 100644
--- a/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json
+++ b/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25h8-g2f4-5mwj",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:03Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26575"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-26rx-wm6q-f3g4/GHSA-26rx-wm6q-f3g4.json b/advisories/unreviewed/2023/10/GHSA-26rx-wm6q-f3g4/GHSA-26rx-wm6q-f3g4.json
index 424089b2885..b9e24872e15 100644
--- a/advisories/unreviewed/2023/10/GHSA-26rx-wm6q-f3g4/GHSA-26rx-wm6q-f3g4.json
+++ b/advisories/unreviewed/2023/10/GHSA-26rx-wm6q-f3g4/GHSA-26rx-wm6q-f3g4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26rx-wm6q-f3g4",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:52Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-34437"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T00:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-272r-9398-x32j/GHSA-272r-9398-x32j.json b/advisories/unreviewed/2023/10/GHSA-272r-9398-x32j/GHSA-272r-9398-x32j.json
index 1a9b8187a66..fec75fe7796 100644
--- a/advisories/unreviewed/2023/10/GHSA-272r-9398-x32j/GHSA-272r-9398-x32j.json
+++ b/advisories/unreviewed/2023/10/GHSA-272r-9398-x32j/GHSA-272r-9398-x32j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-272r-9398-x32j",
- "modified": "2023-10-26T18:30:21Z",
+ "modified": "2024-04-04T08:48:01Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-31046"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T14:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-27j3-ww98-6j8q/GHSA-27j3-ww98-6j8q.json b/advisories/unreviewed/2023/10/GHSA-27j3-ww98-6j8q/GHSA-27j3-ww98-6j8q.json
index f094fa71918..f5c2edb9b5e 100644
--- a/advisories/unreviewed/2023/10/GHSA-27j3-ww98-6j8q/GHSA-27j3-ww98-6j8q.json
+++ b/advisories/unreviewed/2023/10/GHSA-27j3-ww98-6j8q/GHSA-27j3-ww98-6j8q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27j3-ww98-6j8q",
- "modified": "2023-10-19T18:30:29Z",
+ "modified": "2024-04-04T08:45:22Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41711"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json b/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json
index c909970c8ec..eadb34d1bf5 100644
--- a/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json
+++ b/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2962-mm2g-265c",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:35Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40120"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json b/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json
index 8ae1e7431ba..1dd26ad5f3e 100644
--- a/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json
+++ b/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-299r-q2gj-44gj",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:31Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4646"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-29j4-8jcf-4q5w/GHSA-29j4-8jcf-4q5w.json b/advisories/unreviewed/2023/10/GHSA-29j4-8jcf-4q5w/GHSA-29j4-8jcf-4q5w.json
index 1a6aa12addd..3dae31f5f20 100644
--- a/advisories/unreviewed/2023/10/GHSA-29j4-8jcf-4q5w/GHSA-29j4-8jcf-4q5w.json
+++ b/advisories/unreviewed/2023/10/GHSA-29j4-8jcf-4q5w/GHSA-29j4-8jcf-4q5w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29j4-8jcf-4q5w",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:45Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-4938"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-29m7-5q7x-g3fr/GHSA-29m7-5q7x-g3fr.json b/advisories/unreviewed/2023/10/GHSA-29m7-5q7x-g3fr/GHSA-29m7-5q7x-g3fr.json
index b97106fc3a2..d3029b3b6b2 100644
--- a/advisories/unreviewed/2023/10/GHSA-29m7-5q7x-g3fr/GHSA-29m7-5q7x-g3fr.json
+++ b/advisories/unreviewed/2023/10/GHSA-29m7-5q7x-g3fr/GHSA-29m7-5q7x-g3fr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29m7-5q7x-g3fr",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:41Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-25476"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T08:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2cc2-mcjj-r4mp/GHSA-2cc2-mcjj-r4mp.json b/advisories/unreviewed/2023/10/GHSA-2cc2-mcjj-r4mp/GHSA-2cc2-mcjj-r4mp.json
index 525cf38e92b..07ccb00b30c 100644
--- a/advisories/unreviewed/2023/10/GHSA-2cc2-mcjj-r4mp/GHSA-2cc2-mcjj-r4mp.json
+++ b/advisories/unreviewed/2023/10/GHSA-2cc2-mcjj-r4mp/GHSA-2cc2-mcjj-r4mp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cc2-mcjj-r4mp",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:17Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3707"
],
"details": "The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-639"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2cgq-5ww9-3c6v/GHSA-2cgq-5ww9-3c6v.json b/advisories/unreviewed/2023/10/GHSA-2cgq-5ww9-3c6v/GHSA-2cgq-5ww9-3c6v.json
index f0944c08c3c..2819f5b2a0b 100644
--- a/advisories/unreviewed/2023/10/GHSA-2cgq-5ww9-3c6v/GHSA-2cgq-5ww9-3c6v.json
+++ b/advisories/unreviewed/2023/10/GHSA-2cgq-5ww9-3c6v/GHSA-2cgq-5ww9-3c6v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cgq-5ww9-3c6v",
- "modified": "2023-10-19T15:31:08Z",
+ "modified": "2024-04-04T08:48:22Z",
"published": "2023-10-19T15:31:08Z",
"aliases": [
"CVE-2023-43251"
],
"details": "XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-755"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json
index 7f28614482d..6b8046a18a1 100644
--- a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json
+++ b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fcg-hwv9-g767",
- "modified": "2023-10-28T00:30:29Z",
+ "modified": "2024-04-04T08:47:58Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-45883"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2fp9-9cqm-x4p7/GHSA-2fp9-9cqm-x4p7.json b/advisories/unreviewed/2023/10/GHSA-2fp9-9cqm-x4p7/GHSA-2fp9-9cqm-x4p7.json
index 69a24fe0d83..c50c03527ac 100644
--- a/advisories/unreviewed/2023/10/GHSA-2fp9-9cqm-x4p7/GHSA-2fp9-9cqm-x4p7.json
+++ b/advisories/unreviewed/2023/10/GHSA-2fp9-9cqm-x4p7/GHSA-2fp9-9cqm-x4p7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fp9-9cqm-x4p7",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:38Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45752"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json b/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json
index 1a8b00dcad9..a4d4a79659b 100644
--- a/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json
+++ b/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g3g-vvgw-mw65",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:09Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46525"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2gwx-jm42-4548/GHSA-2gwx-jm42-4548.json b/advisories/unreviewed/2023/10/GHSA-2gwx-jm42-4548/GHSA-2gwx-jm42-4548.json
index ed62bd99a8c..11c49b3f189 100644
--- a/advisories/unreviewed/2023/10/GHSA-2gwx-jm42-4548/GHSA-2gwx-jm42-4548.json
+++ b/advisories/unreviewed/2023/10/GHSA-2gwx-jm42-4548/GHSA-2gwx-jm42-4548.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gwx-jm42-4548",
- "modified": "2023-10-30T12:30:31Z",
+ "modified": "2024-04-04T08:53:40Z",
"published": "2023-10-24T00:31:07Z",
"aliases": [
"CVE-2023-45998"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2hcc-ww5c-44wh/GHSA-2hcc-ww5c-44wh.json b/advisories/unreviewed/2023/10/GHSA-2hcc-ww5c-44wh/GHSA-2hcc-ww5c-44wh.json
index 358b6f19bc4..47303b4f5b7 100644
--- a/advisories/unreviewed/2023/10/GHSA-2hcc-ww5c-44wh/GHSA-2hcc-ww5c-44wh.json
+++ b/advisories/unreviewed/2023/10/GHSA-2hcc-ww5c-44wh/GHSA-2hcc-ww5c-44wh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2hcc-ww5c-44wh",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:20Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-24402"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-307"
+ "CWE-307",
+ "CWE-334"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2hmc-82rg-26hv/GHSA-2hmc-82rg-26hv.json b/advisories/unreviewed/2023/10/GHSA-2hmc-82rg-26hv/GHSA-2hmc-82rg-26hv.json
index b9b7d36a4a2..1b70dc55442 100644
--- a/advisories/unreviewed/2023/10/GHSA-2hmc-82rg-26hv/GHSA-2hmc-82rg-26hv.json
+++ b/advisories/unreviewed/2023/10/GHSA-2hmc-82rg-26hv/GHSA-2hmc-82rg-26hv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2hmc-82rg-26hv",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:34Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-37537"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-428"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T15:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json b/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json
index d806c273aa3..79baf52a823 100644
--- a/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json
+++ b/advisories/unreviewed/2023/10/GHSA-2mh6-g78c-5h6c/GHSA-2mh6-g78c-5h6c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mh6-g78c-5h6c",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:47Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4819"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json
index f76cd7b8482..3c1243e0ad7 100644
--- a/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json
+++ b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mqf-694r-32x9",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:57:55Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46208"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2mxq-q8p2-g2c8/GHSA-2mxq-q8p2-g2c8.json b/advisories/unreviewed/2023/10/GHSA-2mxq-q8p2-g2c8/GHSA-2mxq-q8p2-g2c8.json
index 86942f2d5f4..2de34297e65 100644
--- a/advisories/unreviewed/2023/10/GHSA-2mxq-q8p2-g2c8/GHSA-2mxq-q8p2-g2c8.json
+++ b/advisories/unreviewed/2023/10/GHSA-2mxq-q8p2-g2c8/GHSA-2mxq-q8p2-g2c8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mxq-q8p2-g2c8",
- "modified": "2023-10-21T09:30:25Z",
+ "modified": "2024-04-04T08:52:27Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-4939"
@@ -39,7 +39,7 @@
"CWE-287",
"CWE-305"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2pfh-4x3h-w3hm/GHSA-2pfh-4x3h-w3hm.json b/advisories/unreviewed/2023/10/GHSA-2pfh-4x3h-w3hm/GHSA-2pfh-4x3h-w3hm.json
index 76d1f7c89f0..21c3ada0833 100644
--- a/advisories/unreviewed/2023/10/GHSA-2pfh-4x3h-w3hm/GHSA-2pfh-4x3h-w3hm.json
+++ b/advisories/unreviewed/2023/10/GHSA-2pfh-4x3h-w3hm/GHSA-2pfh-4x3h-w3hm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pfh-4x3h-w3hm",
- "modified": "2023-10-25T18:32:20Z",
+ "modified": "2024-04-04T08:53:52Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2022-3698"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2q58-xp4p-xpqc/GHSA-2q58-xp4p-xpqc.json b/advisories/unreviewed/2023/10/GHSA-2q58-xp4p-xpqc/GHSA-2q58-xp4p-xpqc.json
index 6c7ba049010..9c254449a11 100644
--- a/advisories/unreviewed/2023/10/GHSA-2q58-xp4p-xpqc/GHSA-2q58-xp4p-xpqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-2q58-xp4p-xpqc/GHSA-2q58-xp4p-xpqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q58-xp4p-xpqc",
- "modified": "2023-10-14T15:30:18Z",
+ "modified": "2024-04-04T08:38:41Z",
"published": "2023-10-14T15:30:18Z",
"aliases": [
"CVE-2022-33165"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2q77-j9qq-67hg/GHSA-2q77-j9qq-67hg.json b/advisories/unreviewed/2023/10/GHSA-2q77-j9qq-67hg/GHSA-2q77-j9qq-67hg.json
index cc469703285..4ef9afdbeed 100644
--- a/advisories/unreviewed/2023/10/GHSA-2q77-j9qq-67hg/GHSA-2q77-j9qq-67hg.json
+++ b/advisories/unreviewed/2023/10/GHSA-2q77-j9qq-67hg/GHSA-2q77-j9qq-67hg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q77-j9qq-67hg",
- "modified": "2023-10-20T12:31:00Z",
+ "modified": "2024-04-04T08:41:56Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4950"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2q9m-8wj3-95xg/GHSA-2q9m-8wj3-95xg.json b/advisories/unreviewed/2023/10/GHSA-2q9m-8wj3-95xg/GHSA-2q9m-8wj3-95xg.json
index cce0a89fe39..d8b19ebd05e 100644
--- a/advisories/unreviewed/2023/10/GHSA-2q9m-8wj3-95xg/GHSA-2q9m-8wj3-95xg.json
+++ b/advisories/unreviewed/2023/10/GHSA-2q9m-8wj3-95xg/GHSA-2q9m-8wj3-95xg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q9m-8wj3-95xg",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:53:33Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-46602"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2qqg-m8pw-2q2v/GHSA-2qqg-m8pw-2q2v.json b/advisories/unreviewed/2023/10/GHSA-2qqg-m8pw-2q2v/GHSA-2qqg-m8pw-2q2v.json
index 3de61e31730..1978f7e9b24 100644
--- a/advisories/unreviewed/2023/10/GHSA-2qqg-m8pw-2q2v/GHSA-2qqg-m8pw-2q2v.json
+++ b/advisories/unreviewed/2023/10/GHSA-2qqg-m8pw-2q2v/GHSA-2qqg-m8pw-2q2v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qqg-m8pw-2q2v",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:33Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-44229"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2rrh-8pm2-3q2c/GHSA-2rrh-8pm2-3q2c.json b/advisories/unreviewed/2023/10/GHSA-2rrh-8pm2-3q2c/GHSA-2rrh-8pm2-3q2c.json
index 735ccffc8fe..67647f39c4d 100644
--- a/advisories/unreviewed/2023/10/GHSA-2rrh-8pm2-3q2c/GHSA-2rrh-8pm2-3q2c.json
+++ b/advisories/unreviewed/2023/10/GHSA-2rrh-8pm2-3q2c/GHSA-2rrh-8pm2-3q2c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rrh-8pm2-3q2c",
- "modified": "2023-10-31T18:31:43Z",
+ "modified": "2024-04-04T08:52:41Z",
"published": "2023-10-22T06:30:19Z",
"aliases": [
"CVE-2023-46300"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-116"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T04:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json b/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json
index 28eff3b59e3..0a4ad3695d4 100644
--- a/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json
+++ b/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vvx-5g27-9gvj",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:42:00Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5003"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-538"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2w9c-67cj-fxpp/GHSA-2w9c-67cj-fxpp.json b/advisories/unreviewed/2023/10/GHSA-2w9c-67cj-fxpp/GHSA-2w9c-67cj-fxpp.json
index ec86ae690b9..e7c5e81ed67 100644
--- a/advisories/unreviewed/2023/10/GHSA-2w9c-67cj-fxpp/GHSA-2w9c-67cj-fxpp.json
+++ b/advisories/unreviewed/2023/10/GHSA-2w9c-67cj-fxpp/GHSA-2w9c-67cj-fxpp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w9c-67cj-fxpp",
- "modified": "2023-10-23T18:30:46Z",
+ "modified": "2024-04-04T08:53:20Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-38722"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2w9p-mj8f-374x/GHSA-2w9p-mj8f-374x.json b/advisories/unreviewed/2023/10/GHSA-2w9p-mj8f-374x/GHSA-2w9p-mj8f-374x.json
index 87c49884794..7bf661ccdd7 100644
--- a/advisories/unreviewed/2023/10/GHSA-2w9p-mj8f-374x/GHSA-2w9p-mj8f-374x.json
+++ b/advisories/unreviewed/2023/10/GHSA-2w9p-mj8f-374x/GHSA-2w9p-mj8f-374x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w9p-mj8f-374x",
- "modified": "2023-10-24T21:30:19Z",
+ "modified": "2024-04-04T08:42:56Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-5522"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2w9p-mqx6-cvqc/GHSA-2w9p-mqx6-cvqc.json b/advisories/unreviewed/2023/10/GHSA-2w9p-mqx6-cvqc/GHSA-2w9p-mqx6-cvqc.json
index 92790b1094c..c5de937cf64 100644
--- a/advisories/unreviewed/2023/10/GHSA-2w9p-mqx6-cvqc/GHSA-2w9p-mqx6-cvqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-2w9p-mqx6-cvqc/GHSA-2w9p-mqx6-cvqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w9p-mqx6-cvqc",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:57Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-33303"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-613"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:43Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2wg8-2hgh-5f85/GHSA-2wg8-2hgh-5f85.json b/advisories/unreviewed/2023/10/GHSA-2wg8-2hgh-5f85/GHSA-2wg8-2hgh-5f85.json
index 56649e17eab..252884589cd 100644
--- a/advisories/unreviewed/2023/10/GHSA-2wg8-2hgh-5f85/GHSA-2wg8-2hgh-5f85.json
+++ b/advisories/unreviewed/2023/10/GHSA-2wg8-2hgh-5f85/GHSA-2wg8-2hgh-5f85.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wg8-2hgh-5f85",
- "modified": "2023-10-26T18:30:23Z",
+ "modified": "2024-04-04T08:56:56Z",
"published": "2023-10-26T18:30:23Z",
"aliases": [
"CVE-2023-5622"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2wq9-hq2m-2hfq/GHSA-2wq9-hq2m-2hfq.json b/advisories/unreviewed/2023/10/GHSA-2wq9-hq2m-2hfq/GHSA-2wq9-hq2m-2hfq.json
index 4ada7852b37..405d6ea575a 100644
--- a/advisories/unreviewed/2023/10/GHSA-2wq9-hq2m-2hfq/GHSA-2wq9-hq2m-2hfq.json
+++ b/advisories/unreviewed/2023/10/GHSA-2wq9-hq2m-2hfq/GHSA-2wq9-hq2m-2hfq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wq9-hq2m-2hfq",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:34Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2022-3622"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2xg8-857g-4j2x/GHSA-2xg8-857g-4j2x.json b/advisories/unreviewed/2023/10/GHSA-2xg8-857g-4j2x/GHSA-2xg8-857g-4j2x.json
index eb3fc4ed43d..46af9566a3a 100644
--- a/advisories/unreviewed/2023/10/GHSA-2xg8-857g-4j2x/GHSA-2xg8-857g-4j2x.json
+++ b/advisories/unreviewed/2023/10/GHSA-2xg8-857g-4j2x/GHSA-2xg8-857g-4j2x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xg8-857g-4j2x",
- "modified": "2023-10-12T00:30:28Z",
+ "modified": "2024-04-04T08:35:05Z",
"published": "2023-10-12T00:30:28Z",
"aliases": [
"CVE-2023-44190"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-346"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-2xmm-8j84-pj46/GHSA-2xmm-8j84-pj46.json b/advisories/unreviewed/2023/10/GHSA-2xmm-8j84-pj46/GHSA-2xmm-8j84-pj46.json
index 669f7bf2bdf..4ab5c2c175c 100644
--- a/advisories/unreviewed/2023/10/GHSA-2xmm-8j84-pj46/GHSA-2xmm-8j84-pj46.json
+++ b/advisories/unreviewed/2023/10/GHSA-2xmm-8j84-pj46/GHSA-2xmm-8j84-pj46.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xmm-8j84-pj46",
- "modified": "2023-10-18T03:30:28Z",
+ "modified": "2024-04-04T08:34:57Z",
"published": "2023-10-11T21:33:25Z",
"aliases": [
"CVE-2023-40142"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-32jc-368c-fvg6/GHSA-32jc-368c-fvg6.json b/advisories/unreviewed/2023/10/GHSA-32jc-368c-fvg6/GHSA-32jc-368c-fvg6.json
index d738d09b140..195812b59e3 100644
--- a/advisories/unreviewed/2023/10/GHSA-32jc-368c-fvg6/GHSA-32jc-368c-fvg6.json
+++ b/advisories/unreviewed/2023/10/GHSA-32jc-368c-fvg6/GHSA-32jc-368c-fvg6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32jc-368c-fvg6",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:18Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3746"
],
"details": "The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json b/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json
index 1b1dcc38a72..e7ca841afb1 100644
--- a/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json
+++ b/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32qf-g28m-p524",
- "modified": "2023-10-20T18:30:57Z",
+ "modified": "2024-04-04T08:51:28Z",
"published": "2023-10-20T18:30:57Z",
"aliases": [
"CVE-2023-3965"
@@ -35,7 +35,7 @@
"CWE-1321",
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T16:15:19Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-32vv-cw3x-ch8f/GHSA-32vv-cw3x-ch8f.json b/advisories/unreviewed/2023/10/GHSA-32vv-cw3x-ch8f/GHSA-32vv-cw3x-ch8f.json
index 1e0ffb33bed..08ed72cb7e8 100644
--- a/advisories/unreviewed/2023/10/GHSA-32vv-cw3x-ch8f/GHSA-32vv-cw3x-ch8f.json
+++ b/advisories/unreviewed/2023/10/GHSA-32vv-cw3x-ch8f/GHSA-32vv-cw3x-ch8f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32vv-cw3x-ch8f",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:48Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-46077"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-339p-cxqq-7j6j/GHSA-339p-cxqq-7j6j.json b/advisories/unreviewed/2023/10/GHSA-339p-cxqq-7j6j/GHSA-339p-cxqq-7j6j.json
index 8ea6970abb6..c73ce20f964 100644
--- a/advisories/unreviewed/2023/10/GHSA-339p-cxqq-7j6j/GHSA-339p-cxqq-7j6j.json
+++ b/advisories/unreviewed/2023/10/GHSA-339p-cxqq-7j6j/GHSA-339p-cxqq-7j6j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-339p-cxqq-7j6j",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:07Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22127"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-33gx-m93p-j6wc/GHSA-33gx-m93p-j6wc.json b/advisories/unreviewed/2023/10/GHSA-33gx-m93p-j6wc/GHSA-33gx-m93p-j6wc.json
index 9dd88d1dff8..02d312310bc 100644
--- a/advisories/unreviewed/2023/10/GHSA-33gx-m93p-j6wc/GHSA-33gx-m93p-j6wc.json
+++ b/advisories/unreviewed/2023/10/GHSA-33gx-m93p-j6wc/GHSA-33gx-m93p-j6wc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33gx-m93p-j6wc",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:24Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36758"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-33mh-qwc8-jxxx/GHSA-33mh-qwc8-jxxx.json b/advisories/unreviewed/2023/10/GHSA-33mh-qwc8-jxxx/GHSA-33mh-qwc8-jxxx.json
index 4552902d262..3de32ad7307 100644
--- a/advisories/unreviewed/2023/10/GHSA-33mh-qwc8-jxxx/GHSA-33mh-qwc8-jxxx.json
+++ b/advisories/unreviewed/2023/10/GHSA-33mh-qwc8-jxxx/GHSA-33mh-qwc8-jxxx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33mh-qwc8-jxxx",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:53Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-27395"
@@ -32,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-122"
+ "CWE-122",
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-34fg-whr2-93rc/GHSA-34fg-whr2-93rc.json b/advisories/unreviewed/2023/10/GHSA-34fg-whr2-93rc/GHSA-34fg-whr2-93rc.json
index 55cec6a676a..8f43fcbd1d3 100644
--- a/advisories/unreviewed/2023/10/GHSA-34fg-whr2-93rc/GHSA-34fg-whr2-93rc.json
+++ b/advisories/unreviewed/2023/10/GHSA-34fg-whr2-93rc/GHSA-34fg-whr2-93rc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34fg-whr2-93rc",
- "modified": "2023-10-28T03:30:23Z",
+ "modified": "2024-04-04T08:58:02Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-46467"
],
"details": "Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-28T01:15:51Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-34pm-grcc-xjrw/GHSA-34pm-grcc-xjrw.json b/advisories/unreviewed/2023/10/GHSA-34pm-grcc-xjrw/GHSA-34pm-grcc-xjrw.json
index 15432a0b07f..4cbfcc2a473 100644
--- a/advisories/unreviewed/2023/10/GHSA-34pm-grcc-xjrw/GHSA-34pm-grcc-xjrw.json
+++ b/advisories/unreviewed/2023/10/GHSA-34pm-grcc-xjrw/GHSA-34pm-grcc-xjrw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34pm-grcc-xjrw",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:07Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26577"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3579-vvrm-33pp/GHSA-3579-vvrm-33pp.json b/advisories/unreviewed/2023/10/GHSA-3579-vvrm-33pp/GHSA-3579-vvrm-33pp.json
index 1907fb42db6..931d665d391 100644
--- a/advisories/unreviewed/2023/10/GHSA-3579-vvrm-33pp/GHSA-3579-vvrm-33pp.json
+++ b/advisories/unreviewed/2023/10/GHSA-3579-vvrm-33pp/GHSA-3579-vvrm-33pp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3579-vvrm-33pp",
- "modified": "2023-10-19T03:30:29Z",
+ "modified": "2024-04-04T08:47:00Z",
"published": "2023-10-19T03:30:29Z",
"aliases": [
"CVE-2023-5639"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T02:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-35hg-f9qq-236g/GHSA-35hg-f9qq-236g.json b/advisories/unreviewed/2023/10/GHSA-35hg-f9qq-236g/GHSA-35hg-f9qq-236g.json
index ba4b7295c26..f726d45fc4c 100644
--- a/advisories/unreviewed/2023/10/GHSA-35hg-f9qq-236g/GHSA-35hg-f9qq-236g.json
+++ b/advisories/unreviewed/2023/10/GHSA-35hg-f9qq-236g/GHSA-35hg-f9qq-236g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35hg-f9qq-236g",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:07Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-43776"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-261"
+ "CWE-261",
+ "CWE-326"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-364j-ch9m-hp4h/GHSA-364j-ch9m-hp4h.json b/advisories/unreviewed/2023/10/GHSA-364j-ch9m-hp4h/GHSA-364j-ch9m-hp4h.json
index 006e803ef22..5200cc060c3 100644
--- a/advisories/unreviewed/2023/10/GHSA-364j-ch9m-hp4h/GHSA-364j-ch9m-hp4h.json
+++ b/advisories/unreviewed/2023/10/GHSA-364j-ch9m-hp4h/GHSA-364j-ch9m-hp4h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-364j-ch9m-hp4h",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:35Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-3996"
@@ -46,7 +46,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3728-9cr9-4xwr/GHSA-3728-9cr9-4xwr.json b/advisories/unreviewed/2023/10/GHSA-3728-9cr9-4xwr/GHSA-3728-9cr9-4xwr.json
index fce2ed40d36..a47a1a677da 100644
--- a/advisories/unreviewed/2023/10/GHSA-3728-9cr9-4xwr/GHSA-3728-9cr9-4xwr.json
+++ b/advisories/unreviewed/2023/10/GHSA-3728-9cr9-4xwr/GHSA-3728-9cr9-4xwr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3728-9cr9-4xwr",
- "modified": "2023-10-13T03:30:34Z",
+ "modified": "2024-04-04T08:37:23Z",
"published": "2023-10-13T03:30:34Z",
"aliases": [
"CVE-2023-4562"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T02:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3743-q7xh-2hv2/GHSA-3743-q7xh-2hv2.json b/advisories/unreviewed/2023/10/GHSA-3743-q7xh-2hv2/GHSA-3743-q7xh-2hv2.json
index 03466db2be3..52bb5c4906b 100644
--- a/advisories/unreviewed/2023/10/GHSA-3743-q7xh-2hv2/GHSA-3743-q7xh-2hv2.json
+++ b/advisories/unreviewed/2023/10/GHSA-3743-q7xh-2hv2/GHSA-3743-q7xh-2hv2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3743-q7xh-2hv2",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:09Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-4827"
],
"details": "The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-377v-9whx-fp3q/GHSA-377v-9whx-fp3q.json b/advisories/unreviewed/2023/10/GHSA-377v-9whx-fp3q/GHSA-377v-9whx-fp3q.json
index 0b1c841de84..90081e01453 100644
--- a/advisories/unreviewed/2023/10/GHSA-377v-9whx-fp3q/GHSA-377v-9whx-fp3q.json
+++ b/advisories/unreviewed/2023/10/GHSA-377v-9whx-fp3q/GHSA-377v-9whx-fp3q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-377v-9whx-fp3q",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:48Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45051"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-37gq-4hg5-cxqj/GHSA-37gq-4hg5-cxqj.json b/advisories/unreviewed/2023/10/GHSA-37gq-4hg5-cxqj/GHSA-37gq-4hg5-cxqj.json
index 75fe457c38a..f1fa1c446de 100644
--- a/advisories/unreviewed/2023/10/GHSA-37gq-4hg5-cxqj/GHSA-37gq-4hg5-cxqj.json
+++ b/advisories/unreviewed/2023/10/GHSA-37gq-4hg5-cxqj/GHSA-37gq-4hg5-cxqj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37gq-4hg5-cxqj",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:36Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-32124"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T15:15:46Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-37gv-9q37-8946/GHSA-37gv-9q37-8946.json b/advisories/unreviewed/2023/10/GHSA-37gv-9q37-8946/GHSA-37gv-9q37-8946.json
index 00123f4af32..97ba1697cd8 100644
--- a/advisories/unreviewed/2023/10/GHSA-37gv-9q37-8946/GHSA-37gv-9q37-8946.json
+++ b/advisories/unreviewed/2023/10/GHSA-37gv-9q37-8946/GHSA-37gv-9q37-8946.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37gv-9q37-8946",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:58:05Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-46569"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-28T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-37q7-h3xv-cfp3/GHSA-37q7-h3xv-cfp3.json b/advisories/unreviewed/2023/10/GHSA-37q7-h3xv-cfp3/GHSA-37q7-h3xv-cfp3.json
index 638b98bc4fa..13e826410a8 100644
--- a/advisories/unreviewed/2023/10/GHSA-37q7-h3xv-cfp3/GHSA-37q7-h3xv-cfp3.json
+++ b/advisories/unreviewed/2023/10/GHSA-37q7-h3xv-cfp3/GHSA-37q7-h3xv-cfp3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37q7-h3xv-cfp3",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:07Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45070"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json
index c25ecad9a07..c2f39bd072a 100644
--- a/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json
+++ b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3856-cjch-9cv8",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:57:37Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40117"
@@ -38,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-38h4-p674-c649/GHSA-38h4-p674-c649.json b/advisories/unreviewed/2023/10/GHSA-38h4-p674-c649/GHSA-38h4-p674-c649.json
index 3d6d77fba6d..a23a46c74f6 100644
--- a/advisories/unreviewed/2023/10/GHSA-38h4-p674-c649/GHSA-38h4-p674-c649.json
+++ b/advisories/unreviewed/2023/10/GHSA-38h4-p674-c649/GHSA-38h4-p674-c649.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38h4-p674-c649",
- "modified": "2023-10-14T03:31:15Z",
+ "modified": "2024-04-04T08:35:16Z",
"published": "2023-10-12T09:30:26Z",
"aliases": [
"CVE-2023-45047"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T09:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-38rh-4m8x-2658/GHSA-38rh-4m8x-2658.json b/advisories/unreviewed/2023/10/GHSA-38rh-4m8x-2658/GHSA-38rh-4m8x-2658.json
index e1914bce756..04bbb5d56bb 100644
--- a/advisories/unreviewed/2023/10/GHSA-38rh-4m8x-2658/GHSA-38rh-4m8x-2658.json
+++ b/advisories/unreviewed/2023/10/GHSA-38rh-4m8x-2658/GHSA-38rh-4m8x-2658.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38rh-4m8x-2658",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:46Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2023-35024"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3c2j-r5f4-2fcc/GHSA-3c2j-r5f4-2fcc.json b/advisories/unreviewed/2023/10/GHSA-3c2j-r5f4-2fcc/GHSA-3c2j-r5f4-2fcc.json
index 8df2aecdfe8..1434a321d38 100644
--- a/advisories/unreviewed/2023/10/GHSA-3c2j-r5f4-2fcc/GHSA-3c2j-r5f4-2fcc.json
+++ b/advisories/unreviewed/2023/10/GHSA-3c2j-r5f4-2fcc/GHSA-3c2j-r5f4-2fcc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c2j-r5f4-2fcc",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:55Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22119"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3c82-4vr9-q4gw/GHSA-3c82-4vr9-q4gw.json b/advisories/unreviewed/2023/10/GHSA-3c82-4vr9-q4gw/GHSA-3c82-4vr9-q4gw.json
index f02bcd86a13..7b3d200d116 100644
--- a/advisories/unreviewed/2023/10/GHSA-3c82-4vr9-q4gw/GHSA-3c82-4vr9-q4gw.json
+++ b/advisories/unreviewed/2023/10/GHSA-3c82-4vr9-q4gw/GHSA-3c82-4vr9-q4gw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c82-4vr9-q4gw",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:16Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2021-29913"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json
index 4dece94f6c7..e1d8acd5d61 100644
--- a/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json
+++ b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c9r-8wrp-84w3",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:40Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40129"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3f75-cqgv-mw4m/GHSA-3f75-cqgv-mw4m.json b/advisories/unreviewed/2023/10/GHSA-3f75-cqgv-mw4m/GHSA-3f75-cqgv-mw4m.json
index 288dd461828..6a201d9db1e 100644
--- a/advisories/unreviewed/2023/10/GHSA-3f75-cqgv-mw4m/GHSA-3f75-cqgv-mw4m.json
+++ b/advisories/unreviewed/2023/10/GHSA-3f75-cqgv-mw4m/GHSA-3f75-cqgv-mw4m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f75-cqgv-mw4m",
- "modified": "2023-10-18T06:30:30Z",
+ "modified": "2024-04-04T08:45:40Z",
"published": "2023-10-18T06:30:30Z",
"aliases": [
"CVE-2023-3254"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T05:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json b/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json
index 849a4bfa59f..30fa60fd49d 100644
--- a/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json
+++ b/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g9h-f994-3h4c",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:34Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46562"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3h2f-562g-hqwc/GHSA-3h2f-562g-hqwc.json b/advisories/unreviewed/2023/10/GHSA-3h2f-562g-hqwc/GHSA-3h2f-562g-hqwc.json
index 689bf026f7c..dd3c1ef181d 100644
--- a/advisories/unreviewed/2023/10/GHSA-3h2f-562g-hqwc/GHSA-3h2f-562g-hqwc.json
+++ b/advisories/unreviewed/2023/10/GHSA-3h2f-562g-hqwc/GHSA-3h2f-562g-hqwc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h2f-562g-hqwc",
- "modified": "2023-10-19T18:30:29Z",
+ "modified": "2024-04-04T08:45:29Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41712"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3h69-hjjf-qcc3/GHSA-3h69-hjjf-qcc3.json b/advisories/unreviewed/2023/10/GHSA-3h69-hjjf-qcc3/GHSA-3h69-hjjf-qcc3.json
index c4f82310544..341c4cba58e 100644
--- a/advisories/unreviewed/2023/10/GHSA-3h69-hjjf-qcc3/GHSA-3h69-hjjf-qcc3.json
+++ b/advisories/unreviewed/2023/10/GHSA-3h69-hjjf-qcc3/GHSA-3h69-hjjf-qcc3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h69-hjjf-qcc3",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:27Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45628"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json b/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json
index 1c3df6dd06d..4934ce767f4 100644
--- a/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json
+++ b/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j7c-23m3-57jj",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:10Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2018-17559"
],
"details": "Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-59"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3j7w-jp46-9752/GHSA-3j7w-jp46-9752.json b/advisories/unreviewed/2023/10/GHSA-3j7w-jp46-9752/GHSA-3j7w-jp46-9752.json
index f90cc7b8f58..3bf410c5415 100644
--- a/advisories/unreviewed/2023/10/GHSA-3j7w-jp46-9752/GHSA-3j7w-jp46-9752.json
+++ b/advisories/unreviewed/2023/10/GHSA-3j7w-jp46-9752/GHSA-3j7w-jp46-9752.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j7w-jp46-9752",
- "modified": "2023-10-13T09:30:22Z",
+ "modified": "2024-04-04T08:37:30Z",
"published": "2023-10-13T09:30:22Z",
"aliases": [
"CVE-2023-38219"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:40Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3j9j-5462-cpx8/GHSA-3j9j-5462-cpx8.json b/advisories/unreviewed/2023/10/GHSA-3j9j-5462-cpx8/GHSA-3j9j-5462-cpx8.json
index 701eb4d894a..0f794c1ff4f 100644
--- a/advisories/unreviewed/2023/10/GHSA-3j9j-5462-cpx8/GHSA-3j9j-5462-cpx8.json
+++ b/advisories/unreviewed/2023/10/GHSA-3j9j-5462-cpx8/GHSA-3j9j-5462-cpx8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j9j-5462-cpx8",
- "modified": "2023-10-28T03:30:21Z",
+ "modified": "2024-04-04T08:52:44Z",
"published": "2023-10-22T18:30:17Z",
"aliases": [
"CVE-2023-46303"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-918"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T18:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3jqw-qj8r-mjgp/GHSA-3jqw-qj8r-mjgp.json b/advisories/unreviewed/2023/10/GHSA-3jqw-qj8r-mjgp/GHSA-3jqw-qj8r-mjgp.json
index 4a5a2a6afa6..900ab2e7717 100644
--- a/advisories/unreviewed/2023/10/GHSA-3jqw-qj8r-mjgp/GHSA-3jqw-qj8r-mjgp.json
+++ b/advisories/unreviewed/2023/10/GHSA-3jqw-qj8r-mjgp/GHSA-3jqw-qj8r-mjgp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jqw-qj8r-mjgp",
- "modified": "2023-10-18T18:31:38Z",
+ "modified": "2024-04-04T08:46:34Z",
"published": "2023-10-18T18:31:38Z",
"aliases": [
"CVE-2023-30911"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json b/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json
index aa19c199359..648f2f546eb 100644
--- a/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json
+++ b/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m8h-rcx6-p525",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:52Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40135"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3mpm-5q2w-wr7w/GHSA-3mpm-5q2w-wr7w.json b/advisories/unreviewed/2023/10/GHSA-3mpm-5q2w-wr7w/GHSA-3mpm-5q2w-wr7w.json
index 7cadfb23c1e..9f9bb612083 100644
--- a/advisories/unreviewed/2023/10/GHSA-3mpm-5q2w-wr7w/GHSA-3mpm-5q2w-wr7w.json
+++ b/advisories/unreviewed/2023/10/GHSA-3mpm-5q2w-wr7w/GHSA-3mpm-5q2w-wr7w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mpm-5q2w-wr7w",
- "modified": "2023-10-23T18:30:46Z",
+ "modified": "2024-04-04T08:53:17Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-37532"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T17:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3pg9-8r34-25v2/GHSA-3pg9-8r34-25v2.json b/advisories/unreviewed/2023/10/GHSA-3pg9-8r34-25v2/GHSA-3pg9-8r34-25v2.json
index ec8ec635372..28f2c2e0c0c 100644
--- a/advisories/unreviewed/2023/10/GHSA-3pg9-8r34-25v2/GHSA-3pg9-8r34-25v2.json
+++ b/advisories/unreviewed/2023/10/GHSA-3pg9-8r34-25v2/GHSA-3pg9-8r34-25v2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3pg9-8r34-25v2",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:49:13Z",
"published": "2023-10-20T00:30:24Z",
"aliases": [
"CVE-2023-43359"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3ph5-58qm-r6wg/GHSA-3ph5-58qm-r6wg.json b/advisories/unreviewed/2023/10/GHSA-3ph5-58qm-r6wg/GHSA-3ph5-58qm-r6wg.json
index 8c5d95ab340..7d8cab5ca3f 100644
--- a/advisories/unreviewed/2023/10/GHSA-3ph5-58qm-r6wg/GHSA-3ph5-58qm-r6wg.json
+++ b/advisories/unreviewed/2023/10/GHSA-3ph5-58qm-r6wg/GHSA-3ph5-58qm-r6wg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3ph5-58qm-r6wg",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:54Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22118"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json
index cf704693523..fa114db795e 100644
--- a/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json
+++ b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qf9-64j6-3672",
- "modified": "2023-10-20T18:30:56Z",
+ "modified": "2024-04-04T08:51:25Z",
"published": "2023-10-20T18:30:56Z",
"aliases": [
"CVE-2023-3933"
@@ -35,7 +35,7 @@
"CWE-1321",
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T16:15:19Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3qmc-vv7g-wccj/GHSA-3qmc-vv7g-wccj.json b/advisories/unreviewed/2023/10/GHSA-3qmc-vv7g-wccj/GHSA-3qmc-vv7g-wccj.json
index 831acb36715..64e70c5f318 100644
--- a/advisories/unreviewed/2023/10/GHSA-3qmc-vv7g-wccj/GHSA-3qmc-vv7g-wccj.json
+++ b/advisories/unreviewed/2023/10/GHSA-3qmc-vv7g-wccj/GHSA-3qmc-vv7g-wccj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qmc-vv7g-wccj",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:50Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-46449"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-732"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3qmw-7623-hwxf/GHSA-3qmw-7623-hwxf.json b/advisories/unreviewed/2023/10/GHSA-3qmw-7623-hwxf/GHSA-3qmw-7623-hwxf.json
index 7b28d960f4f..38eeee0a867 100644
--- a/advisories/unreviewed/2023/10/GHSA-3qmw-7623-hwxf/GHSA-3qmw-7623-hwxf.json
+++ b/advisories/unreviewed/2023/10/GHSA-3qmw-7623-hwxf/GHSA-3qmw-7623-hwxf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qmw-7623-hwxf",
- "modified": "2023-10-19T15:31:07Z",
+ "modified": "2024-04-04T08:48:16Z",
"published": "2023-10-19T15:31:07Z",
"aliases": [
"CVE-2023-35184"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3rhv-vcmv-prv6/GHSA-3rhv-vcmv-prv6.json b/advisories/unreviewed/2023/10/GHSA-3rhv-vcmv-prv6/GHSA-3rhv-vcmv-prv6.json
index dc95583efea..27accff1e36 100644
--- a/advisories/unreviewed/2023/10/GHSA-3rhv-vcmv-prv6/GHSA-3rhv-vcmv-prv6.json
+++ b/advisories/unreviewed/2023/10/GHSA-3rhv-vcmv-prv6/GHSA-3rhv-vcmv-prv6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rhv-vcmv-prv6",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:11Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5533"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3vfv-wc96-x87r/GHSA-3vfv-wc96-x87r.json b/advisories/unreviewed/2023/10/GHSA-3vfv-wc96-x87r/GHSA-3vfv-wc96-x87r.json
index f6403a45ea7..a3699e06bb5 100644
--- a/advisories/unreviewed/2023/10/GHSA-3vfv-wc96-x87r/GHSA-3vfv-wc96-x87r.json
+++ b/advisories/unreviewed/2023/10/GHSA-3vfv-wc96-x87r/GHSA-3vfv-wc96-x87r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vfv-wc96-x87r",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:03Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44193"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
index 2c1374c34fa..b0d065e58c4 100644
--- a/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
+++ b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vj4-3g37-rf7w",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:52:45Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46085"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3wm5-3g94-xp54/GHSA-3wm5-3g94-xp54.json b/advisories/unreviewed/2023/10/GHSA-3wm5-3g94-xp54/GHSA-3wm5-3g94-xp54.json
index 635bbd2d123..431da1d28c2 100644
--- a/advisories/unreviewed/2023/10/GHSA-3wm5-3g94-xp54/GHSA-3wm5-3g94-xp54.json
+++ b/advisories/unreviewed/2023/10/GHSA-3wm5-3g94-xp54/GHSA-3wm5-3g94-xp54.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wm5-3g94-xp54",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:42:08Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-45542"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T21:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-3x3x-vjcr-56cc/GHSA-3x3x-vjcr-56cc.json b/advisories/unreviewed/2023/10/GHSA-3x3x-vjcr-56cc/GHSA-3x3x-vjcr-56cc.json
index 5b147cc498c..378ac5d4c37 100644
--- a/advisories/unreviewed/2023/10/GHSA-3x3x-vjcr-56cc/GHSA-3x3x-vjcr-56cc.json
+++ b/advisories/unreviewed/2023/10/GHSA-3x3x-vjcr-56cc/GHSA-3x3x-vjcr-56cc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x3x-vjcr-56cc",
- "modified": "2023-10-19T15:31:03Z",
+ "modified": "2024-04-04T08:39:02Z",
"published": "2023-10-16T03:30:31Z",
"aliases": [
"CVE-2023-45898"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lkml.org/lkml/2023/8/13/477"
},
+ {
+ "type": "WEB",
+ "url": "https://lore.kernel.org/lkml/aa03f191-445c-0d2e-d6d7-0a3208d7df7a%40huawei.com/T"
+ },
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/aa03f191-445c-0d2e-d6d7-0a3208d7df7a@huawei.com/T"
@@ -46,7 +50,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T03:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-42hr-vjrg-wjr7/GHSA-42hr-vjrg-wjr7.json b/advisories/unreviewed/2023/10/GHSA-42hr-vjrg-wjr7/GHSA-42hr-vjrg-wjr7.json
index d222ef13697..1f1446874f0 100644
--- a/advisories/unreviewed/2023/10/GHSA-42hr-vjrg-wjr7/GHSA-42hr-vjrg-wjr7.json
+++ b/advisories/unreviewed/2023/10/GHSA-42hr-vjrg-wjr7/GHSA-42hr-vjrg-wjr7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42hr-vjrg-wjr7",
- "modified": "2023-10-31T18:31:43Z",
+ "modified": "2024-04-04T08:49:05Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-45376"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-42jw-237g-7j4r/GHSA-42jw-237g-7j4r.json b/advisories/unreviewed/2023/10/GHSA-42jw-237g-7j4r/GHSA-42jw-237g-7j4r.json
index e675d775526..1996cf96b11 100644
--- a/advisories/unreviewed/2023/10/GHSA-42jw-237g-7j4r/GHSA-42jw-237g-7j4r.json
+++ b/advisories/unreviewed/2023/10/GHSA-42jw-237g-7j4r/GHSA-42jw-237g-7j4r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42jw-237g-7j4r",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:47:49Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-43252"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-433v-4977-67pv/GHSA-433v-4977-67pv.json b/advisories/unreviewed/2023/10/GHSA-433v-4977-67pv/GHSA-433v-4977-67pv.json
index eeb8e69b58c..f8683e59168 100644
--- a/advisories/unreviewed/2023/10/GHSA-433v-4977-67pv/GHSA-433v-4977-67pv.json
+++ b/advisories/unreviewed/2023/10/GHSA-433v-4977-67pv/GHSA-433v-4977-67pv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-433v-4977-67pv",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:26Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45904"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json b/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json
index 24dce786708..fe340edbcfe 100644
--- a/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json
+++ b/advisories/unreviewed/2023/10/GHSA-43pr-r6xw-f56v/GHSA-43pr-r6xw-f56v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43pr-r6xw-f56v",
- "modified": "2023-10-19T21:30:18Z",
+ "modified": "2024-04-04T08:49:10Z",
"published": "2023-10-19T21:30:18Z",
"aliases": [
"CVE-2023-30131"
],
"details": "An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json b/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json
index 1a733440e9c..f72e9438e2a 100644
--- a/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json
+++ b/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4473-7649-rj9x",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:24Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-3042"
@@ -24,13 +24,18 @@
{
"type": "WEB",
"url": "https://auth.dotcms.com/security/SI-68"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.dotcms.com/security/SI-68"
}
],
"database_specific": {
"cwe_ids": [
- "CWE-20"
+ "CWE-20",
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-456w-4cfv-54mf/GHSA-456w-4cfv-54mf.json b/advisories/unreviewed/2023/10/GHSA-456w-4cfv-54mf/GHSA-456w-4cfv-54mf.json
index 6c5e2865bde..784e9ace5d8 100644
--- a/advisories/unreviewed/2023/10/GHSA-456w-4cfv-54mf/GHSA-456w-4cfv-54mf.json
+++ b/advisories/unreviewed/2023/10/GHSA-456w-4cfv-54mf/GHSA-456w-4cfv-54mf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-456w-4cfv-54mf",
- "modified": "2023-10-13T18:30:19Z",
+ "modified": "2024-04-04T08:38:13Z",
"published": "2023-10-13T18:30:19Z",
"aliases": [
"CVE-2023-45270"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T16:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json b/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json
index 9d560c0e59d..1f78807d4f0 100644
--- a/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json
+++ b/advisories/unreviewed/2023/10/GHSA-45rg-4qh3-jxp9/GHSA-45rg-4qh3-jxp9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45rg-4qh3-jxp9",
- "modified": "2023-10-27T15:30:18Z",
+ "modified": "2024-04-04T08:49:41Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4271"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json b/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json
index e9812542ff9..8bda2f0d1d8 100644
--- a/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json
+++ b/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46j9-q72c-3w95",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:52:14Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-46055"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T07:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-474m-7m4r-wvgh/GHSA-474m-7m4r-wvgh.json b/advisories/unreviewed/2023/10/GHSA-474m-7m4r-wvgh/GHSA-474m-7m4r-wvgh.json
index b6f42eefa42..406dd546760 100644
--- a/advisories/unreviewed/2023/10/GHSA-474m-7m4r-wvgh/GHSA-474m-7m4r-wvgh.json
+++ b/advisories/unreviewed/2023/10/GHSA-474m-7m4r-wvgh/GHSA-474m-7m4r-wvgh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-474m-7m4r-wvgh",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:43:53Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22071"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
index fd83a26cc62..113fd59050d 100644
--- a/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
+++ b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47h2-h6q2-ghrw",
- "modified": "2023-10-28T03:30:21Z",
+ "modified": "2024-04-04T08:52:50Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-46319"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T00:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json b/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json
index 5c883df93f9..a56ab0ed409 100644
--- a/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json
+++ b/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4869-ghp2-7x5q",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:53:59Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26571"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-48hc-h5m8-9fxf/GHSA-48hc-h5m8-9fxf.json b/advisories/unreviewed/2023/10/GHSA-48hc-h5m8-9fxf/GHSA-48hc-h5m8-9fxf.json
index 2c157be997d..4b5b1191bcd 100644
--- a/advisories/unreviewed/2023/10/GHSA-48hc-h5m8-9fxf/GHSA-48hc-h5m8-9fxf.json
+++ b/advisories/unreviewed/2023/10/GHSA-48hc-h5m8-9fxf/GHSA-48hc-h5m8-9fxf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48hc-h5m8-9fxf",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:24Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45903"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-48r4-c3jw-rj8r/GHSA-48r4-c3jw-rj8r.json b/advisories/unreviewed/2023/10/GHSA-48r4-c3jw-rj8r/GHSA-48r4-c3jw-rj8r.json
index e1fb51a2a2e..2a1f3180ec4 100644
--- a/advisories/unreviewed/2023/10/GHSA-48r4-c3jw-rj8r/GHSA-48r4-c3jw-rj8r.json
+++ b/advisories/unreviewed/2023/10/GHSA-48r4-c3jw-rj8r/GHSA-48r4-c3jw-rj8r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48r4-c3jw-rj8r",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:51Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22109"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-49gm-5685-8fxv/GHSA-49gm-5685-8fxv.json b/advisories/unreviewed/2023/10/GHSA-49gm-5685-8fxv/GHSA-49gm-5685-8fxv.json
index d1db850161f..4eac54038e7 100644
--- a/advisories/unreviewed/2023/10/GHSA-49gm-5685-8fxv/GHSA-49gm-5685-8fxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-49gm-5685-8fxv/GHSA-49gm-5685-8fxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49gm-5685-8fxv",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:51Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-44311"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-49j2-f7c9-w9qc/GHSA-49j2-f7c9-w9qc.json b/advisories/unreviewed/2023/10/GHSA-49j2-f7c9-w9qc/GHSA-49j2-f7c9-w9qc.json
index e9b69490f20..f237856542e 100644
--- a/advisories/unreviewed/2023/10/GHSA-49j2-f7c9-w9qc/GHSA-49j2-f7c9-w9qc.json
+++ b/advisories/unreviewed/2023/10/GHSA-49j2-f7c9-w9qc/GHSA-49j2-f7c9-w9qc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49j2-f7c9-w9qc",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:39:15Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-45575"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4c7j-v446-xgx3/GHSA-4c7j-v446-xgx3.json b/advisories/unreviewed/2023/10/GHSA-4c7j-v446-xgx3/GHSA-4c7j-v446-xgx3.json
index 36ac2aebad1..1ea8d68a147 100644
--- a/advisories/unreviewed/2023/10/GHSA-4c7j-v446-xgx3/GHSA-4c7j-v446-xgx3.json
+++ b/advisories/unreviewed/2023/10/GHSA-4c7j-v446-xgx3/GHSA-4c7j-v446-xgx3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c7j-v446-xgx3",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:46:42Z",
"published": "2023-10-18T21:33:11Z",
"aliases": [
"CVE-2023-35656"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4cgf-2hf9-w2rc/GHSA-4cgf-2hf9-w2rc.json b/advisories/unreviewed/2023/10/GHSA-4cgf-2hf9-w2rc/GHSA-4cgf-2hf9-w2rc.json
index cd64da784da..3dcc384f32f 100644
--- a/advisories/unreviewed/2023/10/GHSA-4cgf-2hf9-w2rc/GHSA-4cgf-2hf9-w2rc.json
+++ b/advisories/unreviewed/2023/10/GHSA-4cgf-2hf9-w2rc/GHSA-4cgf-2hf9-w2rc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cgf-2hf9-w2rc",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:04Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22126"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json b/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json
index 764a0c09e9b..6feee5e228b 100644
--- a/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json
+++ b/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f7j-xf8r-8572",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:09Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26576"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4g94-rrhw-h5fw/GHSA-4g94-rrhw-h5fw.json b/advisories/unreviewed/2023/10/GHSA-4g94-rrhw-h5fw/GHSA-4g94-rrhw-h5fw.json
index f19d6150cff..bd3e2d10c86 100644
--- a/advisories/unreviewed/2023/10/GHSA-4g94-rrhw-h5fw/GHSA-4g94-rrhw-h5fw.json
+++ b/advisories/unreviewed/2023/10/GHSA-4g94-rrhw-h5fw/GHSA-4g94-rrhw-h5fw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g94-rrhw-h5fw",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:59Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-32275"
@@ -32,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-201"
+ "CWE-201",
+ "CWE-668"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4g9c-4jmr-xrqp/GHSA-4g9c-4jmr-xrqp.json b/advisories/unreviewed/2023/10/GHSA-4g9c-4jmr-xrqp/GHSA-4g9c-4jmr-xrqp.json
index 411853029fc..8ea97e34d77 100644
--- a/advisories/unreviewed/2023/10/GHSA-4g9c-4jmr-xrqp/GHSA-4g9c-4jmr-xrqp.json
+++ b/advisories/unreviewed/2023/10/GHSA-4g9c-4jmr-xrqp/GHSA-4g9c-4jmr-xrqp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g9c-4jmr-xrqp",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:21Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-5562"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T20:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4gh5-3g83-4888/GHSA-4gh5-3g83-4888.json b/advisories/unreviewed/2023/10/GHSA-4gh5-3g83-4888/GHSA-4gh5-3g83-4888.json
index cc15b4788e4..b279536b1b3 100644
--- a/advisories/unreviewed/2023/10/GHSA-4gh5-3g83-4888/GHSA-4gh5-3g83-4888.json
+++ b/advisories/unreviewed/2023/10/GHSA-4gh5-3g83-4888/GHSA-4gh5-3g83-4888.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gh5-3g83-4888",
- "modified": "2023-10-12T06:30:26Z",
+ "modified": "2024-04-04T08:35:06Z",
"published": "2023-10-12T06:30:26Z",
"aliases": [
"CVE-2023-42298"
],
"details": "An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-190"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T04:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4grg-q38c-r772/GHSA-4grg-q38c-r772.json b/advisories/unreviewed/2023/10/GHSA-4grg-q38c-r772/GHSA-4grg-q38c-r772.json
index fc74044acd7..7848f53c06c 100644
--- a/advisories/unreviewed/2023/10/GHSA-4grg-q38c-r772/GHSA-4grg-q38c-r772.json
+++ b/advisories/unreviewed/2023/10/GHSA-4grg-q38c-r772/GHSA-4grg-q38c-r772.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4grg-q38c-r772",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:41Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4648"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4gxq-5q4x-qpf7/GHSA-4gxq-5q4x-qpf7.json b/advisories/unreviewed/2023/10/GHSA-4gxq-5q4x-qpf7/GHSA-4gxq-5q4x-qpf7.json
index 8e2a9c4fe62..d07ea990738 100644
--- a/advisories/unreviewed/2023/10/GHSA-4gxq-5q4x-qpf7/GHSA-4gxq-5q4x-qpf7.json
+++ b/advisories/unreviewed/2023/10/GHSA-4gxq-5q4x-qpf7/GHSA-4gxq-5q4x-qpf7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gxq-5q4x-qpf7",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:49Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45054"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4hqp-42w7-3hv5/GHSA-4hqp-42w7-3hv5.json b/advisories/unreviewed/2023/10/GHSA-4hqp-42w7-3hv5/GHSA-4hqp-42w7-3hv5.json
index 2f2841b9583..44d342b3df2 100644
--- a/advisories/unreviewed/2023/10/GHSA-4hqp-42w7-3hv5/GHSA-4hqp-42w7-3hv5.json
+++ b/advisories/unreviewed/2023/10/GHSA-4hqp-42w7-3hv5/GHSA-4hqp-42w7-3hv5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hqp-42w7-3hv5",
- "modified": "2023-10-13T18:30:19Z",
+ "modified": "2024-04-04T08:38:12Z",
"published": "2023-10-13T18:30:19Z",
"aliases": [
"CVE-2023-40682"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-532"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4j4f-q993-cr2r/GHSA-4j4f-q993-cr2r.json b/advisories/unreviewed/2023/10/GHSA-4j4f-q993-cr2r/GHSA-4j4f-q993-cr2r.json
index e414057a9b9..ed6ef984a38 100644
--- a/advisories/unreviewed/2023/10/GHSA-4j4f-q993-cr2r/GHSA-4j4f-q993-cr2r.json
+++ b/advisories/unreviewed/2023/10/GHSA-4j4f-q993-cr2r/GHSA-4j4f-q993-cr2r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j4f-q993-cr2r",
- "modified": "2023-10-18T21:33:10Z",
+ "modified": "2024-04-04T08:38:29Z",
"published": "2023-10-14T03:31:16Z",
"aliases": [
"CVE-2023-45852"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T02:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json b/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json
index 096d86404d8..d45e067b721 100644
--- a/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json
+++ b/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j6r-mf7f-44jq",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:52:13Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-46054"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T07:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4j8p-h8p2-rc88/GHSA-4j8p-h8p2-rc88.json b/advisories/unreviewed/2023/10/GHSA-4j8p-h8p2-rc88/GHSA-4j8p-h8p2-rc88.json
index 3c05dea116d..44e0f55533e 100644
--- a/advisories/unreviewed/2023/10/GHSA-4j8p-h8p2-rc88/GHSA-4j8p-h8p2-rc88.json
+++ b/advisories/unreviewed/2023/10/GHSA-4j8p-h8p2-rc88/GHSA-4j8p-h8p2-rc88.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j8p-h8p2-rc88",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:45Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-45958"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4j94-2784-394x/GHSA-4j94-2784-394x.json b/advisories/unreviewed/2023/10/GHSA-4j94-2784-394x/GHSA-4j94-2784-394x.json
index cf9a17f6fae..812b34d4099 100644
--- a/advisories/unreviewed/2023/10/GHSA-4j94-2784-394x/GHSA-4j94-2784-394x.json
+++ b/advisories/unreviewed/2023/10/GHSA-4j94-2784-394x/GHSA-4j94-2784-394x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j94-2784-394x",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:15Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-43959"
],
"details": "An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -18,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43959"
},
+ {
+ "type": "WEB",
+ "url": "https://hackmd.io/%40tahaafarooq/auth_rce_voip"
+ },
{
"type": "WEB",
"url": "https://hackmd.io/@tahaafarooq/auth_rce_voip"
@@ -29,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4jh4-mwq8-wx24/GHSA-4jh4-mwq8-wx24.json b/advisories/unreviewed/2023/10/GHSA-4jh4-mwq8-wx24/GHSA-4jh4-mwq8-wx24.json
index 86580d82ac7..3f6f4a183e8 100644
--- a/advisories/unreviewed/2023/10/GHSA-4jh4-mwq8-wx24/GHSA-4jh4-mwq8-wx24.json
+++ b/advisories/unreviewed/2023/10/GHSA-4jh4-mwq8-wx24/GHSA-4jh4-mwq8-wx24.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jh4-mwq8-wx24",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:16Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36714"
@@ -35,7 +35,7 @@
"CWE-285",
"CWE-863"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4jhw-x435-x5f7/GHSA-4jhw-x435-x5f7.json b/advisories/unreviewed/2023/10/GHSA-4jhw-x435-x5f7/GHSA-4jhw-x435-x5f7.json
index 91fedca014a..7a47e436408 100644
--- a/advisories/unreviewed/2023/10/GHSA-4jhw-x435-x5f7/GHSA-4jhw-x435-x5f7.json
+++ b/advisories/unreviewed/2023/10/GHSA-4jhw-x435-x5f7/GHSA-4jhw-x435-x5f7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jhw-x435-x5f7",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:56Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-5632"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-834"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json b/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json
index 7a9b2eecde9..4691174d252 100644
--- a/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json
+++ b/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mh7-v2h4-6vf9",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:16Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2023-43352"
],
"details": "An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4mq9-mp5g-r83q/GHSA-4mq9-mp5g-r83q.json b/advisories/unreviewed/2023/10/GHSA-4mq9-mp5g-r83q/GHSA-4mq9-mp5g-r83q.json
index 3659d3135f8..33de5d14050 100644
--- a/advisories/unreviewed/2023/10/GHSA-4mq9-mp5g-r83q/GHSA-4mq9-mp5g-r83q.json
+++ b/advisories/unreviewed/2023/10/GHSA-4mq9-mp5g-r83q/GHSA-4mq9-mp5g-r83q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mq9-mp5g-r83q",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:15Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3155"
],
"details": "The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-552"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json b/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json
index 0cb84017fe1..b3311a2b51d 100644
--- a/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json
+++ b/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mwj-qxcc-x2p8",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:53:29Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-27149"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4p2x-j6f2-872j/GHSA-4p2x-j6f2-872j.json b/advisories/unreviewed/2023/10/GHSA-4p2x-j6f2-872j/GHSA-4p2x-j6f2-872j.json
index 68d5a12f1a2..382f6cc9238 100644
--- a/advisories/unreviewed/2023/10/GHSA-4p2x-j6f2-872j/GHSA-4p2x-j6f2-872j.json
+++ b/advisories/unreviewed/2023/10/GHSA-4p2x-j6f2-872j/GHSA-4p2x-j6f2-872j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p2x-j6f2-872j",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:10Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-27312"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-250"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T19:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json b/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json
index f2e3c424005..e7a7596b4e4 100644
--- a/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json
+++ b/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p52-qfg6-cwjr",
- "modified": "2023-10-20T21:31:01Z",
+ "modified": "2024-04-04T08:51:31Z",
"published": "2023-10-20T21:31:01Z",
"aliases": [
"CVE-2023-37824"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json b/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json
index 71246015524..f7e0789450f 100644
--- a/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json
+++ b/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pfv-vgmw-jgcr",
- "modified": "2023-10-25T12:30:35Z",
+ "modified": "2024-04-04T08:51:37Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43356"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4pgc-4ghm-q2mf/GHSA-4pgc-4ghm-q2mf.json b/advisories/unreviewed/2023/10/GHSA-4pgc-4ghm-q2mf/GHSA-4pgc-4ghm-q2mf.json
index 6e647725b0f..6d8f8783b11 100644
--- a/advisories/unreviewed/2023/10/GHSA-4pgc-4ghm-q2mf/GHSA-4pgc-4ghm-q2mf.json
+++ b/advisories/unreviewed/2023/10/GHSA-4pgc-4ghm-q2mf/GHSA-4pgc-4ghm-q2mf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pgc-4ghm-q2mf",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:38Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2022-4954"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json b/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json
index ea7f59ff0f4..4354e3aa324 100644
--- a/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json
+++ b/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pm7-5852-9cj6",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:56:29Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46556"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json b/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json
index c09487dab12..7ef16b4293b 100644
--- a/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json
+++ b/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pxq-qc65-2pqq",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:02Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28796"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-347"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4q58-qpcg-q4vf/GHSA-4q58-qpcg-q4vf.json b/advisories/unreviewed/2023/10/GHSA-4q58-qpcg-q4vf/GHSA-4q58-qpcg-q4vf.json
index 4f43aa43ee1..da008a6abe9 100644
--- a/advisories/unreviewed/2023/10/GHSA-4q58-qpcg-q4vf/GHSA-4q58-qpcg-q4vf.json
+++ b/advisories/unreviewed/2023/10/GHSA-4q58-qpcg-q4vf/GHSA-4q58-qpcg-q4vf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q58-qpcg-q4vf",
- "modified": "2023-10-18T18:31:38Z",
+ "modified": "2024-04-04T08:46:33Z",
"published": "2023-10-18T18:31:38Z",
"aliases": [
"CVE-2023-5642"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T16:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4r3r-8gr6-mjmm/GHSA-4r3r-8gr6-mjmm.json b/advisories/unreviewed/2023/10/GHSA-4r3r-8gr6-mjmm/GHSA-4r3r-8gr6-mjmm.json
index b8a1c75ce89..55880511a73 100644
--- a/advisories/unreviewed/2023/10/GHSA-4r3r-8gr6-mjmm/GHSA-4r3r-8gr6-mjmm.json
+++ b/advisories/unreviewed/2023/10/GHSA-4r3r-8gr6-mjmm/GHSA-4r3r-8gr6-mjmm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r3r-8gr6-mjmm",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:52Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22117"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json b/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json
index d8e4ac1e4a0..b4a78e52222 100644
--- a/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json
+++ b/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r9r-cpgw-cf98",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:06Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26574"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4rv5-xm6p-7p7f/GHSA-4rv5-xm6p-7p7f.json b/advisories/unreviewed/2023/10/GHSA-4rv5-xm6p-7p7f/GHSA-4rv5-xm6p-7p7f.json
index e51c95f7bdb..107cca2dd05 100644
--- a/advisories/unreviewed/2023/10/GHSA-4rv5-xm6p-7p7f/GHSA-4rv5-xm6p-7p7f.json
+++ b/advisories/unreviewed/2023/10/GHSA-4rv5-xm6p-7p7f/GHSA-4rv5-xm6p-7p7f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rv5-xm6p-7p7f",
- "modified": "2023-10-18T18:31:35Z",
+ "modified": "2024-04-04T08:38:32Z",
"published": "2023-10-14T06:30:54Z",
"aliases": [
"CVE-2023-30154"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T04:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json b/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json
index 92bc95da24d..470d07550b3 100644
--- a/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json
+++ b/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v9x-wfx7-57r9",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:41Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-29464"
@@ -31,7 +31,7 @@
"CWE-20",
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4vf3-57vh-hmm8/GHSA-4vf3-57vh-hmm8.json b/advisories/unreviewed/2023/10/GHSA-4vf3-57vh-hmm8/GHSA-4vf3-57vh-hmm8.json
index 84d2928b7b9..dc453badb5f 100644
--- a/advisories/unreviewed/2023/10/GHSA-4vf3-57vh-hmm8/GHSA-4vf3-57vh-hmm8.json
+++ b/advisories/unreviewed/2023/10/GHSA-4vf3-57vh-hmm8/GHSA-4vf3-57vh-hmm8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vf3-57vh-hmm8",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:00Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22125"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4vhm-j5mp-9wcg/GHSA-4vhm-j5mp-9wcg.json b/advisories/unreviewed/2023/10/GHSA-4vhm-j5mp-9wcg/GHSA-4vhm-j5mp-9wcg.json
index 82be73605eb..e932c1e235d 100644
--- a/advisories/unreviewed/2023/10/GHSA-4vhm-j5mp-9wcg/GHSA-4vhm-j5mp-9wcg.json
+++ b/advisories/unreviewed/2023/10/GHSA-4vhm-j5mp-9wcg/GHSA-4vhm-j5mp-9wcg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vhm-j5mp-9wcg",
- "modified": "2023-10-25T03:30:34Z",
+ "modified": "2024-04-04T08:46:11Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45073"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4x43-fwgv-cq8j/GHSA-4x43-fwgv-cq8j.json b/advisories/unreviewed/2023/10/GHSA-4x43-fwgv-cq8j/GHSA-4x43-fwgv-cq8j.json
index 564fa07f7df..fb714953736 100644
--- a/advisories/unreviewed/2023/10/GHSA-4x43-fwgv-cq8j/GHSA-4x43-fwgv-cq8j.json
+++ b/advisories/unreviewed/2023/10/GHSA-4x43-fwgv-cq8j/GHSA-4x43-fwgv-cq8j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4x43-fwgv-cq8j",
- "modified": "2023-10-25T18:32:22Z",
+ "modified": "2024-04-04T08:55:05Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39930"
@@ -35,7 +35,7 @@
"CWE-288",
"CWE-306"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4xch-3w57-6pj7/GHSA-4xch-3w57-6pj7.json b/advisories/unreviewed/2023/10/GHSA-4xch-3w57-6pj7/GHSA-4xch-3w57-6pj7.json
index f0e8b09e06e..96a885959e3 100644
--- a/advisories/unreviewed/2023/10/GHSA-4xch-3w57-6pj7/GHSA-4xch-3w57-6pj7.json
+++ b/advisories/unreviewed/2023/10/GHSA-4xch-3w57-6pj7/GHSA-4xch-3w57-6pj7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xch-3w57-6pj7",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:42:38Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-45386"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json b/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json
index 06e0214629f..a50b06626da 100644
--- a/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json
+++ b/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xxx-xjp2-284m",
- "modified": "2023-10-28T00:30:29Z",
+ "modified": "2024-04-04T08:55:19Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45554"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json b/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json
index d51b2391f05..e7f4e043678 100644
--- a/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json
+++ b/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52hf-8hgx-m78v",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:00Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26570"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-537g-m9mx-pvhm/GHSA-537g-m9mx-pvhm.json b/advisories/unreviewed/2023/10/GHSA-537g-m9mx-pvhm/GHSA-537g-m9mx-pvhm.json
index 86593c5453a..e123a31316a 100644
--- a/advisories/unreviewed/2023/10/GHSA-537g-m9mx-pvhm/GHSA-537g-m9mx-pvhm.json
+++ b/advisories/unreviewed/2023/10/GHSA-537g-m9mx-pvhm/GHSA-537g-m9mx-pvhm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-537g-m9mx-pvhm",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:45:13Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-39277"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-53p3-mj4q-6834/GHSA-53p3-mj4q-6834.json b/advisories/unreviewed/2023/10/GHSA-53p3-mj4q-6834/GHSA-53p3-mj4q-6834.json
index 9e64015e335..1f9f14184a4 100644
--- a/advisories/unreviewed/2023/10/GHSA-53p3-mj4q-6834/GHSA-53p3-mj4q-6834.json
+++ b/advisories/unreviewed/2023/10/GHSA-53p3-mj4q-6834/GHSA-53p3-mj4q-6834.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53p3-mj4q-6834",
- "modified": "2023-10-14T15:30:18Z",
+ "modified": "2024-04-04T08:38:40Z",
"published": "2023-10-14T15:30:18Z",
"aliases": [
"CVE-2022-33161"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-311"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-542f-549f-58vm/GHSA-542f-549f-58vm.json b/advisories/unreviewed/2023/10/GHSA-542f-549f-58vm/GHSA-542f-549f-58vm.json
index 63e3fc14fd7..a514148bc36 100644
--- a/advisories/unreviewed/2023/10/GHSA-542f-549f-58vm/GHSA-542f-549f-58vm.json
+++ b/advisories/unreviewed/2023/10/GHSA-542f-549f-58vm/GHSA-542f-549f-58vm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-542f-549f-58vm",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:58Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45391"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5488-g25c-556m/GHSA-5488-g25c-556m.json b/advisories/unreviewed/2023/10/GHSA-5488-g25c-556m/GHSA-5488-g25c-556m.json
index b7d80db14fe..1ce0b7a5373 100644
--- a/advisories/unreviewed/2023/10/GHSA-5488-g25c-556m/GHSA-5488-g25c-556m.json
+++ b/advisories/unreviewed/2023/10/GHSA-5488-g25c-556m/GHSA-5488-g25c-556m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5488-g25c-556m",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:24Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-32974"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-548m-xpmx-h6v4/GHSA-548m-xpmx-h6v4.json b/advisories/unreviewed/2023/10/GHSA-548m-xpmx-h6v4/GHSA-548m-xpmx-h6v4.json
index 6111dbcd6b0..5c76c832d06 100644
--- a/advisories/unreviewed/2023/10/GHSA-548m-xpmx-h6v4/GHSA-548m-xpmx-h6v4.json
+++ b/advisories/unreviewed/2023/10/GHSA-548m-xpmx-h6v4/GHSA-548m-xpmx-h6v4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-548m-xpmx-h6v4",
- "modified": "2023-10-23T21:30:58Z",
+ "modified": "2024-04-04T08:53:31Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-33839"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json b/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json
index 5236992c06d..415de84eb91 100644
--- a/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json
+++ b/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-549w-5fgc-66mp",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:57:58Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46509"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-555p-hvwp-mh56/GHSA-555p-hvwp-mh56.json b/advisories/unreviewed/2023/10/GHSA-555p-hvwp-mh56/GHSA-555p-hvwp-mh56.json
index 2b00b9f78e5..10dabeff8f2 100644
--- a/advisories/unreviewed/2023/10/GHSA-555p-hvwp-mh56/GHSA-555p-hvwp-mh56.json
+++ b/advisories/unreviewed/2023/10/GHSA-555p-hvwp-mh56/GHSA-555p-hvwp-mh56.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-555p-hvwp-mh56",
- "modified": "2023-10-31T18:31:43Z",
+ "modified": "2024-04-04T08:52:42Z",
"published": "2023-10-22T06:30:19Z",
"aliases": [
"CVE-2023-46301"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-116"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T04:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5572-2439-pvwc/GHSA-5572-2439-pvwc.json b/advisories/unreviewed/2023/10/GHSA-5572-2439-pvwc/GHSA-5572-2439-pvwc.json
index 260d5f789b1..e7ca96b52c1 100644
--- a/advisories/unreviewed/2023/10/GHSA-5572-2439-pvwc/GHSA-5572-2439-pvwc.json
+++ b/advisories/unreviewed/2023/10/GHSA-5572-2439-pvwc/GHSA-5572-2439-pvwc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5572-2439-pvwc",
- "modified": "2023-10-19T18:30:29Z",
+ "modified": "2024-04-04T08:45:25Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41715"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-559q-gjf6-hx34/GHSA-559q-gjf6-hx34.json b/advisories/unreviewed/2023/10/GHSA-559q-gjf6-hx34/GHSA-559q-gjf6-hx34.json
index b7fc3627147..f22ca120598 100644
--- a/advisories/unreviewed/2023/10/GHSA-559q-gjf6-hx34/GHSA-559q-gjf6-hx34.json
+++ b/advisories/unreviewed/2023/10/GHSA-559q-gjf6-hx34/GHSA-559q-gjf6-hx34.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-559q-gjf6-hx34",
- "modified": "2023-10-23T15:30:23Z",
+ "modified": "2024-04-04T08:42:39Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-45375"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-55h7-hprj-3g5x/GHSA-55h7-hprj-3g5x.json b/advisories/unreviewed/2023/10/GHSA-55h7-hprj-3g5x/GHSA-55h7-hprj-3g5x.json
index 930c4b26115..a87afbfb8bc 100644
--- a/advisories/unreviewed/2023/10/GHSA-55h7-hprj-3g5x/GHSA-55h7-hprj-3g5x.json
+++ b/advisories/unreviewed/2023/10/GHSA-55h7-hprj-3g5x/GHSA-55h7-hprj-3g5x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55h7-hprj-3g5x",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:53Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4796"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-566r-vx98-9rr7/GHSA-566r-vx98-9rr7.json b/advisories/unreviewed/2023/10/GHSA-566r-vx98-9rr7/GHSA-566r-vx98-9rr7.json
index c8e76516b3e..b80eed8ad49 100644
--- a/advisories/unreviewed/2023/10/GHSA-566r-vx98-9rr7/GHSA-566r-vx98-9rr7.json
+++ b/advisories/unreviewed/2023/10/GHSA-566r-vx98-9rr7/GHSA-566r-vx98-9rr7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-566r-vx98-9rr7",
- "modified": "2023-10-26T18:30:22Z",
+ "modified": "2024-04-04T08:49:36Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-2325"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json b/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json
index 980e63dbaf5..2f8efbda958 100644
--- a/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json
+++ b/advisories/unreviewed/2023/10/GHSA-56p2-xp5h-2cf3/GHSA-56p2-xp5h-2cf3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56p2-xp5h-2cf3",
- "modified": "2023-10-27T15:30:18Z",
+ "modified": "2024-04-04T08:49:16Z",
"published": "2023-10-20T00:30:25Z",
"aliases": [
"CVE-2023-43345"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T23:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-56qj-x9h6-9389/GHSA-56qj-x9h6-9389.json b/advisories/unreviewed/2023/10/GHSA-56qj-x9h6-9389/GHSA-56qj-x9h6-9389.json
index ccc5b0a4e0e..216d1dff92a 100644
--- a/advisories/unreviewed/2023/10/GHSA-56qj-x9h6-9389/GHSA-56qj-x9h6-9389.json
+++ b/advisories/unreviewed/2023/10/GHSA-56qj-x9h6-9389/GHSA-56qj-x9h6-9389.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56qj-x9h6-9389",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:48:57Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-27791"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-338"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-57rr-j54c-gw9x/GHSA-57rr-j54c-gw9x.json b/advisories/unreviewed/2023/10/GHSA-57rr-j54c-gw9x/GHSA-57rr-j54c-gw9x.json
index 8c3273e2e7e..20eea31ca5b 100644
--- a/advisories/unreviewed/2023/10/GHSA-57rr-j54c-gw9x/GHSA-57rr-j54c-gw9x.json
+++ b/advisories/unreviewed/2023/10/GHSA-57rr-j54c-gw9x/GHSA-57rr-j54c-gw9x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57rr-j54c-gw9x",
- "modified": "2023-10-25T03:30:36Z",
+ "modified": "2024-04-04T08:46:30Z",
"published": "2023-10-18T18:31:37Z",
"aliases": [
"CVE-2023-43250"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T16:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json b/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json
index 42174d9a85d..2f8458417a2 100644
--- a/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json
+++ b/advisories/unreviewed/2023/10/GHSA-59mr-825p-2g28/GHSA-59mr-825p-2g28.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59mr-825p-2g28",
- "modified": "2023-10-25T18:32:21Z",
+ "modified": "2024-04-04T08:54:35Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-30912"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:27Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5cg5-8chj-3gqc/GHSA-5cg5-8chj-3gqc.json b/advisories/unreviewed/2023/10/GHSA-5cg5-8chj-3gqc/GHSA-5cg5-8chj-3gqc.json
index dae638fe057..31417c0c499 100644
--- a/advisories/unreviewed/2023/10/GHSA-5cg5-8chj-3gqc/GHSA-5cg5-8chj-3gqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-5cg5-8chj-3gqc/GHSA-5cg5-8chj-3gqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cg5-8chj-3gqc",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:03Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-41843"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5cgm-4jc2-42h7/GHSA-5cgm-4jc2-42h7.json b/advisories/unreviewed/2023/10/GHSA-5cgm-4jc2-42h7/GHSA-5cgm-4jc2-42h7.json
index 868a727ba0c..7e1b5982ed1 100644
--- a/advisories/unreviewed/2023/10/GHSA-5cgm-4jc2-42h7/GHSA-5cgm-4jc2-42h7.json
+++ b/advisories/unreviewed/2023/10/GHSA-5cgm-4jc2-42h7/GHSA-5cgm-4jc2-42h7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cgm-4jc2-42h7",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:10Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45985"
],
"details": "TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T18:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5cq7-9mrf-9vfp/GHSA-5cq7-9mrf-9vfp.json b/advisories/unreviewed/2023/10/GHSA-5cq7-9mrf-9vfp/GHSA-5cq7-9mrf-9vfp.json
index 1efb8d79dcf..fb39a09b55d 100644
--- a/advisories/unreviewed/2023/10/GHSA-5cq7-9mrf-9vfp/GHSA-5cq7-9mrf-9vfp.json
+++ b/advisories/unreviewed/2023/10/GHSA-5cq7-9mrf-9vfp/GHSA-5cq7-9mrf-9vfp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cq7-9mrf-9vfp",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:13Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22083"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json b/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json
index a44b70e278c..dd3f4d83881 100644
--- a/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json
+++ b/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5f5r-qwxj-xhxq",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:07Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28805"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5f6x-wr72-j225/GHSA-5f6x-wr72-j225.json b/advisories/unreviewed/2023/10/GHSA-5f6x-wr72-j225/GHSA-5f6x-wr72-j225.json
index e5999b31ed3..21062b5c5c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-5f6x-wr72-j225/GHSA-5f6x-wr72-j225.json
+++ b/advisories/unreviewed/2023/10/GHSA-5f6x-wr72-j225/GHSA-5f6x-wr72-j225.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5f6x-wr72-j225",
- "modified": "2023-10-20T06:30:19Z",
+ "modified": "2024-04-04T08:49:28Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-5668"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T05:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5g66-7886-w8m2/GHSA-5g66-7886-w8m2.json b/advisories/unreviewed/2023/10/GHSA-5g66-7886-w8m2/GHSA-5g66-7886-w8m2.json
index 271cdc19a83..f05b9ab5791 100644
--- a/advisories/unreviewed/2023/10/GHSA-5g66-7886-w8m2/GHSA-5g66-7886-w8m2.json
+++ b/advisories/unreviewed/2023/10/GHSA-5g66-7886-w8m2/GHSA-5g66-7886-w8m2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g66-7886-w8m2",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:28Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-32976"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5gfj-h4p7-f68x/GHSA-5gfj-h4p7-f68x.json b/advisories/unreviewed/2023/10/GHSA-5gfj-h4p7-f68x/GHSA-5gfj-h4p7-f68x.json
index e0ba1d8c0e8..340c3f4dea5 100644
--- a/advisories/unreviewed/2023/10/GHSA-5gfj-h4p7-f68x/GHSA-5gfj-h4p7-f68x.json
+++ b/advisories/unreviewed/2023/10/GHSA-5gfj-h4p7-f68x/GHSA-5gfj-h4p7-f68x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gfj-h4p7-f68x",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:45Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4482"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5j36-w363-p3jq/GHSA-5j36-w363-p3jq.json b/advisories/unreviewed/2023/10/GHSA-5j36-w363-p3jq/GHSA-5j36-w363-p3jq.json
index ca44aa55b33..b7235557ab4 100644
--- a/advisories/unreviewed/2023/10/GHSA-5j36-w363-p3jq/GHSA-5j36-w363-p3jq.json
+++ b/advisories/unreviewed/2023/10/GHSA-5j36-w363-p3jq/GHSA-5j36-w363-p3jq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5j36-w363-p3jq",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:57Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4961"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5j8w-6m93-cp7q/GHSA-5j8w-6m93-cp7q.json b/advisories/unreviewed/2023/10/GHSA-5j8w-6m93-cp7q/GHSA-5j8w-6m93-cp7q.json
index 9dba56687d3..23397cae1d1 100644
--- a/advisories/unreviewed/2023/10/GHSA-5j8w-6m93-cp7q/GHSA-5j8w-6m93-cp7q.json
+++ b/advisories/unreviewed/2023/10/GHSA-5j8w-6m93-cp7q/GHSA-5j8w-6m93-cp7q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5j8w-6m93-cp7q",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:51Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45605"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5mmq-8hjw-gc3g/GHSA-5mmq-8hjw-gc3g.json b/advisories/unreviewed/2023/10/GHSA-5mmq-8hjw-gc3g/GHSA-5mmq-8hjw-gc3g.json
index ecff5d1467d..1b06d9c6e2b 100644
--- a/advisories/unreviewed/2023/10/GHSA-5mmq-8hjw-gc3g/GHSA-5mmq-8hjw-gc3g.json
+++ b/advisories/unreviewed/2023/10/GHSA-5mmq-8hjw-gc3g/GHSA-5mmq-8hjw-gc3g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mmq-8hjw-gc3g",
- "modified": "2023-10-19T15:31:03Z",
+ "modified": "2024-04-04T08:38:36Z",
"published": "2023-10-14T06:30:55Z",
"aliases": [
"CVE-2023-45856"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T05:15:55Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5pgp-q8pq-w37h/GHSA-5pgp-q8pq-w37h.json b/advisories/unreviewed/2023/10/GHSA-5pgp-q8pq-w37h/GHSA-5pgp-q8pq-w37h.json
index 5cf7a107c84..de902dd8506 100644
--- a/advisories/unreviewed/2023/10/GHSA-5pgp-q8pq-w37h/GHSA-5pgp-q8pq-w37h.json
+++ b/advisories/unreviewed/2023/10/GHSA-5pgp-q8pq-w37h/GHSA-5pgp-q8pq-w37h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5pgp-q8pq-w37h",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:25Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45643"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5prg-5cfp-g266/GHSA-5prg-5cfp-g266.json b/advisories/unreviewed/2023/10/GHSA-5prg-5cfp-g266/GHSA-5prg-5cfp-g266.json
index e8746cf9931..8aafcac14ea 100644
--- a/advisories/unreviewed/2023/10/GHSA-5prg-5cfp-g266/GHSA-5prg-5cfp-g266.json
+++ b/advisories/unreviewed/2023/10/GHSA-5prg-5cfp-g266/GHSA-5prg-5cfp-g266.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5prg-5cfp-g266",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:59Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22123"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5q42-rqhh-m4v6/GHSA-5q42-rqhh-m4v6.json b/advisories/unreviewed/2023/10/GHSA-5q42-rqhh-m4v6/GHSA-5q42-rqhh-m4v6.json
index 40303a763ad..eefd28c514d 100644
--- a/advisories/unreviewed/2023/10/GHSA-5q42-rqhh-m4v6/GHSA-5q42-rqhh-m4v6.json
+++ b/advisories/unreviewed/2023/10/GHSA-5q42-rqhh-m4v6/GHSA-5q42-rqhh-m4v6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q42-rqhh-m4v6",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:16Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26584"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json b/advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json
index 0ef3641d840..9af6985a6ec 100644
--- a/advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json
+++ b/advisories/unreviewed/2023/10/GHSA-5q5q-4pvv-q47c/GHSA-5q5q-4pvv-q47c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q5q-4pvv-q47c",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:52:46Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46089"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5qvw-j8jj-q3w9/GHSA-5qvw-j8jj-q3w9.json b/advisories/unreviewed/2023/10/GHSA-5qvw-j8jj-q3w9/GHSA-5qvw-j8jj-q3w9.json
index 1b7318c3431..3b306f56372 100644
--- a/advisories/unreviewed/2023/10/GHSA-5qvw-j8jj-q3w9/GHSA-5qvw-j8jj-q3w9.json
+++ b/advisories/unreviewed/2023/10/GHSA-5qvw-j8jj-q3w9/GHSA-5qvw-j8jj-q3w9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qvw-j8jj-q3w9",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:29Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-45576"
],
"details": "Buffer Overflow vulnerability in DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json b/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json
index ecb7ba52d07..34d4af5fc62 100644
--- a/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json
+++ b/advisories/unreviewed/2023/10/GHSA-5rj2-m4rq-8fmp/GHSA-5rj2-m4rq-8fmp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rj2-m4rq-8fmp",
- "modified": "2023-10-18T00:31:40Z",
+ "modified": "2024-04-04T08:43:45Z",
"published": "2023-10-18T00:31:40Z",
"aliases": [
"CVE-2023-22019"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json b/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json
index 1e295511124..a0be1d093ee 100644
--- a/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json
+++ b/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rpw-fg4q-7wj5",
- "modified": "2023-10-22T03:30:22Z",
+ "modified": "2024-04-04T08:52:37Z",
"published": "2023-10-22T03:30:22Z",
"aliases": [
"CVE-2023-38275"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T01:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5rqf-6wfj-r66h/GHSA-5rqf-6wfj-r66h.json b/advisories/unreviewed/2023/10/GHSA-5rqf-6wfj-r66h/GHSA-5rqf-6wfj-r66h.json
index 40f8d7f7ff0..d9ec7ff3176 100644
--- a/advisories/unreviewed/2023/10/GHSA-5rqf-6wfj-r66h/GHSA-5rqf-6wfj-r66h.json
+++ b/advisories/unreviewed/2023/10/GHSA-5rqf-6wfj-r66h/GHSA-5rqf-6wfj-r66h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rqf-6wfj-r66h",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:46Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45749"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json b/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json
index b63ffa64026..f2b87b85989 100644
--- a/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json
+++ b/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5v38-92h7-3886",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:12Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46527"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5vgg-9h5w-h365/GHSA-5vgg-9h5w-h365.json b/advisories/unreviewed/2023/10/GHSA-5vgg-9h5w-h365/GHSA-5vgg-9h5w-h365.json
index 7a5fbffce15..28ebd602e4c 100644
--- a/advisories/unreviewed/2023/10/GHSA-5vgg-9h5w-h365/GHSA-5vgg-9h5w-h365.json
+++ b/advisories/unreviewed/2023/10/GHSA-5vgg-9h5w-h365/GHSA-5vgg-9h5w-h365.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vgg-9h5w-h365",
- "modified": "2023-10-26T15:30:26Z",
+ "modified": "2024-04-04T08:48:55Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2022-42150"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://github.com/tinyclub/cloud-lab/blob/d19ff92713685a7fb84b423dea6a184b25c378c9/configs/common/seccomp-profiles-default.json"
},
+ {
+ "type": "WEB",
+ "url": "https://hackmd.io/%40UR9gnr32QymtmtZHnZceOw/ry428EZGo"
+ },
{
"type": "WEB",
"url": "https://hackmd.io/@UR9gnr32QymtmtZHnZceOw/ry428EZGo"
@@ -46,7 +50,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5vgv-43pv-3r7p/GHSA-5vgv-43pv-3r7p.json b/advisories/unreviewed/2023/10/GHSA-5vgv-43pv-3r7p/GHSA-5vgv-43pv-3r7p.json
index 142e43a3a1c..33887860e78 100644
--- a/advisories/unreviewed/2023/10/GHSA-5vgv-43pv-3r7p/GHSA-5vgv-43pv-3r7p.json
+++ b/advisories/unreviewed/2023/10/GHSA-5vgv-43pv-3r7p/GHSA-5vgv-43pv-3r7p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vgv-43pv-3r7p",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:08Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22129"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json b/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json
index 42d478aa3bc..d7603fbba46 100644
--- a/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json
+++ b/advisories/unreviewed/2023/10/GHSA-5vw8-jcpr-5wmv/GHSA-5vw8-jcpr-5wmv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vw8-jcpr-5wmv",
- "modified": "2023-10-25T18:32:22Z",
+ "modified": "2024-04-04T08:55:08Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-3010"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json b/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json
index 4e1c835c34f..bee0a0993f7 100644
--- a/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json
+++ b/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xgm-7mgw-vcg3",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:38Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46574"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-5xpv-3hf7-xx79/GHSA-5xpv-3hf7-xx79.json b/advisories/unreviewed/2023/10/GHSA-5xpv-3hf7-xx79/GHSA-5xpv-3hf7-xx79.json
index 81d57157bee..c4a00fc6a08 100644
--- a/advisories/unreviewed/2023/10/GHSA-5xpv-3hf7-xx79/GHSA-5xpv-3hf7-xx79.json
+++ b/advisories/unreviewed/2023/10/GHSA-5xpv-3hf7-xx79/GHSA-5xpv-3hf7-xx79.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xpv-3hf7-xx79",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:55:16Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-43360"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:31Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-624m-p552-xj26/GHSA-624m-p552-xj26.json b/advisories/unreviewed/2023/10/GHSA-624m-p552-xj26/GHSA-624m-p552-xj26.json
index 3a2d7b6feda..9306ef2b617 100644
--- a/advisories/unreviewed/2023/10/GHSA-624m-p552-xj26/GHSA-624m-p552-xj26.json
+++ b/advisories/unreviewed/2023/10/GHSA-624m-p552-xj26/GHSA-624m-p552-xj26.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-624m-p552-xj26",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:46Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45464"
],
"details": "Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-638j-4q3q-4843/GHSA-638j-4q3q-4843.json b/advisories/unreviewed/2023/10/GHSA-638j-4q3q-4843/GHSA-638j-4q3q-4843.json
index a9320d8c3e3..e23e30dd638 100644
--- a/advisories/unreviewed/2023/10/GHSA-638j-4q3q-4843/GHSA-638j-4q3q-4843.json
+++ b/advisories/unreviewed/2023/10/GHSA-638j-4q3q-4843/GHSA-638j-4q3q-4843.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-638j-4q3q-4843",
- "modified": "2023-10-19T06:30:23Z",
+ "modified": "2024-04-04T08:47:04Z",
"published": "2023-10-19T06:30:23Z",
"aliases": [
"CVE-2023-5254"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T06:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json
index c3fc45cdd8c..7f970f7aa59 100644
--- a/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json
+++ b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63h9-pmmv-4m65",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:48Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40136"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json b/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json
index d0a529c22ec..f2c003e17e7 100644
--- a/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json
+++ b/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63rp-vfr8-4qw7",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:32Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27375"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-63w9-q3qg-2wg7/GHSA-63w9-q3qg-2wg7.json b/advisories/unreviewed/2023/10/GHSA-63w9-q3qg-2wg7/GHSA-63w9-q3qg-2wg7.json
index dc10bf62c03..33460c2e2aa 100644
--- a/advisories/unreviewed/2023/10/GHSA-63w9-q3qg-2wg7/GHSA-63w9-q3qg-2wg7.json
+++ b/advisories/unreviewed/2023/10/GHSA-63w9-q3qg-2wg7/GHSA-63w9-q3qg-2wg7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63w9-q3qg-2wg7",
- "modified": "2023-10-24T21:30:20Z",
+ "modified": "2024-04-04T08:43:40Z",
"published": "2023-10-17T21:30:23Z",
"aliases": [
"CVE-2023-45952"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6436-gq3f-g99g/GHSA-6436-gq3f-g99g.json b/advisories/unreviewed/2023/10/GHSA-6436-gq3f-g99g/GHSA-6436-gq3f-g99g.json
index 8447afff890..46381104ff1 100644
--- a/advisories/unreviewed/2023/10/GHSA-6436-gq3f-g99g/GHSA-6436-gq3f-g99g.json
+++ b/advisories/unreviewed/2023/10/GHSA-6436-gq3f-g99g/GHSA-6436-gq3f-g99g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6436-gq3f-g99g",
- "modified": "2023-10-19T15:31:07Z",
+ "modified": "2024-04-04T08:48:20Z",
"published": "2023-10-19T15:31:07Z",
"aliases": [
"CVE-2023-35187"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json b/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json
index 6cb2a04b9c6..7a4b76c5416 100644
--- a/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json
+++ b/advisories/unreviewed/2023/10/GHSA-644w-28vg-vrrc/GHSA-644w-28vg-vrrc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-644w-28vg-vrrc",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:49Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39733"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-645x-3j3m-f2c2/GHSA-645x-3j3m-f2c2.json b/advisories/unreviewed/2023/10/GHSA-645x-3j3m-f2c2/GHSA-645x-3j3m-f2c2.json
index 912fda02cef..9cb146ff7bd 100644
--- a/advisories/unreviewed/2023/10/GHSA-645x-3j3m-f2c2/GHSA-645x-3j3m-f2c2.json
+++ b/advisories/unreviewed/2023/10/GHSA-645x-3j3m-f2c2/GHSA-645x-3j3m-f2c2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-645x-3j3m-f2c2",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:50:00Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4968"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-64ff-hjjg-hwr8/GHSA-64ff-hjjg-hwr8.json b/advisories/unreviewed/2023/10/GHSA-64ff-hjjg-hwr8/GHSA-64ff-hjjg-hwr8.json
index 9c336ec5090..38845eacfb7 100644
--- a/advisories/unreviewed/2023/10/GHSA-64ff-hjjg-hwr8/GHSA-64ff-hjjg-hwr8.json
+++ b/advisories/unreviewed/2023/10/GHSA-64ff-hjjg-hwr8/GHSA-64ff-hjjg-hwr8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64ff-hjjg-hwr8",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:06Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2022-3761"
],
"details": "OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-295"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-64xv-qmpj-7grf/GHSA-64xv-qmpj-7grf.json b/advisories/unreviewed/2023/10/GHSA-64xv-qmpj-7grf/GHSA-64xv-qmpj-7grf.json
index 8a150bca7d2..4ea1d3b100b 100644
--- a/advisories/unreviewed/2023/10/GHSA-64xv-qmpj-7grf/GHSA-64xv-qmpj-7grf.json
+++ b/advisories/unreviewed/2023/10/GHSA-64xv-qmpj-7grf/GHSA-64xv-qmpj-7grf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64xv-qmpj-7grf",
- "modified": "2023-10-23T21:30:58Z",
+ "modified": "2024-04-04T08:53:34Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-33840"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-652g-v3x6-f997/GHSA-652g-v3x6-f997.json b/advisories/unreviewed/2023/10/GHSA-652g-v3x6-f997/GHSA-652g-v3x6-f997.json
index b4e7f87bf52..1ff8021e243 100644
--- a/advisories/unreviewed/2023/10/GHSA-652g-v3x6-f997/GHSA-652g-v3x6-f997.json
+++ b/advisories/unreviewed/2023/10/GHSA-652g-v3x6-f997/GHSA-652g-v3x6-f997.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-652g-v3x6-f997",
- "modified": "2023-10-12T15:31:08Z",
+ "modified": "2024-04-04T08:35:42Z",
"published": "2023-10-12T15:31:08Z",
"aliases": [
"CVE-2023-45106"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T15:15:47Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-66px-8gqr-866w/GHSA-66px-8gqr-866w.json b/advisories/unreviewed/2023/10/GHSA-66px-8gqr-866w/GHSA-66px-8gqr-866w.json
index 004183d32fa..4a4147a9b73 100644
--- a/advisories/unreviewed/2023/10/GHSA-66px-8gqr-866w/GHSA-66px-8gqr-866w.json
+++ b/advisories/unreviewed/2023/10/GHSA-66px-8gqr-866w/GHSA-66px-8gqr-866w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66px-8gqr-866w",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:36:03Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-43147"
],
"details": "PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-66qc-5f4v-2m8h/GHSA-66qc-5f4v-2m8h.json b/advisories/unreviewed/2023/10/GHSA-66qc-5f4v-2m8h/GHSA-66qc-5f4v-2m8h.json
index ee86a736efc..afc755f2e14 100644
--- a/advisories/unreviewed/2023/10/GHSA-66qc-5f4v-2m8h/GHSA-66qc-5f4v-2m8h.json
+++ b/advisories/unreviewed/2023/10/GHSA-66qc-5f4v-2m8h/GHSA-66qc-5f4v-2m8h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66qc-5f4v-2m8h",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:11Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44197"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-67p5-wmww-f3q5/GHSA-67p5-wmww-f3q5.json b/advisories/unreviewed/2023/10/GHSA-67p5-wmww-f3q5/GHSA-67p5-wmww-f3q5.json
index efe292ce732..4cde950a984 100644
--- a/advisories/unreviewed/2023/10/GHSA-67p5-wmww-f3q5/GHSA-67p5-wmww-f3q5.json
+++ b/advisories/unreviewed/2023/10/GHSA-67p5-wmww-f3q5/GHSA-67p5-wmww-f3q5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67p5-wmww-f3q5",
- "modified": "2023-10-16T15:30:20Z",
+ "modified": "2024-04-04T08:40:59Z",
"published": "2023-10-16T15:30:20Z",
"aliases": [
"CVE-2023-46087"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T15:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-67pv-pwcc-82hx/GHSA-67pv-pwcc-82hx.json b/advisories/unreviewed/2023/10/GHSA-67pv-pwcc-82hx/GHSA-67pv-pwcc-82hx.json
index 80622df693f..e2034a99272 100644
--- a/advisories/unreviewed/2023/10/GHSA-67pv-pwcc-82hx/GHSA-67pv-pwcc-82hx.json
+++ b/advisories/unreviewed/2023/10/GHSA-67pv-pwcc-82hx/GHSA-67pv-pwcc-82hx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67pv-pwcc-82hx",
- "modified": "2023-10-20T06:30:19Z",
+ "modified": "2024-04-04T08:49:27Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-5614"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T05:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-683f-hcw3-5vgr/GHSA-683f-hcw3-5vgr.json b/advisories/unreviewed/2023/10/GHSA-683f-hcw3-5vgr/GHSA-683f-hcw3-5vgr.json
index 15ca981c7b8..b489f3c4baf 100644
--- a/advisories/unreviewed/2023/10/GHSA-683f-hcw3-5vgr/GHSA-683f-hcw3-5vgr.json
+++ b/advisories/unreviewed/2023/10/GHSA-683f-hcw3-5vgr/GHSA-683f-hcw3-5vgr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-683f-hcw3-5vgr",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:35Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-27315"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-256"
+ "CWE-256",
+ "CWE-522"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-687q-46r9-m8ww/GHSA-687q-46r9-m8ww.json b/advisories/unreviewed/2023/10/GHSA-687q-46r9-m8ww/GHSA-687q-46r9-m8ww.json
index f6aece23f2d..1aca7ab5520 100644
--- a/advisories/unreviewed/2023/10/GHSA-687q-46r9-m8ww/GHSA-687q-46r9-m8ww.json
+++ b/advisories/unreviewed/2023/10/GHSA-687q-46r9-m8ww/GHSA-687q-46r9-m8ww.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-687q-46r9-m8ww",
- "modified": "2023-10-13T18:30:20Z",
+ "modified": "2024-04-04T08:38:19Z",
"published": "2023-10-13T18:30:20Z",
"aliases": [
"CVE-2023-5449"
],
"details": "A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature which may allow a monitor’s Theft Deterrence to be deactivated.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json b/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json
index dfe609adb7c..e39ba5ffbbe 100644
--- a/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json
+++ b/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68c3-2gxf-hpcv",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:45Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45162"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6999-r624-hg6j/GHSA-6999-r624-hg6j.json b/advisories/unreviewed/2023/10/GHSA-6999-r624-hg6j/GHSA-6999-r624-hg6j.json
index bc2705de772..5300ead7722 100644
--- a/advisories/unreviewed/2023/10/GHSA-6999-r624-hg6j/GHSA-6999-r624-hg6j.json
+++ b/advisories/unreviewed/2023/10/GHSA-6999-r624-hg6j/GHSA-6999-r624-hg6j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6999-r624-hg6j",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:27Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22096"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6cr3-pfhw-g3c7/GHSA-6cr3-pfhw-g3c7.json b/advisories/unreviewed/2023/10/GHSA-6cr3-pfhw-g3c7/GHSA-6cr3-pfhw-g3c7.json
index af5c6a8c37b..3b5aca8023a 100644
--- a/advisories/unreviewed/2023/10/GHSA-6cr3-pfhw-g3c7/GHSA-6cr3-pfhw-g3c7.json
+++ b/advisories/unreviewed/2023/10/GHSA-6cr3-pfhw-g3c7/GHSA-6cr3-pfhw-g3c7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cr3-pfhw-g3c7",
- "modified": "2023-10-25T18:32:21Z",
+ "modified": "2024-04-04T08:54:41Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-34056"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:27Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6f7x-qj2v-8rh2/GHSA-6f7x-qj2v-8rh2.json b/advisories/unreviewed/2023/10/GHSA-6f7x-qj2v-8rh2/GHSA-6f7x-qj2v-8rh2.json
index 367d733a1d0..80f1f6fe2d9 100644
--- a/advisories/unreviewed/2023/10/GHSA-6f7x-qj2v-8rh2/GHSA-6f7x-qj2v-8rh2.json
+++ b/advisories/unreviewed/2023/10/GHSA-6f7x-qj2v-8rh2/GHSA-6f7x-qj2v-8rh2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f7x-qj2v-8rh2",
- "modified": "2023-10-16T00:30:27Z",
+ "modified": "2024-04-04T08:38:55Z",
"published": "2023-10-16T00:30:27Z",
"aliases": [
"CVE-2023-35013"
@@ -35,7 +35,7 @@
"CWE-540",
"CWE-668"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T00:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json b/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json
index ff46e73c019..7520ae9891a 100644
--- a/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json
+++ b/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gp7-g3rx-2cq6",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:49:01Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-43492"
@@ -35,7 +35,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6gr4-x7gv-xwjp/GHSA-6gr4-x7gv-xwjp.json b/advisories/unreviewed/2023/10/GHSA-6gr4-x7gv-xwjp/GHSA-6gr4-x7gv-xwjp.json
index a77446ffee9..ef9246888a5 100644
--- a/advisories/unreviewed/2023/10/GHSA-6gr4-x7gv-xwjp/GHSA-6gr4-x7gv-xwjp.json
+++ b/advisories/unreviewed/2023/10/GHSA-6gr4-x7gv-xwjp/GHSA-6gr4-x7gv-xwjp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gr4-x7gv-xwjp",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:41Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-38059"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6gwq-qjqq-9xpv/GHSA-6gwq-qjqq-9xpv.json b/advisories/unreviewed/2023/10/GHSA-6gwq-qjqq-9xpv/GHSA-6gwq-qjqq-9xpv.json
index c1d458c7c2a..672e88d2f8c 100644
--- a/advisories/unreviewed/2023/10/GHSA-6gwq-qjqq-9xpv/GHSA-6gwq-qjqq-9xpv.json
+++ b/advisories/unreviewed/2023/10/GHSA-6gwq-qjqq-9xpv/GHSA-6gwq-qjqq-9xpv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gwq-qjqq-9xpv",
- "modified": "2023-10-23T21:30:58Z",
+ "modified": "2024-04-04T08:53:26Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2022-22466"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-798"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6h2p-v2jw-9mc4/GHSA-6h2p-v2jw-9mc4.json b/advisories/unreviewed/2023/10/GHSA-6h2p-v2jw-9mc4/GHSA-6h2p-v2jw-9mc4.json
index 05ac9889c1f..e6eedc04959 100644
--- a/advisories/unreviewed/2023/10/GHSA-6h2p-v2jw-9mc4/GHSA-6h2p-v2jw-9mc4.json
+++ b/advisories/unreviewed/2023/10/GHSA-6h2p-v2jw-9mc4/GHSA-6h2p-v2jw-9mc4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6h2p-v2jw-9mc4",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:09Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22082"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6j74-3j28-p2f4/GHSA-6j74-3j28-p2f4.json b/advisories/unreviewed/2023/10/GHSA-6j74-3j28-p2f4/GHSA-6j74-3j28-p2f4.json
index af58db22217..b63fe1d2444 100644
--- a/advisories/unreviewed/2023/10/GHSA-6j74-3j28-p2f4/GHSA-6j74-3j28-p2f4.json
+++ b/advisories/unreviewed/2023/10/GHSA-6j74-3j28-p2f4/GHSA-6j74-3j28-p2f4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j74-3j28-p2f4",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:05Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45653"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6jpv-f5xm-f87c/GHSA-6jpv-f5xm-f87c.json b/advisories/unreviewed/2023/10/GHSA-6jpv-f5xm-f87c/GHSA-6jpv-f5xm-f87c.json
index da7e6b80a54..37a244d89c3 100644
--- a/advisories/unreviewed/2023/10/GHSA-6jpv-f5xm-f87c/GHSA-6jpv-f5xm-f87c.json
+++ b/advisories/unreviewed/2023/10/GHSA-6jpv-f5xm-f87c/GHSA-6jpv-f5xm-f87c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jpv-f5xm-f87c",
- "modified": "2023-10-21T03:30:17Z",
+ "modified": "2024-04-04T08:52:09Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-5132"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json b/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json
index 941a03be343..f20d37836f0 100644
--- a/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json
+++ b/advisories/unreviewed/2023/10/GHSA-6jvj-rjjj-4gfr/GHSA-6jvj-rjjj-4gfr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jvj-rjjj-4gfr",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:58Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44192"
@@ -31,7 +31,7 @@
"CWE-20",
"CWE-401"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6m4w-xmq7-g92p/GHSA-6m4w-xmq7-g92p.json b/advisories/unreviewed/2023/10/GHSA-6m4w-xmq7-g92p/GHSA-6m4w-xmq7-g92p.json
index b8efa35ae3e..3a9ba3afd14 100644
--- a/advisories/unreviewed/2023/10/GHSA-6m4w-xmq7-g92p/GHSA-6m4w-xmq7-g92p.json
+++ b/advisories/unreviewed/2023/10/GHSA-6m4w-xmq7-g92p/GHSA-6m4w-xmq7-g92p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m4w-xmq7-g92p",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:48Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45767"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6q4v-gp5x-qpwg/GHSA-6q4v-gp5x-qpwg.json b/advisories/unreviewed/2023/10/GHSA-6q4v-gp5x-qpwg/GHSA-6q4v-gp5x-qpwg.json
index a74464d692c..27dd9ed80ac 100644
--- a/advisories/unreviewed/2023/10/GHSA-6q4v-gp5x-qpwg/GHSA-6q4v-gp5x-qpwg.json
+++ b/advisories/unreviewed/2023/10/GHSA-6q4v-gp5x-qpwg/GHSA-6q4v-gp5x-qpwg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q4v-gp5x-qpwg",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:54Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-44987"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6qj5-v722-xhxc/GHSA-6qj5-v722-xhxc.json b/advisories/unreviewed/2023/10/GHSA-6qj5-v722-xhxc/GHSA-6qj5-v722-xhxc.json
index 85a6a4cee3c..474680137dc 100644
--- a/advisories/unreviewed/2023/10/GHSA-6qj5-v722-xhxc/GHSA-6qj5-v722-xhxc.json
+++ b/advisories/unreviewed/2023/10/GHSA-6qj5-v722-xhxc/GHSA-6qj5-v722-xhxc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qj5-v722-xhxc",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:37Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22094"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6r76-9f7g-6w9v/GHSA-6r76-9f7g-6w9v.json b/advisories/unreviewed/2023/10/GHSA-6r76-9f7g-6w9v/GHSA-6r76-9f7g-6w9v.json
index d0f490c97a4..f719586bd60 100644
--- a/advisories/unreviewed/2023/10/GHSA-6r76-9f7g-6w9v/GHSA-6r76-9f7g-6w9v.json
+++ b/advisories/unreviewed/2023/10/GHSA-6r76-9f7g-6w9v/GHSA-6r76-9f7g-6w9v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r76-9f7g-6w9v",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:31Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-26941"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-134"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6v6v-fgmr-w8g2/GHSA-6v6v-fgmr-w8g2.json b/advisories/unreviewed/2023/10/GHSA-6v6v-fgmr-w8g2/GHSA-6v6v-fgmr-w8g2.json
index 3170a30d652..1eb587fdfbe 100644
--- a/advisories/unreviewed/2023/10/GHSA-6v6v-fgmr-w8g2/GHSA-6v6v-fgmr-w8g2.json
+++ b/advisories/unreviewed/2023/10/GHSA-6v6v-fgmr-w8g2/GHSA-6v6v-fgmr-w8g2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v6v-fgmr-w8g2",
- "modified": "2023-10-30T12:30:31Z",
+ "modified": "2024-04-04T08:53:43Z",
"published": "2023-10-24T00:31:07Z",
"aliases": [
"CVE-2023-46059"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-24T00:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6vf3-6gq2-8cgv/GHSA-6vf3-6gq2-8cgv.json b/advisories/unreviewed/2023/10/GHSA-6vf3-6gq2-8cgv/GHSA-6vf3-6gq2-8cgv.json
index 28983cc8403..92f84968b3c 100644
--- a/advisories/unreviewed/2023/10/GHSA-6vf3-6gq2-8cgv/GHSA-6vf3-6gq2-8cgv.json
+++ b/advisories/unreviewed/2023/10/GHSA-6vf3-6gq2-8cgv/GHSA-6vf3-6gq2-8cgv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vf3-6gq2-8cgv",
- "modified": "2023-10-13T18:30:20Z",
+ "modified": "2024-04-04T08:38:14Z",
"published": "2023-10-13T18:30:20Z",
"aliases": [
"CVE-2023-45276"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T16:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6w2r-58cq-54q2/GHSA-6w2r-58cq-54q2.json b/advisories/unreviewed/2023/10/GHSA-6w2r-58cq-54q2/GHSA-6w2r-58cq-54q2.json
index 8eb029554dc..6234bb09048 100644
--- a/advisories/unreviewed/2023/10/GHSA-6w2r-58cq-54q2/GHSA-6w2r-58cq-54q2.json
+++ b/advisories/unreviewed/2023/10/GHSA-6w2r-58cq-54q2/GHSA-6w2r-58cq-54q2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w2r-58cq-54q2",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:11Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-24400"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-639"
+ "CWE-639",
+ "CWE-807"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json b/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json
index 3de8981dfcd..28c97999ff7 100644
--- a/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json
+++ b/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wc2-f8mc-76rv",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:22Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-45510"
],
"details": "tsMuxer version git-2539d07 was discovered to contain an alloc-dealloc-mismatch (operator new [] vs operator delete) error.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T21:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-6wh6-h5jg-ghcx/GHSA-6wh6-h5jg-ghcx.json b/advisories/unreviewed/2023/10/GHSA-6wh6-h5jg-ghcx/GHSA-6wh6-h5jg-ghcx.json
index 2994c885f1d..36b90ca7262 100644
--- a/advisories/unreviewed/2023/10/GHSA-6wh6-h5jg-ghcx/GHSA-6wh6-h5jg-ghcx.json
+++ b/advisories/unreviewed/2023/10/GHSA-6wh6-h5jg-ghcx/GHSA-6wh6-h5jg-ghcx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wh6-h5jg-ghcx",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:43:57Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22076"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7374-hfgm-rm8v/GHSA-7374-hfgm-rm8v.json b/advisories/unreviewed/2023/10/GHSA-7374-hfgm-rm8v/GHSA-7374-hfgm-rm8v.json
index ccda33b8bfb..02c78a60c9d 100644
--- a/advisories/unreviewed/2023/10/GHSA-7374-hfgm-rm8v/GHSA-7374-hfgm-rm8v.json
+++ b/advisories/unreviewed/2023/10/GHSA-7374-hfgm-rm8v/GHSA-7374-hfgm-rm8v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7374-hfgm-rm8v",
- "modified": "2023-10-12T06:30:27Z",
+ "modified": "2024-04-04T08:35:09Z",
"published": "2023-10-12T06:30:27Z",
"aliases": [
"CVE-2023-29453"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-94"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T06:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json b/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json
index 3328facf7c7..83a751aaaf7 100644
--- a/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json
+++ b/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76g7-7jq2-pjg7",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:03Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46522"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-76mp-24cw-7mwq/GHSA-76mp-24cw-7mwq.json b/advisories/unreviewed/2023/10/GHSA-76mp-24cw-7mwq/GHSA-76mp-24cw-7mwq.json
index 4dcf596512f..b5d46dbc5d8 100644
--- a/advisories/unreviewed/2023/10/GHSA-76mp-24cw-7mwq/GHSA-76mp-24cw-7mwq.json
+++ b/advisories/unreviewed/2023/10/GHSA-76mp-24cw-7mwq/GHSA-76mp-24cw-7mwq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76mp-24cw-7mwq",
- "modified": "2023-10-13T18:30:20Z",
+ "modified": "2024-04-04T08:38:16Z",
"published": "2023-10-13T18:30:20Z",
"aliases": [
"CVE-2023-5409"
],
"details": "HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-77wr-jhhf-58xr/GHSA-77wr-jhhf-58xr.json b/advisories/unreviewed/2023/10/GHSA-77wr-jhhf-58xr/GHSA-77wr-jhhf-58xr.json
index 83238931b5c..fe80d17b84f 100644
--- a/advisories/unreviewed/2023/10/GHSA-77wr-jhhf-58xr/GHSA-77wr-jhhf-58xr.json
+++ b/advisories/unreviewed/2023/10/GHSA-77wr-jhhf-58xr/GHSA-77wr-jhhf-58xr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77wr-jhhf-58xr",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:49:15Z",
"published": "2023-10-20T00:30:25Z",
"aliases": [
"CVE-2023-43344"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7c2j-9gcg-5ggw/GHSA-7c2j-9gcg-5ggw.json b/advisories/unreviewed/2023/10/GHSA-7c2j-9gcg-5ggw/GHSA-7c2j-9gcg-5ggw.json
index 7ba80155fec..ffe47f54bed 100644
--- a/advisories/unreviewed/2023/10/GHSA-7c2j-9gcg-5ggw/GHSA-7c2j-9gcg-5ggw.json
+++ b/advisories/unreviewed/2023/10/GHSA-7c2j-9gcg-5ggw/GHSA-7c2j-9gcg-5ggw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c2j-9gcg-5ggw",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:41Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44178"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7c84-qx75-c25g/GHSA-7c84-qx75-c25g.json b/advisories/unreviewed/2023/10/GHSA-7c84-qx75-c25g/GHSA-7c84-qx75-c25g.json
index 8a0648b0854..f4ab369b58c 100644
--- a/advisories/unreviewed/2023/10/GHSA-7c84-qx75-c25g/GHSA-7c84-qx75-c25g.json
+++ b/advisories/unreviewed/2023/10/GHSA-7c84-qx75-c25g/GHSA-7c84-qx75-c25g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c84-qx75-c25g",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:47Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-5621"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7c8x-vv95-q9jj/GHSA-7c8x-vv95-q9jj.json b/advisories/unreviewed/2023/10/GHSA-7c8x-vv95-q9jj/GHSA-7c8x-vv95-q9jj.json
index e72c7656c3e..5477ddddc2a 100644
--- a/advisories/unreviewed/2023/10/GHSA-7c8x-vv95-q9jj/GHSA-7c8x-vv95-q9jj.json
+++ b/advisories/unreviewed/2023/10/GHSA-7c8x-vv95-q9jj/GHSA-7c8x-vv95-q9jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c8x-vv95-q9jj",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:28Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-45577"
],
"details": "An issue in DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7c9p-q9cx-hrg3/GHSA-7c9p-q9cx-hrg3.json b/advisories/unreviewed/2023/10/GHSA-7c9p-q9cx-hrg3/GHSA-7c9p-q9cx-hrg3.json
index c63657d8b9d..74721c6ef78 100644
--- a/advisories/unreviewed/2023/10/GHSA-7c9p-q9cx-hrg3/GHSA-7c9p-q9cx-hrg3.json
+++ b/advisories/unreviewed/2023/10/GHSA-7c9p-q9cx-hrg3/GHSA-7c9p-q9cx-hrg3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c9p-q9cx-hrg3",
- "modified": "2023-10-15T03:30:30Z",
+ "modified": "2024-04-04T08:38:51Z",
"published": "2023-10-15T03:30:30Z",
"aliases": [
"CVE-2023-40378"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-15T02:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7f74-9j92-993v/GHSA-7f74-9j92-993v.json b/advisories/unreviewed/2023/10/GHSA-7f74-9j92-993v/GHSA-7f74-9j92-993v.json
index 36b20d28ecd..d0a6d2fff2c 100644
--- a/advisories/unreviewed/2023/10/GHSA-7f74-9j92-993v/GHSA-7f74-9j92-993v.json
+++ b/advisories/unreviewed/2023/10/GHSA-7f74-9j92-993v/GHSA-7f74-9j92-993v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f74-9j92-993v",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:17Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27254"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7grc-fv66-9g6g/GHSA-7grc-fv66-9g6g.json b/advisories/unreviewed/2023/10/GHSA-7grc-fv66-9g6g/GHSA-7grc-fv66-9g6g.json
index 7276b658fe5..7e66a366374 100644
--- a/advisories/unreviewed/2023/10/GHSA-7grc-fv66-9g6g/GHSA-7grc-fv66-9g6g.json
+++ b/advisories/unreviewed/2023/10/GHSA-7grc-fv66-9g6g/GHSA-7grc-fv66-9g6g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7grc-fv66-9g6g",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:55Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45059"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7gx8-jvcv-jmvj/GHSA-7gx8-jvcv-jmvj.json b/advisories/unreviewed/2023/10/GHSA-7gx8-jvcv-jmvj/GHSA-7gx8-jvcv-jmvj.json
index a5a60f456ae..0414889a713 100644
--- a/advisories/unreviewed/2023/10/GHSA-7gx8-jvcv-jmvj/GHSA-7gx8-jvcv-jmvj.json
+++ b/advisories/unreviewed/2023/10/GHSA-7gx8-jvcv-jmvj/GHSA-7gx8-jvcv-jmvj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gx8-jvcv-jmvj",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:21Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36755"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7hch-jrf6-fjw8/GHSA-7hch-jrf6-fjw8.json b/advisories/unreviewed/2023/10/GHSA-7hch-jrf6-fjw8/GHSA-7hch-jrf6-fjw8.json
index 8746a4cc98f..44efdeaa8a9 100644
--- a/advisories/unreviewed/2023/10/GHSA-7hch-jrf6-fjw8/GHSA-7hch-jrf6-fjw8.json
+++ b/advisories/unreviewed/2023/10/GHSA-7hch-jrf6-fjw8/GHSA-7hch-jrf6-fjw8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hch-jrf6-fjw8",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:47Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45748"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json b/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json
index 28cf3912d9b..3832b3a9509 100644
--- a/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json
+++ b/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hqq-m574-qjp2",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:26Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2023-27858"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-824"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7jqv-m3g3-hfjh/GHSA-7jqv-m3g3-hfjh.json b/advisories/unreviewed/2023/10/GHSA-7jqv-m3g3-hfjh/GHSA-7jqv-m3g3-hfjh.json
index dfcf401dcd7..85cbd92ee56 100644
--- a/advisories/unreviewed/2023/10/GHSA-7jqv-m3g3-hfjh/GHSA-7jqv-m3g3-hfjh.json
+++ b/advisories/unreviewed/2023/10/GHSA-7jqv-m3g3-hfjh/GHSA-7jqv-m3g3-hfjh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jqv-m3g3-hfjh",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:52Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-38190"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T01:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json b/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json
index 3872880ba62..2135849d07e 100644
--- a/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json
+++ b/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jrw-mp94-7v28",
- "modified": "2023-10-18T18:31:38Z",
+ "modified": "2024-04-04T08:46:36Z",
"published": "2023-10-18T18:31:38Z",
"aliases": [
"CVE-2023-45911"
],
"details": "An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-668"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json b/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json
index f39c0ef01a0..2bfee0c4128 100644
--- a/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json
+++ b/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jxg-pm47-89ph",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:13Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2018-17878"
],
"details": "Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7m68-3mc5-7wwf/GHSA-7m68-3mc5-7wwf.json b/advisories/unreviewed/2023/10/GHSA-7m68-3mc5-7wwf/GHSA-7m68-3mc5-7wwf.json
index 1339c697532..8febdcd969f 100644
--- a/advisories/unreviewed/2023/10/GHSA-7m68-3mc5-7wwf/GHSA-7m68-3mc5-7wwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-7m68-3mc5-7wwf/GHSA-7m68-3mc5-7wwf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m68-3mc5-7wwf",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:25Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27262"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7m88-f659-f4w6/GHSA-7m88-f659-f4w6.json b/advisories/unreviewed/2023/10/GHSA-7m88-f659-f4w6/GHSA-7m88-f659-f4w6.json
index ab566fef758..705201266ed 100644
--- a/advisories/unreviewed/2023/10/GHSA-7m88-f659-f4w6/GHSA-7m88-f659-f4w6.json
+++ b/advisories/unreviewed/2023/10/GHSA-7m88-f659-f4w6/GHSA-7m88-f659-f4w6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m88-f659-f4w6",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:52Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-42666"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7mhw-hvfr-5wr9/GHSA-7mhw-hvfr-5wr9.json b/advisories/unreviewed/2023/10/GHSA-7mhw-hvfr-5wr9/GHSA-7mhw-hvfr-5wr9.json
index a8ff9fc2f39..ef7cd3555ad 100644
--- a/advisories/unreviewed/2023/10/GHSA-7mhw-hvfr-5wr9/GHSA-7mhw-hvfr-5wr9.json
+++ b/advisories/unreviewed/2023/10/GHSA-7mhw-hvfr-5wr9/GHSA-7mhw-hvfr-5wr9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mhw-hvfr-5wr9",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:11Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-36955"
],
"details": "TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7mwm-qgvf-37wp/GHSA-7mwm-qgvf-37wp.json b/advisories/unreviewed/2023/10/GHSA-7mwm-qgvf-37wp/GHSA-7mwm-qgvf-37wp.json
index 856b16d8dd1..3498fc36a9b 100644
--- a/advisories/unreviewed/2023/10/GHSA-7mwm-qgvf-37wp/GHSA-7mwm-qgvf-37wp.json
+++ b/advisories/unreviewed/2023/10/GHSA-7mwm-qgvf-37wp/GHSA-7mwm-qgvf-37wp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mwm-qgvf-37wp",
- "modified": "2023-10-23T18:30:46Z",
+ "modified": "2024-04-04T08:53:24Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-43066"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T16:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json b/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json
index bde5727dfab..36c71d44742 100644
--- a/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json
+++ b/advisories/unreviewed/2023/10/GHSA-7pc9-4xmj-8wv3/GHSA-7pc9-4xmj-8wv3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pc9-4xmj-8wv3",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:55:00Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39740"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json b/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json
index 115c8fda6fd..1b6867d7d31 100644
--- a/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json
+++ b/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pfc-834q-h497",
- "modified": "2023-10-13T09:30:23Z",
+ "modified": "2024-04-04T08:37:37Z",
"published": "2023-10-13T09:30:23Z",
"aliases": [
"CVE-2023-38251"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7q52-xpr7-cj38/GHSA-7q52-xpr7-cj38.json b/advisories/unreviewed/2023/10/GHSA-7q52-xpr7-cj38/GHSA-7q52-xpr7-cj38.json
index 093102409d9..43a176c7058 100644
--- a/advisories/unreviewed/2023/10/GHSA-7q52-xpr7-cj38/GHSA-7q52-xpr7-cj38.json
+++ b/advisories/unreviewed/2023/10/GHSA-7q52-xpr7-cj38/GHSA-7q52-xpr7-cj38.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q52-xpr7-cj38",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:18Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36753"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7qx9-qw7h-vvwq/GHSA-7qx9-qw7h-vvwq.json b/advisories/unreviewed/2023/10/GHSA-7qx9-qw7h-vvwq/GHSA-7qx9-qw7h-vvwq.json
index f27ceb5e73c..a94af0f7549 100644
--- a/advisories/unreviewed/2023/10/GHSA-7qx9-qw7h-vvwq/GHSA-7qx9-qw7h-vvwq.json
+++ b/advisories/unreviewed/2023/10/GHSA-7qx9-qw7h-vvwq/GHSA-7qx9-qw7h-vvwq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qx9-qw7h-vvwq",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:45Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22108"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7v28-76v4-349r/GHSA-7v28-76v4-349r.json b/advisories/unreviewed/2023/10/GHSA-7v28-76v4-349r/GHSA-7v28-76v4-349r.json
index c0757e0b373..1c2c01fc6c1 100644
--- a/advisories/unreviewed/2023/10/GHSA-7v28-76v4-349r/GHSA-7v28-76v4-349r.json
+++ b/advisories/unreviewed/2023/10/GHSA-7v28-76v4-349r/GHSA-7v28-76v4-349r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7v28-76v4-349r",
- "modified": "2023-10-14T06:30:54Z",
+ "modified": "2024-04-04T08:38:30Z",
"published": "2023-10-14T06:30:54Z",
"aliases": [
"CVE-2023-30148"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T04:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json b/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json
index d1363287906..cb26e2aefdd 100644
--- a/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json
+++ b/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vm7-mp89-q7c7",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:14Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-44809"
],
"details": "D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7w42-6f8j-cx26/GHSA-7w42-6f8j-cx26.json b/advisories/unreviewed/2023/10/GHSA-7w42-6f8j-cx26/GHSA-7w42-6f8j-cx26.json
index 69771be6dcf..f048fe086d0 100644
--- a/advisories/unreviewed/2023/10/GHSA-7w42-6f8j-cx26/GHSA-7w42-6f8j-cx26.json
+++ b/advisories/unreviewed/2023/10/GHSA-7w42-6f8j-cx26/GHSA-7w42-6f8j-cx26.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w42-6f8j-cx26",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:01Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45685"
],
"details": "Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7wxc-mh8q-7484/GHSA-7wxc-mh8q-7484.json b/advisories/unreviewed/2023/10/GHSA-7wxc-mh8q-7484/GHSA-7wxc-mh8q-7484.json
index d6faa10bef5..b50e4587f13 100644
--- a/advisories/unreviewed/2023/10/GHSA-7wxc-mh8q-7484/GHSA-7wxc-mh8q-7484.json
+++ b/advisories/unreviewed/2023/10/GHSA-7wxc-mh8q-7484/GHSA-7wxc-mh8q-7484.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wxc-mh8q-7484",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:49:04Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-27792"
],
"details": "An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-862"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7x29-jh5v-6wwf/GHSA-7x29-jh5v-6wwf.json b/advisories/unreviewed/2023/10/GHSA-7x29-jh5v-6wwf/GHSA-7x29-jh5v-6wwf.json
index a224e6f8d80..4c1ee8438ae 100644
--- a/advisories/unreviewed/2023/10/GHSA-7x29-jh5v-6wwf/GHSA-7x29-jh5v-6wwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-7x29-jh5v-6wwf/GHSA-7x29-jh5v-6wwf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x29-jh5v-6wwf",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:01Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2021-26737"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-346"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json b/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
index f3bc5835369..6f91b6c913c 100644
--- a/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
+++ b/advisories/unreviewed/2023/10/GHSA-7xp8-vhxc-29v9/GHSA-7xp8-vhxc-29v9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xp8-vhxc-29v9",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:06Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45984"
],
"details": "TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T18:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-82hj-ghm7-6vpg/GHSA-82hj-ghm7-6vpg.json b/advisories/unreviewed/2023/10/GHSA-82hj-ghm7-6vpg/GHSA-82hj-ghm7-6vpg.json
index f8a53eb6b7b..de02f67451c 100644
--- a/advisories/unreviewed/2023/10/GHSA-82hj-ghm7-6vpg/GHSA-82hj-ghm7-6vpg.json
+++ b/advisories/unreviewed/2023/10/GHSA-82hj-ghm7-6vpg/GHSA-82hj-ghm7-6vpg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82hj-ghm7-6vpg",
- "modified": "2023-10-19T15:31:07Z",
+ "modified": "2024-04-04T08:48:13Z",
"published": "2023-10-19T15:31:07Z",
"aliases": [
"CVE-2023-35183"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-834h-7mjv-2g94/GHSA-834h-7mjv-2g94.json b/advisories/unreviewed/2023/10/GHSA-834h-7mjv-2g94/GHSA-834h-7mjv-2g94.json
index 0cfad5e133e..0afe5cde3ca 100644
--- a/advisories/unreviewed/2023/10/GHSA-834h-7mjv-2g94/GHSA-834h-7mjv-2g94.json
+++ b/advisories/unreviewed/2023/10/GHSA-834h-7mjv-2g94/GHSA-834h-7mjv-2g94.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-834h-7mjv-2g94",
- "modified": "2023-10-28T03:30:21Z",
+ "modified": "2024-04-04T08:53:05Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-42295"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-190"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-836w-q8xf-8mq9/GHSA-836w-q8xf-8mq9.json b/advisories/unreviewed/2023/10/GHSA-836w-q8xf-8mq9/GHSA-836w-q8xf-8mq9.json
index f9d60ffc760..683f90aa85b 100644
--- a/advisories/unreviewed/2023/10/GHSA-836w-q8xf-8mq9/GHSA-836w-q8xf-8mq9.json
+++ b/advisories/unreviewed/2023/10/GHSA-836w-q8xf-8mq9/GHSA-836w-q8xf-8mq9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-836w-q8xf-8mq9",
- "modified": "2023-10-21T09:30:25Z",
+ "modified": "2024-04-04T08:52:20Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-4635"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-85q4-wfv9-wrvq/GHSA-85q4-wfv9-wrvq.json b/advisories/unreviewed/2023/10/GHSA-85q4-wfv9-wrvq/GHSA-85q4-wfv9-wrvq.json
index 35b79b931ff..a51bdca5127 100644
--- a/advisories/unreviewed/2023/10/GHSA-85q4-wfv9-wrvq/GHSA-85q4-wfv9-wrvq.json
+++ b/advisories/unreviewed/2023/10/GHSA-85q4-wfv9-wrvq/GHSA-85q4-wfv9-wrvq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85q4-wfv9-wrvq",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:01Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-41682"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-865m-g6fc-h55q/GHSA-865m-g6fc-h55q.json b/advisories/unreviewed/2023/10/GHSA-865m-g6fc-h55q/GHSA-865m-g6fc-h55q.json
index 9d998682228..bf7f8373b4c 100644
--- a/advisories/unreviewed/2023/10/GHSA-865m-g6fc-h55q/GHSA-865m-g6fc-h55q.json
+++ b/advisories/unreviewed/2023/10/GHSA-865m-g6fc-h55q/GHSA-865m-g6fc-h55q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-865m-g6fc-h55q",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:24Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45058"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-87j3-33px-qqww/GHSA-87j3-33px-qqww.json b/advisories/unreviewed/2023/10/GHSA-87j3-33px-qqww/GHSA-87j3-33px-qqww.json
index 14e246c88ad..5c4289aef71 100644
--- a/advisories/unreviewed/2023/10/GHSA-87j3-33px-qqww/GHSA-87j3-33px-qqww.json
+++ b/advisories/unreviewed/2023/10/GHSA-87j3-33px-qqww/GHSA-87j3-33px-qqww.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87j3-33px-qqww",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:35Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-45357"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-668"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-87wm-cfp5-465j/GHSA-87wm-cfp5-465j.json b/advisories/unreviewed/2023/10/GHSA-87wm-cfp5-465j/GHSA-87wm-cfp5-465j.json
index 9672d8b7016..ac71a06f7a1 100644
--- a/advisories/unreviewed/2023/10/GHSA-87wm-cfp5-465j/GHSA-87wm-cfp5-465j.json
+++ b/advisories/unreviewed/2023/10/GHSA-87wm-cfp5-465j/GHSA-87wm-cfp5-465j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87wm-cfp5-465j",
- "modified": "2023-10-19T03:30:28Z",
+ "modified": "2024-04-04T08:46:55Z",
"published": "2023-10-19T03:30:28Z",
"aliases": [
"CVE-2023-4645"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-886f-64fm-9xmm/GHSA-886f-64fm-9xmm.json b/advisories/unreviewed/2023/10/GHSA-886f-64fm-9xmm/GHSA-886f-64fm-9xmm.json
index 0550d82f991..91bf4e20a10 100644
--- a/advisories/unreviewed/2023/10/GHSA-886f-64fm-9xmm/GHSA-886f-64fm-9xmm.json
+++ b/advisories/unreviewed/2023/10/GHSA-886f-64fm-9xmm/GHSA-886f-64fm-9xmm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-886f-64fm-9xmm",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:45:19Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-39279"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json b/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json
index 894c119334b..702ee844a6f 100644
--- a/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json
+++ b/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8992-9q7r-8chp",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:00Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46521"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8c9g-7c4g-j7x7/GHSA-8c9g-7c4g-j7x7.json b/advisories/unreviewed/2023/10/GHSA-8c9g-7c4g-j7x7/GHSA-8c9g-7c4g-j7x7.json
index 0f48d85b7f6..f426a75a5ac 100644
--- a/advisories/unreviewed/2023/10/GHSA-8c9g-7c4g-j7x7/GHSA-8c9g-7c4g-j7x7.json
+++ b/advisories/unreviewed/2023/10/GHSA-8c9g-7c4g-j7x7/GHSA-8c9g-7c4g-j7x7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c9g-7c4g-j7x7",
- "modified": "2023-10-17T18:30:56Z",
+ "modified": "2024-04-04T08:43:36Z",
"published": "2023-10-17T18:30:56Z",
"aliases": [
"CVE-2023-27132"
],
"details": "TSplus Remote Work 16.0.0.0 places a cleartext password on the \"var pass\" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-522"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T16:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8cfv-g2mq-hrpw/GHSA-8cfv-g2mq-hrpw.json b/advisories/unreviewed/2023/10/GHSA-8cfv-g2mq-hrpw/GHSA-8cfv-g2mq-hrpw.json
index 7155870fc64..f099f2adfca 100644
--- a/advisories/unreviewed/2023/10/GHSA-8cfv-g2mq-hrpw/GHSA-8cfv-g2mq-hrpw.json
+++ b/advisories/unreviewed/2023/10/GHSA-8cfv-g2mq-hrpw/GHSA-8cfv-g2mq-hrpw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8cfv-g2mq-hrpw",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:02Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5534"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8ch2-m9x4-vgjv/GHSA-8ch2-m9x4-vgjv.json b/advisories/unreviewed/2023/10/GHSA-8ch2-m9x4-vgjv/GHSA-8ch2-m9x4-vgjv.json
index b5063300b40..7865f2396f8 100644
--- a/advisories/unreviewed/2023/10/GHSA-8ch2-m9x4-vgjv/GHSA-8ch2-m9x4-vgjv.json
+++ b/advisories/unreviewed/2023/10/GHSA-8ch2-m9x4-vgjv/GHSA-8ch2-m9x4-vgjv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8ch2-m9x4-vgjv",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:41:43Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4800"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-425"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8f2j-r3g9-qhmm/GHSA-8f2j-r3g9-qhmm.json b/advisories/unreviewed/2023/10/GHSA-8f2j-r3g9-qhmm/GHSA-8f2j-r3g9-qhmm.json
index 487fd88e4e8..ce7589c192c 100644
--- a/advisories/unreviewed/2023/10/GHSA-8f2j-r3g9-qhmm/GHSA-8f2j-r3g9-qhmm.json
+++ b/advisories/unreviewed/2023/10/GHSA-8f2j-r3g9-qhmm/GHSA-8f2j-r3g9-qhmm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f2j-r3g9-qhmm",
- "modified": "2023-10-25T18:32:22Z",
+ "modified": "2024-04-04T08:55:14Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-42031"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:31Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8h3j-g9f5-qfm7/GHSA-8h3j-g9f5-qfm7.json b/advisories/unreviewed/2023/10/GHSA-8h3j-g9f5-qfm7/GHSA-8h3j-g9f5-qfm7.json
index 686a1a00e32..b52801013c9 100644
--- a/advisories/unreviewed/2023/10/GHSA-8h3j-g9f5-qfm7/GHSA-8h3j-g9f5-qfm7.json
+++ b/advisories/unreviewed/2023/10/GHSA-8h3j-g9f5-qfm7/GHSA-8h3j-g9f5-qfm7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h3j-g9f5-qfm7",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:49Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22106"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8h3p-5f62-5ppm/GHSA-8h3p-5f62-5ppm.json b/advisories/unreviewed/2023/10/GHSA-8h3p-5f62-5ppm/GHSA-8h3p-5f62-5ppm.json
index e0b056b420f..06b19109aaf 100644
--- a/advisories/unreviewed/2023/10/GHSA-8h3p-5f62-5ppm/GHSA-8h3p-5f62-5ppm.json
+++ b/advisories/unreviewed/2023/10/GHSA-8h3p-5f62-5ppm/GHSA-8h3p-5f62-5ppm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h3p-5f62-5ppm",
- "modified": "2023-10-11T21:33:26Z",
+ "modified": "2024-04-04T08:35:01Z",
"published": "2023-10-11T21:33:26Z",
"aliases": [
"CVE-2023-44187"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8h83-vm48-vxjm/GHSA-8h83-vm48-vxjm.json b/advisories/unreviewed/2023/10/GHSA-8h83-vm48-vxjm/GHSA-8h83-vm48-vxjm.json
index 40c33638e50..9ce614eebd3 100644
--- a/advisories/unreviewed/2023/10/GHSA-8h83-vm48-vxjm/GHSA-8h83-vm48-vxjm.json
+++ b/advisories/unreviewed/2023/10/GHSA-8h83-vm48-vxjm/GHSA-8h83-vm48-vxjm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h83-vm48-vxjm",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:14Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22085"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json b/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json
index a03367f59d8..624245deefc 100644
--- a/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json
+++ b/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8hhq-vrcj-6mpj",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:20Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-21413"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-77"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json
index cb039b68a36..0ff1b9c74c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json
+++ b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8j8g-9794-h995",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:58:01Z",
"published": "2023-10-28T00:30:31Z",
"aliases": [
"CVE-2023-46587"
],
"details": "Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T23:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8j9h-fmv7-4h7w/GHSA-8j9h-fmv7-4h7w.json b/advisories/unreviewed/2023/10/GHSA-8j9h-fmv7-4h7w/GHSA-8j9h-fmv7-4h7w.json
index 63917b852d7..0ccc111e0a0 100644
--- a/advisories/unreviewed/2023/10/GHSA-8j9h-fmv7-4h7w/GHSA-8j9h-fmv7-4h7w.json
+++ b/advisories/unreviewed/2023/10/GHSA-8j9h-fmv7-4h7w/GHSA-8j9h-fmv7-4h7w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8j9h-fmv7-4h7w",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:59Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45654"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8jpm-94jj-mfm6/GHSA-8jpm-94jj-mfm6.json b/advisories/unreviewed/2023/10/GHSA-8jpm-94jj-mfm6/GHSA-8jpm-94jj-mfm6.json
index 6455931bbe4..e3b6cb6d1b6 100644
--- a/advisories/unreviewed/2023/10/GHSA-8jpm-94jj-mfm6/GHSA-8jpm-94jj-mfm6.json
+++ b/advisories/unreviewed/2023/10/GHSA-8jpm-94jj-mfm6/GHSA-8jpm-94jj-mfm6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jpm-94jj-mfm6",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:50Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-25774"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8jxc-5f94-22vh/GHSA-8jxc-5f94-22vh.json b/advisories/unreviewed/2023/10/GHSA-8jxc-5f94-22vh/GHSA-8jxc-5f94-22vh.json
index b4389284634..8967c2157bc 100644
--- a/advisories/unreviewed/2023/10/GHSA-8jxc-5f94-22vh/GHSA-8jxc-5f94-22vh.json
+++ b/advisories/unreviewed/2023/10/GHSA-8jxc-5f94-22vh/GHSA-8jxc-5f94-22vh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jxc-5f94-22vh",
- "modified": "2023-10-13T09:30:22Z",
+ "modified": "2024-04-04T08:37:25Z",
"published": "2023-10-13T09:30:22Z",
"aliases": [
"CVE-2023-26366"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-918"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8m6j-x8hv-vfpr/GHSA-8m6j-x8hv-vfpr.json b/advisories/unreviewed/2023/10/GHSA-8m6j-x8hv-vfpr/GHSA-8m6j-x8hv-vfpr.json
index 5221388bd2f..458fa510a14 100644
--- a/advisories/unreviewed/2023/10/GHSA-8m6j-x8hv-vfpr/GHSA-8m6j-x8hv-vfpr.json
+++ b/advisories/unreviewed/2023/10/GHSA-8m6j-x8hv-vfpr/GHSA-8m6j-x8hv-vfpr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8m6j-x8hv-vfpr",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:36Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22101"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8m87-q3vv-mcr6/GHSA-8m87-q3vv-mcr6.json b/advisories/unreviewed/2023/10/GHSA-8m87-q3vv-mcr6/GHSA-8m87-q3vv-mcr6.json
index fefe682a336..1aefc245f8c 100644
--- a/advisories/unreviewed/2023/10/GHSA-8m87-q3vv-mcr6/GHSA-8m87-q3vv-mcr6.json
+++ b/advisories/unreviewed/2023/10/GHSA-8m87-q3vv-mcr6/GHSA-8m87-q3vv-mcr6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8m87-q3vv-mcr6",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:02Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-4975"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8p63-mwfp-hjrv/GHSA-8p63-mwfp-hjrv.json b/advisories/unreviewed/2023/10/GHSA-8p63-mwfp-hjrv/GHSA-8p63-mwfp-hjrv.json
index e747133f4c5..e35ec7c9e03 100644
--- a/advisories/unreviewed/2023/10/GHSA-8p63-mwfp-hjrv/GHSA-8p63-mwfp-hjrv.json
+++ b/advisories/unreviewed/2023/10/GHSA-8p63-mwfp-hjrv/GHSA-8p63-mwfp-hjrv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p63-mwfp-hjrv",
- "modified": "2023-10-18T06:30:29Z",
+ "modified": "2024-04-04T08:45:36Z",
"published": "2023-10-18T06:30:29Z",
"aliases": [
"CVE-2023-35083"
],
"details": "Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T04:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8q5v-q254-rx9v/GHSA-8q5v-q254-rx9v.json b/advisories/unreviewed/2023/10/GHSA-8q5v-q254-rx9v/GHSA-8q5v-q254-rx9v.json
index 489c13b5020..00ec2f049b1 100644
--- a/advisories/unreviewed/2023/10/GHSA-8q5v-q254-rx9v/GHSA-8q5v-q254-rx9v.json
+++ b/advisories/unreviewed/2023/10/GHSA-8q5v-q254-rx9v/GHSA-8q5v-q254-rx9v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q5v-q254-rx9v",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:07Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5292"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json b/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json
index fc9959c8e56..e242fc41acb 100644
--- a/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json
+++ b/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qqf-9w4f-fp2m",
- "modified": "2023-10-27T18:30:24Z",
+ "modified": "2024-04-04T08:49:42Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4274"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8r46-xgxw-rm8j/GHSA-8r46-xgxw-rm8j.json b/advisories/unreviewed/2023/10/GHSA-8r46-xgxw-rm8j/GHSA-8r46-xgxw-rm8j.json
index a7ccb7ea15e..50c1e805d67 100644
--- a/advisories/unreviewed/2023/10/GHSA-8r46-xgxw-rm8j/GHSA-8r46-xgxw-rm8j.json
+++ b/advisories/unreviewed/2023/10/GHSA-8r46-xgxw-rm8j/GHSA-8r46-xgxw-rm8j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r46-xgxw-rm8j",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:25Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45048"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8rj7-wpfp-6wx5/GHSA-8rj7-wpfp-6wx5.json b/advisories/unreviewed/2023/10/GHSA-8rj7-wpfp-6wx5/GHSA-8rj7-wpfp-6wx5.json
index b814c96dc19..61dcc5f096e 100644
--- a/advisories/unreviewed/2023/10/GHSA-8rj7-wpfp-6wx5/GHSA-8rj7-wpfp-6wx5.json
+++ b/advisories/unreviewed/2023/10/GHSA-8rj7-wpfp-6wx5/GHSA-8rj7-wpfp-6wx5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rj7-wpfp-6wx5",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:46Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45764"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json b/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json
index 89738df9a34..47527caa530 100644
--- a/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json
+++ b/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wgv-6377-h5p6",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:52:36Z",
"published": "2023-10-22T00:30:17Z",
"aliases": [
"CVE-2023-46078"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8x86-h5jc-fg6v/GHSA-8x86-h5jc-fg6v.json b/advisories/unreviewed/2023/10/GHSA-8x86-h5jc-fg6v/GHSA-8x86-h5jc-fg6v.json
index edf9a1d5b13..9d4e1917529 100644
--- a/advisories/unreviewed/2023/10/GHSA-8x86-h5jc-fg6v/GHSA-8x86-h5jc-fg6v.json
+++ b/advisories/unreviewed/2023/10/GHSA-8x86-h5jc-fg6v/GHSA-8x86-h5jc-fg6v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x86-h5jc-fg6v",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:43Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-22308"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-191"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-8xrj-3qq4-m659/GHSA-8xrj-3qq4-m659.json b/advisories/unreviewed/2023/10/GHSA-8xrj-3qq4-m659/GHSA-8xrj-3qq4-m659.json
index 6b1f0e533d2..f0e28a16c1b 100644
--- a/advisories/unreviewed/2023/10/GHSA-8xrj-3qq4-m659/GHSA-8xrj-3qq4-m659.json
+++ b/advisories/unreviewed/2023/10/GHSA-8xrj-3qq4-m659/GHSA-8xrj-3qq4-m659.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8xrj-3qq4-m659",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:38Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-41131"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T15:15:46Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json b/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json
index def14f9def8..34eeace17dd 100644
--- a/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json
+++ b/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92g2-c2g8-rfxp",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:07Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46526"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-93hx-mh7c-w6hg/GHSA-93hx-mh7c-w6hg.json b/advisories/unreviewed/2023/10/GHSA-93hx-mh7c-w6hg/GHSA-93hx-mh7c-w6hg.json
index ef4d840a153..b0899970687 100644
--- a/advisories/unreviewed/2023/10/GHSA-93hx-mh7c-w6hg/GHSA-93hx-mh7c-w6hg.json
+++ b/advisories/unreviewed/2023/10/GHSA-93hx-mh7c-w6hg/GHSA-93hx-mh7c-w6hg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93hx-mh7c-w6hg",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:55Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5086"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-93jh-7v3q-c8c6/GHSA-93jh-7v3q-c8c6.json b/advisories/unreviewed/2023/10/GHSA-93jh-7v3q-c8c6/GHSA-93jh-7v3q-c8c6.json
index 5c774465461..eb26d3ff3fa 100644
--- a/advisories/unreviewed/2023/10/GHSA-93jh-7v3q-c8c6/GHSA-93jh-7v3q-c8c6.json
+++ b/advisories/unreviewed/2023/10/GHSA-93jh-7v3q-c8c6/GHSA-93jh-7v3q-c8c6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93jh-7v3q-c8c6",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:44Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-22325"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-835"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json b/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json
index f6c302a09da..4096282065d 100644
--- a/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json
+++ b/advisories/unreviewed/2023/10/GHSA-93rg-x44m-w3fg/GHSA-93rg-x44m-w3fg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93rg-x44m-w3fg",
- "modified": "2023-10-26T21:30:22Z",
+ "modified": "2024-04-04T08:57:03Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-46663"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-284"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T21:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-94mp-fmc5-vxqv/GHSA-94mp-fmc5-vxqv.json b/advisories/unreviewed/2023/10/GHSA-94mp-fmc5-vxqv/GHSA-94mp-fmc5-vxqv.json
index e17e082ae8f..b1432541085 100644
--- a/advisories/unreviewed/2023/10/GHSA-94mp-fmc5-vxqv/GHSA-94mp-fmc5-vxqv.json
+++ b/advisories/unreviewed/2023/10/GHSA-94mp-fmc5-vxqv/GHSA-94mp-fmc5-vxqv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94mp-fmc5-vxqv",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:04Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-45267"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-94xm-wg2w-cvfq/GHSA-94xm-wg2w-cvfq.json b/advisories/unreviewed/2023/10/GHSA-94xm-wg2w-cvfq/GHSA-94xm-wg2w-cvfq.json
index 3dd74bf7055..0cb5fe32178 100644
--- a/advisories/unreviewed/2023/10/GHSA-94xm-wg2w-cvfq/GHSA-94xm-wg2w-cvfq.json
+++ b/advisories/unreviewed/2023/10/GHSA-94xm-wg2w-cvfq/GHSA-94xm-wg2w-cvfq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94xm-wg2w-cvfq",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:50:12Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5523"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-829"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-95pq-x7mh-2f6c/GHSA-95pq-x7mh-2f6c.json b/advisories/unreviewed/2023/10/GHSA-95pq-x7mh-2f6c/GHSA-95pq-x7mh-2f6c.json
index 0cf04fd9626..b70fb8ccc3c 100644
--- a/advisories/unreviewed/2023/10/GHSA-95pq-x7mh-2f6c/GHSA-95pq-x7mh-2f6c.json
+++ b/advisories/unreviewed/2023/10/GHSA-95pq-x7mh-2f6c/GHSA-95pq-x7mh-2f6c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95pq-x7mh-2f6c",
- "modified": "2023-10-19T18:30:27Z",
+ "modified": "2024-04-04T08:39:33Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-45579"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-95vp-23xg-jv7p/GHSA-95vp-23xg-jv7p.json b/advisories/unreviewed/2023/10/GHSA-95vp-23xg-jv7p/GHSA-95vp-23xg-jv7p.json
index 650f1599378..b70d330ba92 100644
--- a/advisories/unreviewed/2023/10/GHSA-95vp-23xg-jv7p/GHSA-95vp-23xg-jv7p.json
+++ b/advisories/unreviewed/2023/10/GHSA-95vp-23xg-jv7p/GHSA-95vp-23xg-jv7p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95vp-23xg-jv7p",
- "modified": "2023-10-16T18:30:27Z",
+ "modified": "2024-04-04T08:36:32Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-41261"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json b/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json
index 76df4ee5144..15e68a42f6e 100644
--- a/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json
+++ b/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96rf-64j2-34rj",
- "modified": "2023-10-27T18:30:24Z",
+ "modified": "2024-04-04T08:49:46Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4488"
@@ -35,7 +35,7 @@
"CWE-829",
"CWE-98"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-97hh-rrpx-8434/GHSA-97hh-rrpx-8434.json b/advisories/unreviewed/2023/10/GHSA-97hh-rrpx-8434/GHSA-97hh-rrpx-8434.json
index d7860593a01..543e0cc85dc 100644
--- a/advisories/unreviewed/2023/10/GHSA-97hh-rrpx-8434/GHSA-97hh-rrpx-8434.json
+++ b/advisories/unreviewed/2023/10/GHSA-97hh-rrpx-8434/GHSA-97hh-rrpx-8434.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97hh-rrpx-8434",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:06Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44194"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-97mp-43rr-5rcx/GHSA-97mp-43rr-5rcx.json b/advisories/unreviewed/2023/10/GHSA-97mp-43rr-5rcx/GHSA-97mp-43rr-5rcx.json
index 8aaca170acf..fe9aa3feee2 100644
--- a/advisories/unreviewed/2023/10/GHSA-97mp-43rr-5rcx/GHSA-97mp-43rr-5rcx.json
+++ b/advisories/unreviewed/2023/10/GHSA-97mp-43rr-5rcx/GHSA-97mp-43rr-5rcx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97mp-43rr-5rcx",
- "modified": "2023-10-23T18:30:46Z",
+ "modified": "2024-04-04T08:53:16Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-43067"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-611"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T16:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-98q6-96hr-7jxp/GHSA-98q6-96hr-7jxp.json b/advisories/unreviewed/2023/10/GHSA-98q6-96hr-7jxp/GHSA-98q6-96hr-7jxp.json
index 5299b4a90c3..7ba5a80da4a 100644
--- a/advisories/unreviewed/2023/10/GHSA-98q6-96hr-7jxp/GHSA-98q6-96hr-7jxp.json
+++ b/advisories/unreviewed/2023/10/GHSA-98q6-96hr-7jxp/GHSA-98q6-96hr-7jxp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-98q6-96hr-7jxp",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:49:12Z",
"published": "2023-10-20T00:30:24Z",
"aliases": [
"CVE-2023-43342"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-992r-442f-c792/GHSA-992r-442f-c792.json b/advisories/unreviewed/2023/10/GHSA-992r-442f-c792/GHSA-992r-442f-c792.json
index d2fbd2d444c..ef780d568e8 100644
--- a/advisories/unreviewed/2023/10/GHSA-992r-442f-c792/GHSA-992r-442f-c792.json
+++ b/advisories/unreviewed/2023/10/GHSA-992r-442f-c792/GHSA-992r-442f-c792.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-992r-442f-c792",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:51Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45769"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-99v8-x8w9-cmfp/GHSA-99v8-x8w9-cmfp.json b/advisories/unreviewed/2023/10/GHSA-99v8-x8w9-cmfp/GHSA-99v8-x8w9-cmfp.json
index 2bb79dca971..c413a412805 100644
--- a/advisories/unreviewed/2023/10/GHSA-99v8-x8w9-cmfp/GHSA-99v8-x8w9-cmfp.json
+++ b/advisories/unreviewed/2023/10/GHSA-99v8-x8w9-cmfp/GHSA-99v8-x8w9-cmfp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99v8-x8w9-cmfp",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:42Z",
"published": "2023-10-26T12:31:06Z",
"aliases": [
"CVE-2023-46074"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T12:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json b/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json
index ad326278486..a761f74974a 100644
--- a/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json
+++ b/advisories/unreviewed/2023/10/GHSA-9c5w-974x-xjxh/GHSA-9c5w-974x-xjxh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c5w-974x-xjxh",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:50Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4821"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9f28-p89f-245f/GHSA-9f28-p89f-245f.json b/advisories/unreviewed/2023/10/GHSA-9f28-p89f-245f/GHSA-9f28-p89f-245f.json
index 55efc02884a..f97c47425a7 100644
--- a/advisories/unreviewed/2023/10/GHSA-9f28-p89f-245f/GHSA-9f28-p89f-245f.json
+++ b/advisories/unreviewed/2023/10/GHSA-9f28-p89f-245f/GHSA-9f28-p89f-245f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f28-p89f-245f",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:45Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4924"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9gjr-ph32-5q54/GHSA-9gjr-ph32-5q54.json b/advisories/unreviewed/2023/10/GHSA-9gjr-ph32-5q54/GHSA-9gjr-ph32-5q54.json
index d66fe5ddde5..a9fe65052b2 100644
--- a/advisories/unreviewed/2023/10/GHSA-9gjr-ph32-5q54/GHSA-9gjr-ph32-5q54.json
+++ b/advisories/unreviewed/2023/10/GHSA-9gjr-ph32-5q54/GHSA-9gjr-ph32-5q54.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gjr-ph32-5q54",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:45:16Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-39276"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9h4p-65h5-f3vx/GHSA-9h4p-65h5-f3vx.json b/advisories/unreviewed/2023/10/GHSA-9h4p-65h5-f3vx/GHSA-9h4p-65h5-f3vx.json
index cf9cfd6e5d0..240460928ad 100644
--- a/advisories/unreviewed/2023/10/GHSA-9h4p-65h5-f3vx/GHSA-9h4p-65h5-f3vx.json
+++ b/advisories/unreviewed/2023/10/GHSA-9h4p-65h5-f3vx/GHSA-9h4p-65h5-f3vx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h4p-65h5-f3vx",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:49Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-23581"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9h5h-vqj6-gf88/GHSA-9h5h-vqj6-gf88.json b/advisories/unreviewed/2023/10/GHSA-9h5h-vqj6-gf88/GHSA-9h5h-vqj6-gf88.json
index 00ce62381e8..75f4cb21b4f 100644
--- a/advisories/unreviewed/2023/10/GHSA-9h5h-vqj6-gf88/GHSA-9h5h-vqj6-gf88.json
+++ b/advisories/unreviewed/2023/10/GHSA-9h5h-vqj6-gf88/GHSA-9h5h-vqj6-gf88.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h5h-vqj6-gf88",
- "modified": "2023-10-12T06:30:26Z",
+ "modified": "2024-04-04T08:35:07Z",
"published": "2023-10-12T06:30:26Z",
"aliases": [
"CVE-2023-40829"
],
"details": "There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T05:15:46Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9j4q-chv7-qjv6/GHSA-9j4q-chv7-qjv6.json b/advisories/unreviewed/2023/10/GHSA-9j4q-chv7-qjv6/GHSA-9j4q-chv7-qjv6.json
index 28d4df2fc92..7fa3fc8a6ca 100644
--- a/advisories/unreviewed/2023/10/GHSA-9j4q-chv7-qjv6/GHSA-9j4q-chv7-qjv6.json
+++ b/advisories/unreviewed/2023/10/GHSA-9j4q-chv7-qjv6/GHSA-9j4q-chv7-qjv6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9j4q-chv7-qjv6",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:48Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4941"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9jcp-r9cp-5qwf/GHSA-9jcp-r9cp-5qwf.json b/advisories/unreviewed/2023/10/GHSA-9jcp-r9cp-5qwf/GHSA-9jcp-r9cp-5qwf.json
index 0bd1d0cc908..568d8dfd313 100644
--- a/advisories/unreviewed/2023/10/GHSA-9jcp-r9cp-5qwf/GHSA-9jcp-r9cp-5qwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-9jcp-r9cp-5qwf/GHSA-9jcp-r9cp-5qwf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jcp-r9cp-5qwf",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:19Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-46007"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9jhj-p8jf-q52w/GHSA-9jhj-p8jf-q52w.json b/advisories/unreviewed/2023/10/GHSA-9jhj-p8jf-q52w/GHSA-9jhj-p8jf-q52w.json
index c5b9f08c249..88224795808 100644
--- a/advisories/unreviewed/2023/10/GHSA-9jhj-p8jf-q52w/GHSA-9jhj-p8jf-q52w.json
+++ b/advisories/unreviewed/2023/10/GHSA-9jhj-p8jf-q52w/GHSA-9jhj-p8jf-q52w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jhj-p8jf-q52w",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:05Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5200"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json
index 5dc79fdd1b2..fa7a9722701 100644
--- a/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json
+++ b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jm2-h589-xc6m",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:57:30Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40116"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9jm9-9xjf-h3x2/GHSA-9jm9-9xjf-h3x2.json b/advisories/unreviewed/2023/10/GHSA-9jm9-9xjf-h3x2/GHSA-9jm9-9xjf-h3x2.json
index 415a886e073..bae74695332 100644
--- a/advisories/unreviewed/2023/10/GHSA-9jm9-9xjf-h3x2/GHSA-9jm9-9xjf-h3x2.json
+++ b/advisories/unreviewed/2023/10/GHSA-9jm9-9xjf-h3x2/GHSA-9jm9-9xjf-h3x2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jm9-9xjf-h3x2",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:32Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45905"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9jrm-qw53-pvvc/GHSA-9jrm-qw53-pvvc.json b/advisories/unreviewed/2023/10/GHSA-9jrm-qw53-pvvc/GHSA-9jrm-qw53-pvvc.json
index 8e87e1aff21..18ba6d9e183 100644
--- a/advisories/unreviewed/2023/10/GHSA-9jrm-qw53-pvvc/GHSA-9jrm-qw53-pvvc.json
+++ b/advisories/unreviewed/2023/10/GHSA-9jrm-qw53-pvvc/GHSA-9jrm-qw53-pvvc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jrm-qw53-pvvc",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:42Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44181"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-835"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9m58-r896-qpmc/GHSA-9m58-r896-qpmc.json b/advisories/unreviewed/2023/10/GHSA-9m58-r896-qpmc/GHSA-9m58-r896-qpmc.json
index c1c4aa0d141..40b135a2ab1 100644
--- a/advisories/unreviewed/2023/10/GHSA-9m58-r896-qpmc/GHSA-9m58-r896-qpmc.json
+++ b/advisories/unreviewed/2023/10/GHSA-9m58-r896-qpmc/GHSA-9m58-r896-qpmc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9m58-r896-qpmc",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:55:07Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39924"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9mqf-3pqw-75gf/GHSA-9mqf-3pqw-75gf.json b/advisories/unreviewed/2023/10/GHSA-9mqf-3pqw-75gf/GHSA-9mqf-3pqw-75gf.json
index fb900b69960..d4ef03028d9 100644
--- a/advisories/unreviewed/2023/10/GHSA-9mqf-3pqw-75gf/GHSA-9mqf-3pqw-75gf.json
+++ b/advisories/unreviewed/2023/10/GHSA-9mqf-3pqw-75gf/GHSA-9mqf-3pqw-75gf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mqf-3pqw-75gf",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:44Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4923"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json
index 8c38799a160..81a5d0fad76 100644
--- a/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json
+++ b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mvw-c7r6-xcpq",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:51Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40137"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9mx6-4gg4-85xj/GHSA-9mx6-4gg4-85xj.json b/advisories/unreviewed/2023/10/GHSA-9mx6-4gg4-85xj/GHSA-9mx6-4gg4-85xj.json
index 10f706bd31d..d43488e1a13 100644
--- a/advisories/unreviewed/2023/10/GHSA-9mx6-4gg4-85xj/GHSA-9mx6-4gg4-85xj.json
+++ b/advisories/unreviewed/2023/10/GHSA-9mx6-4gg4-85xj/GHSA-9mx6-4gg4-85xj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mx6-4gg4-85xj",
- "modified": "2023-10-13T09:30:22Z",
+ "modified": "2024-04-04T08:37:27Z",
"published": "2023-10-13T09:30:22Z",
"aliases": [
"CVE-2023-26367"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9p9h-72r2-r3gj/GHSA-9p9h-72r2-r3gj.json b/advisories/unreviewed/2023/10/GHSA-9p9h-72r2-r3gj/GHSA-9p9h-72r2-r3gj.json
index 33aadbb2827..fb17275c489 100644
--- a/advisories/unreviewed/2023/10/GHSA-9p9h-72r2-r3gj/GHSA-9p9h-72r2-r3gj.json
+++ b/advisories/unreviewed/2023/10/GHSA-9p9h-72r2-r3gj/GHSA-9p9h-72r2-r3gj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9p9h-72r2-r3gj",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:58Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45064"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9pvh-gq43-pqc3/GHSA-9pvh-gq43-pqc3.json b/advisories/unreviewed/2023/10/GHSA-9pvh-gq43-pqc3/GHSA-9pvh-gq43-pqc3.json
index 3743a9da983..dbaf00fe702 100644
--- a/advisories/unreviewed/2023/10/GHSA-9pvh-gq43-pqc3/GHSA-9pvh-gq43-pqc3.json
+++ b/advisories/unreviewed/2023/10/GHSA-9pvh-gq43-pqc3/GHSA-9pvh-gq43-pqc3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pvh-gq43-pqc3",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:58Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22122"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json b/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json
index b88f95f256f..5da35b24680 100644
--- a/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json
+++ b/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q57-wj63-96j5",
- "modified": "2023-10-22T03:30:23Z",
+ "modified": "2024-04-04T08:52:38Z",
"published": "2023-10-22T03:30:23Z",
"aliases": [
"CVE-2023-38735"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9q93-64jr-x633/GHSA-9q93-64jr-x633.json b/advisories/unreviewed/2023/10/GHSA-9q93-64jr-x633/GHSA-9q93-64jr-x633.json
index 3b74f223ff3..c4eac5019ea 100644
--- a/advisories/unreviewed/2023/10/GHSA-9q93-64jr-x633/GHSA-9q93-64jr-x633.json
+++ b/advisories/unreviewed/2023/10/GHSA-9q93-64jr-x633/GHSA-9q93-64jr-x633.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q93-64jr-x633",
- "modified": "2023-10-13T06:30:34Z",
+ "modified": "2024-04-04T08:35:17Z",
"published": "2023-10-12T12:30:24Z",
"aliases": [
"CVE-2023-5554"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-295"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T10:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json
index 53b0274d883..9c0af081b69 100644
--- a/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json
+++ b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qr5-85g4-f6rq",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:21Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2022-34886"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:40Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9qvm-7q24-7mg9/GHSA-9qvm-7q24-7mg9.json b/advisories/unreviewed/2023/10/GHSA-9qvm-7q24-7mg9/GHSA-9qvm-7q24-7mg9.json
index 04cc9b62a42..f3f163e4a53 100644
--- a/advisories/unreviewed/2023/10/GHSA-9qvm-7q24-7mg9/GHSA-9qvm-7q24-7mg9.json
+++ b/advisories/unreviewed/2023/10/GHSA-9qvm-7q24-7mg9/GHSA-9qvm-7q24-7mg9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qvm-7q24-7mg9",
- "modified": "2023-10-18T12:30:20Z",
+ "modified": "2024-04-04T08:46:03Z",
"published": "2023-10-18T12:30:20Z",
"aliases": [
"CVE-2023-32089"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T12:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9r4m-vc45-52hp/GHSA-9r4m-vc45-52hp.json b/advisories/unreviewed/2023/10/GHSA-9r4m-vc45-52hp/GHSA-9r4m-vc45-52hp.json
index 7caacb42e55..94ac59c5ef3 100644
--- a/advisories/unreviewed/2023/10/GHSA-9r4m-vc45-52hp/GHSA-9r4m-vc45-52hp.json
+++ b/advisories/unreviewed/2023/10/GHSA-9r4m-vc45-52hp/GHSA-9r4m-vc45-52hp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9r4m-vc45-52hp",
- "modified": "2023-10-18T21:33:11Z",
+ "modified": "2024-04-04T08:46:44Z",
"published": "2023-10-18T21:33:11Z",
"aliases": [
"CVE-2023-4601"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9v76-7rmr-76cm/GHSA-9v76-7rmr-76cm.json b/advisories/unreviewed/2023/10/GHSA-9v76-7rmr-76cm/GHSA-9v76-7rmr-76cm.json
index 355d7588984..73e9087f67f 100644
--- a/advisories/unreviewed/2023/10/GHSA-9v76-7rmr-76cm/GHSA-9v76-7rmr-76cm.json
+++ b/advisories/unreviewed/2023/10/GHSA-9v76-7rmr-76cm/GHSA-9v76-7rmr-76cm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v76-7rmr-76cm",
- "modified": "2023-10-16T21:30:25Z",
+ "modified": "2024-04-04T08:41:11Z",
"published": "2023-10-16T21:30:25Z",
"aliases": [
"CVE-2023-43120"
],
"details": "An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T19:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9vf3-vw7m-x4rr/GHSA-9vf3-vw7m-x4rr.json b/advisories/unreviewed/2023/10/GHSA-9vf3-vw7m-x4rr/GHSA-9vf3-vw7m-x4rr.json
index d57e2c03d93..c24a8e1e720 100644
--- a/advisories/unreviewed/2023/10/GHSA-9vf3-vw7m-x4rr/GHSA-9vf3-vw7m-x4rr.json
+++ b/advisories/unreviewed/2023/10/GHSA-9vf3-vw7m-x4rr/GHSA-9vf3-vw7m-x4rr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vf3-vw7m-x4rr",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:10Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45071"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9vp9-v4wh-433r/GHSA-9vp9-v4wh-433r.json b/advisories/unreviewed/2023/10/GHSA-9vp9-v4wh-433r/GHSA-9vp9-v4wh-433r.json
index 27cfdc13861..1e320c319b8 100644
--- a/advisories/unreviewed/2023/10/GHSA-9vp9-v4wh-433r/GHSA-9vp9-v4wh-433r.json
+++ b/advisories/unreviewed/2023/10/GHSA-9vp9-v4wh-433r/GHSA-9vp9-v4wh-433r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vp9-v4wh-433r",
- "modified": "2023-10-24T18:30:23Z",
+ "modified": "2024-04-04T08:41:09Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45689"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9vph-3jrp-5jwh/GHSA-9vph-3jrp-5jwh.json b/advisories/unreviewed/2023/10/GHSA-9vph-3jrp-5jwh/GHSA-9vph-3jrp-5jwh.json
index e9c1d617567..eaf16ccb893 100644
--- a/advisories/unreviewed/2023/10/GHSA-9vph-3jrp-5jwh/GHSA-9vph-3jrp-5jwh.json
+++ b/advisories/unreviewed/2023/10/GHSA-9vph-3jrp-5jwh/GHSA-9vph-3jrp-5jwh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vph-3jrp-5jwh",
- "modified": "2023-10-17T18:30:55Z",
+ "modified": "2024-04-04T08:35:19Z",
"published": "2023-10-12T12:30:24Z",
"aliases": [
"CVE-2023-23737"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9w2j-4f43-pmmh/GHSA-9w2j-4f43-pmmh.json b/advisories/unreviewed/2023/10/GHSA-9w2j-4f43-pmmh/GHSA-9w2j-4f43-pmmh.json
index 7af288ac843..e52e3e3f03e 100644
--- a/advisories/unreviewed/2023/10/GHSA-9w2j-4f43-pmmh/GHSA-9w2j-4f43-pmmh.json
+++ b/advisories/unreviewed/2023/10/GHSA-9w2j-4f43-pmmh/GHSA-9w2j-4f43-pmmh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w2j-4f43-pmmh",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:52Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-5246"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-9wx6-ggqr-p55x/GHSA-9wx6-ggqr-p55x.json b/advisories/unreviewed/2023/10/GHSA-9wx6-ggqr-p55x/GHSA-9wx6-ggqr-p55x.json
index b499067be48..2e616e5b007 100644
--- a/advisories/unreviewed/2023/10/GHSA-9wx6-ggqr-p55x/GHSA-9wx6-ggqr-p55x.json
+++ b/advisories/unreviewed/2023/10/GHSA-9wx6-ggqr-p55x/GHSA-9wx6-ggqr-p55x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9wx6-ggqr-p55x",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:47Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4598"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c2qp-qqm8-h8cw/GHSA-c2qp-qqm8-h8cw.json b/advisories/unreviewed/2023/10/GHSA-c2qp-qqm8-h8cw/GHSA-c2qp-qqm8-h8cw.json
index f9a06ffd378..3e102fa8c6f 100644
--- a/advisories/unreviewed/2023/10/GHSA-c2qp-qqm8-h8cw/GHSA-c2qp-qqm8-h8cw.json
+++ b/advisories/unreviewed/2023/10/GHSA-c2qp-qqm8-h8cw/GHSA-c2qp-qqm8-h8cw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2qp-qqm8-h8cw",
- "modified": "2023-10-25T18:32:19Z",
+ "modified": "2024-04-04T08:46:06Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45065"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c359-g3mh-v8vw/GHSA-c359-g3mh-v8vw.json b/advisories/unreviewed/2023/10/GHSA-c359-g3mh-v8vw/GHSA-c359-g3mh-v8vw.json
index 579e3ced22d..8a957cbf3c2 100644
--- a/advisories/unreviewed/2023/10/GHSA-c359-g3mh-v8vw/GHSA-c359-g3mh-v8vw.json
+++ b/advisories/unreviewed/2023/10/GHSA-c359-g3mh-v8vw/GHSA-c359-g3mh-v8vw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c359-g3mh-v8vw",
- "modified": "2023-10-31T15:30:19Z",
+ "modified": "2024-04-04T08:53:36Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-27152"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-307"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c36p-pqfp-h5j2/GHSA-c36p-pqfp-h5j2.json b/advisories/unreviewed/2023/10/GHSA-c36p-pqfp-h5j2/GHSA-c36p-pqfp-h5j2.json
index 6e3fa9f8491..5d20b97fd78 100644
--- a/advisories/unreviewed/2023/10/GHSA-c36p-pqfp-h5j2/GHSA-c36p-pqfp-h5j2.json
+++ b/advisories/unreviewed/2023/10/GHSA-c36p-pqfp-h5j2/GHSA-c36p-pqfp-h5j2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c36p-pqfp-h5j2",
- "modified": "2023-10-19T18:30:30Z",
+ "modified": "2024-04-04T08:48:28Z",
"published": "2023-10-19T18:30:30Z",
"aliases": [
"CVE-2023-35126"
@@ -39,7 +39,7 @@
"CWE-129",
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c3v3-8wvp-5mg4/GHSA-c3v3-8wvp-5mg4.json b/advisories/unreviewed/2023/10/GHSA-c3v3-8wvp-5mg4/GHSA-c3v3-8wvp-5mg4.json
index 2f7d3bd340a..cfea18a0933 100644
--- a/advisories/unreviewed/2023/10/GHSA-c3v3-8wvp-5mg4/GHSA-c3v3-8wvp-5mg4.json
+++ b/advisories/unreviewed/2023/10/GHSA-c3v3-8wvp-5mg4/GHSA-c3v3-8wvp-5mg4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c3v3-8wvp-5mg4",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:15Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-24401"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-323",
"CWE-639"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c3vw-3m8x-p7qv/GHSA-c3vw-3m8x-p7qv.json b/advisories/unreviewed/2023/10/GHSA-c3vw-3m8x-p7qv/GHSA-c3vw-3m8x-p7qv.json
index f536816941b..1aa429ad0fb 100644
--- a/advisories/unreviewed/2023/10/GHSA-c3vw-3m8x-p7qv/GHSA-c3vw-3m8x-p7qv.json
+++ b/advisories/unreviewed/2023/10/GHSA-c3vw-3m8x-p7qv/GHSA-c3vw-3m8x-p7qv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c3vw-3m8x-p7qv",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:54Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45650"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json b/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json
index 979fea9e23c..17068427f3e 100644
--- a/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json
+++ b/advisories/unreviewed/2023/10/GHSA-c3xg-7w53-6ghf/GHSA-c3xg-7w53-6ghf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c3xg-7w53-6ghf",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:23Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-27316"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c55p-cv2w-vc32/GHSA-c55p-cv2w-vc32.json b/advisories/unreviewed/2023/10/GHSA-c55p-cv2w-vc32/GHSA-c55p-cv2w-vc32.json
index 3614b2c3bf5..51ec8fd892d 100644
--- a/advisories/unreviewed/2023/10/GHSA-c55p-cv2w-vc32/GHSA-c55p-cv2w-vc32.json
+++ b/advisories/unreviewed/2023/10/GHSA-c55p-cv2w-vc32/GHSA-c55p-cv2w-vc32.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c55p-cv2w-vc32",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:31Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2020-36698"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json
index 76aec95c5a8..38f45c8e633 100644
--- a/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json
+++ b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c5qj-vxvj-r553",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:57:59Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46211"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c752-3p6c-46qc/GHSA-c752-3p6c-46qc.json b/advisories/unreviewed/2023/10/GHSA-c752-3p6c-46qc/GHSA-c752-3p6c-46qc.json
index 45fe5bd4128..0c10ddcab94 100644
--- a/advisories/unreviewed/2023/10/GHSA-c752-3p6c-46qc/GHSA-c752-3p6c-46qc.json
+++ b/advisories/unreviewed/2023/10/GHSA-c752-3p6c-46qc/GHSA-c752-3p6c-46qc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c752-3p6c-46qc",
- "modified": "2023-10-25T03:30:36Z",
+ "modified": "2024-04-04T08:46:24Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45630"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c79c-7rg5-qq47/GHSA-c79c-7rg5-qq47.json b/advisories/unreviewed/2023/10/GHSA-c79c-7rg5-qq47/GHSA-c79c-7rg5-qq47.json
index b6ad90d7801..d14387fa1d9 100644
--- a/advisories/unreviewed/2023/10/GHSA-c79c-7rg5-qq47/GHSA-c79c-7rg5-qq47.json
+++ b/advisories/unreviewed/2023/10/GHSA-c79c-7rg5-qq47/GHSA-c79c-7rg5-qq47.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c79c-7rg5-qq47",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:09Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-41680"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c7fp-g3rh-mvf7/GHSA-c7fp-g3rh-mvf7.json b/advisories/unreviewed/2023/10/GHSA-c7fp-g3rh-mvf7/GHSA-c7fp-g3rh-mvf7.json
index bdf257a5b2d..8c61a1c714d 100644
--- a/advisories/unreviewed/2023/10/GHSA-c7fp-g3rh-mvf7/GHSA-c7fp-g3rh-mvf7.json
+++ b/advisories/unreviewed/2023/10/GHSA-c7fp-g3rh-mvf7/GHSA-c7fp-g3rh-mvf7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7fp-g3rh-mvf7",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:22Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-43118"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c7mx-g2c4-4phj/GHSA-c7mx-g2c4-4phj.json b/advisories/unreviewed/2023/10/GHSA-c7mx-g2c4-4phj/GHSA-c7mx-g2c4-4phj.json
index 7e4dc36ae59..def67d80473 100644
--- a/advisories/unreviewed/2023/10/GHSA-c7mx-g2c4-4phj/GHSA-c7mx-g2c4-4phj.json
+++ b/advisories/unreviewed/2023/10/GHSA-c7mx-g2c4-4phj/GHSA-c7mx-g2c4-4phj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7mx-g2c4-4phj",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:20Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27255"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c82f-8fqm-wg4g/GHSA-c82f-8fqm-wg4g.json b/advisories/unreviewed/2023/10/GHSA-c82f-8fqm-wg4g/GHSA-c82f-8fqm-wg4g.json
index a37dbca8e63..b1468f2d028 100644
--- a/advisories/unreviewed/2023/10/GHSA-c82f-8fqm-wg4g/GHSA-c82f-8fqm-wg4g.json
+++ b/advisories/unreviewed/2023/10/GHSA-c82f-8fqm-wg4g/GHSA-c82f-8fqm-wg4g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c82f-8fqm-wg4g",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:53:57Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26569"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json b/advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json
index 580d89e4fa5..bc14562fbb8 100644
--- a/advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json
+++ b/advisories/unreviewed/2023/10/GHSA-c89h-9543-w7hx/GHSA-c89h-9543-w7hx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c89h-9543-w7hx",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:52:49Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46095"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c8wx-v976-xhgj/GHSA-c8wx-v976-xhgj.json b/advisories/unreviewed/2023/10/GHSA-c8wx-v976-xhgj/GHSA-c8wx-v976-xhgj.json
index 5fc816ac0a9..9f130ee9d21 100644
--- a/advisories/unreviewed/2023/10/GHSA-c8wx-v976-xhgj/GHSA-c8wx-v976-xhgj.json
+++ b/advisories/unreviewed/2023/10/GHSA-c8wx-v976-xhgj/GHSA-c8wx-v976-xhgj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8wx-v976-xhgj",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:34Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2021-4353"
@@ -35,7 +35,7 @@
"CWE-288",
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-c9pj-4j3g-856x/GHSA-c9pj-4j3g-856x.json b/advisories/unreviewed/2023/10/GHSA-c9pj-4j3g-856x/GHSA-c9pj-4j3g-856x.json
index 7f47d9b4c4b..88f3922c7f9 100644
--- a/advisories/unreviewed/2023/10/GHSA-c9pj-4j3g-856x/GHSA-c9pj-4j3g-856x.json
+++ b/advisories/unreviewed/2023/10/GHSA-c9pj-4j3g-856x/GHSA-c9pj-4j3g-856x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9pj-4j3g-856x",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:46Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44184"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-119"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cc3f-r3m3-h7f9/GHSA-cc3f-r3m3-h7f9.json b/advisories/unreviewed/2023/10/GHSA-cc3f-r3m3-h7f9/GHSA-cc3f-r3m3-h7f9.json
index 15cf851c9a5..e1dca188c53 100644
--- a/advisories/unreviewed/2023/10/GHSA-cc3f-r3m3-h7f9/GHSA-cc3f-r3m3-h7f9.json
+++ b/advisories/unreviewed/2023/10/GHSA-cc3f-r3m3-h7f9/GHSA-cc3f-r3m3-h7f9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc3f-r3m3-h7f9",
- "modified": "2023-10-19T06:30:23Z",
+ "modified": "2024-04-04T08:47:02Z",
"published": "2023-10-19T06:30:23Z",
"aliases": [
"CVE-2023-46228"
],
"details": "zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-190"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T05:15:58Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cc6c-373w-hg4m/GHSA-cc6c-373w-hg4m.json b/advisories/unreviewed/2023/10/GHSA-cc6c-373w-hg4m/GHSA-cc6c-373w-hg4m.json
index 04da98c7058..010663c77fa 100644
--- a/advisories/unreviewed/2023/10/GHSA-cc6c-373w-hg4m/GHSA-cc6c-373w-hg4m.json
+++ b/advisories/unreviewed/2023/10/GHSA-cc6c-373w-hg4m/GHSA-cc6c-373w-hg4m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc6c-373w-hg4m",
- "modified": "2023-10-19T15:31:05Z",
+ "modified": "2024-04-04T08:47:44Z",
"published": "2023-10-19T15:31:05Z",
"aliases": [
"CVE-2022-37830"
],
"details": "Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cc6j-mm94-2h5g/GHSA-cc6j-mm94-2h5g.json b/advisories/unreviewed/2023/10/GHSA-cc6j-mm94-2h5g/GHSA-cc6j-mm94-2h5g.json
index a718d3f41c8..9dc5c432cc8 100644
--- a/advisories/unreviewed/2023/10/GHSA-cc6j-mm94-2h5g/GHSA-cc6j-mm94-2h5g.json
+++ b/advisories/unreviewed/2023/10/GHSA-cc6j-mm94-2h5g/GHSA-cc6j-mm94-2h5g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc6j-mm94-2h5g",
- "modified": "2023-10-25T18:32:19Z",
+ "modified": "2024-04-04T08:46:09Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45067"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cc7h-9j52-gh84/GHSA-cc7h-9j52-gh84.json b/advisories/unreviewed/2023/10/GHSA-cc7h-9j52-gh84/GHSA-cc7h-9j52-gh84.json
index ed0e364c93d..e4b79a94b9e 100644
--- a/advisories/unreviewed/2023/10/GHSA-cc7h-9j52-gh84/GHSA-cc7h-9j52-gh84.json
+++ b/advisories/unreviewed/2023/10/GHSA-cc7h-9j52-gh84/GHSA-cc7h-9j52-gh84.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc7h-9j52-gh84",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:01Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45655"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cf5j-jfg7-qmqc/GHSA-cf5j-jfg7-qmqc.json b/advisories/unreviewed/2023/10/GHSA-cf5j-jfg7-qmqc/GHSA-cf5j-jfg7-qmqc.json
index 4cfe9a1e94b..958d8f22cd3 100644
--- a/advisories/unreviewed/2023/10/GHSA-cf5j-jfg7-qmqc/GHSA-cf5j-jfg7-qmqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-cf5j-jfg7-qmqc/GHSA-cf5j-jfg7-qmqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cf5j-jfg7-qmqc",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:53:55Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26568"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json b/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json
index 5f7fe160084..c4b655115bb 100644
--- a/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json
+++ b/advisories/unreviewed/2023/10/GHSA-cggm-fc75-c35c/GHSA-cggm-fc75-c35c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cggm-fc75-c35c",
- "modified": "2023-10-26T21:30:22Z",
+ "modified": "2024-04-04T08:57:05Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-46665"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-284"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cgm3-875w-4qq8/GHSA-cgm3-875w-4qq8.json b/advisories/unreviewed/2023/10/GHSA-cgm3-875w-4qq8/GHSA-cgm3-875w-4qq8.json
index bbec075a6c4..cf893248c2f 100644
--- a/advisories/unreviewed/2023/10/GHSA-cgm3-875w-4qq8/GHSA-cgm3-875w-4qq8.json
+++ b/advisories/unreviewed/2023/10/GHSA-cgm3-875w-4qq8/GHSA-cgm3-875w-4qq8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgm3-875w-4qq8",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:43Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45008"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T08:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cgm3-p7mh-qpqx/GHSA-cgm3-p7mh-qpqx.json b/advisories/unreviewed/2023/10/GHSA-cgm3-p7mh-qpqx/GHSA-cgm3-p7mh-qpqx.json
index 84335636ed0..a1eda9004cd 100644
--- a/advisories/unreviewed/2023/10/GHSA-cgm3-p7mh-qpqx/GHSA-cgm3-p7mh-qpqx.json
+++ b/advisories/unreviewed/2023/10/GHSA-cgm3-p7mh-qpqx/GHSA-cgm3-p7mh-qpqx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgm3-p7mh-qpqx",
- "modified": "2023-10-18T06:30:30Z",
+ "modified": "2024-04-04T08:45:37Z",
"published": "2023-10-18T06:30:30Z",
"aliases": [
"CVE-2023-35084"
],
"details": "Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-502"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T04:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-chgw-cwwq-79xg/GHSA-chgw-cwwq-79xg.json b/advisories/unreviewed/2023/10/GHSA-chgw-cwwq-79xg/GHSA-chgw-cwwq-79xg.json
index 649d1071694..e3c72ef60f2 100644
--- a/advisories/unreviewed/2023/10/GHSA-chgw-cwwq-79xg/GHSA-chgw-cwwq-79xg.json
+++ b/advisories/unreviewed/2023/10/GHSA-chgw-cwwq-79xg/GHSA-chgw-cwwq-79xg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chgw-cwwq-79xg",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:46:41Z",
"published": "2023-10-18T21:33:11Z",
"aliases": [
"CVE-2023-35663"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-chwf-pr57-9wm2/GHSA-chwf-pr57-9wm2.json b/advisories/unreviewed/2023/10/GHSA-chwf-pr57-9wm2/GHSA-chwf-pr57-9wm2.json
index 97c2f6d6a4c..b5497fca0c3 100644
--- a/advisories/unreviewed/2023/10/GHSA-chwf-pr57-9wm2/GHSA-chwf-pr57-9wm2.json
+++ b/advisories/unreviewed/2023/10/GHSA-chwf-pr57-9wm2/GHSA-chwf-pr57-9wm2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chwf-pr57-9wm2",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:50Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-41089"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json b/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json
index cc659316682..269884ade4e 100644
--- a/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json
+++ b/advisories/unreviewed/2023/10/GHSA-cj23-4vc3-qpfc/GHSA-cj23-4vc3-qpfc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj23-4vc3-qpfc",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:15Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22087"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json b/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json
index c1fce2a387d..60287fc1879 100644
--- a/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json
+++ b/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj2w-wj5h-c44x",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:40Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-26943"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-338"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cj3f-w95j-x9xv/GHSA-cj3f-w95j-x9xv.json b/advisories/unreviewed/2023/10/GHSA-cj3f-w95j-x9xv/GHSA-cj3f-w95j-x9xv.json
index 37a1e3121b8..cd5c3d92995 100644
--- a/advisories/unreviewed/2023/10/GHSA-cj3f-w95j-x9xv/GHSA-cj3f-w95j-x9xv.json
+++ b/advisories/unreviewed/2023/10/GHSA-cj3f-w95j-x9xv/GHSA-cj3f-w95j-x9xv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj3f-w95j-x9xv",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:43:00Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-39902"
@@ -32,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-281"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T12:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cjff-m8pq-m7x6/GHSA-cjff-m8pq-m7x6.json b/advisories/unreviewed/2023/10/GHSA-cjff-m8pq-m7x6/GHSA-cjff-m8pq-m7x6.json
index cb99d2ae82e..9a1fccc3c45 100644
--- a/advisories/unreviewed/2023/10/GHSA-cjff-m8pq-m7x6/GHSA-cjff-m8pq-m7x6.json
+++ b/advisories/unreviewed/2023/10/GHSA-cjff-m8pq-m7x6/GHSA-cjff-m8pq-m7x6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjff-m8pq-m7x6",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:14Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44203"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-703"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json b/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json
index 89422a43a7a..c2359433ccf 100644
--- a/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json
+++ b/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjgx-jx6j-cmg7",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:11Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-20598"
],
"details": "\n\n\nAn improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.\n\n\n\n",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json b/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json
index 746fad3d0bf..ebf7d5240e3 100644
--- a/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json
+++ b/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjjx-jw4j-6587",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:56:21Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46554"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cmfg-v75g-8wm3/GHSA-cmfg-v75g-8wm3.json b/advisories/unreviewed/2023/10/GHSA-cmfg-v75g-8wm3/GHSA-cmfg-v75g-8wm3.json
index 9cd2beb43d7..6fffe97212e 100644
--- a/advisories/unreviewed/2023/10/GHSA-cmfg-v75g-8wm3/GHSA-cmfg-v75g-8wm3.json
+++ b/advisories/unreviewed/2023/10/GHSA-cmfg-v75g-8wm3/GHSA-cmfg-v75g-8wm3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmfg-v75g-8wm3",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:58Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2021-26736"
@@ -31,7 +31,7 @@
"CWE-20",
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cp3v-75fh-g783/GHSA-cp3v-75fh-g783.json b/advisories/unreviewed/2023/10/GHSA-cp3v-75fh-g783/GHSA-cp3v-75fh-g783.json
index bde62358387..ad782b1d543 100644
--- a/advisories/unreviewed/2023/10/GHSA-cp3v-75fh-g783/GHSA-cp3v-75fh-g783.json
+++ b/advisories/unreviewed/2023/10/GHSA-cp3v-75fh-g783/GHSA-cp3v-75fh-g783.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp3v-75fh-g783",
- "modified": "2023-10-14T15:30:18Z",
+ "modified": "2024-04-04T08:38:39Z",
"published": "2023-10-14T15:30:18Z",
"aliases": [
"CVE-2022-32755"
@@ -35,7 +35,7 @@
"CWE-611",
"CWE-91"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cpgw-pm36-mfq9/GHSA-cpgw-pm36-mfq9.json b/advisories/unreviewed/2023/10/GHSA-cpgw-pm36-mfq9/GHSA-cpgw-pm36-mfq9.json
index 0d0688b76eb..2e1dc766df8 100644
--- a/advisories/unreviewed/2023/10/GHSA-cpgw-pm36-mfq9/GHSA-cpgw-pm36-mfq9.json
+++ b/advisories/unreviewed/2023/10/GHSA-cpgw-pm36-mfq9/GHSA-cpgw-pm36-mfq9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpgw-pm36-mfq9",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:47Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4668"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json b/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json
index 160286ace66..97dc5bc194f 100644
--- a/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json
+++ b/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cq8v-q3f4-9cwp",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:55:58Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46520"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json b/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json
index 341f8cf41c8..dc0ab981501 100644
--- a/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json
+++ b/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqgr-82mv-j79r",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:24Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2023-27854"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cqjm-c96f-4qp5/GHSA-cqjm-c96f-4qp5.json b/advisories/unreviewed/2023/10/GHSA-cqjm-c96f-4qp5/GHSA-cqjm-c96f-4qp5.json
index 43370c5f184..d6e851a9735 100644
--- a/advisories/unreviewed/2023/10/GHSA-cqjm-c96f-4qp5/GHSA-cqjm-c96f-4qp5.json
+++ b/advisories/unreviewed/2023/10/GHSA-cqjm-c96f-4qp5/GHSA-cqjm-c96f-4qp5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqjm-c96f-4qp5",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:51Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45763"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:45Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json b/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json
index 54f256ad7ea..b812324b8b2 100644
--- a/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json
+++ b/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqv4-m6cq-x9jx",
- "modified": "2023-10-30T15:30:44Z",
+ "modified": "2024-04-04T08:49:19Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-45471"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T04:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cr2w-gfw6-cgj8/GHSA-cr2w-gfw6-cgj8.json b/advisories/unreviewed/2023/10/GHSA-cr2w-gfw6-cgj8/GHSA-cr2w-gfw6-cgj8.json
index c7e0bb1d404..a8d22870a9f 100644
--- a/advisories/unreviewed/2023/10/GHSA-cr2w-gfw6-cgj8/GHSA-cr2w-gfw6-cgj8.json
+++ b/advisories/unreviewed/2023/10/GHSA-cr2w-gfw6-cgj8/GHSA-cr2w-gfw6-cgj8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr2w-gfw6-cgj8",
- "modified": "2023-10-19T15:31:03Z",
+ "modified": "2024-04-04T08:38:33Z",
"published": "2023-10-14T06:30:55Z",
"aliases": [
"CVE-2023-45855"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T05:15:55Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cr8h-8gv8-gxxv/GHSA-cr8h-8gv8-gxxv.json b/advisories/unreviewed/2023/10/GHSA-cr8h-8gv8-gxxv/GHSA-cr8h-8gv8-gxxv.json
index 0d76741a611..cc9d5d8f3c5 100644
--- a/advisories/unreviewed/2023/10/GHSA-cr8h-8gv8-gxxv/GHSA-cr8h-8gv8-gxxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-cr8h-8gv8-gxxv/GHSA-cr8h-8gv8-gxxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr8h-8gv8-gxxv",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:56Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2021-26738"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-426"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cv24-gm95-4rrg/GHSA-cv24-gm95-4rrg.json b/advisories/unreviewed/2023/10/GHSA-cv24-gm95-4rrg/GHSA-cv24-gm95-4rrg.json
index 95c239d8bc6..320c9ba3a9b 100644
--- a/advisories/unreviewed/2023/10/GHSA-cv24-gm95-4rrg/GHSA-cv24-gm95-4rrg.json
+++ b/advisories/unreviewed/2023/10/GHSA-cv24-gm95-4rrg/GHSA-cv24-gm95-4rrg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv24-gm95-4rrg",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:07Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-36952"
],
"details": "TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T05:15:49Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cv5w-p79v-vvxq/GHSA-cv5w-p79v-vvxq.json b/advisories/unreviewed/2023/10/GHSA-cv5w-p79v-vvxq/GHSA-cv5w-p79v-vvxq.json
index b2026eefadd..604b0f21fcc 100644
--- a/advisories/unreviewed/2023/10/GHSA-cv5w-p79v-vvxq/GHSA-cv5w-p79v-vvxq.json
+++ b/advisories/unreviewed/2023/10/GHSA-cv5w-p79v-vvxq/GHSA-cv5w-p79v-vvxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv5w-p79v-vvxq",
- "modified": "2023-10-23T15:30:23Z",
+ "modified": "2024-04-04T08:41:42Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4798"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cw54-cgwp-3c3v/GHSA-cw54-cgwp-3c3v.json b/advisories/unreviewed/2023/10/GHSA-cw54-cgwp-3c3v/GHSA-cw54-cgwp-3c3v.json
index 17836baa2ac..bce404908e5 100644
--- a/advisories/unreviewed/2023/10/GHSA-cw54-cgwp-3c3v/GHSA-cw54-cgwp-3c3v.json
+++ b/advisories/unreviewed/2023/10/GHSA-cw54-cgwp-3c3v/GHSA-cw54-cgwp-3c3v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cw54-cgwp-3c3v",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:29Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45607"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cw58-3hpw-976j/GHSA-cw58-3hpw-976j.json b/advisories/unreviewed/2023/10/GHSA-cw58-3hpw-976j/GHSA-cw58-3hpw-976j.json
index 9d182b10464..4b0c372165d 100644
--- a/advisories/unreviewed/2023/10/GHSA-cw58-3hpw-976j/GHSA-cw58-3hpw-976j.json
+++ b/advisories/unreviewed/2023/10/GHSA-cw58-3hpw-976j/GHSA-cw58-3hpw-976j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cw58-3hpw-976j",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:52Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-27516"
@@ -32,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-1188",
"CWE-453"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cwfq-h62h-3hg5/GHSA-cwfq-h62h-3hg5.json b/advisories/unreviewed/2023/10/GHSA-cwfq-h62h-3hg5/GHSA-cwfq-h62h-3hg5.json
index b7bc2207e29..dfbd91cba4c 100644
--- a/advisories/unreviewed/2023/10/GHSA-cwfq-h62h-3hg5/GHSA-cwfq-h62h-3hg5.json
+++ b/advisories/unreviewed/2023/10/GHSA-cwfq-h62h-3hg5/GHSA-cwfq-h62h-3hg5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwfq-h62h-3hg5",
- "modified": "2023-10-17T09:30:23Z",
+ "modified": "2024-04-04T08:42:47Z",
"published": "2023-10-17T09:30:23Z",
"aliases": [
"CVE-2023-24385"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cx68-9cx9-qmrj/GHSA-cx68-9cx9-qmrj.json b/advisories/unreviewed/2023/10/GHSA-cx68-9cx9-qmrj/GHSA-cx68-9cx9-qmrj.json
index 13c2c40e617..e7c08d465b4 100644
--- a/advisories/unreviewed/2023/10/GHSA-cx68-9cx9-qmrj/GHSA-cx68-9cx9-qmrj.json
+++ b/advisories/unreviewed/2023/10/GHSA-cx68-9cx9-qmrj/GHSA-cx68-9cx9-qmrj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx68-9cx9-qmrj",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:10Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5050"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-cx9h-wv2x-v9rg/GHSA-cx9h-wv2x-v9rg.json b/advisories/unreviewed/2023/10/GHSA-cx9h-wv2x-v9rg/GHSA-cx9h-wv2x-v9rg.json
index b2cf26be524..9a0b9ed3911 100644
--- a/advisories/unreviewed/2023/10/GHSA-cx9h-wv2x-v9rg/GHSA-cx9h-wv2x-v9rg.json
+++ b/advisories/unreviewed/2023/10/GHSA-cx9h-wv2x-v9rg/GHSA-cx9h-wv2x-v9rg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx9h-wv2x-v9rg",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:03Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45687"
],
"details": "A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id of their choosing",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-384"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f2ch-w95m-q82q/GHSA-f2ch-w95m-q82q.json b/advisories/unreviewed/2023/10/GHSA-f2ch-w95m-q82q/GHSA-f2ch-w95m-q82q.json
index e833a4ad58e..b2ab42ef939 100644
--- a/advisories/unreviewed/2023/10/GHSA-f2ch-w95m-q82q/GHSA-f2ch-w95m-q82q.json
+++ b/advisories/unreviewed/2023/10/GHSA-f2ch-w95m-q82q/GHSA-f2ch-w95m-q82q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2ch-w95m-q82q",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:19Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45639"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f35c-gw68-7hgr/GHSA-f35c-gw68-7hgr.json b/advisories/unreviewed/2023/10/GHSA-f35c-gw68-7hgr/GHSA-f35c-gw68-7hgr.json
index 4e3a56ca582..34594e5db06 100644
--- a/advisories/unreviewed/2023/10/GHSA-f35c-gw68-7hgr/GHSA-f35c-gw68-7hgr.json
+++ b/advisories/unreviewed/2023/10/GHSA-f35c-gw68-7hgr/GHSA-f35c-gw68-7hgr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f35c-gw68-7hgr",
- "modified": "2023-10-25T18:32:19Z",
+ "modified": "2024-04-04T08:46:56Z",
"published": "2023-10-19T03:30:28Z",
"aliases": [
"CVE-2023-5336"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f37j-rr3j-w7mq/GHSA-f37j-rr3j-w7mq.json b/advisories/unreviewed/2023/10/GHSA-f37j-rr3j-w7mq/GHSA-f37j-rr3j-w7mq.json
index 492692b3f92..fc6f62ce8f0 100644
--- a/advisories/unreviewed/2023/10/GHSA-f37j-rr3j-w7mq/GHSA-f37j-rr3j-w7mq.json
+++ b/advisories/unreviewed/2023/10/GHSA-f37j-rr3j-w7mq/GHSA-f37j-rr3j-w7mq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f37j-rr3j-w7mq",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:21Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22090"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f3jw-63xv-7wfj/GHSA-f3jw-63xv-7wfj.json b/advisories/unreviewed/2023/10/GHSA-f3jw-63xv-7wfj/GHSA-f3jw-63xv-7wfj.json
index a7fc2319b77..37c23997281 100644
--- a/advisories/unreviewed/2023/10/GHSA-f3jw-63xv-7wfj/GHSA-f3jw-63xv-7wfj.json
+++ b/advisories/unreviewed/2023/10/GHSA-f3jw-63xv-7wfj/GHSA-f3jw-63xv-7wfj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3jw-63xv-7wfj",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:08Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22080"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f3v7-7g27-82qw/GHSA-f3v7-7g27-82qw.json b/advisories/unreviewed/2023/10/GHSA-f3v7-7g27-82qw/GHSA-f3v7-7g27-82qw.json
index 938e8ab7dce..081d882dcd1 100644
--- a/advisories/unreviewed/2023/10/GHSA-f3v7-7g27-82qw/GHSA-f3v7-7g27-82qw.json
+++ b/advisories/unreviewed/2023/10/GHSA-f3v7-7g27-82qw/GHSA-f3v7-7g27-82qw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3v7-7g27-82qw",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:43:02Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-45004"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f42h-c5pj-9hxp/GHSA-f42h-c5pj-9hxp.json b/advisories/unreviewed/2023/10/GHSA-f42h-c5pj-9hxp/GHSA-f42h-c5pj-9hxp.json
index f9d872aa620..419b1ab73b5 100644
--- a/advisories/unreviewed/2023/10/GHSA-f42h-c5pj-9hxp/GHSA-f42h-c5pj-9hxp.json
+++ b/advisories/unreviewed/2023/10/GHSA-f42h-c5pj-9hxp/GHSA-f42h-c5pj-9hxp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f42h-c5pj-9hxp",
- "modified": "2023-10-16T15:30:20Z",
+ "modified": "2024-04-04T08:36:07Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-43149"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T18:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json
index 4974d046cc9..fc3da2b2bc2 100644
--- a/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json
+++ b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f43r-fv98-jc2w",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:57:56Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46209"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json b/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json
index 7aa43561128..bdfa6f8ff28 100644
--- a/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json
+++ b/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f464-84q7-49hm",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:37Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-38128"
@@ -39,7 +39,7 @@
"CWE-787",
"CWE-843"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f4h9-mcvf-w57c/GHSA-f4h9-mcvf-w57c.json b/advisories/unreviewed/2023/10/GHSA-f4h9-mcvf-w57c/GHSA-f4h9-mcvf-w57c.json
index 121b85896bc..0f29832ef05 100644
--- a/advisories/unreviewed/2023/10/GHSA-f4h9-mcvf-w57c/GHSA-f4h9-mcvf-w57c.json
+++ b/advisories/unreviewed/2023/10/GHSA-f4h9-mcvf-w57c/GHSA-f4h9-mcvf-w57c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4h9-mcvf-w57c",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:26Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22093"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f4vf-79gp-p96v/GHSA-f4vf-79gp-p96v.json b/advisories/unreviewed/2023/10/GHSA-f4vf-79gp-p96v/GHSA-f4vf-79gp-p96v.json
index a5e85381724..279caef1514 100644
--- a/advisories/unreviewed/2023/10/GHSA-f4vf-79gp-p96v/GHSA-f4vf-79gp-p96v.json
+++ b/advisories/unreviewed/2023/10/GHSA-f4vf-79gp-p96v/GHSA-f4vf-79gp-p96v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4vf-79gp-p96v",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:23Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45011"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f4x5-257x-2739/GHSA-f4x5-257x-2739.json b/advisories/unreviewed/2023/10/GHSA-f4x5-257x-2739/GHSA-f4x5-257x-2739.json
index cf2cb4fa3eb..7dd73e82685 100644
--- a/advisories/unreviewed/2023/10/GHSA-f4x5-257x-2739/GHSA-f4x5-257x-2739.json
+++ b/advisories/unreviewed/2023/10/GHSA-f4x5-257x-2739/GHSA-f4x5-257x-2739.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4x5-257x-2739",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:24Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-25333"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-347"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f54w-qppp-5xp8/GHSA-f54w-qppp-5xp8.json b/advisories/unreviewed/2023/10/GHSA-f54w-qppp-5xp8/GHSA-f54w-qppp-5xp8.json
index b567f00b2e6..41373109e19 100644
--- a/advisories/unreviewed/2023/10/GHSA-f54w-qppp-5xp8/GHSA-f54w-qppp-5xp8.json
+++ b/advisories/unreviewed/2023/10/GHSA-f54w-qppp-5xp8/GHSA-f54w-qppp-5xp8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f54w-qppp-5xp8",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:35Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2022-4712"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f5q5-79ff-jh27/GHSA-f5q5-79ff-jh27.json b/advisories/unreviewed/2023/10/GHSA-f5q5-79ff-jh27/GHSA-f5q5-79ff-jh27.json
index a20ae7e86fa..0493b26fda3 100644
--- a/advisories/unreviewed/2023/10/GHSA-f5q5-79ff-jh27/GHSA-f5q5-79ff-jh27.json
+++ b/advisories/unreviewed/2023/10/GHSA-f5q5-79ff-jh27/GHSA-f5q5-79ff-jh27.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5q5-79ff-jh27",
- "modified": "2023-10-13T18:30:20Z",
+ "modified": "2024-04-04T08:38:17Z",
"published": "2023-10-13T18:30:20Z",
"aliases": [
"CVE-2023-4499"
],
"details": "A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-295"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f5qf-87r9-8v7q/GHSA-f5qf-87r9-8v7q.json b/advisories/unreviewed/2023/10/GHSA-f5qf-87r9-8v7q/GHSA-f5qf-87r9-8v7q.json
index 4f4440461ed..c4af09f9cc2 100644
--- a/advisories/unreviewed/2023/10/GHSA-f5qf-87r9-8v7q/GHSA-f5qf-87r9-8v7q.json
+++ b/advisories/unreviewed/2023/10/GHSA-f5qf-87r9-8v7q/GHSA-f5qf-87r9-8v7q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5qf-87r9-8v7q",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:30Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-34207"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T04:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f5v4-cqgf-pfvv/GHSA-f5v4-cqgf-pfvv.json b/advisories/unreviewed/2023/10/GHSA-f5v4-cqgf-pfvv/GHSA-f5v4-cqgf-pfvv.json
index 3a836ba165f..45cea24470e 100644
--- a/advisories/unreviewed/2023/10/GHSA-f5v4-cqgf-pfvv/GHSA-f5v4-cqgf-pfvv.json
+++ b/advisories/unreviewed/2023/10/GHSA-f5v4-cqgf-pfvv/GHSA-f5v4-cqgf-pfvv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5v4-cqgf-pfvv",
- "modified": "2023-10-20T12:31:01Z",
+ "modified": "2024-04-04T08:42:07Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-40852"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T21:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json b/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json
index f69a02d30b2..74a0a9992c8 100644
--- a/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json
+++ b/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5w9-q8fj-h9jj",
- "modified": "2023-10-26T18:30:23Z",
+ "modified": "2024-04-04T08:56:54Z",
"published": "2023-10-26T18:30:23Z",
"aliases": [
"CVE-2023-5623"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f69q-975j-f6mc/GHSA-f69q-975j-f6mc.json b/advisories/unreviewed/2023/10/GHSA-f69q-975j-f6mc/GHSA-f69q-975j-f6mc.json
index 56c58ffe047..e6ab149f926 100644
--- a/advisories/unreviewed/2023/10/GHSA-f69q-975j-f6mc/GHSA-f69q-975j-f6mc.json
+++ b/advisories/unreviewed/2023/10/GHSA-f69q-975j-f6mc/GHSA-f69q-975j-f6mc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f69q-975j-f6mc",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:22Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-22385"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f7rx-678f-vf6q/GHSA-f7rx-678f-vf6q.json b/advisories/unreviewed/2023/10/GHSA-f7rx-678f-vf6q/GHSA-f7rx-678f-vf6q.json
index 72610e953fa..58a98d92483 100644
--- a/advisories/unreviewed/2023/10/GHSA-f7rx-678f-vf6q/GHSA-f7rx-678f-vf6q.json
+++ b/advisories/unreviewed/2023/10/GHSA-f7rx-678f-vf6q/GHSA-f7rx-678f-vf6q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7rx-678f-vf6q",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:16Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44195"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-923"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f7v3-rpm4-hwv2/GHSA-f7v3-rpm4-hwv2.json b/advisories/unreviewed/2023/10/GHSA-f7v3-rpm4-hwv2/GHSA-f7v3-rpm4-hwv2.json
index cf2fac15f66..37db1f69fd1 100644
--- a/advisories/unreviewed/2023/10/GHSA-f7v3-rpm4-hwv2/GHSA-f7v3-rpm4-hwv2.json
+++ b/advisories/unreviewed/2023/10/GHSA-f7v3-rpm4-hwv2/GHSA-f7v3-rpm4-hwv2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7v3-rpm4-hwv2",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:41:38Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4776"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json b/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json
index 1caaa0b3bf0..87c859e74d7 100644
--- a/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json
+++ b/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f865-7gxm-95r4",
- "modified": "2023-10-30T15:30:44Z",
+ "modified": "2024-04-04T08:49:20Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-45394"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T04:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json b/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json
index ae60e9a05af..b8e80b34231 100644
--- a/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json
+++ b/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8h4-8cx8-j35m",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:29Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-36843"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-168"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f8xx-2rx5-fc4w/GHSA-f8xx-2rx5-fc4w.json b/advisories/unreviewed/2023/10/GHSA-f8xx-2rx5-fc4w/GHSA-f8xx-2rx5-fc4w.json
index c325cd4a4a3..45443306d9d 100644
--- a/advisories/unreviewed/2023/10/GHSA-f8xx-2rx5-fc4w/GHSA-f8xx-2rx5-fc4w.json
+++ b/advisories/unreviewed/2023/10/GHSA-f8xx-2rx5-fc4w/GHSA-f8xx-2rx5-fc4w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8xx-2rx5-fc4w",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:57Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39736"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f96p-9v3g-ffm4/GHSA-f96p-9v3g-ffm4.json b/advisories/unreviewed/2023/10/GHSA-f96p-9v3g-ffm4/GHSA-f96p-9v3g-ffm4.json
index 065448547b1..49941d125e4 100644
--- a/advisories/unreviewed/2023/10/GHSA-f96p-9v3g-ffm4/GHSA-f96p-9v3g-ffm4.json
+++ b/advisories/unreviewed/2023/10/GHSA-f96p-9v3g-ffm4/GHSA-f96p-9v3g-ffm4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f96p-9v3g-ffm4",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:13Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-44808"
],
"details": "D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f9cg-fxjq-h54m/GHSA-f9cg-fxjq-h54m.json b/advisories/unreviewed/2023/10/GHSA-f9cg-fxjq-h54m/GHSA-f9cg-fxjq-h54m.json
index 81f399da183..b2da4f6b555 100644
--- a/advisories/unreviewed/2023/10/GHSA-f9cg-fxjq-h54m/GHSA-f9cg-fxjq-h54m.json
+++ b/advisories/unreviewed/2023/10/GHSA-f9cg-fxjq-h54m/GHSA-f9cg-fxjq-h54m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f9cg-fxjq-h54m",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:32Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-42506"
],
"details": "Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-119"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-f9vm-fr8w-hm2v/GHSA-f9vm-fr8w-hm2v.json b/advisories/unreviewed/2023/10/GHSA-f9vm-fr8w-hm2v/GHSA-f9vm-fr8w-hm2v.json
index 2a1a2bb3e12..646d91c7814 100644
--- a/advisories/unreviewed/2023/10/GHSA-f9vm-fr8w-hm2v/GHSA-f9vm-fr8w-hm2v.json
+++ b/advisories/unreviewed/2023/10/GHSA-f9vm-fr8w-hm2v/GHSA-f9vm-fr8w-hm2v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f9vm-fr8w-hm2v",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:35Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-38127"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-190"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json b/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json
index d2e23354836..5a208d07910 100644
--- a/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json
+++ b/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc5f-gc6j-gfhf",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:42:04Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5177"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-209"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fc94-mp7c-xmpq/GHSA-fc94-mp7c-xmpq.json b/advisories/unreviewed/2023/10/GHSA-fc94-mp7c-xmpq/GHSA-fc94-mp7c-xmpq.json
index ae903a79134..2dc66d73f20 100644
--- a/advisories/unreviewed/2023/10/GHSA-fc94-mp7c-xmpq/GHSA-fc94-mp7c-xmpq.json
+++ b/advisories/unreviewed/2023/10/GHSA-fc94-mp7c-xmpq/GHSA-fc94-mp7c-xmpq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc94-mp7c-xmpq",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:38Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-3998"
@@ -35,7 +35,7 @@
"CWE-639",
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fcmv-m5pv-9mj4/GHSA-fcmv-m5pv-9mj4.json b/advisories/unreviewed/2023/10/GHSA-fcmv-m5pv-9mj4/GHSA-fcmv-m5pv-9mj4.json
index 5f98c5e7265..45c56a92ef6 100644
--- a/advisories/unreviewed/2023/10/GHSA-fcmv-m5pv-9mj4/GHSA-fcmv-m5pv-9mj4.json
+++ b/advisories/unreviewed/2023/10/GHSA-fcmv-m5pv-9mj4/GHSA-fcmv-m5pv-9mj4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcmv-m5pv-9mj4",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:55Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45638"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json
index cecce734c90..c32be7bcbc7 100644
--- a/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json
+++ b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcv4-fw97-74j9",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:22Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2022-34887"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:40Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ff5g-xv9r-r383/GHSA-ff5g-xv9r-r383.json b/advisories/unreviewed/2023/10/GHSA-ff5g-xv9r-r383/GHSA-ff5g-xv9r-r383.json
index fb7ff40f832..ea4acc9b7c5 100644
--- a/advisories/unreviewed/2023/10/GHSA-ff5g-xv9r-r383/GHSA-ff5g-xv9r-r383.json
+++ b/advisories/unreviewed/2023/10/GHSA-ff5g-xv9r-r383/GHSA-ff5g-xv9r-r383.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ff5g-xv9r-r383",
- "modified": "2023-10-16T06:32:22Z",
+ "modified": "2024-04-04T08:39:03Z",
"published": "2023-10-16T06:32:22Z",
"aliases": [
"CVE-2023-36340"
],
"details": "TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T05:15:49Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json b/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json
index 672c1cd8882..332f9163b66 100644
--- a/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json
+++ b/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffqm-rxh4-r75f",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:19Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2023-27170"
],
"details": "Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T23:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ffxw-phw3-h58r/GHSA-ffxw-phw3-h58r.json b/advisories/unreviewed/2023/10/GHSA-ffxw-phw3-h58r/GHSA-ffxw-phw3-h58r.json
index d93d252b637..fc31e8c3ba8 100644
--- a/advisories/unreviewed/2023/10/GHSA-ffxw-phw3-h58r/GHSA-ffxw-phw3-h58r.json
+++ b/advisories/unreviewed/2023/10/GHSA-ffxw-phw3-h58r/GHSA-ffxw-phw3-h58r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffxw-phw3-h58r",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:18Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44201"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-732"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fgvx-4256-89cx/GHSA-fgvx-4256-89cx.json b/advisories/unreviewed/2023/10/GHSA-fgvx-4256-89cx/GHSA-fgvx-4256-89cx.json
index 2786e72f9fb..a4e2553b4e6 100644
--- a/advisories/unreviewed/2023/10/GHSA-fgvx-4256-89cx/GHSA-fgvx-4256-89cx.json
+++ b/advisories/unreviewed/2023/10/GHSA-fgvx-4256-89cx/GHSA-fgvx-4256-89cx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgvx-4256-89cx",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:15Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28797"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-59"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fh5x-h6r2-7rvf/GHSA-fh5x-h6r2-7rvf.json b/advisories/unreviewed/2023/10/GHSA-fh5x-h6r2-7rvf/GHSA-fh5x-h6r2-7rvf.json
index 32d2ebde9b0..ce1e19d43ac 100644
--- a/advisories/unreviewed/2023/10/GHSA-fh5x-h6r2-7rvf/GHSA-fh5x-h6r2-7rvf.json
+++ b/advisories/unreviewed/2023/10/GHSA-fh5x-h6r2-7rvf/GHSA-fh5x-h6r2-7rvf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fh5x-h6r2-7rvf",
- "modified": "2023-10-26T15:30:26Z",
+ "modified": "2024-04-04T08:49:09Z",
"published": "2023-10-19T21:30:18Z",
"aliases": [
"CVE-2023-30132"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-326"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fhx9-p329-4x23/GHSA-fhx9-p329-4x23.json b/advisories/unreviewed/2023/10/GHSA-fhx9-p329-4x23/GHSA-fhx9-p329-4x23.json
index e87d6f48b87..16a92e2812b 100644
--- a/advisories/unreviewed/2023/10/GHSA-fhx9-p329-4x23/GHSA-fhx9-p329-4x23.json
+++ b/advisories/unreviewed/2023/10/GHSA-fhx9-p329-4x23/GHSA-fhx9-p329-4x23.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhx9-p329-4x23",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:49Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4919"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json b/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json
index 3ba0cd2d499..ab268a519e0 100644
--- a/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json
+++ b/advisories/unreviewed/2023/10/GHSA-fj34-c7pj-j8xq/GHSA-fj34-c7pj-j8xq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj34-c7pj-j8xq",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:46Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4805"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json
index 9b712fe03f2..278fef04153 100644
--- a/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json
+++ b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj49-xvp9-p96q",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:12Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2018-17558"
],
"details": "Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-798"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fjcg-2rqh-mpj3/GHSA-fjcg-2rqh-mpj3.json b/advisories/unreviewed/2023/10/GHSA-fjcg-2rqh-mpj3/GHSA-fjcg-2rqh-mpj3.json
index e957e9313af..614115b1546 100644
--- a/advisories/unreviewed/2023/10/GHSA-fjcg-2rqh-mpj3/GHSA-fjcg-2rqh-mpj3.json
+++ b/advisories/unreviewed/2023/10/GHSA-fjcg-2rqh-mpj3/GHSA-fjcg-2rqh-mpj3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fjcg-2rqh-mpj3",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:12Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26579"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-306"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fm3x-qgq6-7xmf/GHSA-fm3x-qgq6-7xmf.json b/advisories/unreviewed/2023/10/GHSA-fm3x-qgq6-7xmf/GHSA-fm3x-qgq6-7xmf.json
index edad1e83f31..ec5d090375b 100644
--- a/advisories/unreviewed/2023/10/GHSA-fm3x-qgq6-7xmf/GHSA-fm3x-qgq6-7xmf.json
+++ b/advisories/unreviewed/2023/10/GHSA-fm3x-qgq6-7xmf/GHSA-fm3x-qgq6-7xmf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fm3x-qgq6-7xmf",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:32Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2021-4335"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-285"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fm9q-gf87-g4h8/GHSA-fm9q-gf87-g4h8.json b/advisories/unreviewed/2023/10/GHSA-fm9q-gf87-g4h8/GHSA-fm9q-gf87-g4h8.json
index d8f3c8e4e2e..498244e3b97 100644
--- a/advisories/unreviewed/2023/10/GHSA-fm9q-gf87-g4h8/GHSA-fm9q-gf87-g4h8.json
+++ b/advisories/unreviewed/2023/10/GHSA-fm9q-gf87-g4h8/GHSA-fm9q-gf87-g4h8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fm9q-gf87-g4h8",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:26Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-34977"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fp27-qfpm-95w8/GHSA-fp27-qfpm-95w8.json b/advisories/unreviewed/2023/10/GHSA-fp27-qfpm-95w8/GHSA-fp27-qfpm-95w8.json
index 8c4a42eb7be..47337bcad98 100644
--- a/advisories/unreviewed/2023/10/GHSA-fp27-qfpm-95w8/GHSA-fp27-qfpm-95w8.json
+++ b/advisories/unreviewed/2023/10/GHSA-fp27-qfpm-95w8/GHSA-fp27-qfpm-95w8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fp27-qfpm-95w8",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:25Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-21415"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fp5c-vf9m-6gv3/GHSA-fp5c-vf9m-6gv3.json b/advisories/unreviewed/2023/10/GHSA-fp5c-vf9m-6gv3/GHSA-fp5c-vf9m-6gv3.json
index 1e004026dd0..8ab1e9189d1 100644
--- a/advisories/unreviewed/2023/10/GHSA-fp5c-vf9m-6gv3/GHSA-fp5c-vf9m-6gv3.json
+++ b/advisories/unreviewed/2023/10/GHSA-fp5c-vf9m-6gv3/GHSA-fp5c-vf9m-6gv3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fp5c-vf9m-6gv3",
- "modified": "2023-10-26T18:30:22Z",
+ "modified": "2024-04-04T08:49:30Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2020-36706"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fq23-mhmq-5hc5/GHSA-fq23-mhmq-5hc5.json b/advisories/unreviewed/2023/10/GHSA-fq23-mhmq-5hc5/GHSA-fq23-mhmq-5hc5.json
index a162f404e5c..6e109b17c97 100644
--- a/advisories/unreviewed/2023/10/GHSA-fq23-mhmq-5hc5/GHSA-fq23-mhmq-5hc5.json
+++ b/advisories/unreviewed/2023/10/GHSA-fq23-mhmq-5hc5/GHSA-fq23-mhmq-5hc5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq23-mhmq-5hc5",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:44Z",
"published": "2023-10-26T12:31:07Z",
"aliases": [
"CVE-2023-5802"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T12:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json b/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json
index c9e2e0860ad..ba07172bf2e 100644
--- a/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json
+++ b/advisories/unreviewed/2023/10/GHSA-fq72-4xq4-w8hg/GHSA-fq72-4xq4-w8hg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq72-4xq4-w8hg",
- "modified": "2023-10-26T21:30:22Z",
+ "modified": "2024-04-04T08:57:04Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-46664"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-284"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T21:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json b/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json
index e7ed9a38339..10018117b31 100644
--- a/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json
+++ b/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq8c-93h2-hrr9",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:51:00Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5109"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fqv5-4rc8-87p9/GHSA-fqv5-4rc8-87p9.json b/advisories/unreviewed/2023/10/GHSA-fqv5-4rc8-87p9/GHSA-fqv5-4rc8-87p9.json
index f00d25b2e57..926d1121eee 100644
--- a/advisories/unreviewed/2023/10/GHSA-fqv5-4rc8-87p9/GHSA-fqv5-4rc8-87p9.json
+++ b/advisories/unreviewed/2023/10/GHSA-fqv5-4rc8-87p9/GHSA-fqv5-4rc8-87p9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqv5-4rc8-87p9",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:51Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45057"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fr4c-rcw2-hh8p/GHSA-fr4c-rcw2-hh8p.json b/advisories/unreviewed/2023/10/GHSA-fr4c-rcw2-hh8p/GHSA-fr4c-rcw2-hh8p.json
index 0b320c71f57..7dfc7c9dbb2 100644
--- a/advisories/unreviewed/2023/10/GHSA-fr4c-rcw2-hh8p/GHSA-fr4c-rcw2-hh8p.json
+++ b/advisories/unreviewed/2023/10/GHSA-fr4c-rcw2-hh8p/GHSA-fr4c-rcw2-hh8p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr4c-rcw2-hh8p",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:54Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45393"
],
"details": "An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-639"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fr4f-6grf-fhqw/GHSA-fr4f-6grf-fhqw.json b/advisories/unreviewed/2023/10/GHSA-fr4f-6grf-fhqw/GHSA-fr4f-6grf-fhqw.json
index c54423f5b35..1d7af3a55b6 100644
--- a/advisories/unreviewed/2023/10/GHSA-fr4f-6grf-fhqw/GHSA-fr4f-6grf-fhqw.json
+++ b/advisories/unreviewed/2023/10/GHSA-fr4f-6grf-fhqw/GHSA-fr4f-6grf-fhqw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr4f-6grf-fhqw",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:53Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4940"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-frhp-4qgh-c626/GHSA-frhp-4qgh-c626.json b/advisories/unreviewed/2023/10/GHSA-frhp-4qgh-c626/GHSA-frhp-4qgh-c626.json
index 061e4184a4e..5b552b0c96f 100644
--- a/advisories/unreviewed/2023/10/GHSA-frhp-4qgh-c626/GHSA-frhp-4qgh-c626.json
+++ b/advisories/unreviewed/2023/10/GHSA-frhp-4qgh-c626/GHSA-frhp-4qgh-c626.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frhp-4qgh-c626",
- "modified": "2023-10-19T00:30:19Z",
+ "modified": "2024-04-04T08:46:48Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-45909"
],
"details": "zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-601"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T23:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fvrc-4g4c-396g/GHSA-fvrc-4g4c-396g.json b/advisories/unreviewed/2023/10/GHSA-fvrc-4g4c-396g/GHSA-fvrc-4g4c-396g.json
index a0f4617cd72..6195ee7ba57 100644
--- a/advisories/unreviewed/2023/10/GHSA-fvrc-4g4c-396g/GHSA-fvrc-4g4c-396g.json
+++ b/advisories/unreviewed/2023/10/GHSA-fvrc-4g4c-396g/GHSA-fvrc-4g4c-396g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvrc-4g4c-396g",
- "modified": "2023-10-19T18:30:27Z",
+ "modified": "2024-04-04T08:39:31Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-45578"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fwh4-pm54-qx88/GHSA-fwh4-pm54-qx88.json b/advisories/unreviewed/2023/10/GHSA-fwh4-pm54-qx88/GHSA-fwh4-pm54-qx88.json
index de1bed5d035..58ce1e50929 100644
--- a/advisories/unreviewed/2023/10/GHSA-fwh4-pm54-qx88/GHSA-fwh4-pm54-qx88.json
+++ b/advisories/unreviewed/2023/10/GHSA-fwh4-pm54-qx88/GHSA-fwh4-pm54-qx88.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwh4-pm54-qx88",
- "modified": "2023-10-12T00:30:28Z",
+ "modified": "2024-04-04T08:35:03Z",
"published": "2023-10-12T00:30:28Z",
"aliases": [
"CVE-2023-44189"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-346"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fwj5-xh52-x3wv/GHSA-fwj5-xh52-x3wv.json b/advisories/unreviewed/2023/10/GHSA-fwj5-xh52-x3wv/GHSA-fwj5-xh52-x3wv.json
index f0cfedafa53..abd594639e9 100644
--- a/advisories/unreviewed/2023/10/GHSA-fwj5-xh52-x3wv/GHSA-fwj5-xh52-x3wv.json
+++ b/advisories/unreviewed/2023/10/GHSA-fwj5-xh52-x3wv/GHSA-fwj5-xh52-x3wv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwj5-xh52-x3wv",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:41Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22107"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-fx4r-ccm6-2q6f/GHSA-fx4r-ccm6-2q6f.json b/advisories/unreviewed/2023/10/GHSA-fx4r-ccm6-2q6f/GHSA-fx4r-ccm6-2q6f.json
index 5f35eb393ab..01b8e511439 100644
--- a/advisories/unreviewed/2023/10/GHSA-fx4r-ccm6-2q6f/GHSA-fx4r-ccm6-2q6f.json
+++ b/advisories/unreviewed/2023/10/GHSA-fx4r-ccm6-2q6f/GHSA-fx4r-ccm6-2q6f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fx4r-ccm6-2q6f",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:36Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26582"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g28m-wpc6-78c8/GHSA-g28m-wpc6-78c8.json b/advisories/unreviewed/2023/10/GHSA-g28m-wpc6-78c8/GHSA-g28m-wpc6-78c8.json
index af3b124d4be..4ca29bb073d 100644
--- a/advisories/unreviewed/2023/10/GHSA-g28m-wpc6-78c8/GHSA-g28m-wpc6-78c8.json
+++ b/advisories/unreviewed/2023/10/GHSA-g28m-wpc6-78c8/GHSA-g28m-wpc6-78c8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g28m-wpc6-78c8",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:45:17Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-39278"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g3px-65r8-wfgx/GHSA-g3px-65r8-wfgx.json b/advisories/unreviewed/2023/10/GHSA-g3px-65r8-wfgx/GHSA-g3px-65r8-wfgx.json
index 71ffb178f33..e7ed0c1d481 100644
--- a/advisories/unreviewed/2023/10/GHSA-g3px-65r8-wfgx/GHSA-g3px-65r8-wfgx.json
+++ b/advisories/unreviewed/2023/10/GHSA-g3px-65r8-wfgx/GHSA-g3px-65r8-wfgx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3px-65r8-wfgx",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:22Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2020-36759"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g47w-cvcq-qh23/GHSA-g47w-cvcq-qh23.json b/advisories/unreviewed/2023/10/GHSA-g47w-cvcq-qh23/GHSA-g47w-cvcq-qh23.json
index c014ccdc450..1ea29c97ebb 100644
--- a/advisories/unreviewed/2023/10/GHSA-g47w-cvcq-qh23/GHSA-g47w-cvcq-qh23.json
+++ b/advisories/unreviewed/2023/10/GHSA-g47w-cvcq-qh23/GHSA-g47w-cvcq-qh23.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g47w-cvcq-qh23",
- "modified": "2023-10-12T09:30:26Z",
+ "modified": "2024-04-04T08:35:12Z",
"published": "2023-10-12T09:30:26Z",
"aliases": [
"CVE-2023-32722"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T07:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g49j-6p9j-4r5c/GHSA-g49j-6p9j-4r5c.json b/advisories/unreviewed/2023/10/GHSA-g49j-6p9j-4r5c/GHSA-g49j-6p9j-4r5c.json
index ea67d1ced2e..40cbda2560d 100644
--- a/advisories/unreviewed/2023/10/GHSA-g49j-6p9j-4r5c/GHSA-g49j-6p9j-4r5c.json
+++ b/advisories/unreviewed/2023/10/GHSA-g49j-6p9j-4r5c/GHSA-g49j-6p9j-4r5c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g49j-6p9j-4r5c",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:31Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45063"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g4j5-f2j8-q53j/GHSA-g4j5-f2j8-q53j.json b/advisories/unreviewed/2023/10/GHSA-g4j5-f2j8-q53j/GHSA-g4j5-f2j8-q53j.json
index 9d38a1711a1..4067df6b484 100644
--- a/advisories/unreviewed/2023/10/GHSA-g4j5-f2j8-q53j/GHSA-g4j5-f2j8-q53j.json
+++ b/advisories/unreviewed/2023/10/GHSA-g4j5-f2j8-q53j/GHSA-g4j5-f2j8-q53j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4j5-f2j8-q53j",
- "modified": "2023-10-20T12:31:01Z",
+ "modified": "2024-04-04T08:42:06Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-40851"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T21:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g574-v9wx-6x2q/GHSA-g574-v9wx-6x2q.json b/advisories/unreviewed/2023/10/GHSA-g574-v9wx-6x2q/GHSA-g574-v9wx-6x2q.json
index a8479cfade9..edb0dd1e8c8 100644
--- a/advisories/unreviewed/2023/10/GHSA-g574-v9wx-6x2q/GHSA-g574-v9wx-6x2q.json
+++ b/advisories/unreviewed/2023/10/GHSA-g574-v9wx-6x2q/GHSA-g574-v9wx-6x2q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g574-v9wx-6x2q",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:47:55Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-45384"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g6cq-79gq-xhxv/GHSA-g6cq-79gq-xhxv.json b/advisories/unreviewed/2023/10/GHSA-g6cq-79gq-xhxv/GHSA-g6cq-79gq-xhxv.json
index f03de878eda..ad9914fd061 100644
--- a/advisories/unreviewed/2023/10/GHSA-g6cq-79gq-xhxv/GHSA-g6cq-79gq-xhxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-g6cq-79gq-xhxv/GHSA-g6cq-79gq-xhxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6cq-79gq-xhxv",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:43:52Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22072"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json b/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json
index 0bfad6d506b..48f49514b73 100644
--- a/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json
+++ b/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7rr-rj9q-jfww",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:24Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45555"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g8cv-hhj5-2rjx/GHSA-g8cv-hhj5-2rjx.json b/advisories/unreviewed/2023/10/GHSA-g8cv-hhj5-2rjx/GHSA-g8cv-hhj5-2rjx.json
index c66670abba9..22101fbfed0 100644
--- a/advisories/unreviewed/2023/10/GHSA-g8cv-hhj5-2rjx/GHSA-g8cv-hhj5-2rjx.json
+++ b/advisories/unreviewed/2023/10/GHSA-g8cv-hhj5-2rjx/GHSA-g8cv-hhj5-2rjx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8cv-hhj5-2rjx",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:54Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5070"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g92q-cp9m-6xg3/GHSA-g92q-cp9m-6xg3.json b/advisories/unreviewed/2023/10/GHSA-g92q-cp9m-6xg3/GHSA-g92q-cp9m-6xg3.json
index 3c57bea55a6..63fed2340d1 100644
--- a/advisories/unreviewed/2023/10/GHSA-g92q-cp9m-6xg3/GHSA-g92q-cp9m-6xg3.json
+++ b/advisories/unreviewed/2023/10/GHSA-g92q-cp9m-6xg3/GHSA-g92q-cp9m-6xg3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g92q-cp9m-6xg3",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:48:29Z",
"published": "2023-10-19T18:30:30Z",
"aliases": [
"CVE-2023-45281"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g95v-666p-2m3x/GHSA-g95v-666p-2m3x.json b/advisories/unreviewed/2023/10/GHSA-g95v-666p-2m3x/GHSA-g95v-666p-2m3x.json
index 9a73406ce36..f07c7875c7a 100644
--- a/advisories/unreviewed/2023/10/GHSA-g95v-666p-2m3x/GHSA-g95v-666p-2m3x.json
+++ b/advisories/unreviewed/2023/10/GHSA-g95v-666p-2m3x/GHSA-g95v-666p-2m3x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g95v-666p-2m3x",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:17Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-3991"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g978-26j8-v9jj/GHSA-g978-26j8-v9jj.json b/advisories/unreviewed/2023/10/GHSA-g978-26j8-v9jj/GHSA-g978-26j8-v9jj.json
index f3ab9e53a0c..4cd0672dc0d 100644
--- a/advisories/unreviewed/2023/10/GHSA-g978-26j8-v9jj/GHSA-g978-26j8-v9jj.json
+++ b/advisories/unreviewed/2023/10/GHSA-g978-26j8-v9jj/GHSA-g978-26j8-v9jj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g978-26j8-v9jj",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:37Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-45358"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json b/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json
index dc5d6d564c2..383212e5bbf 100644
--- a/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json
+++ b/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g99m-655w-j95w",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:59Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28793"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g9fr-v3jx-9jph/GHSA-g9fr-v3jx-9jph.json b/advisories/unreviewed/2023/10/GHSA-g9fr-v3jx-9jph/GHSA-g9fr-v3jx-9jph.json
index c7b935cad62..c61545fa2e9 100644
--- a/advisories/unreviewed/2023/10/GHSA-g9fr-v3jx-9jph/GHSA-g9fr-v3jx-9jph.json
+++ b/advisories/unreviewed/2023/10/GHSA-g9fr-v3jx-9jph/GHSA-g9fr-v3jx-9jph.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9fr-v3jx-9jph",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:46:47Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-37502"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T23:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-g9r5-p2qr-8f4f/GHSA-g9r5-p2qr-8f4f.json b/advisories/unreviewed/2023/10/GHSA-g9r5-p2qr-8f4f/GHSA-g9r5-p2qr-8f4f.json
index 9a327d1bc47..41c8285defd 100644
--- a/advisories/unreviewed/2023/10/GHSA-g9r5-p2qr-8f4f/GHSA-g9r5-p2qr-8f4f.json
+++ b/advisories/unreviewed/2023/10/GHSA-g9r5-p2qr-8f4f/GHSA-g9r5-p2qr-8f4f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9r5-p2qr-8f4f",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:43Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45107"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gc74-6h94-8cfj/GHSA-gc74-6h94-8cfj.json b/advisories/unreviewed/2023/10/GHSA-gc74-6h94-8cfj/GHSA-gc74-6h94-8cfj.json
index 2383b3aae0c..6c188405883 100644
--- a/advisories/unreviewed/2023/10/GHSA-gc74-6h94-8cfj/GHSA-gc74-6h94-8cfj.json
+++ b/advisories/unreviewed/2023/10/GHSA-gc74-6h94-8cfj/GHSA-gc74-6h94-8cfj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc74-6h94-8cfj",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:46Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-46081"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gc7q-964p-3f2q/GHSA-gc7q-964p-3f2q.json b/advisories/unreviewed/2023/10/GHSA-gc7q-964p-3f2q/GHSA-gc7q-964p-3f2q.json
index 2d5bc6d6053..f429fa06fab 100644
--- a/advisories/unreviewed/2023/10/GHSA-gc7q-964p-3f2q/GHSA-gc7q-964p-3f2q.json
+++ b/advisories/unreviewed/2023/10/GHSA-gc7q-964p-3f2q/GHSA-gc7q-964p-3f2q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc7q-964p-3f2q",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:39Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-44986"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gg84-68cr-5wgm/GHSA-gg84-68cr-5wgm.json b/advisories/unreviewed/2023/10/GHSA-gg84-68cr-5wgm/GHSA-gg84-68cr-5wgm.json
index 8cdd8ac931a..f7cda21ca28 100644
--- a/advisories/unreviewed/2023/10/GHSA-gg84-68cr-5wgm/GHSA-gg84-68cr-5wgm.json
+++ b/advisories/unreviewed/2023/10/GHSA-gg84-68cr-5wgm/GHSA-gg84-68cr-5wgm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg84-68cr-5wgm",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:52Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44191"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-770"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ggq5-xv35-rxhf/GHSA-ggq5-xv35-rxhf.json b/advisories/unreviewed/2023/10/GHSA-ggq5-xv35-rxhf/GHSA-ggq5-xv35-rxhf.json
index 3cf3dbd0039..8048088ffe2 100644
--- a/advisories/unreviewed/2023/10/GHSA-ggq5-xv35-rxhf/GHSA-ggq5-xv35-rxhf.json
+++ b/advisories/unreviewed/2023/10/GHSA-ggq5-xv35-rxhf/GHSA-ggq5-xv35-rxhf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggq5-xv35-rxhf",
- "modified": "2023-10-13T12:30:16Z",
+ "modified": "2024-04-04T08:37:38Z",
"published": "2023-10-13T12:30:16Z",
"aliases": [
"CVE-2023-38000"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ggr8-3hwx-4f2m/GHSA-ggr8-3hwx-4f2m.json b/advisories/unreviewed/2023/10/GHSA-ggr8-3hwx-4f2m/GHSA-ggr8-3hwx-4f2m.json
index 86251f7d484..a0b7f141ec2 100644
--- a/advisories/unreviewed/2023/10/GHSA-ggr8-3hwx-4f2m/GHSA-ggr8-3hwx-4f2m.json
+++ b/advisories/unreviewed/2023/10/GHSA-ggr8-3hwx-4f2m/GHSA-ggr8-3hwx-4f2m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggr8-3hwx-4f2m",
- "modified": "2023-10-13T09:30:22Z",
+ "modified": "2024-04-04T08:37:32Z",
"published": "2023-10-13T09:30:22Z",
"aliases": [
"CVE-2023-38221"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:40Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ggrv-94gh-qf9g/GHSA-ggrv-94gh-qf9g.json b/advisories/unreviewed/2023/10/GHSA-ggrv-94gh-qf9g/GHSA-ggrv-94gh-qf9g.json
index 02ebe0bcb85..ed0826a3831 100644
--- a/advisories/unreviewed/2023/10/GHSA-ggrv-94gh-qf9g/GHSA-ggrv-94gh-qf9g.json
+++ b/advisories/unreviewed/2023/10/GHSA-ggrv-94gh-qf9g/GHSA-ggrv-94gh-qf9g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggrv-94gh-qf9g",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:07Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-45268"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json b/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json
index 696d804472f..bb3cbdd90a1 100644
--- a/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json
+++ b/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh52-2rq4-cqx2",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:15Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46535"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ghc9-27wr-4w58/GHSA-ghc9-27wr-4w58.json b/advisories/unreviewed/2023/10/GHSA-ghc9-27wr-4w58/GHSA-ghc9-27wr-4w58.json
index c5c73366225..b281396cac9 100644
--- a/advisories/unreviewed/2023/10/GHSA-ghc9-27wr-4w58/GHSA-ghc9-27wr-4w58.json
+++ b/advisories/unreviewed/2023/10/GHSA-ghc9-27wr-4w58/GHSA-ghc9-27wr-4w58.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghc9-27wr-4w58",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:09Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44196"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-754"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json
index 4456df70a8b..6afb3dcc3f8 100644
--- a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json
+++ b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghvx-5v39-7hv5",
- "modified": "2023-10-30T15:30:44Z",
+ "modified": "2024-04-04T08:49:21Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-34051"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-863"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T05:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gj95-8384-wrh5/GHSA-gj95-8384-wrh5.json b/advisories/unreviewed/2023/10/GHSA-gj95-8384-wrh5/GHSA-gj95-8384-wrh5.json
index 72aac301d0b..a3319e1e318 100644
--- a/advisories/unreviewed/2023/10/GHSA-gj95-8384-wrh5/GHSA-gj95-8384-wrh5.json
+++ b/advisories/unreviewed/2023/10/GHSA-gj95-8384-wrh5/GHSA-gj95-8384-wrh5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gj95-8384-wrh5",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:20Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-22380"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-295"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gjv4-9pfg-rv2p/GHSA-gjv4-9pfg-rv2p.json b/advisories/unreviewed/2023/10/GHSA-gjv4-9pfg-rv2p/GHSA-gjv4-9pfg-rv2p.json
index 97dcf483ce7..8e634b7ef06 100644
--- a/advisories/unreviewed/2023/10/GHSA-gjv4-9pfg-rv2p/GHSA-gjv4-9pfg-rv2p.json
+++ b/advisories/unreviewed/2023/10/GHSA-gjv4-9pfg-rv2p/GHSA-gjv4-9pfg-rv2p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjv4-9pfg-rv2p",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:20Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45902"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json b/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json
index d7ea8686305..5aff617794e 100644
--- a/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json
+++ b/advisories/unreviewed/2023/10/GHSA-gprh-65m4-pxq9/GHSA-gprh-65m4-pxq9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gprh-65m4-pxq9",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:54Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39734"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gq43-3jqj-7h4q/GHSA-gq43-3jqj-7h4q.json b/advisories/unreviewed/2023/10/GHSA-gq43-3jqj-7h4q/GHSA-gq43-3jqj-7h4q.json
index c29ef8e6251..db1c349642d 100644
--- a/advisories/unreviewed/2023/10/GHSA-gq43-3jqj-7h4q/GHSA-gq43-3jqj-7h4q.json
+++ b/advisories/unreviewed/2023/10/GHSA-gq43-3jqj-7h4q/GHSA-gq43-3jqj-7h4q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gq43-3jqj-7h4q",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:47Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22105"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gq92-gmhv-53v8/GHSA-gq92-gmhv-53v8.json b/advisories/unreviewed/2023/10/GHSA-gq92-gmhv-53v8/GHSA-gq92-gmhv-53v8.json
index f7813c953d9..c96174b0a33 100644
--- a/advisories/unreviewed/2023/10/GHSA-gq92-gmhv-53v8/GHSA-gq92-gmhv-53v8.json
+++ b/advisories/unreviewed/2023/10/GHSA-gq92-gmhv-53v8/GHSA-gq92-gmhv-53v8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gq92-gmhv-53v8",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:53:49Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2022-38485"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gqc6-p5c3-q963/GHSA-gqc6-p5c3-q963.json b/advisories/unreviewed/2023/10/GHSA-gqc6-p5c3-q963/GHSA-gqc6-p5c3-q963.json
index e1276c087ee..2e88134180c 100644
--- a/advisories/unreviewed/2023/10/GHSA-gqc6-p5c3-q963/GHSA-gqc6-p5c3-q963.json
+++ b/advisories/unreviewed/2023/10/GHSA-gqc6-p5c3-q963/GHSA-gqc6-p5c3-q963.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqc6-p5c3-q963",
- "modified": "2023-10-25T18:32:22Z",
+ "modified": "2024-04-04T08:54:43Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39231"
@@ -35,7 +35,7 @@
"CWE-288",
"CWE-306"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gqww-mmf9-7x23/GHSA-gqww-mmf9-7x23.json b/advisories/unreviewed/2023/10/GHSA-gqww-mmf9-7x23/GHSA-gqww-mmf9-7x23.json
index 85373913503..3b8bf9160ba 100644
--- a/advisories/unreviewed/2023/10/GHSA-gqww-mmf9-7x23/GHSA-gqww-mmf9-7x23.json
+++ b/advisories/unreviewed/2023/10/GHSA-gqww-mmf9-7x23/GHSA-gqww-mmf9-7x23.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqww-mmf9-7x23",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:19Z",
"published": "2023-10-20T12:31:04Z",
"aliases": [
"CVE-2023-34045"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T10:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gr46-9pmg-323c/GHSA-gr46-9pmg-323c.json b/advisories/unreviewed/2023/10/GHSA-gr46-9pmg-323c/GHSA-gr46-9pmg-323c.json
index 50992ed11c8..e15d38b272f 100644
--- a/advisories/unreviewed/2023/10/GHSA-gr46-9pmg-323c/GHSA-gr46-9pmg-323c.json
+++ b/advisories/unreviewed/2023/10/GHSA-gr46-9pmg-323c/GHSA-gr46-9pmg-323c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gr46-9pmg-323c",
- "modified": "2023-10-25T18:32:19Z",
+ "modified": "2024-04-04T08:46:05Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-31217"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-grc6-r6f8-xj7c/GHSA-grc6-r6f8-xj7c.json b/advisories/unreviewed/2023/10/GHSA-grc6-r6f8-xj7c/GHSA-grc6-r6f8-xj7c.json
index 9aa451dbb3c..b0672b5633b 100644
--- a/advisories/unreviewed/2023/10/GHSA-grc6-r6f8-xj7c/GHSA-grc6-r6f8-xj7c.json
+++ b/advisories/unreviewed/2023/10/GHSA-grc6-r6f8-xj7c/GHSA-grc6-r6f8-xj7c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grc6-r6f8-xj7c",
- "modified": "2023-10-13T09:30:22Z",
+ "modified": "2024-04-04T08:37:29Z",
"published": "2023-10-13T09:30:22Z",
"aliases": [
"CVE-2023-38220"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-285"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:40Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-grfg-rxx4-pppc/GHSA-grfg-rxx4-pppc.json b/advisories/unreviewed/2023/10/GHSA-grfg-rxx4-pppc/GHSA-grfg-rxx4-pppc.json
index 1de00defcc2..c6ed1808116 100644
--- a/advisories/unreviewed/2023/10/GHSA-grfg-rxx4-pppc/GHSA-grfg-rxx4-pppc.json
+++ b/advisories/unreviewed/2023/10/GHSA-grfg-rxx4-pppc/GHSA-grfg-rxx4-pppc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grfg-rxx4-pppc",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:52Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45831"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:45Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-grgw-cqmv-xp2v/GHSA-grgw-cqmv-xp2v.json b/advisories/unreviewed/2023/10/GHSA-grgw-cqmv-xp2v/GHSA-grgw-cqmv-xp2v.json
index 76cf7a9481b..44195e68d12 100644
--- a/advisories/unreviewed/2023/10/GHSA-grgw-cqmv-xp2v/GHSA-grgw-cqmv-xp2v.json
+++ b/advisories/unreviewed/2023/10/GHSA-grgw-cqmv-xp2v/GHSA-grgw-cqmv-xp2v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grgw-cqmv-xp2v",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:37Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2022-2441"
@@ -50,7 +50,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-grvj-w989-52pr/GHSA-grvj-w989-52pr.json b/advisories/unreviewed/2023/10/GHSA-grvj-w989-52pr/GHSA-grvj-w989-52pr.json
index 627e8f5b8d9..1b52dcab45f 100644
--- a/advisories/unreviewed/2023/10/GHSA-grvj-w989-52pr/GHSA-grvj-w989-52pr.json
+++ b/advisories/unreviewed/2023/10/GHSA-grvj-w989-52pr/GHSA-grvj-w989-52pr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grvj-w989-52pr",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:31Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45645"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json b/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json
index 1265f647d50..6a2146be42f 100644
--- a/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json
+++ b/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gx5h-6g66-6r78",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:26Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4290"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-gxg6-4mhh-v28x/GHSA-gxg6-4mhh-v28x.json b/advisories/unreviewed/2023/10/GHSA-gxg6-4mhh-v28x/GHSA-gxg6-4mhh-v28x.json
index 8b85c474528..e5e91399170 100644
--- a/advisories/unreviewed/2023/10/GHSA-gxg6-4mhh-v28x/GHSA-gxg6-4mhh-v28x.json
+++ b/advisories/unreviewed/2023/10/GHSA-gxg6-4mhh-v28x/GHSA-gxg6-4mhh-v28x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxg6-4mhh-v28x",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:50Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4926"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h223-ghxp-jcj3/GHSA-h223-ghxp-jcj3.json b/advisories/unreviewed/2023/10/GHSA-h223-ghxp-jcj3/GHSA-h223-ghxp-jcj3.json
index 72519293f32..cd2787e3628 100644
--- a/advisories/unreviewed/2023/10/GHSA-h223-ghxp-jcj3/GHSA-h223-ghxp-jcj3.json
+++ b/advisories/unreviewed/2023/10/GHSA-h223-ghxp-jcj3/GHSA-h223-ghxp-jcj3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h223-ghxp-jcj3",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:48Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-42435"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h2q7-whv7-5m3x/GHSA-h2q7-whv7-5m3x.json b/advisories/unreviewed/2023/10/GHSA-h2q7-whv7-5m3x/GHSA-h2q7-whv7-5m3x.json
index 6a0f65f974b..011e9b3bdd9 100644
--- a/advisories/unreviewed/2023/10/GHSA-h2q7-whv7-5m3x/GHSA-h2q7-whv7-5m3x.json
+++ b/advisories/unreviewed/2023/10/GHSA-h2q7-whv7-5m3x/GHSA-h2q7-whv7-5m3x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2q7-whv7-5m3x",
- "modified": "2023-10-26T18:30:22Z",
+ "modified": "2024-04-04T08:49:25Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-40361"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-732"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T06:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h35v-vvv3-ww3x/GHSA-h35v-vvv3-ww3x.json b/advisories/unreviewed/2023/10/GHSA-h35v-vvv3-ww3x/GHSA-h35v-vvv3-ww3x.json
index dc55cf9a065..632e75c0591 100644
--- a/advisories/unreviewed/2023/10/GHSA-h35v-vvv3-ww3x/GHSA-h35v-vvv3-ww3x.json
+++ b/advisories/unreviewed/2023/10/GHSA-h35v-vvv3-ww3x/GHSA-h35v-vvv3-ww3x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h35v-vvv3-ww3x",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:20Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-30781"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h3g9-cwr6-hphx/GHSA-h3g9-cwr6-hphx.json b/advisories/unreviewed/2023/10/GHSA-h3g9-cwr6-hphx/GHSA-h3g9-cwr6-hphx.json
index e505339bb1a..c3ac185731e 100644
--- a/advisories/unreviewed/2023/10/GHSA-h3g9-cwr6-hphx/GHSA-h3g9-cwr6-hphx.json
+++ b/advisories/unreviewed/2023/10/GHSA-h3g9-cwr6-hphx/GHSA-h3g9-cwr6-hphx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3g9-cwr6-hphx",
- "modified": "2023-10-13T09:30:23Z",
+ "modified": "2024-04-04T08:37:35Z",
"published": "2023-10-13T09:30:23Z",
"aliases": [
"CVE-2023-38250"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h3vv-x3m8-whmj/GHSA-h3vv-x3m8-whmj.json b/advisories/unreviewed/2023/10/GHSA-h3vv-x3m8-whmj/GHSA-h3vv-x3m8-whmj.json
index ef67ae40a28..f99cee8fe50 100644
--- a/advisories/unreviewed/2023/10/GHSA-h3vv-x3m8-whmj/GHSA-h3vv-x3m8-whmj.json
+++ b/advisories/unreviewed/2023/10/GHSA-h3vv-x3m8-whmj/GHSA-h3vv-x3m8-whmj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3vv-x3m8-whmj",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:34Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-34366"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json b/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json
index 65724d26eea..0aeb3d7a9a3 100644
--- a/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json
+++ b/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h43q-h523-j594",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:33Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46560"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h4vh-xjqq-7hrh/GHSA-h4vh-xjqq-7hrh.json b/advisories/unreviewed/2023/10/GHSA-h4vh-xjqq-7hrh/GHSA-h4vh-xjqq-7hrh.json
index 248ec100b05..c9d1a2cf8ed 100644
--- a/advisories/unreviewed/2023/10/GHSA-h4vh-xjqq-7hrh/GHSA-h4vh-xjqq-7hrh.json
+++ b/advisories/unreviewed/2023/10/GHSA-h4vh-xjqq-7hrh/GHSA-h4vh-xjqq-7hrh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4vh-xjqq-7hrh",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:34Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-44984"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h5pw-9677-4hqp/GHSA-h5pw-9677-4hqp.json b/advisories/unreviewed/2023/10/GHSA-h5pw-9677-4hqp/GHSA-h5pw-9677-4hqp.json
index e31bdb03f2a..bbf99d76ada 100644
--- a/advisories/unreviewed/2023/10/GHSA-h5pw-9677-4hqp/GHSA-h5pw-9677-4hqp.json
+++ b/advisories/unreviewed/2023/10/GHSA-h5pw-9677-4hqp/GHSA-h5pw-9677-4hqp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5pw-9677-4hqp",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:18Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26583"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h6p5-xfhf-88h8/GHSA-h6p5-xfhf-88h8.json b/advisories/unreviewed/2023/10/GHSA-h6p5-xfhf-88h8/GHSA-h6p5-xfhf-88h8.json
index 83e51bd0855..e6482439bff 100644
--- a/advisories/unreviewed/2023/10/GHSA-h6p5-xfhf-88h8/GHSA-h6p5-xfhf-88h8.json
+++ b/advisories/unreviewed/2023/10/GHSA-h6p5-xfhf-88h8/GHSA-h6p5-xfhf-88h8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6p5-xfhf-88h8",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:17Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-24404"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-353",
"CWE-354"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json b/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json
index 1fc2de78e45..10890c9f563 100644
--- a/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json
+++ b/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7m2-v987-3v73",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:36Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40123"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h7x8-97pc-7qrv/GHSA-h7x8-97pc-7qrv.json b/advisories/unreviewed/2023/10/GHSA-h7x8-97pc-7qrv/GHSA-h7x8-97pc-7qrv.json
index f463efd6f62..085bb4f98cd 100644
--- a/advisories/unreviewed/2023/10/GHSA-h7x8-97pc-7qrv/GHSA-h7x8-97pc-7qrv.json
+++ b/advisories/unreviewed/2023/10/GHSA-h7x8-97pc-7qrv/GHSA-h7x8-97pc-7qrv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7x8-97pc-7qrv",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:12Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28804"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-347"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json b/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json
index 2d39b2ec47f..10b312145d6 100644
--- a/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json
+++ b/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h87j-f78f-m3fm",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:04Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26573"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h8wx-v5rf-mxrf/GHSA-h8wx-v5rf-mxrf.json b/advisories/unreviewed/2023/10/GHSA-h8wx-v5rf-mxrf/GHSA-h8wx-v5rf-mxrf.json
index 2c436e0b3ec..f23241814a3 100644
--- a/advisories/unreviewed/2023/10/GHSA-h8wx-v5rf-mxrf/GHSA-h8wx-v5rf-mxrf.json
+++ b/advisories/unreviewed/2023/10/GHSA-h8wx-v5rf-mxrf/GHSA-h8wx-v5rf-mxrf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8wx-v5rf-mxrf",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:39Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-39431"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h9fc-752h-284m/GHSA-h9fc-752h-284m.json b/advisories/unreviewed/2023/10/GHSA-h9fc-752h-284m/GHSA-h9fc-752h-284m.json
index 2db2a0ee404..3e6ecf478a8 100644
--- a/advisories/unreviewed/2023/10/GHSA-h9fc-752h-284m/GHSA-h9fc-752h-284m.json
+++ b/advisories/unreviewed/2023/10/GHSA-h9fc-752h-284m/GHSA-h9fc-752h-284m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9fc-752h-284m",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:10Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-41681"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json b/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json
index cec4f62cd9d..ae545b593c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json
+++ b/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9gw-q7wq-vrfv",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:30Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4643"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json b/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json
index 578716db079..3f61c0306da 100644
--- a/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json
+++ b/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9p2-g8w7-8363",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:33Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40125"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hch9-gprw-2g9j/GHSA-hch9-gprw-2g9j.json b/advisories/unreviewed/2023/10/GHSA-hch9-gprw-2g9j/GHSA-hch9-gprw-2g9j.json
index 8cc641dbe93..e68c0ca99c6 100644
--- a/advisories/unreviewed/2023/10/GHSA-hch9-gprw-2g9j/GHSA-hch9-gprw-2g9j.json
+++ b/advisories/unreviewed/2023/10/GHSA-hch9-gprw-2g9j/GHSA-hch9-gprw-2g9j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hch9-gprw-2g9j",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:13Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-5718"
@@ -31,7 +31,7 @@
"CWE-200",
"CWE-346"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hcph-762f-fp48/GHSA-hcph-762f-fp48.json b/advisories/unreviewed/2023/10/GHSA-hcph-762f-fp48/GHSA-hcph-762f-fp48.json
index b69b08745fc..5ab7c75eaea 100644
--- a/advisories/unreviewed/2023/10/GHSA-hcph-762f-fp48/GHSA-hcph-762f-fp48.json
+++ b/advisories/unreviewed/2023/10/GHSA-hcph-762f-fp48/GHSA-hcph-762f-fp48.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcph-762f-fp48",
- "modified": "2023-10-19T18:30:27Z",
+ "modified": "2024-04-04T08:38:34Z",
"published": "2023-10-14T06:30:55Z",
"aliases": [
"CVE-2023-44037"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-312"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T05:15:55Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hcpj-5jqq-8232/GHSA-hcpj-5jqq-8232.json b/advisories/unreviewed/2023/10/GHSA-hcpj-5jqq-8232/GHSA-hcpj-5jqq-8232.json
index 70a599bc9c5..b4d7db5e1df 100644
--- a/advisories/unreviewed/2023/10/GHSA-hcpj-5jqq-8232/GHSA-hcpj-5jqq-8232.json
+++ b/advisories/unreviewed/2023/10/GHSA-hcpj-5jqq-8232/GHSA-hcpj-5jqq-8232.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcpj-5jqq-8232",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:42Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45108"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hcpq-pf4q-ppwv/GHSA-hcpq-pf4q-ppwv.json b/advisories/unreviewed/2023/10/GHSA-hcpq-pf4q-ppwv/GHSA-hcpq-pf4q-ppwv.json
index 799bb3bc8e1..108ea16040a 100644
--- a/advisories/unreviewed/2023/10/GHSA-hcpq-pf4q-ppwv/GHSA-hcpq-pf4q-ppwv.json
+++ b/advisories/unreviewed/2023/10/GHSA-hcpq-pf4q-ppwv/GHSA-hcpq-pf4q-ppwv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcpq-pf4q-ppwv",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:23Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-22386"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-311"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hf28-wjr8-2h5p/GHSA-hf28-wjr8-2h5p.json b/advisories/unreviewed/2023/10/GHSA-hf28-wjr8-2h5p/GHSA-hf28-wjr8-2h5p.json
index b09b8584d87..dbc673cba82 100644
--- a/advisories/unreviewed/2023/10/GHSA-hf28-wjr8-2h5p/GHSA-hf28-wjr8-2h5p.json
+++ b/advisories/unreviewed/2023/10/GHSA-hf28-wjr8-2h5p/GHSA-hf28-wjr8-2h5p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf28-wjr8-2h5p",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:58:03Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-46570"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-28T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hfmf-h398-rr97/GHSA-hfmf-h398-rr97.json b/advisories/unreviewed/2023/10/GHSA-hfmf-h398-rr97/GHSA-hfmf-h398-rr97.json
index 8ce8118b949..d42f67d1074 100644
--- a/advisories/unreviewed/2023/10/GHSA-hfmf-h398-rr97/GHSA-hfmf-h398-rr97.json
+++ b/advisories/unreviewed/2023/10/GHSA-hfmf-h398-rr97/GHSA-hfmf-h398-rr97.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfmf-h398-rr97",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:29Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2022-4290"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json b/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json
index c93bd99aef9..f528699da72 100644
--- a/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json
+++ b/advisories/unreviewed/2023/10/GHSA-hfr4-7364-jv2q/GHSA-hfr4-7364-jv2q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfr4-7364-jv2q",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:48Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4820"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json b/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json
index dd4103fb82d..188e9ca2a2b 100644
--- a/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json
+++ b/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg5g-m3rr-7xx2",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:27Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4289"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hgjj-3x23-5xv2/GHSA-hgjj-3x23-5xv2.json b/advisories/unreviewed/2023/10/GHSA-hgjj-3x23-5xv2/GHSA-hgjj-3x23-5xv2.json
index cb7111d97b4..e5bd413b97b 100644
--- a/advisories/unreviewed/2023/10/GHSA-hgjj-3x23-5xv2/GHSA-hgjj-3x23-5xv2.json
+++ b/advisories/unreviewed/2023/10/GHSA-hgjj-3x23-5xv2/GHSA-hgjj-3x23-5xv2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgjj-3x23-5xv2",
- "modified": "2023-10-26T21:30:22Z",
+ "modified": "2024-04-04T08:57:01Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-33559"
],
"details": "A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-829"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T21:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hh2j-wjqr-83pc/GHSA-hh2j-wjqr-83pc.json b/advisories/unreviewed/2023/10/GHSA-hh2j-wjqr-83pc/GHSA-hh2j-wjqr-83pc.json
index 0a04e85bf4f..e77eb767b8f 100644
--- a/advisories/unreviewed/2023/10/GHSA-hh2j-wjqr-83pc/GHSA-hh2j-wjqr-83pc.json
+++ b/advisories/unreviewed/2023/10/GHSA-hh2j-wjqr-83pc/GHSA-hh2j-wjqr-83pc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh2j-wjqr-83pc",
- "modified": "2023-10-12T09:30:26Z",
+ "modified": "2024-04-04T08:35:14Z",
"published": "2023-10-12T09:30:26Z",
"aliases": [
"CVE-2023-5470"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T07:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hhpr-xj4f-5p6q/GHSA-hhpr-xj4f-5p6q.json b/advisories/unreviewed/2023/10/GHSA-hhpr-xj4f-5p6q/GHSA-hhpr-xj4f-5p6q.json
index 0ec4c40f73a..843e9ea0866 100644
--- a/advisories/unreviewed/2023/10/GHSA-hhpr-xj4f-5p6q/GHSA-hhpr-xj4f-5p6q.json
+++ b/advisories/unreviewed/2023/10/GHSA-hhpr-xj4f-5p6q/GHSA-hhpr-xj4f-5p6q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhpr-xj4f-5p6q",
- "modified": "2023-10-20T12:31:04Z",
+ "modified": "2024-04-04T08:51:20Z",
"published": "2023-10-20T12:31:04Z",
"aliases": [
"CVE-2023-5618"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T12:15:24Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hmvm-g3wg-h58r/GHSA-hmvm-g3wg-h58r.json b/advisories/unreviewed/2023/10/GHSA-hmvm-g3wg-h58r/GHSA-hmvm-g3wg-h58r.json
index 6c00439e9c8..424c234e49a 100644
--- a/advisories/unreviewed/2023/10/GHSA-hmvm-g3wg-h58r/GHSA-hmvm-g3wg-h58r.json
+++ b/advisories/unreviewed/2023/10/GHSA-hmvm-g3wg-h58r/GHSA-hmvm-g3wg-h58r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmvm-g3wg-h58r",
- "modified": "2023-10-17T03:32:42Z",
+ "modified": "2024-04-04T08:42:15Z",
"published": "2023-10-17T03:32:42Z",
"aliases": [
"CVE-2021-20581"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-613"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hp8q-38h9-gmmv/GHSA-hp8q-38h9-gmmv.json b/advisories/unreviewed/2023/10/GHSA-hp8q-38h9-gmmv/GHSA-hp8q-38h9-gmmv.json
index a67a3c6fb13..b9403ad07bc 100644
--- a/advisories/unreviewed/2023/10/GHSA-hp8q-38h9-gmmv/GHSA-hp8q-38h9-gmmv.json
+++ b/advisories/unreviewed/2023/10/GHSA-hp8q-38h9-gmmv/GHSA-hp8q-38h9-gmmv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp8q-38h9-gmmv",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:10Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-36954"
],
"details": "TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hqj4-p6qw-7mf2/GHSA-hqj4-p6qw-7mf2.json b/advisories/unreviewed/2023/10/GHSA-hqj4-p6qw-7mf2/GHSA-hqj4-p6qw-7mf2.json
index c420c652ba2..fff72699286 100644
--- a/advisories/unreviewed/2023/10/GHSA-hqj4-p6qw-7mf2/GHSA-hqj4-p6qw-7mf2.json
+++ b/advisories/unreviewed/2023/10/GHSA-hqj4-p6qw-7mf2/GHSA-hqj4-p6qw-7mf2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqj4-p6qw-7mf2",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:14Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-5421"
@@ -31,7 +31,7 @@
"CWE-20",
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hqmv-5rff-cqrx/GHSA-hqmv-5rff-cqrx.json b/advisories/unreviewed/2023/10/GHSA-hqmv-5rff-cqrx/GHSA-hqmv-5rff-cqrx.json
index c565b16ee4d..044f8cc56e6 100644
--- a/advisories/unreviewed/2023/10/GHSA-hqmv-5rff-cqrx/GHSA-hqmv-5rff-cqrx.json
+++ b/advisories/unreviewed/2023/10/GHSA-hqmv-5rff-cqrx/GHSA-hqmv-5rff-cqrx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqmv-5rff-cqrx",
- "modified": "2023-10-19T15:31:06Z",
+ "modified": "2024-04-04T08:48:05Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-35180"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hrf7-7wwm-qrvh/GHSA-hrf7-7wwm-qrvh.json b/advisories/unreviewed/2023/10/GHSA-hrf7-7wwm-qrvh/GHSA-hrf7-7wwm-qrvh.json
index 2993c7d7c95..5149fad4249 100644
--- a/advisories/unreviewed/2023/10/GHSA-hrf7-7wwm-qrvh/GHSA-hrf7-7wwm-qrvh.json
+++ b/advisories/unreviewed/2023/10/GHSA-hrf7-7wwm-qrvh/GHSA-hrf7-7wwm-qrvh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrf7-7wwm-qrvh",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:39Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-39680"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hrjc-cqfh-wxgv/GHSA-hrjc-cqfh-wxgv.json b/advisories/unreviewed/2023/10/GHSA-hrjc-cqfh-wxgv/GHSA-hrjc-cqfh-wxgv.json
index a6f4cca0cbd..f4b508e6af5 100644
--- a/advisories/unreviewed/2023/10/GHSA-hrjc-cqfh-wxgv/GHSA-hrjc-cqfh-wxgv.json
+++ b/advisories/unreviewed/2023/10/GHSA-hrjc-cqfh-wxgv/GHSA-hrjc-cqfh-wxgv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrjc-cqfh-wxgv",
- "modified": "2023-10-16T00:30:27Z",
+ "modified": "2024-04-04T08:38:56Z",
"published": "2023-10-16T00:30:27Z",
"aliases": [
"CVE-2023-35018"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T00:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hv42-72cg-mr2j/GHSA-hv42-72cg-mr2j.json b/advisories/unreviewed/2023/10/GHSA-hv42-72cg-mr2j/GHSA-hv42-72cg-mr2j.json
index 111d3249f30..6506fd5542b 100644
--- a/advisories/unreviewed/2023/10/GHSA-hv42-72cg-mr2j/GHSA-hv42-72cg-mr2j.json
+++ b/advisories/unreviewed/2023/10/GHSA-hv42-72cg-mr2j/GHSA-hv42-72cg-mr2j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv42-72cg-mr2j",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:56Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45651"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hw85-44xg-3h9f/GHSA-hw85-44xg-3h9f.json b/advisories/unreviewed/2023/10/GHSA-hw85-44xg-3h9f/GHSA-hw85-44xg-3h9f.json
index 97ecec17aba..8b4d46311b1 100644
--- a/advisories/unreviewed/2023/10/GHSA-hw85-44xg-3h9f/GHSA-hw85-44xg-3h9f.json
+++ b/advisories/unreviewed/2023/10/GHSA-hw85-44xg-3h9f/GHSA-hw85-44xg-3h9f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hw85-44xg-3h9f",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:54Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45062"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hwcv-rwgg-wfrh/GHSA-hwcv-rwgg-wfrh.json b/advisories/unreviewed/2023/10/GHSA-hwcv-rwgg-wfrh/GHSA-hwcv-rwgg-wfrh.json
index 66acacaa557..57ba0f577aa 100644
--- a/advisories/unreviewed/2023/10/GHSA-hwcv-rwgg-wfrh/GHSA-hwcv-rwgg-wfrh.json
+++ b/advisories/unreviewed/2023/10/GHSA-hwcv-rwgg-wfrh/GHSA-hwcv-rwgg-wfrh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwcv-rwgg-wfrh",
- "modified": "2023-10-25T18:32:20Z",
+ "modified": "2024-04-04T08:53:50Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2022-3699"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hwhm-x7h4-2284/GHSA-hwhm-x7h4-2284.json b/advisories/unreviewed/2023/10/GHSA-hwhm-x7h4-2284/GHSA-hwhm-x7h4-2284.json
index 5d0ef782c92..212212d4600 100644
--- a/advisories/unreviewed/2023/10/GHSA-hwhm-x7h4-2284/GHSA-hwhm-x7h4-2284.json
+++ b/advisories/unreviewed/2023/10/GHSA-hwhm-x7h4-2284/GHSA-hwhm-x7h4-2284.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwhm-x7h4-2284",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:03Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5071"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-hx67-h5vf-9cfq/GHSA-hx67-h5vf-9cfq.json b/advisories/unreviewed/2023/10/GHSA-hx67-h5vf-9cfq/GHSA-hx67-h5vf-9cfq.json
index 22584ea4244..b6433000d6f 100644
--- a/advisories/unreviewed/2023/10/GHSA-hx67-h5vf-9cfq/GHSA-hx67-h5vf-9cfq.json
+++ b/advisories/unreviewed/2023/10/GHSA-hx67-h5vf-9cfq/GHSA-hx67-h5vf-9cfq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hx67-h5vf-9cfq",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:18Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-46006"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j2h9-jq5m-473h/GHSA-j2h9-jq5m-473h.json b/advisories/unreviewed/2023/10/GHSA-j2h9-jq5m-473h/GHSA-j2h9-jq5m-473h.json
index a7e8ce3bd66..c2588fd91d4 100644
--- a/advisories/unreviewed/2023/10/GHSA-j2h9-jq5m-473h/GHSA-j2h9-jq5m-473h.json
+++ b/advisories/unreviewed/2023/10/GHSA-j2h9-jq5m-473h/GHSA-j2h9-jq5m-473h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2h9-jq5m-473h",
- "modified": "2023-10-13T15:30:20Z",
+ "modified": "2024-04-04T08:38:06Z",
"published": "2023-10-13T15:30:20Z",
"aliases": [
"CVE-2023-41836"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T15:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json b/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json
index 4d0b187734a..0526a62be45 100644
--- a/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json
+++ b/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2q7-6q2x-2q9p",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:37Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46564"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json b/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json
index 12099ec9cf7..0e80d133cca 100644
--- a/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json
+++ b/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j38r-mq7j-wgvr",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:32Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45747"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j438-gf7h-pvjh/GHSA-j438-gf7h-pvjh.json b/advisories/unreviewed/2023/10/GHSA-j438-gf7h-pvjh/GHSA-j438-gf7h-pvjh.json
index 0cf7bdd6c5f..7e016c08ba7 100644
--- a/advisories/unreviewed/2023/10/GHSA-j438-gf7h-pvjh/GHSA-j438-gf7h-pvjh.json
+++ b/advisories/unreviewed/2023/10/GHSA-j438-gf7h-pvjh/GHSA-j438-gf7h-pvjh.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j438-gf7h-pvjh",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:42Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-44693"
],
"details": "D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T06:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j5gv-w838-mmcx/GHSA-j5gv-w838-mmcx.json b/advisories/unreviewed/2023/10/GHSA-j5gv-w838-mmcx/GHSA-j5gv-w838-mmcx.json
index 0376a73fcb3..934427bdec5 100644
--- a/advisories/unreviewed/2023/10/GHSA-j5gv-w838-mmcx/GHSA-j5gv-w838-mmcx.json
+++ b/advisories/unreviewed/2023/10/GHSA-j5gv-w838-mmcx/GHSA-j5gv-w838-mmcx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5gv-w838-mmcx",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:49Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-44310"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j5wm-92c4-p546/GHSA-j5wm-92c4-p546.json b/advisories/unreviewed/2023/10/GHSA-j5wm-92c4-p546/GHSA-j5wm-92c4-p546.json
index 5a964c77d38..fb9a0553685 100644
--- a/advisories/unreviewed/2023/10/GHSA-j5wm-92c4-p546/GHSA-j5wm-92c4-p546.json
+++ b/advisories/unreviewed/2023/10/GHSA-j5wm-92c4-p546/GHSA-j5wm-92c4-p546.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5wm-92c4-p546",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:02Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41630"
],
"details": "eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j5xw-gh42-g53c/GHSA-j5xw-gh42-g53c.json b/advisories/unreviewed/2023/10/GHSA-j5xw-gh42-g53c/GHSA-j5xw-gh42-g53c.json
index 8b308fcdd14..7b9d39fac99 100644
--- a/advisories/unreviewed/2023/10/GHSA-j5xw-gh42-g53c/GHSA-j5xw-gh42-g53c.json
+++ b/advisories/unreviewed/2023/10/GHSA-j5xw-gh42-g53c/GHSA-j5xw-gh42-g53c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5xw-gh42-g53c",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:25Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-36841"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j62j-mjvg-xgrq/GHSA-j62j-mjvg-xgrq.json b/advisories/unreviewed/2023/10/GHSA-j62j-mjvg-xgrq/GHSA-j62j-mjvg-xgrq.json
index 30155b25c27..a56ed50f28b 100644
--- a/advisories/unreviewed/2023/10/GHSA-j62j-mjvg-xgrq/GHSA-j62j-mjvg-xgrq.json
+++ b/advisories/unreviewed/2023/10/GHSA-j62j-mjvg-xgrq/GHSA-j62j-mjvg-xgrq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j62j-mjvg-xgrq",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:13Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44199"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-754"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json b/advisories/unreviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json
index 38bd2e96b3a..b243c6ed5a2 100644
--- a/advisories/unreviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json
+++ b/advisories/unreviewed/2023/10/GHSA-j663-6jpj-xx8c/GHSA-j663-6jpj-xx8c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j663-6jpj-xx8c",
- "modified": "2023-10-17T09:30:23Z",
+ "modified": "2024-04-04T08:42:48Z",
"published": "2023-10-17T09:30:23Z",
"aliases": [
"CVE-2023-44309"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j6cr-wmfq-h73p/GHSA-j6cr-wmfq-h73p.json b/advisories/unreviewed/2023/10/GHSA-j6cr-wmfq-h73p/GHSA-j6cr-wmfq-h73p.json
index 734d7c5a2e3..2938eec33a5 100644
--- a/advisories/unreviewed/2023/10/GHSA-j6cr-wmfq-h73p/GHSA-j6cr-wmfq-h73p.json
+++ b/advisories/unreviewed/2023/10/GHSA-j6cr-wmfq-h73p/GHSA-j6cr-wmfq-h73p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6cr-wmfq-h73p",
- "modified": "2023-10-25T21:30:26Z",
+ "modified": "2024-04-04T08:48:51Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-43986"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json b/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json
index 3cdcf3d7bf4..2c929c1fc6e 100644
--- a/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json
+++ b/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6r3-vq2c-4ghw",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:42:02Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5089"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-209"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j6vq-hjmf-4p85/GHSA-j6vq-hjmf-4p85.json b/advisories/unreviewed/2023/10/GHSA-j6vq-hjmf-4p85/GHSA-j6vq-hjmf-4p85.json
index e04880a2d66..69448657018 100644
--- a/advisories/unreviewed/2023/10/GHSA-j6vq-hjmf-4p85/GHSA-j6vq-hjmf-4p85.json
+++ b/advisories/unreviewed/2023/10/GHSA-j6vq-hjmf-4p85/GHSA-j6vq-hjmf-4p85.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6vq-hjmf-4p85",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:06Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-4620"
],
"details": "The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j76p-cmp2-vxj3/GHSA-j76p-cmp2-vxj3.json b/advisories/unreviewed/2023/10/GHSA-j76p-cmp2-vxj3/GHSA-j76p-cmp2-vxj3.json
index 63d8d75edd4..509408925d7 100644
--- a/advisories/unreviewed/2023/10/GHSA-j76p-cmp2-vxj3/GHSA-j76p-cmp2-vxj3.json
+++ b/advisories/unreviewed/2023/10/GHSA-j76p-cmp2-vxj3/GHSA-j76p-cmp2-vxj3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j76p-cmp2-vxj3",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:42Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-5059"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json b/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json
index c47ebcc6cf0..7443eb92101 100644
--- a/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json
+++ b/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7gf-5v9f-v496",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46559"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j7mh-fcjh-vp2q/GHSA-j7mh-fcjh-vp2q.json b/advisories/unreviewed/2023/10/GHSA-j7mh-fcjh-vp2q/GHSA-j7mh-fcjh-vp2q.json
index 412ca96deb8..bf977a0697a 100644
--- a/advisories/unreviewed/2023/10/GHSA-j7mh-fcjh-vp2q/GHSA-j7mh-fcjh-vp2q.json
+++ b/advisories/unreviewed/2023/10/GHSA-j7mh-fcjh-vp2q/GHSA-j7mh-fcjh-vp2q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7mh-fcjh-vp2q",
- "modified": "2023-10-30T12:30:31Z",
+ "modified": "2024-04-04T08:53:39Z",
"published": "2023-10-24T00:31:07Z",
"aliases": [
"CVE-2023-43358"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T22:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json
index fa651a79eb6..fe18337871c 100644
--- a/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json
+++ b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7wf-qmpf-6v3c",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:44Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40131"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j8cp-xjh5-74x4/GHSA-j8cp-xjh5-74x4.json b/advisories/unreviewed/2023/10/GHSA-j8cp-xjh5-74x4/GHSA-j8cp-xjh5-74x4.json
index 244422a8317..79a8dd59b75 100644
--- a/advisories/unreviewed/2023/10/GHSA-j8cp-xjh5-74x4/GHSA-j8cp-xjh5-74x4.json
+++ b/advisories/unreviewed/2023/10/GHSA-j8cp-xjh5-74x4/GHSA-j8cp-xjh5-74x4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8cp-xjh5-74x4",
- "modified": "2023-10-18T00:31:40Z",
+ "modified": "2024-04-04T08:43:47Z",
"published": "2023-10-18T00:31:40Z",
"aliases": [
"CVE-2023-22029"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j8g4-qgjp-w2g8/GHSA-j8g4-qgjp-w2g8.json b/advisories/unreviewed/2023/10/GHSA-j8g4-qgjp-w2g8/GHSA-j8g4-qgjp-w2g8.json
index cb7bc893e80..fb6c863dfd2 100644
--- a/advisories/unreviewed/2023/10/GHSA-j8g4-qgjp-w2g8/GHSA-j8g4-qgjp-w2g8.json
+++ b/advisories/unreviewed/2023/10/GHSA-j8g4-qgjp-w2g8/GHSA-j8g4-qgjp-w2g8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8g4-qgjp-w2g8",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:53Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2021-26735"
@@ -31,7 +31,7 @@
"CWE-346",
"CWE-428"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json b/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json
index dad72c89acf..da50a6cb7d6 100644
--- a/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json
+++ b/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8rr-p259-7wpm",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:24Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27259"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-j98c-6x58-jmvw/GHSA-j98c-6x58-jmvw.json b/advisories/unreviewed/2023/10/GHSA-j98c-6x58-jmvw/GHSA-j98c-6x58-jmvw.json
index e4ea81de629..7e8729bcb75 100644
--- a/advisories/unreviewed/2023/10/GHSA-j98c-6x58-jmvw/GHSA-j98c-6x58-jmvw.json
+++ b/advisories/unreviewed/2023/10/GHSA-j98c-6x58-jmvw/GHSA-j98c-6x58-jmvw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j98c-6x58-jmvw",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:27Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2021-4418"
@@ -62,7 +62,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jf22-c97p-4hxv/GHSA-jf22-c97p-4hxv.json b/advisories/unreviewed/2023/10/GHSA-jf22-c97p-4hxv/GHSA-jf22-c97p-4hxv.json
index c183169e0dc..bb67f802c23 100644
--- a/advisories/unreviewed/2023/10/GHSA-jf22-c97p-4hxv/GHSA-jf22-c97p-4hxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-jf22-c97p-4hxv/GHSA-jf22-c97p-4hxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf22-c97p-4hxv",
- "modified": "2023-10-18T03:30:28Z",
+ "modified": "2024-04-04T08:34:58Z",
"published": "2023-10-11T21:33:25Z",
"aliases": [
"CVE-2023-35662"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json b/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json
index 77233a30b74..e27be2e4bea 100644
--- a/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json
+++ b/advisories/unreviewed/2023/10/GHSA-jf4r-vjvc-pj36/GHSA-jf4r-vjvc-pj36.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf4r-vjvc-pj36",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:49:07Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-27793"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json b/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json
index 696a9183df4..35f2ef97ce0 100644
--- a/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json
+++ b/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfmm-v8pp-89h8",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:20Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46539"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jgfr-c5jr-627r/GHSA-jgfr-c5jr-627r.json b/advisories/unreviewed/2023/10/GHSA-jgfr-c5jr-627r/GHSA-jgfr-c5jr-627r.json
index 33a731c5b6a..0c13e9f9f88 100644
--- a/advisories/unreviewed/2023/10/GHSA-jgfr-c5jr-627r/GHSA-jgfr-c5jr-627r.json
+++ b/advisories/unreviewed/2023/10/GHSA-jgfr-c5jr-627r/GHSA-jgfr-c5jr-627r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgfr-c5jr-627r",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:30Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-41262"
],
"details": "An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jgpr-gfxw-cgxq/GHSA-jgpr-gfxw-cgxq.json b/advisories/unreviewed/2023/10/GHSA-jgpr-gfxw-cgxq/GHSA-jgpr-gfxw-cgxq.json
index edb494c3001..1cd071f6ae3 100644
--- a/advisories/unreviewed/2023/10/GHSA-jgpr-gfxw-cgxq/GHSA-jgpr-gfxw-cgxq.json
+++ b/advisories/unreviewed/2023/10/GHSA-jgpr-gfxw-cgxq/GHSA-jgpr-gfxw-cgxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgpr-gfxw-cgxq",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:19Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44204"
@@ -31,7 +31,7 @@
"CWE-1286",
"CWE-20"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jh8v-f3wq-v85p/GHSA-jh8v-f3wq-v85p.json b/advisories/unreviewed/2023/10/GHSA-jh8v-f3wq-v85p/GHSA-jh8v-f3wq-v85p.json
index 28d5f56c37d..c9b2fe93abc 100644
--- a/advisories/unreviewed/2023/10/GHSA-jh8v-f3wq-v85p/GHSA-jh8v-f3wq-v85p.json
+++ b/advisories/unreviewed/2023/10/GHSA-jh8v-f3wq-v85p/GHSA-jh8v-f3wq-v85p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh8v-f3wq-v85p",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:50Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2023-40367"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jhcx-vwjq-7w4c/GHSA-jhcx-vwjq-7w4c.json b/advisories/unreviewed/2023/10/GHSA-jhcx-vwjq-7w4c/GHSA-jhcx-vwjq-7w4c.json
index 302374ff558..e46658d424b 100644
--- a/advisories/unreviewed/2023/10/GHSA-jhcx-vwjq-7w4c/GHSA-jhcx-vwjq-7w4c.json
+++ b/advisories/unreviewed/2023/10/GHSA-jhcx-vwjq-7w4c/GHSA-jhcx-vwjq-7w4c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhcx-vwjq-7w4c",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:10Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22124"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jhg8-2q46-wfq7/GHSA-jhg8-2q46-wfq7.json b/advisories/unreviewed/2023/10/GHSA-jhg8-2q46-wfq7/GHSA-jhg8-2q46-wfq7.json
index a5df242a0f7..bdc76a529cd 100644
--- a/advisories/unreviewed/2023/10/GHSA-jhg8-2q46-wfq7/GHSA-jhg8-2q46-wfq7.json
+++ b/advisories/unreviewed/2023/10/GHSA-jhg8-2q46-wfq7/GHSA-jhg8-2q46-wfq7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhg8-2q46-wfq7",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:59Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-38584"
@@ -35,7 +35,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jhg8-jx4g-7x8h/GHSA-jhg8-jx4g-7x8h.json b/advisories/unreviewed/2023/10/GHSA-jhg8-jx4g-7x8h/GHSA-jhg8-jx4g-7x8h.json
index 5f43c66ebc7..b38ba0a5950 100644
--- a/advisories/unreviewed/2023/10/GHSA-jhg8-jx4g-7x8h/GHSA-jhg8-jx4g-7x8h.json
+++ b/advisories/unreviewed/2023/10/GHSA-jhg8-jx4g-7x8h/GHSA-jhg8-jx4g-7x8h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhg8-jx4g-7x8h",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:56Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4947"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jjxw-34h2-rrhg/GHSA-jjxw-34h2-rrhg.json b/advisories/unreviewed/2023/10/GHSA-jjxw-34h2-rrhg/GHSA-jjxw-34h2-rrhg.json
index f3bdee246b0..28f88e86a7f 100644
--- a/advisories/unreviewed/2023/10/GHSA-jjxw-34h2-rrhg/GHSA-jjxw-34h2-rrhg.json
+++ b/advisories/unreviewed/2023/10/GHSA-jjxw-34h2-rrhg/GHSA-jjxw-34h2-rrhg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjxw-34h2-rrhg",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:19Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-45511"
],
"details": "A memory leak in tsMuxer version git-2539d07 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T21:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jm5q-9m8m-p5p5/GHSA-jm5q-9m8m-p5p5.json b/advisories/unreviewed/2023/10/GHSA-jm5q-9m8m-p5p5/GHSA-jm5q-9m8m-p5p5.json
index ff1cb548ff8..7b84f9be597 100644
--- a/advisories/unreviewed/2023/10/GHSA-jm5q-9m8m-p5p5/GHSA-jm5q-9m8m-p5p5.json
+++ b/advisories/unreviewed/2023/10/GHSA-jm5q-9m8m-p5p5/GHSA-jm5q-9m8m-p5p5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jm5q-9m8m-p5p5",
- "modified": "2023-10-17T03:32:42Z",
+ "modified": "2024-04-04T08:42:12Z",
"published": "2023-10-17T03:32:42Z",
"aliases": [
"CVE-2022-22377"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-311"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T01:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jp3p-m9qw-pgfj/GHSA-jp3p-m9qw-pgfj.json b/advisories/unreviewed/2023/10/GHSA-jp3p-m9qw-pgfj/GHSA-jp3p-m9qw-pgfj.json
index dbeb7238ef0..29778615fcb 100644
--- a/advisories/unreviewed/2023/10/GHSA-jp3p-m9qw-pgfj/GHSA-jp3p-m9qw-pgfj.json
+++ b/advisories/unreviewed/2023/10/GHSA-jp3p-m9qw-pgfj/GHSA-jp3p-m9qw-pgfj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jp3p-m9qw-pgfj",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:14Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3154"
],
"details": "The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jp8v-q88c-wmpm/GHSA-jp8v-q88c-wmpm.json b/advisories/unreviewed/2023/10/GHSA-jp8v-q88c-wmpm/GHSA-jp8v-q88c-wmpm.json
index f5167cc3f81..9a42c302af4 100644
--- a/advisories/unreviewed/2023/10/GHSA-jp8v-q88c-wmpm/GHSA-jp8v-q88c-wmpm.json
+++ b/advisories/unreviewed/2023/10/GHSA-jp8v-q88c-wmpm/GHSA-jp8v-q88c-wmpm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jp8v-q88c-wmpm",
- "modified": "2023-10-16T15:30:20Z",
+ "modified": "2024-04-04T08:35:34Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45068"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json b/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json
index 52abddda9ce..5eac217366a 100644
--- a/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json
+++ b/advisories/unreviewed/2023/10/GHSA-jpgp-pmqh-538w/GHSA-jpgp-pmqh-538w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jpgp-pmqh-538w",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:49:08Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-27795"
],
"details": "An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jppc-gxqh-pgw5/GHSA-jppc-gxqh-pgw5.json b/advisories/unreviewed/2023/10/GHSA-jppc-gxqh-pgw5/GHSA-jppc-gxqh-pgw5.json
index 63a4bf38b56..b2605174cd7 100644
--- a/advisories/unreviewed/2023/10/GHSA-jppc-gxqh-pgw5/GHSA-jppc-gxqh-pgw5.json
+++ b/advisories/unreviewed/2023/10/GHSA-jppc-gxqh-pgw5/GHSA-jppc-gxqh-pgw5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jppc-gxqh-pgw5",
- "modified": "2023-10-31T21:32:35Z",
+ "modified": "2024-04-04T08:46:40Z",
"published": "2023-10-18T21:33:11Z",
"aliases": [
"CVE-2023-26300"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T19:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json
index 6369748c87e..5c972b1dff3 100644
--- a/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json
+++ b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jpq4-mchv-jv8r",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:15Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2023-38328"
],
"details": "An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-522"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json b/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json
index d19b3802be5..e60e6422584 100644
--- a/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json
+++ b/advisories/unreviewed/2023/10/GHSA-jq2h-j9qf-53rv/GHSA-jq2h-j9qf-53rv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq2h-j9qf-53rv",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:52:48Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46315"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jqqc-vv26-h55v/GHSA-jqqc-vv26-h55v.json b/advisories/unreviewed/2023/10/GHSA-jqqc-vv26-h55v/GHSA-jqqc-vv26-h55v.json
index 93818a6ebb8..440e30c39a7 100644
--- a/advisories/unreviewed/2023/10/GHSA-jqqc-vv26-h55v/GHSA-jqqc-vv26-h55v.json
+++ b/advisories/unreviewed/2023/10/GHSA-jqqc-vv26-h55v/GHSA-jqqc-vv26-h55v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqqc-vv26-h55v",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:35:56Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-31192"
@@ -32,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-457"
+ "CWE-457",
+ "CWE-908"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json b/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json
index ba2b25e4159..125d4bf6428 100644
--- a/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json
+++ b/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqxm-w4mh-hq99",
- "modified": "2023-10-20T21:31:00Z",
+ "modified": "2024-04-04T08:41:59Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5133"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-290"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jr64-37xj-g5qc/GHSA-jr64-37xj-g5qc.json b/advisories/unreviewed/2023/10/GHSA-jr64-37xj-g5qc/GHSA-jr64-37xj-g5qc.json
index a9bdd59b49f..82b93f3efe0 100644
--- a/advisories/unreviewed/2023/10/GHSA-jr64-37xj-g5qc/GHSA-jr64-37xj-g5qc.json
+++ b/advisories/unreviewed/2023/10/GHSA-jr64-37xj-g5qc/GHSA-jr64-37xj-g5qc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr64-37xj-g5qc",
- "modified": "2023-10-14T03:31:15Z",
+ "modified": "2024-04-04T08:35:20Z",
"published": "2023-10-12T12:30:24Z",
"aliases": [
"CVE-2023-23651"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jrmm-33p6-jvrr/GHSA-jrmm-33p6-jvrr.json b/advisories/unreviewed/2023/10/GHSA-jrmm-33p6-jvrr/GHSA-jrmm-33p6-jvrr.json
index f61d5b22bc6..c3420e35070 100644
--- a/advisories/unreviewed/2023/10/GHSA-jrmm-33p6-jvrr/GHSA-jrmm-33p6-jvrr.json
+++ b/advisories/unreviewed/2023/10/GHSA-jrmm-33p6-jvrr/GHSA-jrmm-33p6-jvrr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrmm-33p6-jvrr",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:02Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22075"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json b/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json
index fee49ff6aad..a392ccf3749 100644
--- a/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json
+++ b/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrq4-jwcw-x9x4",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:51:36Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43353"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jrqx-4ghm-m5qq/GHSA-jrqx-4ghm-m5qq.json b/advisories/unreviewed/2023/10/GHSA-jrqx-4ghm-m5qq/GHSA-jrqx-4ghm-m5qq.json
index c18999bb1f3..3415744f3a6 100644
--- a/advisories/unreviewed/2023/10/GHSA-jrqx-4ghm-m5qq/GHSA-jrqx-4ghm-m5qq.json
+++ b/advisories/unreviewed/2023/10/GHSA-jrqx-4ghm-m5qq/GHSA-jrqx-4ghm-m5qq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrqx-4ghm-m5qq",
- "modified": "2023-10-25T18:32:22Z",
+ "modified": "2024-04-04T08:55:09Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-3112"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:30Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json b/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json
index 8e8390fa937..8167cc4beec 100644
--- a/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json
+++ b/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv9m-jp3m-8vjq",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:31Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27261"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jvcq-3v53-v38c/GHSA-jvcq-3v53-v38c.json b/advisories/unreviewed/2023/10/GHSA-jvcq-3v53-v38c/GHSA-jvcq-3v53-v38c.json
index 052167ddc3f..4d9b4443db6 100644
--- a/advisories/unreviewed/2023/10/GHSA-jvcq-3v53-v38c/GHSA-jvcq-3v53-v38c.json
+++ b/advisories/unreviewed/2023/10/GHSA-jvcq-3v53-v38c/GHSA-jvcq-3v53-v38c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvcq-3v53-v38c",
- "modified": "2023-10-19T03:30:29Z",
+ "modified": "2024-04-04T08:46:59Z",
"published": "2023-10-19T03:30:29Z",
"aliases": [
"CVE-2023-37503"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-521"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T03:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jx3j-p7wg-qg83/GHSA-jx3j-p7wg-qg83.json b/advisories/unreviewed/2023/10/GHSA-jx3j-p7wg-qg83/GHSA-jx3j-p7wg-qg83.json
index 3c308dee46c..30b1c27653e 100644
--- a/advisories/unreviewed/2023/10/GHSA-jx3j-p7wg-qg83/GHSA-jx3j-p7wg-qg83.json
+++ b/advisories/unreviewed/2023/10/GHSA-jx3j-p7wg-qg83/GHSA-jx3j-p7wg-qg83.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx3j-p7wg-qg83",
- "modified": "2023-10-25T18:32:20Z",
+ "modified": "2024-04-04T08:53:46Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2022-0353"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:16:54Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-jxhx-66x5-h397/GHSA-jxhx-66x5-h397.json b/advisories/unreviewed/2023/10/GHSA-jxhx-66x5-h397/GHSA-jxhx-66x5-h397.json
index bbdfb8e83aa..1098c1404bc 100644
--- a/advisories/unreviewed/2023/10/GHSA-jxhx-66x5-h397/GHSA-jxhx-66x5-h397.json
+++ b/advisories/unreviewed/2023/10/GHSA-jxhx-66x5-h397/GHSA-jxhx-66x5-h397.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxhx-66x5-h397",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:44Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2022-43868"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m276-5338-rwf8/GHSA-m276-5338-rwf8.json b/advisories/unreviewed/2023/10/GHSA-m276-5338-rwf8/GHSA-m276-5338-rwf8.json
index 82470f0c1a8..40332f92068 100644
--- a/advisories/unreviewed/2023/10/GHSA-m276-5338-rwf8/GHSA-m276-5338-rwf8.json
+++ b/advisories/unreviewed/2023/10/GHSA-m276-5338-rwf8/GHSA-m276-5338-rwf8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m276-5338-rwf8",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:56Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-38192"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T01:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m276-v8xm-46jm/GHSA-m276-v8xm-46jm.json b/advisories/unreviewed/2023/10/GHSA-m276-v8xm-46jm/GHSA-m276-v8xm-46jm.json
index 5e3afd60f80..1fb9744ac88 100644
--- a/advisories/unreviewed/2023/10/GHSA-m276-v8xm-46jm/GHSA-m276-v8xm-46jm.json
+++ b/advisories/unreviewed/2023/10/GHSA-m276-v8xm-46jm/GHSA-m276-v8xm-46jm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m276-v8xm-46jm",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:43:48Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22069"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json b/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json
index 99dc0e3b2a6..1e02df9f23b 100644
--- a/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json
+++ b/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2cg-wrh8-h3xx",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:30Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46558"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m2g3-pg3w-frm3/GHSA-m2g3-pg3w-frm3.json b/advisories/unreviewed/2023/10/GHSA-m2g3-pg3w-frm3/GHSA-m2g3-pg3w-frm3.json
index 31379e8ea07..bc320db23b0 100644
--- a/advisories/unreviewed/2023/10/GHSA-m2g3-pg3w-frm3/GHSA-m2g3-pg3w-frm3.json
+++ b/advisories/unreviewed/2023/10/GHSA-m2g3-pg3w-frm3/GHSA-m2g3-pg3w-frm3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2g3-pg3w-frm3",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:33Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-5552"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-200"
+ "CWE-200",
+ "CWE-522"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T00:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m37q-25f6-v3p9/GHSA-m37q-25f6-v3p9.json b/advisories/unreviewed/2023/10/GHSA-m37q-25f6-v3p9/GHSA-m37q-25f6-v3p9.json
index 274909d1325..050e5b9610d 100644
--- a/advisories/unreviewed/2023/10/GHSA-m37q-25f6-v3p9/GHSA-m37q-25f6-v3p9.json
+++ b/advisories/unreviewed/2023/10/GHSA-m37q-25f6-v3p9/GHSA-m37q-25f6-v3p9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m37q-25f6-v3p9",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:19Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-22375"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m3cj-392g-3vvg/GHSA-m3cj-392g-3vvg.json b/advisories/unreviewed/2023/10/GHSA-m3cj-392g-3vvg/GHSA-m3cj-392g-3vvg.json
index e870d8a5800..72dd2109778 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3cj-392g-3vvg/GHSA-m3cj-392g-3vvg.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3cj-392g-3vvg/GHSA-m3cj-392g-3vvg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3cj-392g-3vvg",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:55:04Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39739"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json b/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
index f7bb0468bb8..40c165d3e78 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3gg-5v93-qrhg/GHSA-m3gg-5v93-qrhg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3gg-5v93-qrhg",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:06Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-36950"
],
"details": "TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m3gw-cj93-vpfv/GHSA-m3gw-cj93-vpfv.json b/advisories/unreviewed/2023/10/GHSA-m3gw-cj93-vpfv/GHSA-m3gw-cj93-vpfv.json
index d5bd4abce09..d4fda009f66 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3gw-cj93-vpfv/GHSA-m3gw-cj93-vpfv.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3gw-cj93-vpfv/GHSA-m3gw-cj93-vpfv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3gw-cj93-vpfv",
- "modified": "2023-10-16T03:30:30Z",
+ "modified": "2024-04-04T08:38:59Z",
"published": "2023-10-16T03:30:30Z",
"aliases": [
"CVE-2023-40377"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T01:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m3q4-xp7h-m6pw/GHSA-m3q4-xp7h-m6pw.json b/advisories/unreviewed/2023/10/GHSA-m3q4-xp7h-m6pw/GHSA-m3q4-xp7h-m6pw.json
index 3a8b3070cd7..54b447d1e6b 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3q4-xp7h-m6pw/GHSA-m3q4-xp7h-m6pw.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3q4-xp7h-m6pw/GHSA-m3q4-xp7h-m6pw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3q4-xp7h-m6pw",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:01Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26572"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m3x8-pm7x-r5mj/GHSA-m3x8-pm7x-r5mj.json b/advisories/unreviewed/2023/10/GHSA-m3x8-pm7x-r5mj/GHSA-m3x8-pm7x-r5mj.json
index 3f4f4d089c2..afa73a53958 100644
--- a/advisories/unreviewed/2023/10/GHSA-m3x8-pm7x-r5mj/GHSA-m3x8-pm7x-r5mj.json
+++ b/advisories/unreviewed/2023/10/GHSA-m3x8-pm7x-r5mj/GHSA-m3x8-pm7x-r5mj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3x8-pm7x-r5mj",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:58Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4942"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m486-7gcf-2983/GHSA-m486-7gcf-2983.json b/advisories/unreviewed/2023/10/GHSA-m486-7gcf-2983/GHSA-m486-7gcf-2983.json
index 771f800fe34..67a91d6d5ee 100644
--- a/advisories/unreviewed/2023/10/GHSA-m486-7gcf-2983/GHSA-m486-7gcf-2983.json
+++ b/advisories/unreviewed/2023/10/GHSA-m486-7gcf-2983/GHSA-m486-7gcf-2983.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m486-7gcf-2983",
- "modified": "2023-10-12T06:30:27Z",
+ "modified": "2024-04-04T08:35:10Z",
"published": "2023-10-12T06:30:27Z",
"aliases": [
"CVE-2023-5531"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T06:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m4g4-hvch-vhgf/GHSA-m4g4-hvch-vhgf.json b/advisories/unreviewed/2023/10/GHSA-m4g4-hvch-vhgf/GHSA-m4g4-hvch-vhgf.json
index 8a153c5cdc8..bf06c9bb351 100644
--- a/advisories/unreviewed/2023/10/GHSA-m4g4-hvch-vhgf/GHSA-m4g4-hvch-vhgf.json
+++ b/advisories/unreviewed/2023/10/GHSA-m4g4-hvch-vhgf/GHSA-m4g4-hvch-vhgf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4g4-hvch-vhgf",
- "modified": "2023-10-17T18:30:56Z",
+ "modified": "2024-04-04T08:43:37Z",
"published": "2023-10-17T18:30:56Z",
"aliases": [
"CVE-2023-27133"
],
"details": "TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\\TSplus-RemoteWork\\Clients\\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product, not the TSplus Remote Work product.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-276"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m5x7-2x5r-8m3f/GHSA-m5x7-2x5r-8m3f.json b/advisories/unreviewed/2023/10/GHSA-m5x7-2x5r-8m3f/GHSA-m5x7-2x5r-8m3f.json
index 02f1e1b29b4..e624b669511 100644
--- a/advisories/unreviewed/2023/10/GHSA-m5x7-2x5r-8m3f/GHSA-m5x7-2x5r-8m3f.json
+++ b/advisories/unreviewed/2023/10/GHSA-m5x7-2x5r-8m3f/GHSA-m5x7-2x5r-8m3f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m5x7-2x5r-8m3f",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:51Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45467"
],
"details": "Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-78"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m63v-p8hp-rg28/GHSA-m63v-p8hp-rg28.json b/advisories/unreviewed/2023/10/GHSA-m63v-p8hp-rg28/GHSA-m63v-p8hp-rg28.json
index 1bf11e90742..e3ff94c7899 100644
--- a/advisories/unreviewed/2023/10/GHSA-m63v-p8hp-rg28/GHSA-m63v-p8hp-rg28.json
+++ b/advisories/unreviewed/2023/10/GHSA-m63v-p8hp-rg28/GHSA-m63v-p8hp-rg28.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m63v-p8hp-rg28",
- "modified": "2023-10-19T15:31:03Z",
+ "modified": "2024-04-04T08:38:52Z",
"published": "2023-10-15T21:30:26Z",
"aliases": [
"CVE-2023-38312"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-15T19:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m6cj-mh5r-8m7w/GHSA-m6cj-mh5r-8m7w.json b/advisories/unreviewed/2023/10/GHSA-m6cj-mh5r-8m7w/GHSA-m6cj-mh5r-8m7w.json
index 8bd09b228bf..852a548be16 100644
--- a/advisories/unreviewed/2023/10/GHSA-m6cj-mh5r-8m7w/GHSA-m6cj-mh5r-8m7w.json
+++ b/advisories/unreviewed/2023/10/GHSA-m6cj-mh5r-8m7w/GHSA-m6cj-mh5r-8m7w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6cj-mh5r-8m7w",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:09Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-43777"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-256"
+ "CWE-256",
+ "CWE-522"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T13:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json b/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json
index 22cb9faf114..e61b8b64942 100644
--- a/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json
+++ b/advisories/unreviewed/2023/10/GHSA-m6mv-6jvc-p4xv/GHSA-m6mv-6jvc-p4xv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6mv-6jvc-p4xv",
- "modified": "2023-10-31T21:32:35Z",
+ "modified": "2024-04-04T08:54:45Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39732"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json b/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json
index 49eb7067862..04486113494 100644
--- a/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json
+++ b/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6vm-37g8-gqvh",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:38Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22102"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22102"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20231027-0007"
+ },
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m6vw-rhwf-xjxq/GHSA-m6vw-rhwf-xjxq.json b/advisories/unreviewed/2023/10/GHSA-m6vw-rhwf-xjxq/GHSA-m6vw-rhwf-xjxq.json
index b24a870d9d3..0999fb8f65a 100644
--- a/advisories/unreviewed/2023/10/GHSA-m6vw-rhwf-xjxq/GHSA-m6vw-rhwf-xjxq.json
+++ b/advisories/unreviewed/2023/10/GHSA-m6vw-rhwf-xjxq/GHSA-m6vw-rhwf-xjxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6vw-rhwf-xjxq",
- "modified": "2023-10-17T00:30:17Z",
+ "modified": "2024-04-04T08:42:11Z",
"published": "2023-10-17T00:30:17Z",
"aliases": [
"CVE-2023-4215"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m745-jcvj-8cx6/GHSA-m745-jcvj-8cx6.json b/advisories/unreviewed/2023/10/GHSA-m745-jcvj-8cx6/GHSA-m745-jcvj-8cx6.json
index 09b35585c2f..f40f1f36702 100644
--- a/advisories/unreviewed/2023/10/GHSA-m745-jcvj-8cx6/GHSA-m745-jcvj-8cx6.json
+++ b/advisories/unreviewed/2023/10/GHSA-m745-jcvj-8cx6/GHSA-m745-jcvj-8cx6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m745-jcvj-8cx6",
- "modified": "2023-10-18T12:30:20Z",
+ "modified": "2024-04-04T08:45:59Z",
"published": "2023-10-18T12:30:20Z",
"aliases": [
"CVE-2023-45727"
],
"details": "Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-611"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T10:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m79x-fpgm-vgr7/GHSA-m79x-fpgm-vgr7.json b/advisories/unreviewed/2023/10/GHSA-m79x-fpgm-vgr7/GHSA-m79x-fpgm-vgr7.json
index 02f51afb149..2389ab8f5c6 100644
--- a/advisories/unreviewed/2023/10/GHSA-m79x-fpgm-vgr7/GHSA-m79x-fpgm-vgr7.json
+++ b/advisories/unreviewed/2023/10/GHSA-m79x-fpgm-vgr7/GHSA-m79x-fpgm-vgr7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m79x-fpgm-vgr7",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:18Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-23632"
],
"details": "BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-287"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T20:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json b/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json
index e6e18b83287..a176e611193 100644
--- a/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7jf-8pgq-2mqc",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:29Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45646"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m8hv-934h-rrx4/GHSA-m8hv-934h-rrx4.json b/advisories/unreviewed/2023/10/GHSA-m8hv-934h-rrx4/GHSA-m8hv-934h-rrx4.json
index adc564546eb..632b52d37df 100644
--- a/advisories/unreviewed/2023/10/GHSA-m8hv-934h-rrx4/GHSA-m8hv-934h-rrx4.json
+++ b/advisories/unreviewed/2023/10/GHSA-m8hv-934h-rrx4/GHSA-m8hv-934h-rrx4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8hv-934h-rrx4",
- "modified": "2023-10-18T21:33:11Z",
+ "modified": "2024-04-04T08:39:44Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-3392"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m8m2-8cm8-p8jv/GHSA-m8m2-8cm8-p8jv.json b/advisories/unreviewed/2023/10/GHSA-m8m2-8cm8-p8jv/GHSA-m8m2-8cm8-p8jv.json
index 5d67f3d838d..947eecc4c75 100644
--- a/advisories/unreviewed/2023/10/GHSA-m8m2-8cm8-p8jv/GHSA-m8m2-8cm8-p8jv.json
+++ b/advisories/unreviewed/2023/10/GHSA-m8m2-8cm8-p8jv/GHSA-m8m2-8cm8-p8jv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8m2-8cm8-p8jv",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:37Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-27813"
@@ -28,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-1260"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m8qw-xmhp-rq5v/GHSA-m8qw-xmhp-rq5v.json b/advisories/unreviewed/2023/10/GHSA-m8qw-xmhp-rq5v/GHSA-m8qw-xmhp-rq5v.json
index ac0f7a8940e..a030488b0d3 100644
--- a/advisories/unreviewed/2023/10/GHSA-m8qw-xmhp-rq5v/GHSA-m8qw-xmhp-rq5v.json
+++ b/advisories/unreviewed/2023/10/GHSA-m8qw-xmhp-rq5v/GHSA-m8qw-xmhp-rq5v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8qw-xmhp-rq5v",
- "modified": "2023-10-24T15:31:18Z",
+ "modified": "2024-04-04T08:41:13Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-29484"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-863"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m95x-53px-rf76/GHSA-m95x-53px-rf76.json b/advisories/unreviewed/2023/10/GHSA-m95x-53px-rf76/GHSA-m95x-53px-rf76.json
index d2710e9fb6f..a3560e84f7c 100644
--- a/advisories/unreviewed/2023/10/GHSA-m95x-53px-rf76/GHSA-m95x-53px-rf76.json
+++ b/advisories/unreviewed/2023/10/GHSA-m95x-53px-rf76/GHSA-m95x-53px-rf76.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m95x-53px-rf76",
- "modified": "2023-10-30T12:30:30Z",
+ "modified": "2024-04-04T08:51:06Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5121"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json b/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json
index 8b96b8c7a34..b43ea25fe6d 100644
--- a/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json
+++ b/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m98r-vcx2-w27j",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:18Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46537"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m9mf-9j6p-6pq4/GHSA-m9mf-9j6p-6pq4.json b/advisories/unreviewed/2023/10/GHSA-m9mf-9j6p-6pq4/GHSA-m9mf-9j6p-6pq4.json
index d4cb9497eae..ac31f722a12 100644
--- a/advisories/unreviewed/2023/10/GHSA-m9mf-9j6p-6pq4/GHSA-m9mf-9j6p-6pq4.json
+++ b/advisories/unreviewed/2023/10/GHSA-m9mf-9j6p-6pq4/GHSA-m9mf-9j6p-6pq4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9mf-9j6p-6pq4",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:52Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45468"
],
"details": "Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-m9q5-2qrh-wq37/GHSA-m9q5-2qrh-wq37.json b/advisories/unreviewed/2023/10/GHSA-m9q5-2qrh-wq37/GHSA-m9q5-2qrh-wq37.json
index 7f0dc75bd1e..3711cc3e051 100644
--- a/advisories/unreviewed/2023/10/GHSA-m9q5-2qrh-wq37/GHSA-m9q5-2qrh-wq37.json
+++ b/advisories/unreviewed/2023/10/GHSA-m9q5-2qrh-wq37/GHSA-m9q5-2qrh-wq37.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m9q5-2qrh-wq37",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:28Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27260"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mc66-gqxj-pwmg/GHSA-mc66-gqxj-pwmg.json b/advisories/unreviewed/2023/10/GHSA-mc66-gqxj-pwmg/GHSA-mc66-gqxj-pwmg.json
index 71d8c150b23..826b3e34ac2 100644
--- a/advisories/unreviewed/2023/10/GHSA-mc66-gqxj-pwmg/GHSA-mc66-gqxj-pwmg.json
+++ b/advisories/unreviewed/2023/10/GHSA-mc66-gqxj-pwmg/GHSA-mc66-gqxj-pwmg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc66-gqxj-pwmg",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:21Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3706"
],
"details": "The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-639"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json b/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json
index 857da27c583..2a2d4b36bac 100644
--- a/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json
+++ b/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc6f-pv36-prr2",
- "modified": "2023-10-27T21:30:23Z",
+ "modified": "2024-04-04T08:57:29Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-32738"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json b/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json
index 6fa0a2c05dc..93c433902d0 100644
--- a/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json
+++ b/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcm3-pfm7-4jqc",
- "modified": "2023-10-25T12:30:35Z",
+ "modified": "2024-04-04T08:51:40Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43355"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mf6p-742g-5xxf/GHSA-mf6p-742g-5xxf.json b/advisories/unreviewed/2023/10/GHSA-mf6p-742g-5xxf/GHSA-mf6p-742g-5xxf.json
index d9f19126363..3ea870b80ce 100644
--- a/advisories/unreviewed/2023/10/GHSA-mf6p-742g-5xxf/GHSA-mf6p-742g-5xxf.json
+++ b/advisories/unreviewed/2023/10/GHSA-mf6p-742g-5xxf/GHSA-mf6p-742g-5xxf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf6p-742g-5xxf",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:39Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45102"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T15:15:47Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mfjh-chmq-4prp/GHSA-mfjh-chmq-4prp.json b/advisories/unreviewed/2023/10/GHSA-mfjh-chmq-4prp/GHSA-mfjh-chmq-4prp.json
index b82d961ec07..65250ac14f7 100644
--- a/advisories/unreviewed/2023/10/GHSA-mfjh-chmq-4prp/GHSA-mfjh-chmq-4prp.json
+++ b/advisories/unreviewed/2023/10/GHSA-mfjh-chmq-4prp/GHSA-mfjh-chmq-4prp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfjh-chmq-4prp",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:07Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45690"
],
"details": "Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mfrv-mqm7-5gq4/GHSA-mfrv-mqm7-5gq4.json b/advisories/unreviewed/2023/10/GHSA-mfrv-mqm7-5gq4/GHSA-mfrv-mqm7-5gq4.json
index dea1c531235..e2f970797d9 100644
--- a/advisories/unreviewed/2023/10/GHSA-mfrv-mqm7-5gq4/GHSA-mfrv-mqm7-5gq4.json
+++ b/advisories/unreviewed/2023/10/GHSA-mfrv-mqm7-5gq4/GHSA-mfrv-mqm7-5gq4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfrv-mqm7-5gq4",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:49Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-46076"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mhh8-w4c2-86mr/GHSA-mhh8-w4c2-86mr.json b/advisories/unreviewed/2023/10/GHSA-mhh8-w4c2-86mr/GHSA-mhh8-w4c2-86mr.json
index 8fec9420f0a..6b88d8b6218 100644
--- a/advisories/unreviewed/2023/10/GHSA-mhh8-w4c2-86mr/GHSA-mhh8-w4c2-86mr.json
+++ b/advisories/unreviewed/2023/10/GHSA-mhh8-w4c2-86mr/GHSA-mhh8-w4c2-86mr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhh8-w4c2-86mr",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:08Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5308"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mj48-4fj3-6fjg/GHSA-mj48-4fj3-6fjg.json b/advisories/unreviewed/2023/10/GHSA-mj48-4fj3-6fjg/GHSA-mj48-4fj3-6fjg.json
index 06958bbdfda..a76e5fdf5fb 100644
--- a/advisories/unreviewed/2023/10/GHSA-mj48-4fj3-6fjg/GHSA-mj48-4fj3-6fjg.json
+++ b/advisories/unreviewed/2023/10/GHSA-mj48-4fj3-6fjg/GHSA-mj48-4fj3-6fjg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj48-4fj3-6fjg",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:15Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-34044"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T09:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mjf7-677g-49gx/GHSA-mjf7-677g-49gx.json b/advisories/unreviewed/2023/10/GHSA-mjf7-677g-49gx/GHSA-mjf7-677g-49gx.json
index cc4999952b2..6eab43430c3 100644
--- a/advisories/unreviewed/2023/10/GHSA-mjf7-677g-49gx/GHSA-mjf7-677g-49gx.json
+++ b/advisories/unreviewed/2023/10/GHSA-mjf7-677g-49gx/GHSA-mjf7-677g-49gx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjf7-677g-49gx",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:52Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45056"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T09:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mjq5-3fch-g47q/GHSA-mjq5-3fch-g47q.json b/advisories/unreviewed/2023/10/GHSA-mjq5-3fch-g47q/GHSA-mjq5-3fch-g47q.json
index e6bcb7639f0..21b61230848 100644
--- a/advisories/unreviewed/2023/10/GHSA-mjq5-3fch-g47q/GHSA-mjq5-3fch-g47q.json
+++ b/advisories/unreviewed/2023/10/GHSA-mjq5-3fch-g47q/GHSA-mjq5-3fch-g47q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjq5-3fch-g47q",
- "modified": "2023-10-19T18:30:29Z",
+ "modified": "2024-04-04T08:45:21Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-39280"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mm53-7fpm-65wv/GHSA-mm53-7fpm-65wv.json b/advisories/unreviewed/2023/10/GHSA-mm53-7fpm-65wv/GHSA-mm53-7fpm-65wv.json
index 99cbba97203..1b701684649 100644
--- a/advisories/unreviewed/2023/10/GHSA-mm53-7fpm-65wv/GHSA-mm53-7fpm-65wv.json
+++ b/advisories/unreviewed/2023/10/GHSA-mm53-7fpm-65wv/GHSA-mm53-7fpm-65wv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm53-7fpm-65wv",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:24Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22089"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json
index eb2a5c428ec..c5b46c78de0 100644
--- a/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json
+++ b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm89-gccr-q279",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:25Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2022-3429"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mphg-9rp5-xxj5/GHSA-mphg-9rp5-xxj5.json b/advisories/unreviewed/2023/10/GHSA-mphg-9rp5-xxj5/GHSA-mphg-9rp5-xxj5.json
index ce6327922b3..2760c1f3a67 100644
--- a/advisories/unreviewed/2023/10/GHSA-mphg-9rp5-xxj5/GHSA-mphg-9rp5-xxj5.json
+++ b/advisories/unreviewed/2023/10/GHSA-mphg-9rp5-xxj5/GHSA-mphg-9rp5-xxj5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mphg-9rp5-xxj5",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:03Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22130"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json b/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json
index 76b3ce3c5a1..b5849fb08cd 100644
--- a/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json
+++ b/advisories/unreviewed/2023/10/GHSA-mqx8-vg45-6p4q/GHSA-mqx8-vg45-6p4q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqx8-vg45-6p4q",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:34Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4687"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json b/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json
index 0c1050b59dd..52e6c1f03ff 100644
--- a/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json
+++ b/advisories/unreviewed/2023/10/GHSA-mrh7-ghhj-6r6w/GHSA-mrh7-ghhj-6r6w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mrh7-ghhj-6r6w",
- "modified": "2023-10-26T18:30:22Z",
+ "modified": "2024-04-04T08:49:17Z",
"published": "2023-10-20T00:30:25Z",
"aliases": [
"CVE-2023-39731"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T00:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mrmx-w3x5-x556/GHSA-mrmx-w3x5-x556.json b/advisories/unreviewed/2023/10/GHSA-mrmx-w3x5-x556/GHSA-mrmx-w3x5-x556.json
index 98b36b4ddc4..e6d5b64b55d 100644
--- a/advisories/unreviewed/2023/10/GHSA-mrmx-w3x5-x556/GHSA-mrmx-w3x5-x556.json
+++ b/advisories/unreviewed/2023/10/GHSA-mrmx-w3x5-x556/GHSA-mrmx-w3x5-x556.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mrmx-w3x5-x556",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:20Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22088"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mvgw-crv9-m67p/GHSA-mvgw-crv9-m67p.json b/advisories/unreviewed/2023/10/GHSA-mvgw-crv9-m67p/GHSA-mvgw-crv9-m67p.json
index 4708d479c11..d34622c55e6 100644
--- a/advisories/unreviewed/2023/10/GHSA-mvgw-crv9-m67p/GHSA-mvgw-crv9-m67p.json
+++ b/advisories/unreviewed/2023/10/GHSA-mvgw-crv9-m67p/GHSA-mvgw-crv9-m67p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvgw-crv9-m67p",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:22Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-32973"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mw6g-jfc3-6x9v/GHSA-mw6g-jfc3-6x9v.json b/advisories/unreviewed/2023/10/GHSA-mw6g-jfc3-6x9v/GHSA-mw6g-jfc3-6x9v.json
index 667cd095855..72bf338ae2d 100644
--- a/advisories/unreviewed/2023/10/GHSA-mw6g-jfc3-6x9v/GHSA-mw6g-jfc3-6x9v.json
+++ b/advisories/unreviewed/2023/10/GHSA-mw6g-jfc3-6x9v/GHSA-mw6g-jfc3-6x9v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw6g-jfc3-6x9v",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:33Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-34209"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-497"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mwvw-6ggj-fhv5/GHSA-mwvw-6ggj-fhv5.json b/advisories/unreviewed/2023/10/GHSA-mwvw-6ggj-fhv5/GHSA-mwvw-6ggj-fhv5.json
index fa6e5cdbbfb..66d96c6ea1a 100644
--- a/advisories/unreviewed/2023/10/GHSA-mwvw-6ggj-fhv5/GHSA-mwvw-6ggj-fhv5.json
+++ b/advisories/unreviewed/2023/10/GHSA-mwvw-6ggj-fhv5/GHSA-mwvw-6ggj-fhv5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwvw-6ggj-fhv5",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:09Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28803"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-290"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mwx4-p8m2-4p2h/GHSA-mwx4-p8m2-4p2h.json b/advisories/unreviewed/2023/10/GHSA-mwx4-p8m2-4p2h/GHSA-mwx4-p8m2-4p2h.json
index 27fb201600d..7bc2065c35f 100644
--- a/advisories/unreviewed/2023/10/GHSA-mwx4-p8m2-4p2h/GHSA-mwx4-p8m2-4p2h.json
+++ b/advisories/unreviewed/2023/10/GHSA-mwx4-p8m2-4p2h/GHSA-mwx4-p8m2-4p2h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwx4-p8m2-4p2h",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:38:00Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45109"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mx2h-qjgg-2vv4/GHSA-mx2h-qjgg-2vv4.json b/advisories/unreviewed/2023/10/GHSA-mx2h-qjgg-2vv4/GHSA-mx2h-qjgg-2vv4.json
index d97fb5dcc2e..1bf720c9cdf 100644
--- a/advisories/unreviewed/2023/10/GHSA-mx2h-qjgg-2vv4/GHSA-mx2h-qjgg-2vv4.json
+++ b/advisories/unreviewed/2023/10/GHSA-mx2h-qjgg-2vv4/GHSA-mx2h-qjgg-2vv4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx2h-qjgg-2vv4",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:48Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45465"
],
"details": "Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-mxc9-v9vg-4xfw/GHSA-mxc9-v9vg-4xfw.json b/advisories/unreviewed/2023/10/GHSA-mxc9-v9vg-4xfw/GHSA-mxc9-v9vg-4xfw.json
index ce309026f5d..b6d994368e5 100644
--- a/advisories/unreviewed/2023/10/GHSA-mxc9-v9vg-4xfw/GHSA-mxc9-v9vg-4xfw.json
+++ b/advisories/unreviewed/2023/10/GHSA-mxc9-v9vg-4xfw/GHSA-mxc9-v9vg-4xfw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxc9-v9vg-4xfw",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:32Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4021"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json b/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json
index 226ba19af84..5b5f1063130 100644
--- a/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json
+++ b/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p28p-p2pv-wq98",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:23Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45634"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p32x-38hp-2r9x/GHSA-p32x-38hp-2r9x.json b/advisories/unreviewed/2023/10/GHSA-p32x-38hp-2r9x/GHSA-p32x-38hp-2r9x.json
index 895f29540e5..c5cb4aaf84b 100644
--- a/advisories/unreviewed/2023/10/GHSA-p32x-38hp-2r9x/GHSA-p32x-38hp-2r9x.json
+++ b/advisories/unreviewed/2023/10/GHSA-p32x-38hp-2r9x/GHSA-p32x-38hp-2r9x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p32x-38hp-2r9x",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:26Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-43893"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p3c7-jpcr-hr4q/GHSA-p3c7-jpcr-hr4q.json b/advisories/unreviewed/2023/10/GHSA-p3c7-jpcr-hr4q/GHSA-p3c7-jpcr-hr4q.json
index d99e14b9f51..e9b4b85a69a 100644
--- a/advisories/unreviewed/2023/10/GHSA-p3c7-jpcr-hr4q/GHSA-p3c7-jpcr-hr4q.json
+++ b/advisories/unreviewed/2023/10/GHSA-p3c7-jpcr-hr4q/GHSA-p3c7-jpcr-hr4q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3c7-jpcr-hr4q",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:53Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-45005"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json b/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json
index 2c4562ff58d..de5270475d8 100644
--- a/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json
+++ b/advisories/unreviewed/2023/10/GHSA-p3m2-9555-cgrw/GHSA-p3m2-9555-cgrw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3m2-9555-cgrw",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:35Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4691"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p3qx-72c8-xc9p/GHSA-p3qx-72c8-xc9p.json b/advisories/unreviewed/2023/10/GHSA-p3qx-72c8-xc9p/GHSA-p3qx-72c8-xc9p.json
index 24748818d96..570b06e4da9 100644
--- a/advisories/unreviewed/2023/10/GHSA-p3qx-72c8-xc9p/GHSA-p3qx-72c8-xc9p.json
+++ b/advisories/unreviewed/2023/10/GHSA-p3qx-72c8-xc9p/GHSA-p3qx-72c8-xc9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3qx-72c8-xc9p",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:41:44Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4811"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p42g-23f7-4prj/GHSA-p42g-23f7-4prj.json b/advisories/unreviewed/2023/10/GHSA-p42g-23f7-4prj/GHSA-p42g-23f7-4prj.json
index d2b7fd30d4b..0cd5088960a 100644
--- a/advisories/unreviewed/2023/10/GHSA-p42g-23f7-4prj/GHSA-p42g-23f7-4prj.json
+++ b/advisories/unreviewed/2023/10/GHSA-p42g-23f7-4prj/GHSA-p42g-23f7-4prj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p42g-23f7-4prj",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:51Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-36857"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-294"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T00:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p47p-mr97-m42h/GHSA-p47p-mr97-m42h.json b/advisories/unreviewed/2023/10/GHSA-p47p-mr97-m42h/GHSA-p47p-mr97-m42h.json
index 4338ba920c7..b3052860c22 100644
--- a/advisories/unreviewed/2023/10/GHSA-p47p-mr97-m42h/GHSA-p47p-mr97-m42h.json
+++ b/advisories/unreviewed/2023/10/GHSA-p47p-mr97-m42h/GHSA-p47p-mr97-m42h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p47p-mr97-m42h",
- "modified": "2023-10-25T21:30:26Z",
+ "modified": "2024-04-04T08:48:54Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-45381"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json b/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json
index 5b7a862e6fe..6ee93eb9b01 100644
--- a/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json
+++ b/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p492-rhv2-844c",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:23Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27258"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json b/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json
index 060dadf2f69..76e4e751f8f 100644
--- a/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json
+++ b/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4f9-fq6j-5cff",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:35Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45755"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p54m-3wc3-2mv6/GHSA-p54m-3wc3-2mv6.json b/advisories/unreviewed/2023/10/GHSA-p54m-3wc3-2mv6/GHSA-p54m-3wc3-2mv6.json
index 8eb417a6409..3cb83b0f728 100644
--- a/advisories/unreviewed/2023/10/GHSA-p54m-3wc3-2mv6/GHSA-p54m-3wc3-2mv6.json
+++ b/advisories/unreviewed/2023/10/GHSA-p54m-3wc3-2mv6/GHSA-p54m-3wc3-2mv6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p54m-3wc3-2mv6",
- "modified": "2023-10-18T12:30:20Z",
+ "modified": "2024-04-04T08:46:02Z",
"published": "2023-10-18T12:30:20Z",
"aliases": [
"CVE-2023-32088"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T12:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p567-4mpc-fq6p/GHSA-p567-4mpc-fq6p.json b/advisories/unreviewed/2023/10/GHSA-p567-4mpc-fq6p/GHSA-p567-4mpc-fq6p.json
index 7c8a72f9e8a..f84c19d8987 100644
--- a/advisories/unreviewed/2023/10/GHSA-p567-4mpc-fq6p/GHSA-p567-4mpc-fq6p.json
+++ b/advisories/unreviewed/2023/10/GHSA-p567-4mpc-fq6p/GHSA-p567-4mpc-fq6p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p567-4mpc-fq6p",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:53:22Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-46331"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T17:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p583-5mfr-xmp2/GHSA-p583-5mfr-xmp2.json b/advisories/unreviewed/2023/10/GHSA-p583-5mfr-xmp2/GHSA-p583-5mfr-xmp2.json
index ac840109bc2..12daecc22c6 100644
--- a/advisories/unreviewed/2023/10/GHSA-p583-5mfr-xmp2/GHSA-p583-5mfr-xmp2.json
+++ b/advisories/unreviewed/2023/10/GHSA-p583-5mfr-xmp2/GHSA-p583-5mfr-xmp2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p583-5mfr-xmp2",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:21Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-44998"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json b/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json
index 7c456b69545..fb181e83b6c 100644
--- a/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json
+++ b/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p678-r7cm-66fh",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:36Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46563"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p6qf-pwx3-wfwf/GHSA-p6qf-pwx3-wfwf.json b/advisories/unreviewed/2023/10/GHSA-p6qf-pwx3-wfwf/GHSA-p6qf-pwx3-wfwf.json
index 7880aaeab58..0b6135641af 100644
--- a/advisories/unreviewed/2023/10/GHSA-p6qf-pwx3-wfwf/GHSA-p6qf-pwx3-wfwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-p6qf-pwx3-wfwf/GHSA-p6qf-pwx3-wfwf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6qf-pwx3-wfwf",
- "modified": "2023-10-17T12:30:27Z",
+ "modified": "2024-04-04T08:43:04Z",
"published": "2023-10-17T12:30:27Z",
"aliases": [
"CVE-2023-45007"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p78w-ghp7-m4p3/GHSA-p78w-ghp7-m4p3.json b/advisories/unreviewed/2023/10/GHSA-p78w-ghp7-m4p3/GHSA-p78w-ghp7-m4p3.json
index 362bb7fc1c3..6c34705ab16 100644
--- a/advisories/unreviewed/2023/10/GHSA-p78w-ghp7-m4p3/GHSA-p78w-ghp7-m4p3.json
+++ b/advisories/unreviewed/2023/10/GHSA-p78w-ghp7-m4p3/GHSA-p78w-ghp7-m4p3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p78w-ghp7-m4p3",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:21Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45641"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p7g5-687r-f7jc/GHSA-p7g5-687r-f7jc.json b/advisories/unreviewed/2023/10/GHSA-p7g5-687r-f7jc/GHSA-p7g5-687r-f7jc.json
index 5460560701a..cf60e010f39 100644
--- a/advisories/unreviewed/2023/10/GHSA-p7g5-687r-f7jc/GHSA-p7g5-687r-f7jc.json
+++ b/advisories/unreviewed/2023/10/GHSA-p7g5-687r-f7jc/GHSA-p7g5-687r-f7jc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7g5-687r-f7jc",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:17Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-43148"
],
"details": "SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T19:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json b/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json
index 778466dc364..d806f2b6da8 100644
--- a/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json
+++ b/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7jx-m4x8-cghf",
- "modified": "2023-10-18T18:31:38Z",
+ "modified": "2024-04-04T08:46:37Z",
"published": "2023-10-18T18:31:38Z",
"aliases": [
"CVE-2023-45912"
],
"details": "WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json b/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json
index 30c2f1e9282..f84b1f94bd8 100644
--- a/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json
+++ b/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7q4-fcj5-j6x7",
- "modified": "2023-10-20T21:31:00Z",
+ "modified": "2024-04-04T08:42:03Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5167"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p8w3-h8rp-r2hj/GHSA-p8w3-h8rp-r2hj.json b/advisories/unreviewed/2023/10/GHSA-p8w3-h8rp-r2hj/GHSA-p8w3-h8rp-r2hj.json
index fcab10ddf08..a632a0cd8ac 100644
--- a/advisories/unreviewed/2023/10/GHSA-p8w3-h8rp-r2hj/GHSA-p8w3-h8rp-r2hj.json
+++ b/advisories/unreviewed/2023/10/GHSA-p8w3-h8rp-r2hj/GHSA-p8w3-h8rp-r2hj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8w3-h8rp-r2hj",
- "modified": "2023-10-26T21:30:20Z",
+ "modified": "2024-04-04T08:56:59Z",
"published": "2023-10-26T21:30:20Z",
"aliases": [
"CVE-2023-0897"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-384"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p96p-f58w-gwc6/GHSA-p96p-f58w-gwc6.json b/advisories/unreviewed/2023/10/GHSA-p96p-f58w-gwc6/GHSA-p96p-f58w-gwc6.json
index 15ff7dc4d3e..60624c09af2 100644
--- a/advisories/unreviewed/2023/10/GHSA-p96p-f58w-gwc6/GHSA-p96p-f58w-gwc6.json
+++ b/advisories/unreviewed/2023/10/GHSA-p96p-f58w-gwc6/GHSA-p96p-f58w-gwc6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p96p-f58w-gwc6",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:23Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-43121"
],
"details": "A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-p9mf-x9hh-r538/GHSA-p9mf-x9hh-r538.json b/advisories/unreviewed/2023/10/GHSA-p9mf-x9hh-r538/GHSA-p9mf-x9hh-r538.json
index 18a4ceb0988..b291f99d5bb 100644
--- a/advisories/unreviewed/2023/10/GHSA-p9mf-x9hh-r538/GHSA-p9mf-x9hh-r538.json
+++ b/advisories/unreviewed/2023/10/GHSA-p9mf-x9hh-r538/GHSA-p9mf-x9hh-r538.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9mf-x9hh-r538",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:25Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-34976"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json b/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json
index d0d4943be71..09aedf33d54 100644
--- a/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json
+++ b/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc6g-crww-hwrf",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:57:28Z",
"published": "2023-10-27T21:30:22Z",
"aliases": [
"CVE-2023-46289"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T19:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json b/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json
index 641a7827157..b572e84f260 100644
--- a/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json
+++ b/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfv4-p727-hwgq",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:21Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27256"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json
index f546d8af60a..baecd36fd41 100644
--- a/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json
+++ b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfwv-624m-h3m9",
- "modified": "2023-10-28T00:30:29Z",
+ "modified": "2024-04-04T08:51:32Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-38191"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pg47-79wc-w499/GHSA-pg47-79wc-w499.json b/advisories/unreviewed/2023/10/GHSA-pg47-79wc-w499/GHSA-pg47-79wc-w499.json
index ad9e52b0da4..67df107fec6 100644
--- a/advisories/unreviewed/2023/10/GHSA-pg47-79wc-w499/GHSA-pg47-79wc-w499.json
+++ b/advisories/unreviewed/2023/10/GHSA-pg47-79wc-w499/GHSA-pg47-79wc-w499.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pg47-79wc-w499",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:41Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45103"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T15:15:47Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pgcm-23q3-r64w/GHSA-pgcm-23q3-r64w.json b/advisories/unreviewed/2023/10/GHSA-pgcm-23q3-r64w/GHSA-pgcm-23q3-r64w.json
index 2899d54c30d..ba72e4e1f36 100644
--- a/advisories/unreviewed/2023/10/GHSA-pgcm-23q3-r64w/GHSA-pgcm-23q3-r64w.json
+++ b/advisories/unreviewed/2023/10/GHSA-pgcm-23q3-r64w/GHSA-pgcm-23q3-r64w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pgcm-23q3-r64w",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:46Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45273"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pj73-2q4q-jx35/GHSA-pj73-2q4q-jx35.json b/advisories/unreviewed/2023/10/GHSA-pj73-2q4q-jx35/GHSA-pj73-2q4q-jx35.json
index c53a7f8f053..221f6c2d747 100644
--- a/advisories/unreviewed/2023/10/GHSA-pj73-2q4q-jx35/GHSA-pj73-2q4q-jx35.json
+++ b/advisories/unreviewed/2023/10/GHSA-pj73-2q4q-jx35/GHSA-pj73-2q4q-jx35.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj73-2q4q-jx35",
- "modified": "2023-10-17T03:32:42Z",
+ "modified": "2024-04-04T08:42:14Z",
"published": "2023-10-17T03:32:42Z",
"aliases": [
"CVE-2022-22384"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T01:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pj99-jgm5-c727/GHSA-pj99-jgm5-c727.json b/advisories/unreviewed/2023/10/GHSA-pj99-jgm5-c727/GHSA-pj99-jgm5-c727.json
index c6d02e235ab..c6156334283 100644
--- a/advisories/unreviewed/2023/10/GHSA-pj99-jgm5-c727/GHSA-pj99-jgm5-c727.json
+++ b/advisories/unreviewed/2023/10/GHSA-pj99-jgm5-c727/GHSA-pj99-jgm5-c727.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj99-jgm5-c727",
- "modified": "2023-10-26T06:30:25Z",
+ "modified": "2024-04-04T08:56:40Z",
"published": "2023-10-26T06:30:25Z",
"aliases": [
"CVE-2023-46754"
],
"details": "The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T05:15:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pjgc-6mr2-9jx3/GHSA-pjgc-6mr2-9jx3.json b/advisories/unreviewed/2023/10/GHSA-pjgc-6mr2-9jx3/GHSA-pjgc-6mr2-9jx3.json
index cca66ced4e0..ecc9edcf92a 100644
--- a/advisories/unreviewed/2023/10/GHSA-pjgc-6mr2-9jx3/GHSA-pjgc-6mr2-9jx3.json
+++ b/advisories/unreviewed/2023/10/GHSA-pjgc-6mr2-9jx3/GHSA-pjgc-6mr2-9jx3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjgc-6mr2-9jx3",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:24Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45642"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json
index 619b0625b16..1f0fdaec733 100644
--- a/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json
+++ b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjgc-q78w-v6ph",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:41Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40128"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pjgq-qrmj-w46x/GHSA-pjgq-qrmj-w46x.json b/advisories/unreviewed/2023/10/GHSA-pjgq-qrmj-w46x/GHSA-pjgq-qrmj-w46x.json
index f0b33420c3a..a84b2c1bdb5 100644
--- a/advisories/unreviewed/2023/10/GHSA-pjgq-qrmj-w46x/GHSA-pjgq-qrmj-w46x.json
+++ b/advisories/unreviewed/2023/10/GHSA-pjgq-qrmj-w46x/GHSA-pjgq-qrmj-w46x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjgq-qrmj-w46x",
- "modified": "2023-10-30T21:33:39Z",
+ "modified": "2024-04-04T08:53:23Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-46332"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T16:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pmmx-5xxg-mxh5/GHSA-pmmx-5xxg-mxh5.json b/advisories/unreviewed/2023/10/GHSA-pmmx-5xxg-mxh5/GHSA-pmmx-5xxg-mxh5.json
index 1119021d1cf..b01c89df5a4 100644
--- a/advisories/unreviewed/2023/10/GHSA-pmmx-5xxg-mxh5/GHSA-pmmx-5xxg-mxh5.json
+++ b/advisories/unreviewed/2023/10/GHSA-pmmx-5xxg-mxh5/GHSA-pmmx-5xxg-mxh5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmmx-5xxg-mxh5",
- "modified": "2023-10-18T18:31:37Z",
+ "modified": "2024-04-04T08:46:31Z",
"published": "2023-10-18T18:31:37Z",
"aliases": [
"CVE-2023-45383"
],
"details": "In the module \"SoNice etiquetage\" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T16:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json b/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json
index 1cf31b340e3..78cc10e1bd3 100644
--- a/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json
+++ b/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqgv-m3cr-37hw",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:55Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5087"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pr44-2445-9366/GHSA-pr44-2445-9366.json b/advisories/unreviewed/2023/10/GHSA-pr44-2445-9366/GHSA-pr44-2445-9366.json
index a6950a922a2..4214075a9dc 100644
--- a/advisories/unreviewed/2023/10/GHSA-pr44-2445-9366/GHSA-pr44-2445-9366.json
+++ b/advisories/unreviewed/2023/10/GHSA-pr44-2445-9366/GHSA-pr44-2445-9366.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pr44-2445-9366",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:43Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2022-43740"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-prmr-w665-vw34/GHSA-prmr-w665-vw34.json b/advisories/unreviewed/2023/10/GHSA-prmr-w665-vw34/GHSA-prmr-w665-vw34.json
index 36ee36cbe34..b8f98289dd9 100644
--- a/advisories/unreviewed/2023/10/GHSA-prmr-w665-vw34/GHSA-prmr-w665-vw34.json
+++ b/advisories/unreviewed/2023/10/GHSA-prmr-w665-vw34/GHSA-prmr-w665-vw34.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-prmr-w665-vw34",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:13Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5337"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pv22-ff8w-9h7r/GHSA-pv22-ff8w-9h7r.json b/advisories/unreviewed/2023/10/GHSA-pv22-ff8w-9h7r/GHSA-pv22-ff8w-9h7r.json
index b87f5792cc4..cbcd6a7931b 100644
--- a/advisories/unreviewed/2023/10/GHSA-pv22-ff8w-9h7r/GHSA-pv22-ff8w-9h7r.json
+++ b/advisories/unreviewed/2023/10/GHSA-pv22-ff8w-9h7r/GHSA-pv22-ff8w-9h7r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv22-ff8w-9h7r",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:15Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-27314"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T19:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pv8r-9v7r-hr5c/GHSA-pv8r-9v7r-hr5c.json b/advisories/unreviewed/2023/10/GHSA-pv8r-9v7r-hr5c/GHSA-pv8r-9v7r-hr5c.json
index 9a968efb692..dc893286239 100644
--- a/advisories/unreviewed/2023/10/GHSA-pv8r-9v7r-hr5c/GHSA-pv8r-9v7r-hr5c.json
+++ b/advisories/unreviewed/2023/10/GHSA-pv8r-9v7r-hr5c/GHSA-pv8r-9v7r-hr5c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv8r-9v7r-hr5c",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:59Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4943"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pvjf-v9wm-73fj/GHSA-pvjf-v9wm-73fj.json b/advisories/unreviewed/2023/10/GHSA-pvjf-v9wm-73fj/GHSA-pvjf-v9wm-73fj.json
index 5a186efcdaf..55115a21d0a 100644
--- a/advisories/unreviewed/2023/10/GHSA-pvjf-v9wm-73fj/GHSA-pvjf-v9wm-73fj.json
+++ b/advisories/unreviewed/2023/10/GHSA-pvjf-v9wm-73fj/GHSA-pvjf-v9wm-73fj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvjf-v9wm-73fj",
- "modified": "2023-10-18T00:31:43Z",
+ "modified": "2024-04-04T08:45:34Z",
"published": "2023-10-18T00:31:43Z",
"aliases": [
"CVE-2023-22128"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pwfh-gp98-cccx/GHSA-pwfh-gp98-cccx.json b/advisories/unreviewed/2023/10/GHSA-pwfh-gp98-cccx/GHSA-pwfh-gp98-cccx.json
index f786e614d21..54aa208efbd 100644
--- a/advisories/unreviewed/2023/10/GHSA-pwfh-gp98-cccx/GHSA-pwfh-gp98-cccx.json
+++ b/advisories/unreviewed/2023/10/GHSA-pwfh-gp98-cccx/GHSA-pwfh-gp98-cccx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwfh-gp98-cccx",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:43Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-40153"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pwfx-qrrf-76cp/GHSA-pwfx-qrrf-76cp.json b/advisories/unreviewed/2023/10/GHSA-pwfx-qrrf-76cp/GHSA-pwfx-qrrf-76cp.json
index 706f424eb5e..37ee7a6c742 100644
--- a/advisories/unreviewed/2023/10/GHSA-pwfx-qrrf-76cp/GHSA-pwfx-qrrf-76cp.json
+++ b/advisories/unreviewed/2023/10/GHSA-pwfx-qrrf-76cp/GHSA-pwfx-qrrf-76cp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwfx-qrrf-76cp",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:39Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44177"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-pxfv-24mx-mrvc/GHSA-pxfv-24mx-mrvc.json b/advisories/unreviewed/2023/10/GHSA-pxfv-24mx-mrvc/GHSA-pxfv-24mx-mrvc.json
index ca9e66f5a28..51dea073814 100644
--- a/advisories/unreviewed/2023/10/GHSA-pxfv-24mx-mrvc/GHSA-pxfv-24mx-mrvc.json
+++ b/advisories/unreviewed/2023/10/GHSA-pxfv-24mx-mrvc/GHSA-pxfv-24mx-mrvc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxfv-24mx-mrvc",
- "modified": "2023-10-17T09:30:22Z",
+ "modified": "2024-04-04T08:42:44Z",
"published": "2023-10-17T09:30:22Z",
"aliases": [
"CVE-2023-4089"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-610"
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T07:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q235-62fh-xp9w/GHSA-q235-62fh-xp9w.json b/advisories/unreviewed/2023/10/GHSA-q235-62fh-xp9w/GHSA-q235-62fh-xp9w.json
index ee063ddbbbf..58730b24020 100644
--- a/advisories/unreviewed/2023/10/GHSA-q235-62fh-xp9w/GHSA-q235-62fh-xp9w.json
+++ b/advisories/unreviewed/2023/10/GHSA-q235-62fh-xp9w/GHSA-q235-62fh-xp9w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q235-62fh-xp9w",
- "modified": "2023-10-19T03:30:28Z",
+ "modified": "2024-04-04T08:46:57Z",
"published": "2023-10-19T03:30:28Z",
"aliases": [
"CVE-2023-5638"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json b/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json
index 2a976a9003f..0ccb844c0dd 100644
--- a/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json
+++ b/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2mj-6ff7-3gvh",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:38Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27257"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q438-9265-rccj/GHSA-q438-9265-rccj.json b/advisories/unreviewed/2023/10/GHSA-q438-9265-rccj/GHSA-q438-9265-rccj.json
index d4f0223a34b..7681c80857c 100644
--- a/advisories/unreviewed/2023/10/GHSA-q438-9265-rccj/GHSA-q438-9265-rccj.json
+++ b/advisories/unreviewed/2023/10/GHSA-q438-9265-rccj/GHSA-q438-9265-rccj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q438-9265-rccj",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:19Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-3279"
],
"details": "The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json
index 3db10dce933..c618e14828e 100644
--- a/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json
+++ b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q499-4369-cpxq",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:46Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40133"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q4q3-fg32-45m8/GHSA-q4q3-fg32-45m8.json b/advisories/unreviewed/2023/10/GHSA-q4q3-fg32-45m8/GHSA-q4q3-fg32-45m8.json
index 88e2c5e5d78..211ffad40fd 100644
--- a/advisories/unreviewed/2023/10/GHSA-q4q3-fg32-45m8/GHSA-q4q3-fg32-45m8.json
+++ b/advisories/unreviewed/2023/10/GHSA-q4q3-fg32-45m8/GHSA-q4q3-fg32-45m8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4q3-fg32-45m8",
- "modified": "2023-10-31T15:30:19Z",
+ "modified": "2024-04-04T08:53:53Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-1356"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:22Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q5cp-3jrf-3q9p/GHSA-q5cp-3jrf-3q9p.json b/advisories/unreviewed/2023/10/GHSA-q5cp-3jrf-3q9p/GHSA-q5cp-3jrf-3q9p.json
index 6647e7c4b46..6221e45231e 100644
--- a/advisories/unreviewed/2023/10/GHSA-q5cp-3jrf-3q9p/GHSA-q5cp-3jrf-3q9p.json
+++ b/advisories/unreviewed/2023/10/GHSA-q5cp-3jrf-3q9p/GHSA-q5cp-3jrf-3q9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5cp-3jrf-3q9p",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:29Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-29973"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-770"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:27Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q5mg-3r24-hvx2/GHSA-q5mg-3r24-hvx2.json b/advisories/unreviewed/2023/10/GHSA-q5mg-3r24-hvx2/GHSA-q5mg-3r24-hvx2.json
index d5afa39350b..cfb8e424bac 100644
--- a/advisories/unreviewed/2023/10/GHSA-q5mg-3r24-hvx2/GHSA-q5mg-3r24-hvx2.json
+++ b/advisories/unreviewed/2023/10/GHSA-q5mg-3r24-hvx2/GHSA-q5mg-3r24-hvx2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5mg-3r24-hvx2",
- "modified": "2023-10-12T18:30:28Z",
+ "modified": "2024-04-04T08:36:02Z",
"published": "2023-10-12T18:30:28Z",
"aliases": [
"CVE-2023-32634"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-300"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T16:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json b/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json
index b8bf3c7472a..feef9d19c65 100644
--- a/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json
+++ b/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5qf-qc2j-h64w",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:33Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45750"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json b/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json
index 1c0ae3d1256..37c42ba594b 100644
--- a/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json
+++ b/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5xh-mxrq-59gx",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:29Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4388"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q62w-24vx-vhfg/GHSA-q62w-24vx-vhfg.json b/advisories/unreviewed/2023/10/GHSA-q62w-24vx-vhfg/GHSA-q62w-24vx-vhfg.json
index e26f70b452c..547fe90bb70 100644
--- a/advisories/unreviewed/2023/10/GHSA-q62w-24vx-vhfg/GHSA-q62w-24vx-vhfg.json
+++ b/advisories/unreviewed/2023/10/GHSA-q62w-24vx-vhfg/GHSA-q62w-24vx-vhfg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q62w-24vx-vhfg",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:45Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45761"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q6rf-xpm8-9wqx/GHSA-q6rf-xpm8-9wqx.json b/advisories/unreviewed/2023/10/GHSA-q6rf-xpm8-9wqx/GHSA-q6rf-xpm8-9wqx.json
index e314923d9a2..73a27920067 100644
--- a/advisories/unreviewed/2023/10/GHSA-q6rf-xpm8-9wqx/GHSA-q6rf-xpm8-9wqx.json
+++ b/advisories/unreviewed/2023/10/GHSA-q6rf-xpm8-9wqx/GHSA-q6rf-xpm8-9wqx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6rf-xpm8-9wqx",
- "modified": "2023-10-17T00:30:17Z",
+ "modified": "2024-04-04T08:42:10Z",
"published": "2023-10-17T00:30:17Z",
"aliases": [
"CVE-2023-45540"
],
"details": "An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-74"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q775-f869-g43r/GHSA-q775-f869-g43r.json b/advisories/unreviewed/2023/10/GHSA-q775-f869-g43r/GHSA-q775-f869-g43r.json
index 9530fcd80fa..bb05550d9d0 100644
--- a/advisories/unreviewed/2023/10/GHSA-q775-f869-g43r/GHSA-q775-f869-g43r.json
+++ b/advisories/unreviewed/2023/10/GHSA-q775-f869-g43r/GHSA-q775-f869-g43r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q775-f869-g43r",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:15Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-46005"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q7vg-v528-qjwj/GHSA-q7vg-v528-qjwj.json b/advisories/unreviewed/2023/10/GHSA-q7vg-v528-qjwj/GHSA-q7vg-v528-qjwj.json
index f30f46dd2a2..11d63d5cd11 100644
--- a/advisories/unreviewed/2023/10/GHSA-q7vg-v528-qjwj/GHSA-q7vg-v528-qjwj.json
+++ b/advisories/unreviewed/2023/10/GHSA-q7vg-v528-qjwj/GHSA-q7vg-v528-qjwj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q7vg-v528-qjwj",
- "modified": "2023-10-14T12:30:23Z",
+ "modified": "2024-04-04T08:38:37Z",
"published": "2023-10-14T12:30:23Z",
"aliases": [
"CVE-2023-1259"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T12:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q84w-p2g5-rxw9/GHSA-q84w-p2g5-rxw9.json b/advisories/unreviewed/2023/10/GHSA-q84w-p2g5-rxw9/GHSA-q84w-p2g5-rxw9.json
index 14af8e66bce..fde2091c880 100644
--- a/advisories/unreviewed/2023/10/GHSA-q84w-p2g5-rxw9/GHSA-q84w-p2g5-rxw9.json
+++ b/advisories/unreviewed/2023/10/GHSA-q84w-p2g5-rxw9/GHSA-q84w-p2g5-rxw9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q84w-p2g5-rxw9",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:28Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-25334"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q8cx-3xf8-m9w4/GHSA-q8cx-3xf8-m9w4.json b/advisories/unreviewed/2023/10/GHSA-q8cx-3xf8-m9w4/GHSA-q8cx-3xf8-m9w4.json
index c9da723b1aa..642b7f6f5d5 100644
--- a/advisories/unreviewed/2023/10/GHSA-q8cx-3xf8-m9w4/GHSA-q8cx-3xf8-m9w4.json
+++ b/advisories/unreviewed/2023/10/GHSA-q8cx-3xf8-m9w4/GHSA-q8cx-3xf8-m9w4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8cx-3xf8-m9w4",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:46:49Z",
"published": "2023-10-19T00:30:19Z",
"aliases": [
"CVE-2023-34441"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T00:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q8pj-w683-cp52/GHSA-q8pj-w683-cp52.json b/advisories/unreviewed/2023/10/GHSA-q8pj-w683-cp52/GHSA-q8pj-w683-cp52.json
index b8b6a685562..0d4dab252c9 100644
--- a/advisories/unreviewed/2023/10/GHSA-q8pj-w683-cp52/GHSA-q8pj-w683-cp52.json
+++ b/advisories/unreviewed/2023/10/GHSA-q8pj-w683-cp52/GHSA-q8pj-w683-cp52.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8pj-w683-cp52",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:56Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22121"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q8w9-3c5w-2mhv/GHSA-q8w9-3c5w-2mhv.json b/advisories/unreviewed/2023/10/GHSA-q8w9-3c5w-2mhv/GHSA-q8w9-3c5w-2mhv.json
index 52215a705cf..f96a74b1100 100644
--- a/advisories/unreviewed/2023/10/GHSA-q8w9-3c5w-2mhv/GHSA-q8w9-3c5w-2mhv.json
+++ b/advisories/unreviewed/2023/10/GHSA-q8w9-3c5w-2mhv/GHSA-q8w9-3c5w-2mhv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8w9-3c5w-2mhv",
- "modified": "2023-10-20T12:31:01Z",
+ "modified": "2024-04-04T08:41:54Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4971"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q92r-cx7h-2f3j/GHSA-q92r-cx7h-2f3j.json b/advisories/unreviewed/2023/10/GHSA-q92r-cx7h-2f3j/GHSA-q92r-cx7h-2f3j.json
index 447b0fde22f..2f4125e3fba 100644
--- a/advisories/unreviewed/2023/10/GHSA-q92r-cx7h-2f3j/GHSA-q92r-cx7h-2f3j.json
+++ b/advisories/unreviewed/2023/10/GHSA-q92r-cx7h-2f3j/GHSA-q92r-cx7h-2f3j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q92r-cx7h-2f3j",
- "modified": "2023-10-28T03:30:21Z",
+ "modified": "2024-04-04T08:52:07Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-46003"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/leekenghwa/CVE-2023-46003"
},
+ {
+ "type": "WEB",
+ "url": "https://medium.com/%40ray.999/stored-xss-in-i-doit-pro-25-and-below-cve-2023-46003-17fb8d6fe2e9"
+ },
{
"type": "WEB",
"url": "https://medium.com/@ray.999/stored-xss-in-i-doit-pro-25-and-below-cve-2023-46003-17fb8d6fe2e9"
@@ -38,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T01:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q98j-84jm-w837/GHSA-q98j-84jm-w837.json b/advisories/unreviewed/2023/10/GHSA-q98j-84jm-w837/GHSA-q98j-84jm-w837.json
index 0ecc04ce351..dffb3f43d39 100644
--- a/advisories/unreviewed/2023/10/GHSA-q98j-84jm-w837/GHSA-q98j-84jm-w837.json
+++ b/advisories/unreviewed/2023/10/GHSA-q98j-84jm-w837/GHSA-q98j-84jm-w837.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q98j-84jm-w837",
- "modified": "2023-10-31T21:32:35Z",
+ "modified": "2024-04-04T08:48:58Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-30633"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-q9v9-cm52-vqj5/GHSA-q9v9-cm52-vqj5.json b/advisories/unreviewed/2023/10/GHSA-q9v9-cm52-vqj5/GHSA-q9v9-cm52-vqj5.json
index 44d366a2339..13d095a77b2 100644
--- a/advisories/unreviewed/2023/10/GHSA-q9v9-cm52-vqj5/GHSA-q9v9-cm52-vqj5.json
+++ b/advisories/unreviewed/2023/10/GHSA-q9v9-cm52-vqj5/GHSA-q9v9-cm52-vqj5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9v9-cm52-vqj5",
- "modified": "2023-10-16T09:30:18Z",
+ "modified": "2024-04-04T08:39:21Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-21414"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T07:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qc92-q864-m3mh/GHSA-qc92-q864-m3mh.json b/advisories/unreviewed/2023/10/GHSA-qc92-q864-m3mh/GHSA-qc92-q864-m3mh.json
index 60864dd3d26..6b1ec3f987b 100644
--- a/advisories/unreviewed/2023/10/GHSA-qc92-q864-m3mh/GHSA-qc92-q864-m3mh.json
+++ b/advisories/unreviewed/2023/10/GHSA-qc92-q864-m3mh/GHSA-qc92-q864-m3mh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc92-q864-m3mh",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:29Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45060"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qfw9-g7jh-72p3/GHSA-qfw9-g7jh-72p3.json b/advisories/unreviewed/2023/10/GHSA-qfw9-g7jh-72p3/GHSA-qfw9-g7jh-72p3.json
index 57983904153..243fb753cd5 100644
--- a/advisories/unreviewed/2023/10/GHSA-qfw9-g7jh-72p3/GHSA-qfw9-g7jh-72p3.json
+++ b/advisories/unreviewed/2023/10/GHSA-qfw9-g7jh-72p3/GHSA-qfw9-g7jh-72p3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfw9-g7jh-72p3",
- "modified": "2023-10-25T03:30:34Z",
+ "modified": "2024-04-04T08:46:13Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45072"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json b/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json
index 4761cf7e57f..24f29c2cc75 100644
--- a/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json
+++ b/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qg2v-xqqh-rxvv",
- "modified": "2023-10-28T00:30:31Z",
+ "modified": "2024-04-04T08:56:27Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46557"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qgg9-7g95-6v4j/GHSA-qgg9-7g95-6v4j.json b/advisories/unreviewed/2023/10/GHSA-qgg9-7g95-6v4j/GHSA-qgg9-7g95-6v4j.json
index f13ca64231b..c54b019428a 100644
--- a/advisories/unreviewed/2023/10/GHSA-qgg9-7g95-6v4j/GHSA-qgg9-7g95-6v4j.json
+++ b/advisories/unreviewed/2023/10/GHSA-qgg9-7g95-6v4j/GHSA-qgg9-7g95-6v4j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgg9-7g95-6v4j",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:27Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45906"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qgm6-p3q3-r5mp/GHSA-qgm6-p3q3-r5mp.json b/advisories/unreviewed/2023/10/GHSA-qgm6-p3q3-r5mp/GHSA-qgm6-p3q3-r5mp.json
index 8400c74c78b..50bb012dbb8 100644
--- a/advisories/unreviewed/2023/10/GHSA-qgm6-p3q3-r5mp/GHSA-qgm6-p3q3-r5mp.json
+++ b/advisories/unreviewed/2023/10/GHSA-qgm6-p3q3-r5mp/GHSA-qgm6-p3q3-r5mp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgm6-p3q3-r5mp",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:47Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2023-45176"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T16:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json
index 842112a64ec..1d27e0de1a6 100644
--- a/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json
+++ b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qh48-5646-82cv",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:43Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40130"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qhc9-rg5r-4qv3/GHSA-qhc9-rg5r-4qv3.json b/advisories/unreviewed/2023/10/GHSA-qhc9-rg5r-4qv3/GHSA-qhc9-rg5r-4qv3.json
index 0344d2814b3..797078b6365 100644
--- a/advisories/unreviewed/2023/10/GHSA-qhc9-rg5r-4qv3/GHSA-qhc9-rg5r-4qv3.json
+++ b/advisories/unreviewed/2023/10/GHSA-qhc9-rg5r-4qv3/GHSA-qhc9-rg5r-4qv3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qhc9-rg5r-4qv3",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:57Z",
"published": "2023-10-26T18:30:23Z",
"aliases": [
"CVE-2023-46435"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T18:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json b/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json
index abe6d7ffa07..355e5c2afba 100644
--- a/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json
+++ b/advisories/unreviewed/2023/10/GHSA-qj3c-jhpr-p28m/GHSA-qj3c-jhpr-p28m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qj3c-jhpr-p28m",
- "modified": "2023-10-25T15:30:21Z",
+ "modified": "2024-04-04T08:48:23Z",
"published": "2023-10-19T15:31:08Z",
"aliases": [
"CVE-2023-46042"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qmhg-c8c8-6m24/GHSA-qmhg-c8c8-6m24.json b/advisories/unreviewed/2023/10/GHSA-qmhg-c8c8-6m24/GHSA-qmhg-c8c8-6m24.json
index ee960f1159f..682c971925f 100644
--- a/advisories/unreviewed/2023/10/GHSA-qmhg-c8c8-6m24/GHSA-qmhg-c8c8-6m24.json
+++ b/advisories/unreviewed/2023/10/GHSA-qmhg-c8c8-6m24/GHSA-qmhg-c8c8-6m24.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmhg-c8c8-6m24",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:04Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22073"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json b/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json
index a3c88fe4577..8250fcff72b 100644
--- a/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json
+++ b/advisories/unreviewed/2023/10/GHSA-qmv3-76vc-754w/GHSA-qmv3-76vc-754w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmv3-76vc-754w",
- "modified": "2023-10-20T15:30:28Z",
+ "modified": "2024-04-04T08:41:51Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4861"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-94"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qp4h-xpf2-fc6c/GHSA-qp4h-xpf2-fc6c.json b/advisories/unreviewed/2023/10/GHSA-qp4h-xpf2-fc6c/GHSA-qp4h-xpf2-fc6c.json
index 8f1d874fdc1..51acdc8dc2b 100644
--- a/advisories/unreviewed/2023/10/GHSA-qp4h-xpf2-fc6c/GHSA-qp4h-xpf2-fc6c.json
+++ b/advisories/unreviewed/2023/10/GHSA-qp4h-xpf2-fc6c/GHSA-qp4h-xpf2-fc6c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp4h-xpf2-fc6c",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:39Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26581"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qpg6-4w2g-v5f5/GHSA-qpg6-4w2g-v5f5.json b/advisories/unreviewed/2023/10/GHSA-qpg6-4w2g-v5f5/GHSA-qpg6-4w2g-v5f5.json
index 8af3c87234a..fc39a02cc21 100644
--- a/advisories/unreviewed/2023/10/GHSA-qpg6-4w2g-v5f5/GHSA-qpg6-4w2g-v5f5.json
+++ b/advisories/unreviewed/2023/10/GHSA-qpg6-4w2g-v5f5/GHSA-qpg6-4w2g-v5f5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpg6-4w2g-v5f5",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:51:12Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-5602"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qq98-52pp-9245/GHSA-qq98-52pp-9245.json b/advisories/unreviewed/2023/10/GHSA-qq98-52pp-9245/GHSA-qq98-52pp-9245.json
index 4ca23261507..311dddaffd2 100644
--- a/advisories/unreviewed/2023/10/GHSA-qq98-52pp-9245/GHSA-qq98-52pp-9245.json
+++ b/advisories/unreviewed/2023/10/GHSA-qq98-52pp-9245/GHSA-qq98-52pp-9245.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qq98-52pp-9245",
- "modified": "2023-10-25T18:32:21Z",
+ "modified": "2024-04-04T08:54:42Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-34085"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-359"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:28Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qqmx-f648-jpq4/GHSA-qqmx-f648-jpq4.json b/advisories/unreviewed/2023/10/GHSA-qqmx-f648-jpq4/GHSA-qqmx-f648-jpq4.json
index a55c9f3e680..bd8d63ef738 100644
--- a/advisories/unreviewed/2023/10/GHSA-qqmx-f648-jpq4/GHSA-qqmx-f648-jpq4.json
+++ b/advisories/unreviewed/2023/10/GHSA-qqmx-f648-jpq4/GHSA-qqmx-f648-jpq4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qqmx-f648-jpq4",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:45Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45753"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:45Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json b/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json
index 1c415276485..d8764c9c718 100644
--- a/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json
+++ b/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr56-4922-vccv",
- "modified": "2023-10-20T18:30:57Z",
+ "modified": "2024-04-04T08:51:30Z",
"published": "2023-10-20T18:30:57Z",
"aliases": [
"CVE-2023-23373"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T17:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qr8h-rg34-whwf/GHSA-qr8h-rg34-whwf.json b/advisories/unreviewed/2023/10/GHSA-qr8h-rg34-whwf/GHSA-qr8h-rg34-whwf.json
index 3b516870401..9877f83d0fc 100644
--- a/advisories/unreviewed/2023/10/GHSA-qr8h-rg34-whwf/GHSA-qr8h-rg34-whwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-qr8h-rg34-whwf/GHSA-qr8h-rg34-whwf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr8h-rg34-whwf",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:02Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45686"
],
"details": "Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json b/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json
index 989d4296f67..920aa2c0bd1 100644
--- a/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json
+++ b/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrhv-m52g-wcw8",
- "modified": "2023-10-30T15:30:44Z",
+ "modified": "2024-04-04T08:49:23Z",
"published": "2023-10-20T06:30:19Z",
"aliases": [
"CVE-2023-34052"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T05:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qrm9-mm7m-8xgw/GHSA-qrm9-mm7m-8xgw.json b/advisories/unreviewed/2023/10/GHSA-qrm9-mm7m-8xgw/GHSA-qrm9-mm7m-8xgw.json
index 5d2a5cb9d2b..879cb259ef4 100644
--- a/advisories/unreviewed/2023/10/GHSA-qrm9-mm7m-8xgw/GHSA-qrm9-mm7m-8xgw.json
+++ b/advisories/unreviewed/2023/10/GHSA-qrm9-mm7m-8xgw/GHSA-qrm9-mm7m-8xgw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrm9-mm7m-8xgw",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:10Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26580"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qvh2-rg4v-27xj/GHSA-qvh2-rg4v-27xj.json b/advisories/unreviewed/2023/10/GHSA-qvh2-rg4v-27xj/GHSA-qvh2-rg4v-27xj.json
index 5490a599d6a..0049ed9bde2 100644
--- a/advisories/unreviewed/2023/10/GHSA-qvh2-rg4v-27xj/GHSA-qvh2-rg4v-27xj.json
+++ b/advisories/unreviewed/2023/10/GHSA-qvh2-rg4v-27xj/GHSA-qvh2-rg4v-27xj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvh2-rg4v-27xj",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:56Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-4995"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json b/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json
index e32a4e6b588..8d8c3c8ffa7 100644
--- a/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json
+++ b/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxjh-36c6-ww4r",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:36Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45756"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qxp6-m9jg-58rw/GHSA-qxp6-m9jg-58rw.json b/advisories/unreviewed/2023/10/GHSA-qxp6-m9jg-58rw/GHSA-qxp6-m9jg-58rw.json
index edf4674df7d..f1ebb84163c 100644
--- a/advisories/unreviewed/2023/10/GHSA-qxp6-m9jg-58rw/GHSA-qxp6-m9jg-58rw.json
+++ b/advisories/unreviewed/2023/10/GHSA-qxp6-m9jg-58rw/GHSA-qxp6-m9jg-58rw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxp6-m9jg-58rw",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:15Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-5422"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-295"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-qxr9-324x-2r4p/GHSA-qxr9-324x-2r4p.json b/advisories/unreviewed/2023/10/GHSA-qxr9-324x-2r4p/GHSA-qxr9-324x-2r4p.json
index b9b01439032..f420ce6a5da 100644
--- a/advisories/unreviewed/2023/10/GHSA-qxr9-324x-2r4p/GHSA-qxr9-324x-2r4p.json
+++ b/advisories/unreviewed/2023/10/GHSA-qxr9-324x-2r4p/GHSA-qxr9-324x-2r4p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxr9-324x-2r4p",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:55Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-45836"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:45Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r22f-cv66-85xr/GHSA-r22f-cv66-85xr.json b/advisories/unreviewed/2023/10/GHSA-r22f-cv66-85xr/GHSA-r22f-cv66-85xr.json
index f41c639f544..a7984708e45 100644
--- a/advisories/unreviewed/2023/10/GHSA-r22f-cv66-85xr/GHSA-r22f-cv66-85xr.json
+++ b/advisories/unreviewed/2023/10/GHSA-r22f-cv66-85xr/GHSA-r22f-cv66-85xr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r22f-cv66-85xr",
- "modified": "2023-10-18T06:30:30Z",
+ "modified": "2024-04-04T08:45:39Z",
"published": "2023-10-18T06:30:30Z",
"aliases": [
"CVE-2023-5538"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T05:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json b/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json
index 99e27b220a5..a3d66464efd 100644
--- a/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json
+++ b/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2hq-xr24-chr5",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:53:27Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-27148"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r2vj-428g-v68v/GHSA-r2vj-428g-v68v.json b/advisories/unreviewed/2023/10/GHSA-r2vj-428g-v68v/GHSA-r2vj-428g-v68v.json
index 1fe3eeca1b0..da358b3ceed 100644
--- a/advisories/unreviewed/2023/10/GHSA-r2vj-428g-v68v/GHSA-r2vj-428g-v68v.json
+++ b/advisories/unreviewed/2023/10/GHSA-r2vj-428g-v68v/GHSA-r2vj-428g-v68v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2vj-428g-v68v",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:13Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5524"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r3c5-fgch-pmpm/GHSA-r3c5-fgch-pmpm.json b/advisories/unreviewed/2023/10/GHSA-r3c5-fgch-pmpm/GHSA-r3c5-fgch-pmpm.json
index dbbe942d468..793d31f1c2e 100644
--- a/advisories/unreviewed/2023/10/GHSA-r3c5-fgch-pmpm/GHSA-r3c5-fgch-pmpm.json
+++ b/advisories/unreviewed/2023/10/GHSA-r3c5-fgch-pmpm/GHSA-r3c5-fgch-pmpm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3c5-fgch-pmpm",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:41Z",
"published": "2023-10-26T12:31:06Z",
"aliases": [
"CVE-2023-30492"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T12:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json
index dfd4d72db3e..d97e58a4660 100644
--- a/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json
+++ b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3xw-5c7m-743g",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:50Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40138"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r45f-qh5g-8496/GHSA-r45f-qh5g-8496.json b/advisories/unreviewed/2023/10/GHSA-r45f-qh5g-8496/GHSA-r45f-qh5g-8496.json
index 63c992df06d..6e3bc069c54 100644
--- a/advisories/unreviewed/2023/10/GHSA-r45f-qh5g-8496/GHSA-r45f-qh5g-8496.json
+++ b/advisories/unreviewed/2023/10/GHSA-r45f-qh5g-8496/GHSA-r45f-qh5g-8496.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r45f-qh5g-8496",
- "modified": "2023-10-17T18:30:55Z",
+ "modified": "2024-04-04T08:37:53Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-5240"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r4fj-mm48-prvv/GHSA-r4fj-mm48-prvv.json b/advisories/unreviewed/2023/10/GHSA-r4fj-mm48-prvv/GHSA-r4fj-mm48-prvv.json
index 642c1569e42..627b57274c8 100644
--- a/advisories/unreviewed/2023/10/GHSA-r4fj-mm48-prvv/GHSA-r4fj-mm48-prvv.json
+++ b/advisories/unreviewed/2023/10/GHSA-r4fj-mm48-prvv/GHSA-r4fj-mm48-prvv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4fj-mm48-prvv",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:52:55Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2021-26734"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r4g9-49vg-wwc7/GHSA-r4g9-49vg-wwc7.json b/advisories/unreviewed/2023/10/GHSA-r4g9-49vg-wwc7/GHSA-r4g9-49vg-wwc7.json
index d2005e5c599..5a7b36d8d57 100644
--- a/advisories/unreviewed/2023/10/GHSA-r4g9-49vg-wwc7/GHSA-r4g9-49vg-wwc7.json
+++ b/advisories/unreviewed/2023/10/GHSA-r4g9-49vg-wwc7/GHSA-r4g9-49vg-wwc7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4g9-49vg-wwc7",
- "modified": "2023-10-17T15:30:27Z",
+ "modified": "2024-04-04T08:43:17Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-45901"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\\/category\\/add.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r4p3-fhf3-gwvv/GHSA-r4p3-fhf3-gwvv.json b/advisories/unreviewed/2023/10/GHSA-r4p3-fhf3-gwvv/GHSA-r4p3-fhf3-gwvv.json
index 070d0e3025d..917ded72666 100644
--- a/advisories/unreviewed/2023/10/GHSA-r4p3-fhf3-gwvv/GHSA-r4p3-fhf3-gwvv.json
+++ b/advisories/unreviewed/2023/10/GHSA-r4p3-fhf3-gwvv/GHSA-r4p3-fhf3-gwvv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4p3-fhf3-gwvv",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:52Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-46450"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r57m-5qwg-3ccx/GHSA-r57m-5qwg-3ccx.json b/advisories/unreviewed/2023/10/GHSA-r57m-5qwg-3ccx/GHSA-r57m-5qwg-3ccx.json
index 7343b0f96d6..84a7925a8e4 100644
--- a/advisories/unreviewed/2023/10/GHSA-r57m-5qwg-3ccx/GHSA-r57m-5qwg-3ccx.json
+++ b/advisories/unreviewed/2023/10/GHSA-r57m-5qwg-3ccx/GHSA-r57m-5qwg-3ccx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r57m-5qwg-3ccx",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:11Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-36321"
],
"details": "Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 wwas discovered to contain a buffer overflow via the component /shared/dlt_common.c.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r6cf-cv75-5928/GHSA-r6cf-cv75-5928.json b/advisories/unreviewed/2023/10/GHSA-r6cf-cv75-5928/GHSA-r6cf-cv75-5928.json
index 26c7b9e07ef..ed8e29c429c 100644
--- a/advisories/unreviewed/2023/10/GHSA-r6cf-cv75-5928/GHSA-r6cf-cv75-5928.json
+++ b/advisories/unreviewed/2023/10/GHSA-r6cf-cv75-5928/GHSA-r6cf-cv75-5928.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6cf-cv75-5928",
- "modified": "2023-10-19T15:31:06Z",
+ "modified": "2024-04-04T08:48:07Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-35181"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json b/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json
index cdaef91b2a8..b6121575532 100644
--- a/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json
+++ b/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6fm-r8h7-c67g",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:52:33Z",
"published": "2023-10-21T21:30:25Z",
"aliases": [
"CVE-2023-46067"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json
index 4e6e629a28b..2ccdf69fc81 100644
--- a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json
+++ b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6j8-w974-w846",
- "modified": "2023-10-26T21:30:22Z",
+ "modified": "2024-04-04T08:57:00Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-39726"
],
"details": "An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T21:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r6wp-r547-f9gf/GHSA-r6wp-r547-f9gf.json b/advisories/unreviewed/2023/10/GHSA-r6wp-r547-f9gf/GHSA-r6wp-r547-f9gf.json
index ac07d9c1879..305246c3370 100644
--- a/advisories/unreviewed/2023/10/GHSA-r6wp-r547-f9gf/GHSA-r6wp-r547-f9gf.json
+++ b/advisories/unreviewed/2023/10/GHSA-r6wp-r547-f9gf/GHSA-r6wp-r547-f9gf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6wp-r547-f9gf",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:35Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-44175"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-617"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json b/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json
index f0b74d45942..8296b56814d 100644
--- a/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json
+++ b/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r738-3h9r-fpvv",
- "modified": "2023-10-20T18:30:56Z",
+ "modified": "2024-04-04T08:51:26Z",
"published": "2023-10-20T18:30:56Z",
"aliases": [
"CVE-2023-3962"
@@ -35,7 +35,7 @@
"CWE-1321",
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T16:15:19Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r78r-gvgq-2chj/GHSA-r78r-gvgq-2chj.json b/advisories/unreviewed/2023/10/GHSA-r78r-gvgq-2chj/GHSA-r78r-gvgq-2chj.json
index 460115ff2a8..6f5324827fc 100644
--- a/advisories/unreviewed/2023/10/GHSA-r78r-gvgq-2chj/GHSA-r78r-gvgq-2chj.json
+++ b/advisories/unreviewed/2023/10/GHSA-r78r-gvgq-2chj/GHSA-r78r-gvgq-2chj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r78r-gvgq-2chj",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:00Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22077"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r7w5-7g5j-xmxj/GHSA-r7w5-7g5j-xmxj.json b/advisories/unreviewed/2023/10/GHSA-r7w5-7g5j-xmxj/GHSA-r7w5-7g5j-xmxj.json
index 2ab64561ac3..47a04f047dc 100644
--- a/advisories/unreviewed/2023/10/GHSA-r7w5-7g5j-xmxj/GHSA-r7w5-7g5j-xmxj.json
+++ b/advisories/unreviewed/2023/10/GHSA-r7w5-7g5j-xmxj/GHSA-r7w5-7g5j-xmxj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r7w5-7g5j-xmxj",
- "modified": "2023-10-30T12:30:30Z",
+ "modified": "2024-04-04T08:53:37Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-45966"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-918"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r86r-95mc-vg6p/GHSA-r86r-95mc-vg6p.json b/advisories/unreviewed/2023/10/GHSA-r86r-95mc-vg6p/GHSA-r86r-95mc-vg6p.json
index ae8ee3229e2..5fa03fcc0c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-r86r-95mc-vg6p/GHSA-r86r-95mc-vg6p.json
+++ b/advisories/unreviewed/2023/10/GHSA-r86r-95mc-vg6p/GHSA-r86r-95mc-vg6p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r86r-95mc-vg6p",
- "modified": "2023-10-30T12:30:31Z",
+ "modified": "2024-04-04T08:53:45Z",
"published": "2023-10-24T00:31:07Z",
"aliases": [
"CVE-2023-46058"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-24T00:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-r8wq-3m37-8m4m/GHSA-r8wq-3m37-8m4m.json b/advisories/unreviewed/2023/10/GHSA-r8wq-3m37-8m4m/GHSA-r8wq-3m37-8m4m.json
index d10cdad7a70..e79596f9967 100644
--- a/advisories/unreviewed/2023/10/GHSA-r8wq-3m37-8m4m/GHSA-r8wq-3m37-8m4m.json
+++ b/advisories/unreviewed/2023/10/GHSA-r8wq-3m37-8m4m/GHSA-r8wq-3m37-8m4m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8wq-3m37-8m4m",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:18Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2021-38859"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rcf7-xjfr-3cgc/GHSA-rcf7-xjfr-3cgc.json b/advisories/unreviewed/2023/10/GHSA-rcf7-xjfr-3cgc/GHSA-rcf7-xjfr-3cgc.json
index 0498435b134..e71f2a955e5 100644
--- a/advisories/unreviewed/2023/10/GHSA-rcf7-xjfr-3cgc/GHSA-rcf7-xjfr-3cgc.json
+++ b/advisories/unreviewed/2023/10/GHSA-rcf7-xjfr-3cgc/GHSA-rcf7-xjfr-3cgc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcf7-xjfr-3cgc",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:44Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44182"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-252"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json b/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json
index 1b1b6043ed0..64142f3b30a 100644
--- a/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json
+++ b/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcgg-pr6j-3pmh",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:58Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5057"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rcq5-59gf-jqxv/GHSA-rcq5-59gf-jqxv.json b/advisories/unreviewed/2023/10/GHSA-rcq5-59gf-jqxv/GHSA-rcq5-59gf-jqxv.json
index f4cad0156b4..87cb27d26e2 100644
--- a/advisories/unreviewed/2023/10/GHSA-rcq5-59gf-jqxv/GHSA-rcq5-59gf-jqxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-rcq5-59gf-jqxv/GHSA-rcq5-59gf-jqxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcq5-59gf-jqxv",
- "modified": "2023-10-16T03:30:30Z",
+ "modified": "2024-04-04T08:39:00Z",
"published": "2023-10-16T03:30:30Z",
"aliases": [
"CVE-2023-38280"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T02:15:47Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rff2-w9c9-q4gc/GHSA-rff2-w9c9-q4gc.json b/advisories/unreviewed/2023/10/GHSA-rff2-w9c9-q4gc/GHSA-rff2-w9c9-q4gc.json
index 7ce76aa2e67..698c31dcaeb 100644
--- a/advisories/unreviewed/2023/10/GHSA-rff2-w9c9-q4gc/GHSA-rff2-w9c9-q4gc.json
+++ b/advisories/unreviewed/2023/10/GHSA-rff2-w9c9-q4gc/GHSA-rff2-w9c9-q4gc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rff2-w9c9-q4gc",
- "modified": "2023-10-18T15:30:24Z",
+ "modified": "2024-04-04T08:46:16Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-46004"
],
"details": "Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json b/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json
index c421b3eab60..84df58a657f 100644
--- a/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json
+++ b/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rff8-hf8p-29h7",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:56:23Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46555"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:39Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rfmr-g36p-h7hg/GHSA-rfmr-g36p-h7hg.json b/advisories/unreviewed/2023/10/GHSA-rfmr-g36p-h7hg/GHSA-rfmr-g36p-h7hg.json
index d23b0566f8b..9437ec6731b 100644
--- a/advisories/unreviewed/2023/10/GHSA-rfmr-g36p-h7hg/GHSA-rfmr-g36p-h7hg.json
+++ b/advisories/unreviewed/2023/10/GHSA-rfmr-g36p-h7hg/GHSA-rfmr-g36p-h7hg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfmr-g36p-h7hg",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:46:53Z",
"published": "2023-10-19T03:30:28Z",
"aliases": [
"CVE-2023-37504"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-613"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T01:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json b/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json
index 56da2aa1ef0..fd9b2d8d6d0 100644
--- a/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json
+++ b/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfrw-m2jx-m42j",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:16Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46536"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rg52-86vx-997f/GHSA-rg52-86vx-997f.json b/advisories/unreviewed/2023/10/GHSA-rg52-86vx-997f/GHSA-rg52-86vx-997f.json
index 3840630be57..604e25a31f5 100644
--- a/advisories/unreviewed/2023/10/GHSA-rg52-86vx-997f/GHSA-rg52-86vx-997f.json
+++ b/advisories/unreviewed/2023/10/GHSA-rg52-86vx-997f/GHSA-rg52-86vx-997f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rg52-86vx-997f",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:53Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45768"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rg8p-4m72-g4mp/GHSA-rg8p-4m72-g4mp.json b/advisories/unreviewed/2023/10/GHSA-rg8p-4m72-g4mp/GHSA-rg8p-4m72-g4mp.json
index a8e71d47551..8d9d7cd05bd 100644
--- a/advisories/unreviewed/2023/10/GHSA-rg8p-4m72-g4mp/GHSA-rg8p-4m72-g4mp.json
+++ b/advisories/unreviewed/2023/10/GHSA-rg8p-4m72-g4mp/GHSA-rg8p-4m72-g4mp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rg8p-4m72-g4mp",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:28Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2022-4943"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json
index 912d571194e..3224193856d 100644
--- a/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json
+++ b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgg4-rgq7-84pp",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:57:18Z",
"published": "2023-10-27T00:30:18Z",
"aliases": [
"CVE-2018-17879"
],
"details": "An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-78"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T22:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rggm-rhpj-48vx/GHSA-rggm-rhpj-48vx.json b/advisories/unreviewed/2023/10/GHSA-rggm-rhpj-48vx/GHSA-rggm-rhpj-48vx.json
index 13bb5362d5e..1032c08756d 100644
--- a/advisories/unreviewed/2023/10/GHSA-rggm-rhpj-48vx/GHSA-rggm-rhpj-48vx.json
+++ b/advisories/unreviewed/2023/10/GHSA-rggm-rhpj-48vx/GHSA-rggm-rhpj-48vx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rggm-rhpj-48vx",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:30Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-45647"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T10:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json b/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json
index 214fd2ad0e3..34f4c168506 100644
--- a/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json
+++ b/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgx4-jh4p-m887",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:14Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46534"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rjg8-3hfx-6fxx/GHSA-rjg8-3hfx-6fxx.json b/advisories/unreviewed/2023/10/GHSA-rjg8-3hfx-6fxx/GHSA-rjg8-3hfx-6fxx.json
index c720ed80b39..46a5d02cde7 100644
--- a/advisories/unreviewed/2023/10/GHSA-rjg8-3hfx-6fxx/GHSA-rjg8-3hfx-6fxx.json
+++ b/advisories/unreviewed/2023/10/GHSA-rjg8-3hfx-6fxx/GHSA-rjg8-3hfx-6fxx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjg8-3hfx-6fxx",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:26Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45602"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rjhv-95gq-rwv4/GHSA-rjhv-95gq-rwv4.json b/advisories/unreviewed/2023/10/GHSA-rjhv-95gq-rwv4/GHSA-rjhv-95gq-rwv4.json
index 88e84d4de56..7bc8cec9a95 100644
--- a/advisories/unreviewed/2023/10/GHSA-rjhv-95gq-rwv4/GHSA-rjhv-95gq-rwv4.json
+++ b/advisories/unreviewed/2023/10/GHSA-rjhv-95gq-rwv4/GHSA-rjhv-95gq-rwv4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjhv-95gq-rwv4",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:52Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45606"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rjj3-fg8r-3rr5/GHSA-rjj3-fg8r-3rr5.json b/advisories/unreviewed/2023/10/GHSA-rjj3-fg8r-3rr5/GHSA-rjj3-fg8r-3rr5.json
index 0124360d4c6..c1679910a73 100644
--- a/advisories/unreviewed/2023/10/GHSA-rjj3-fg8r-3rr5/GHSA-rjj3-fg8r-3rr5.json
+++ b/advisories/unreviewed/2023/10/GHSA-rjj3-fg8r-3rr5/GHSA-rjj3-fg8r-3rr5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjj3-fg8r-3rr5",
- "modified": "2023-10-19T18:30:28Z",
+ "modified": "2024-04-04T08:40:02Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45757"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rjm7-96c8-22jg/GHSA-rjm7-96c8-22jg.json b/advisories/unreviewed/2023/10/GHSA-rjm7-96c8-22jg/GHSA-rjm7-96c8-22jg.json
index c8d6fc9dba0..34635da04a4 100644
--- a/advisories/unreviewed/2023/10/GHSA-rjm7-96c8-22jg/GHSA-rjm7-96c8-22jg.json
+++ b/advisories/unreviewed/2023/10/GHSA-rjm7-96c8-22jg/GHSA-rjm7-96c8-22jg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjm7-96c8-22jg",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:37:08Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44198"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-754"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rm5h-68jf-f7v7/GHSA-rm5h-68jf-f7v7.json b/advisories/unreviewed/2023/10/GHSA-rm5h-68jf-f7v7/GHSA-rm5h-68jf-f7v7.json
index 9baacd70736..94f1aae3a31 100644
--- a/advisories/unreviewed/2023/10/GHSA-rm5h-68jf-f7v7/GHSA-rm5h-68jf-f7v7.json
+++ b/advisories/unreviewed/2023/10/GHSA-rm5h-68jf-f7v7/GHSA-rm5h-68jf-f7v7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm5h-68jf-f7v7",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:53:47Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2022-38484"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rm9j-9ph9-4h45/GHSA-rm9j-9ph9-4h45.json b/advisories/unreviewed/2023/10/GHSA-rm9j-9ph9-4h45/GHSA-rm9j-9ph9-4h45.json
index 8b6816ce3c9..bc3318050b4 100644
--- a/advisories/unreviewed/2023/10/GHSA-rm9j-9ph9-4h45/GHSA-rm9j-9ph9-4h45.json
+++ b/advisories/unreviewed/2023/10/GHSA-rm9j-9ph9-4h45/GHSA-rm9j-9ph9-4h45.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm9j-9ph9-4h45",
- "modified": "2023-10-19T21:30:16Z",
+ "modified": "2024-04-04T08:41:39Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4783"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rq36-9f5f-2gw7/GHSA-rq36-9f5f-2gw7.json b/advisories/unreviewed/2023/10/GHSA-rq36-9f5f-2gw7/GHSA-rq36-9f5f-2gw7.json
index 9178539b3f3..661764436c0 100644
--- a/advisories/unreviewed/2023/10/GHSA-rq36-9f5f-2gw7/GHSA-rq36-9f5f-2gw7.json
+++ b/advisories/unreviewed/2023/10/GHSA-rq36-9f5f-2gw7/GHSA-rq36-9f5f-2gw7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq36-9f5f-2gw7",
- "modified": "2023-10-13T09:30:23Z",
+ "modified": "2024-04-04T08:37:33Z",
"published": "2023-10-13T09:30:23Z",
"aliases": [
"CVE-2023-38249"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T07:15:41Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rq7j-h64w-rghf/GHSA-rq7j-h64w-rghf.json b/advisories/unreviewed/2023/10/GHSA-rq7j-h64w-rghf/GHSA-rq7j-h64w-rghf.json
index 4148c491af9..5bd2c04610c 100644
--- a/advisories/unreviewed/2023/10/GHSA-rq7j-h64w-rghf/GHSA-rq7j-h64w-rghf.json
+++ b/advisories/unreviewed/2023/10/GHSA-rq7j-h64w-rghf/GHSA-rq7j-h64w-rghf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq7j-h64w-rghf",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:44:32Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-22100"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:14Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rq9v-22cg-86qc/GHSA-rq9v-22cg-86qc.json b/advisories/unreviewed/2023/10/GHSA-rq9v-22cg-86qc/GHSA-rq9v-22cg-86qc.json
index ac28f247cdf..396c9092797 100644
--- a/advisories/unreviewed/2023/10/GHSA-rq9v-22cg-86qc/GHSA-rq9v-22cg-86qc.json
+++ b/advisories/unreviewed/2023/10/GHSA-rq9v-22cg-86qc/GHSA-rq9v-22cg-86qc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq9v-22cg-86qc",
- "modified": "2023-10-24T21:30:20Z",
+ "modified": "2024-04-04T08:43:39Z",
"published": "2023-10-17T21:30:23Z",
"aliases": [
"CVE-2023-45951"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rqj6-qq4v-5w96/GHSA-rqj6-qq4v-5w96.json b/advisories/unreviewed/2023/10/GHSA-rqj6-qq4v-5w96/GHSA-rqj6-qq4v-5w96.json
index 2c15615ed4c..8f221007304 100644
--- a/advisories/unreviewed/2023/10/GHSA-rqj6-qq4v-5w96/GHSA-rqj6-qq4v-5w96.json
+++ b/advisories/unreviewed/2023/10/GHSA-rqj6-qq4v-5w96/GHSA-rqj6-qq4v-5w96.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqj6-qq4v-5w96",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:49:03Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-40145"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rqp9-whcw-xww5/GHSA-rqp9-whcw-xww5.json b/advisories/unreviewed/2023/10/GHSA-rqp9-whcw-xww5/GHSA-rqp9-whcw-xww5.json
index c7cb738856b..ba1c3cc1328 100644
--- a/advisories/unreviewed/2023/10/GHSA-rqp9-whcw-xww5/GHSA-rqp9-whcw-xww5.json
+++ b/advisories/unreviewed/2023/10/GHSA-rqp9-whcw-xww5/GHSA-rqp9-whcw-xww5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqp9-whcw-xww5",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:08Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-4834"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rqr7-5xf4-6wh2/GHSA-rqr7-5xf4-6wh2.json b/advisories/unreviewed/2023/10/GHSA-rqr7-5xf4-6wh2/GHSA-rqr7-5xf4-6wh2.json
index 3e3a0db2c84..66fe83b5a8c 100644
--- a/advisories/unreviewed/2023/10/GHSA-rqr7-5xf4-6wh2/GHSA-rqr7-5xf4-6wh2.json
+++ b/advisories/unreviewed/2023/10/GHSA-rqr7-5xf4-6wh2/GHSA-rqr7-5xf4-6wh2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqr7-5xf4-6wh2",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:09Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-36953"
],
"details": "TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rqrp-8f48-953h/GHSA-rqrp-8f48-953h.json b/advisories/unreviewed/2023/10/GHSA-rqrp-8f48-953h/GHSA-rqrp-8f48-953h.json
index f390f4c22e3..365c29425f7 100644
--- a/advisories/unreviewed/2023/10/GHSA-rqrp-8f48-953h/GHSA-rqrp-8f48-953h.json
+++ b/advisories/unreviewed/2023/10/GHSA-rqrp-8f48-953h/GHSA-rqrp-8f48-953h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqrp-8f48-953h",
- "modified": "2023-10-30T18:30:23Z",
+ "modified": "2024-04-04T08:56:45Z",
"published": "2023-10-26T15:30:27Z",
"aliases": [
"CVE-2023-32116"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json b/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json
index cd68fa763c1..1f7fa35b778 100644
--- a/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json
+++ b/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rv9v-x78f-m73w",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:40:58Z",
"published": "2023-10-16T15:30:20Z",
"aliases": [
"CVE-2023-5575"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rvj7-4p84-v4cg/GHSA-rvj7-4p84-v4cg.json b/advisories/unreviewed/2023/10/GHSA-rvj7-4p84-v4cg/GHSA-rvj7-4p84-v4cg.json
index 2b14c85d336..771a2bb9ca0 100644
--- a/advisories/unreviewed/2023/10/GHSA-rvj7-4p84-v4cg/GHSA-rvj7-4p84-v4cg.json
+++ b/advisories/unreviewed/2023/10/GHSA-rvj7-4p84-v4cg/GHSA-rvj7-4p84-v4cg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvj7-4p84-v4cg",
- "modified": "2023-10-13T15:30:19Z",
+ "modified": "2024-04-04T08:37:49Z",
"published": "2023-10-13T15:30:19Z",
"aliases": [
"CVE-2023-45466"
],
"details": "Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-77"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T13:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rvw9-8m2p-4pgm/GHSA-rvw9-8m2p-4pgm.json b/advisories/unreviewed/2023/10/GHSA-rvw9-8m2p-4pgm/GHSA-rvw9-8m2p-4pgm.json
index 4b0850b76d1..479fffd9963 100644
--- a/advisories/unreviewed/2023/10/GHSA-rvw9-8m2p-4pgm/GHSA-rvw9-8m2p-4pgm.json
+++ b/advisories/unreviewed/2023/10/GHSA-rvw9-8m2p-4pgm/GHSA-rvw9-8m2p-4pgm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvw9-8m2p-4pgm",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:50Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44185"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-20"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-rwvj-m246-jv4x/GHSA-rwvj-m246-jv4x.json b/advisories/unreviewed/2023/10/GHSA-rwvj-m246-jv4x/GHSA-rwvj-m246-jv4x.json
index 695e07bf5e2..7eb178e55c4 100644
--- a/advisories/unreviewed/2023/10/GHSA-rwvj-m246-jv4x/GHSA-rwvj-m246-jv4x.json
+++ b/advisories/unreviewed/2023/10/GHSA-rwvj-m246-jv4x/GHSA-rwvj-m246-jv4x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwvj-m246-jv4x",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:34Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-34210"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T05:15:50Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v2hx-f34m-8276/GHSA-v2hx-f34m-8276.json b/advisories/unreviewed/2023/10/GHSA-v2hx-f34m-8276/GHSA-v2hx-f34m-8276.json
index ccc4580de7c..52b428271e8 100644
--- a/advisories/unreviewed/2023/10/GHSA-v2hx-f34m-8276/GHSA-v2hx-f34m-8276.json
+++ b/advisories/unreviewed/2023/10/GHSA-v2hx-f34m-8276/GHSA-v2hx-f34m-8276.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v2hx-f34m-8276",
- "modified": "2023-10-26T18:30:23Z",
+ "modified": "2024-04-04T08:56:53Z",
"published": "2023-10-26T18:30:23Z",
"aliases": [
"CVE-2023-46666"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-284"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v38m-2fgx-2r9p/GHSA-v38m-2fgx-2r9p.json b/advisories/unreviewed/2023/10/GHSA-v38m-2fgx-2r9p/GHSA-v38m-2fgx-2r9p.json
index df5146dde73..23ca246df54 100644
--- a/advisories/unreviewed/2023/10/GHSA-v38m-2fgx-2r9p/GHSA-v38m-2fgx-2r9p.json
+++ b/advisories/unreviewed/2023/10/GHSA-v38m-2fgx-2r9p/GHSA-v38m-2fgx-2r9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v38m-2fgx-2r9p",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:37Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44176"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v3fx-p4xm-rv4x/GHSA-v3fx-p4xm-rv4x.json b/advisories/unreviewed/2023/10/GHSA-v3fx-p4xm-rv4x/GHSA-v3fx-p4xm-rv4x.json
index 189d9de63c9..ed54b38e749 100644
--- a/advisories/unreviewed/2023/10/GHSA-v3fx-p4xm-rv4x/GHSA-v3fx-p4xm-rv4x.json
+++ b/advisories/unreviewed/2023/10/GHSA-v3fx-p4xm-rv4x/GHSA-v3fx-p4xm-rv4x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3fx-p4xm-rv4x",
- "modified": "2023-10-26T18:30:22Z",
+ "modified": "2024-04-04T08:50:06Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5120"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v3qf-4pxv-m9xf/GHSA-v3qf-4pxv-m9xf.json b/advisories/unreviewed/2023/10/GHSA-v3qf-4pxv-m9xf/GHSA-v3qf-4pxv-m9xf.json
index 4077d5412e7..35449626c86 100644
--- a/advisories/unreviewed/2023/10/GHSA-v3qf-4pxv-m9xf/GHSA-v3qf-4pxv-m9xf.json
+++ b/advisories/unreviewed/2023/10/GHSA-v3qf-4pxv-m9xf/GHSA-v3qf-4pxv-m9xf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3qf-4pxv-m9xf",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:22Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45604"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json b/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json
index 0164529a9dd..eab1b1ae1da 100644
--- a/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json
+++ b/advisories/unreviewed/2023/10/GHSA-v4vw-f7vp-84w3/GHSA-v4vw-f7vp-84w3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4vw-f7vp-84w3",
- "modified": "2023-10-26T18:30:23Z",
+ "modified": "2024-04-04T08:51:22Z",
"published": "2023-10-20T15:30:29Z",
"aliases": [
"CVE-2023-46287"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T14:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v697-7hq7-978f/GHSA-v697-7hq7-978f.json b/advisories/unreviewed/2023/10/GHSA-v697-7hq7-978f/GHSA-v697-7hq7-978f.json
index 686dfef0f9c..c51cd28104f 100644
--- a/advisories/unreviewed/2023/10/GHSA-v697-7hq7-978f/GHSA-v697-7hq7-978f.json
+++ b/advisories/unreviewed/2023/10/GHSA-v697-7hq7-978f/GHSA-v697-7hq7-978f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v697-7hq7-978f",
- "modified": "2023-10-16T06:32:23Z",
+ "modified": "2024-04-04T08:39:17Z",
"published": "2023-10-16T06:32:23Z",
"aliases": [
"CVE-2023-45574"
],
"details": "Buffer Overflow vulnerability in DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T06:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v725-xj67-9v99/GHSA-v725-xj67-9v99.json b/advisories/unreviewed/2023/10/GHSA-v725-xj67-9v99/GHSA-v725-xj67-9v99.json
index 777ebdd764c..fb18cecb46a 100644
--- a/advisories/unreviewed/2023/10/GHSA-v725-xj67-9v99/GHSA-v725-xj67-9v99.json
+++ b/advisories/unreviewed/2023/10/GHSA-v725-xj67-9v99/GHSA-v725-xj67-9v99.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v725-xj67-9v99",
- "modified": "2023-10-24T18:30:23Z",
+ "modified": "2024-04-04T08:42:55Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-5339"
@@ -31,7 +31,7 @@
"CWE-200",
"CWE-532"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v7qj-g6j7-8wq9/GHSA-v7qj-g6j7-8wq9.json b/advisories/unreviewed/2023/10/GHSA-v7qj-g6j7-8wq9/GHSA-v7qj-g6j7-8wq9.json
index 39a9a5afd73..a4494ddbc3b 100644
--- a/advisories/unreviewed/2023/10/GHSA-v7qj-g6j7-8wq9/GHSA-v7qj-g6j7-8wq9.json
+++ b/advisories/unreviewed/2023/10/GHSA-v7qj-g6j7-8wq9/GHSA-v7qj-g6j7-8wq9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7qj-g6j7-8wq9",
- "modified": "2023-10-19T15:31:07Z",
+ "modified": "2024-04-04T08:48:17Z",
"published": "2023-10-19T15:31:07Z",
"aliases": [
"CVE-2023-35186"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v85h-7j57-3529/GHSA-v85h-7j57-3529.json b/advisories/unreviewed/2023/10/GHSA-v85h-7j57-3529/GHSA-v85h-7j57-3529.json
index f3e76070282..f6ee96be804 100644
--- a/advisories/unreviewed/2023/10/GHSA-v85h-7j57-3529/GHSA-v85h-7j57-3529.json
+++ b/advisories/unreviewed/2023/10/GHSA-v85h-7j57-3529/GHSA-v85h-7j57-3529.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v85h-7j57-3529",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:55Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45770"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v986-xf39-cqrw/GHSA-v986-xf39-cqrw.json b/advisories/unreviewed/2023/10/GHSA-v986-xf39-cqrw/GHSA-v986-xf39-cqrw.json
index 07febb125fc..082d07137c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-v986-xf39-cqrw/GHSA-v986-xf39-cqrw.json
+++ b/advisories/unreviewed/2023/10/GHSA-v986-xf39-cqrw/GHSA-v986-xf39-cqrw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v986-xf39-cqrw",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:14Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41631"
],
"details": "eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json
index f94c4ba2c70..74d94da6735 100644
--- a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json
+++ b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v994-7f87-hh83",
- "modified": "2023-10-23T21:30:58Z",
+ "modified": "2024-04-04T08:53:30Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-33837"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-311"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T20:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vcf5-8489-9vj6/GHSA-vcf5-8489-9vj6.json b/advisories/unreviewed/2023/10/GHSA-vcf5-8489-9vj6/GHSA-vcf5-8489-9vj6.json
index 7b935132c2c..db00cb0edb6 100644
--- a/advisories/unreviewed/2023/10/GHSA-vcf5-8489-9vj6/GHSA-vcf5-8489-9vj6.json
+++ b/advisories/unreviewed/2023/10/GHSA-vcf5-8489-9vj6/GHSA-vcf5-8489-9vj6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcf5-8489-9vj6",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:40Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-44694"
],
"details": "D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T06:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vcrv-8fh9-j64x/GHSA-vcrv-8fh9-j64x.json b/advisories/unreviewed/2023/10/GHSA-vcrv-8fh9-j64x/GHSA-vcrv-8fh9-j64x.json
index 530b945b6ec..32ada0f5f87 100644
--- a/advisories/unreviewed/2023/10/GHSA-vcrv-8fh9-j64x/GHSA-vcrv-8fh9-j64x.json
+++ b/advisories/unreviewed/2023/10/GHSA-vcrv-8fh9-j64x/GHSA-vcrv-8fh9-j64x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcrv-8fh9-j64x",
- "modified": "2023-10-25T03:30:36Z",
+ "modified": "2024-04-04T08:46:23Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45632"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vfgj-vqjw-hh7g/GHSA-vfgj-vqjw-hh7g.json b/advisories/unreviewed/2023/10/GHSA-vfgj-vqjw-hh7g/GHSA-vfgj-vqjw-hh7g.json
index c52af4902d7..f1fb32a4786 100644
--- a/advisories/unreviewed/2023/10/GHSA-vfgj-vqjw-hh7g/GHSA-vfgj-vqjw-hh7g.json
+++ b/advisories/unreviewed/2023/10/GHSA-vfgj-vqjw-hh7g/GHSA-vfgj-vqjw-hh7g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfgj-vqjw-hh7g",
- "modified": "2023-10-13T21:30:21Z",
+ "modified": "2024-04-04T08:38:20Z",
"published": "2023-10-13T21:30:21Z",
"aliases": [
"CVE-2023-32970"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T20:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json
index 40a429aeb1d..9fb1ca5262b 100644
--- a/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json
+++ b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vg5x-5wm4-7r4x",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:47Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40134"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json b/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json
index a58060d4c10..3aaaa799ab1 100644
--- a/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json
+++ b/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vj2w-frgg-mff6",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:19Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46538"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json b/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json
index 67415377686..5be59ff39fc 100644
--- a/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json
+++ b/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vm4p-cgrm-3hvm",
- "modified": "2023-10-22T03:30:23Z",
+ "modified": "2024-04-04T08:52:40Z",
"published": "2023-10-22T03:30:23Z",
"aliases": [
"CVE-2023-38276"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-22T02:15:07Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vm8f-qpq4-4vw6/GHSA-vm8f-qpq4-4vw6.json b/advisories/unreviewed/2023/10/GHSA-vm8f-qpq4-4vw6/GHSA-vm8f-qpq4-4vw6.json
index 48dedb64ed7..0698b43958f 100644
--- a/advisories/unreviewed/2023/10/GHSA-vm8f-qpq4-4vw6/GHSA-vm8f-qpq4-4vw6.json
+++ b/advisories/unreviewed/2023/10/GHSA-vm8f-qpq4-4vw6/GHSA-vm8f-qpq4-4vw6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vm8f-qpq4-4vw6",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:33Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-41263"
],
"details": "An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debug/ URL path. With knowledge of valid IP addresses and source types, an unauthenticated attacker can download debug logs containing application-related information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-532"
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vmvv-5f2v-26q8/GHSA-vmvv-5f2v-26q8.json b/advisories/unreviewed/2023/10/GHSA-vmvv-5f2v-26q8/GHSA-vmvv-5f2v-26q8.json
index fb33c69a5ce..591dad40617 100644
--- a/advisories/unreviewed/2023/10/GHSA-vmvv-5f2v-26q8/GHSA-vmvv-5f2v-26q8.json
+++ b/advisories/unreviewed/2023/10/GHSA-vmvv-5f2v-26q8/GHSA-vmvv-5f2v-26q8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmvv-5f2v-26q8",
- "modified": "2023-10-25T18:32:20Z",
+ "modified": "2024-04-04T08:47:54Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-45379"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vmx7-gqgq-2jhh/GHSA-vmx7-gqgq-2jhh.json b/advisories/unreviewed/2023/10/GHSA-vmx7-gqgq-2jhh/GHSA-vmx7-gqgq-2jhh.json
index 3e1c511f009..06c93618325 100644
--- a/advisories/unreviewed/2023/10/GHSA-vmx7-gqgq-2jhh/GHSA-vmx7-gqgq-2jhh.json
+++ b/advisories/unreviewed/2023/10/GHSA-vmx7-gqgq-2jhh/GHSA-vmx7-gqgq-2jhh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmx7-gqgq-2jhh",
- "modified": "2023-10-12T21:30:58Z",
+ "modified": "2024-04-04T08:36:11Z",
"published": "2023-10-12T21:30:58Z",
"aliases": [
"CVE-2023-27313"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-250"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T19:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vpx5-mhrx-64h5/GHSA-vpx5-mhrx-64h5.json b/advisories/unreviewed/2023/10/GHSA-vpx5-mhrx-64h5/GHSA-vpx5-mhrx-64h5.json
index 9bdf3c69397..acca9cbed8b 100644
--- a/advisories/unreviewed/2023/10/GHSA-vpx5-mhrx-64h5/GHSA-vpx5-mhrx-64h5.json
+++ b/advisories/unreviewed/2023/10/GHSA-vpx5-mhrx-64h5/GHSA-vpx5-mhrx-64h5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpx5-mhrx-64h5",
- "modified": "2023-10-16T18:30:28Z",
+ "modified": "2024-04-04T08:41:05Z",
"published": "2023-10-16T18:30:28Z",
"aliases": [
"CVE-2023-45688"
],
"details": "Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to get the size of an arbitrary file on the filesystem using path traversal in the ftp \"SIZE\" command",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T17:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vr7r-prw9-wjpq/GHSA-vr7r-prw9-wjpq.json b/advisories/unreviewed/2023/10/GHSA-vr7r-prw9-wjpq/GHSA-vr7r-prw9-wjpq.json
index a7c6c354134..c81a325673e 100644
--- a/advisories/unreviewed/2023/10/GHSA-vr7r-prw9-wjpq/GHSA-vr7r-prw9-wjpq.json
+++ b/advisories/unreviewed/2023/10/GHSA-vr7r-prw9-wjpq/GHSA-vr7r-prw9-wjpq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vr7r-prw9-wjpq",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:58Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-45003"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T11:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vrpg-hfmh-2gwf/GHSA-vrpg-hfmh-2gwf.json b/advisories/unreviewed/2023/10/GHSA-vrpg-hfmh-2gwf/GHSA-vrpg-hfmh-2gwf.json
index 4408e28ff3f..aef4aeaaa17 100644
--- a/advisories/unreviewed/2023/10/GHSA-vrpg-hfmh-2gwf/GHSA-vrpg-hfmh-2gwf.json
+++ b/advisories/unreviewed/2023/10/GHSA-vrpg-hfmh-2gwf/GHSA-vrpg-hfmh-2gwf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrpg-hfmh-2gwf",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:17Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-34046"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-367"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T09:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json b/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json
index 7800ec61a80..bbc73f882af 100644
--- a/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json
+++ b/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvc5-h94x-p72m",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:32Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40121"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vwm5-j2mm-8pxx/GHSA-vwm5-j2mm-8pxx.json b/advisories/unreviewed/2023/10/GHSA-vwm5-j2mm-8pxx/GHSA-vwm5-j2mm-8pxx.json
index 80490b10f05..370d6f0d6f1 100644
--- a/advisories/unreviewed/2023/10/GHSA-vwm5-j2mm-8pxx/GHSA-vwm5-j2mm-8pxx.json
+++ b/advisories/unreviewed/2023/10/GHSA-vwm5-j2mm-8pxx/GHSA-vwm5-j2mm-8pxx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vwm5-j2mm-8pxx",
- "modified": "2023-10-18T12:30:20Z",
+ "modified": "2024-04-04T08:46:01Z",
"published": "2023-10-18T12:30:20Z",
"aliases": [
"CVE-2023-32087"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T12:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json
index bc04334ee5b..b819a823660 100644
--- a/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json
+++ b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx25-5r7c-m73f",
- "modified": "2023-10-20T15:30:29Z",
+ "modified": "2024-04-04T08:51:24Z",
"published": "2023-10-20T15:30:29Z",
"aliases": [
"CVE-2023-3487"
@@ -35,7 +35,7 @@
"CWE-125",
"CWE-190"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T15:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vx32-2j79-22fm/GHSA-vx32-2j79-22fm.json b/advisories/unreviewed/2023/10/GHSA-vx32-2j79-22fm/GHSA-vx32-2j79-22fm.json
index 97554b5e55d..5f74abc87df 100644
--- a/advisories/unreviewed/2023/10/GHSA-vx32-2j79-22fm/GHSA-vx32-2j79-22fm.json
+++ b/advisories/unreviewed/2023/10/GHSA-vx32-2j79-22fm/GHSA-vx32-2j79-22fm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx32-2j79-22fm",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:52Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4935"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vx4h-jx68-6g52/GHSA-vx4h-jx68-6g52.json b/advisories/unreviewed/2023/10/GHSA-vx4h-jx68-6g52/GHSA-vx4h-jx68-6g52.json
index e055fb8748c..b2ad3f5a025 100644
--- a/advisories/unreviewed/2023/10/GHSA-vx4h-jx68-6g52/GHSA-vx4h-jx68-6g52.json
+++ b/advisories/unreviewed/2023/10/GHSA-vx4h-jx68-6g52/GHSA-vx4h-jx68-6g52.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx4h-jx68-6g52",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:25Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2021-4334"
@@ -35,7 +35,7 @@
"CWE-285",
"CWE-863"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vx79-v9rq-vjp5/GHSA-vx79-v9rq-vjp5.json b/advisories/unreviewed/2023/10/GHSA-vx79-v9rq-vjp5/GHSA-vx79-v9rq-vjp5.json
index 0d926f6cd6e..1fc3ea46701 100644
--- a/advisories/unreviewed/2023/10/GHSA-vx79-v9rq-vjp5/GHSA-vx79-v9rq-vjp5.json
+++ b/advisories/unreviewed/2023/10/GHSA-vx79-v9rq-vjp5/GHSA-vx79-v9rq-vjp5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx79-v9rq-vjp5",
- "modified": "2023-10-18T21:33:11Z",
+ "modified": "2024-04-04T08:39:36Z",
"published": "2023-10-16T09:30:18Z",
"aliases": [
"CVE-2023-45158"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-78"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T08:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-vxwp-6hpw-p9g4/GHSA-vxwp-6hpw-p9g4.json b/advisories/unreviewed/2023/10/GHSA-vxwp-6hpw-p9g4/GHSA-vxwp-6hpw-p9g4.json
index f660b79a02e..4093531479a 100644
--- a/advisories/unreviewed/2023/10/GHSA-vxwp-6hpw-p9g4/GHSA-vxwp-6hpw-p9g4.json
+++ b/advisories/unreviewed/2023/10/GHSA-vxwp-6hpw-p9g4/GHSA-vxwp-6hpw-p9g4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxwp-6hpw-p9g4",
- "modified": "2023-10-23T18:30:46Z",
+ "modified": "2024-04-04T08:53:19Z",
"published": "2023-10-23T18:30:46Z",
"aliases": [
"CVE-2023-43045"
@@ -35,7 +35,7 @@
"CWE-288",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T18:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w25r-hpmc-xhc2/GHSA-w25r-hpmc-xhc2.json b/advisories/unreviewed/2023/10/GHSA-w25r-hpmc-xhc2/GHSA-w25r-hpmc-xhc2.json
index f810439fa74..593ce9e4630 100644
--- a/advisories/unreviewed/2023/10/GHSA-w25r-hpmc-xhc2/GHSA-w25r-hpmc-xhc2.json
+++ b/advisories/unreviewed/2023/10/GHSA-w25r-hpmc-xhc2/GHSA-w25r-hpmc-xhc2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w25r-hpmc-xhc2",
- "modified": "2023-10-17T12:30:27Z",
+ "modified": "2024-04-04T08:43:03Z",
"published": "2023-10-17T12:30:27Z",
"aliases": [
"CVE-2023-45006"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json b/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json
index 080e0e0fee5..7559a34d691 100644
--- a/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json
+++ b/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w25v-58xw-9xcx",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:06Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41629"
],
"details": "A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w279-72w5-rrq7/GHSA-w279-72w5-rrq7.json b/advisories/unreviewed/2023/10/GHSA-w279-72w5-rrq7/GHSA-w279-72w5-rrq7.json
index 092677ed4b4..b0108f33f1f 100644
--- a/advisories/unreviewed/2023/10/GHSA-w279-72w5-rrq7/GHSA-w279-72w5-rrq7.json
+++ b/advisories/unreviewed/2023/10/GHSA-w279-72w5-rrq7/GHSA-w279-72w5-rrq7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w279-72w5-rrq7",
- "modified": "2023-10-16T21:30:26Z",
+ "modified": "2024-04-04T08:41:25Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-43119"
],
"details": "An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-863"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w2g3-j73q-7qv7/GHSA-w2g3-j73q-7qv7.json b/advisories/unreviewed/2023/10/GHSA-w2g3-j73q-7qv7/GHSA-w2g3-j73q-7qv7.json
index e6956b9b4c0..f1756d5905d 100644
--- a/advisories/unreviewed/2023/10/GHSA-w2g3-j73q-7qv7/GHSA-w2g3-j73q-7qv7.json
+++ b/advisories/unreviewed/2023/10/GHSA-w2g3-j73q-7qv7/GHSA-w2g3-j73q-7qv7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2g3-j73q-7qv7",
- "modified": "2023-10-17T09:30:23Z",
+ "modified": "2024-04-04T08:42:45Z",
"published": "2023-10-17T09:30:23Z",
"aliases": [
"CVE-2023-42497"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T08:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w2mg-g9h8-g57f/GHSA-w2mg-g9h8-g57f.json b/advisories/unreviewed/2023/10/GHSA-w2mg-g9h8-g57f/GHSA-w2mg-g9h8-g57f.json
index 11b268451a9..55019aaf1d3 100644
--- a/advisories/unreviewed/2023/10/GHSA-w2mg-g9h8-g57f/GHSA-w2mg-g9h8-g57f.json
+++ b/advisories/unreviewed/2023/10/GHSA-w2mg-g9h8-g57f/GHSA-w2mg-g9h8-g57f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2mg-g9h8-g57f",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:59Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-45010"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T11:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json b/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json
index 3434cad3797..4a01ac0dc84 100644
--- a/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json
+++ b/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3wr-rggh-27pq",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:34Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27377"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-287"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json b/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json
index f7b60d01aea..51595c40a13 100644
--- a/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json
+++ b/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w42r-qhq4-9fc9",
- "modified": "2023-10-27T21:30:22Z",
+ "modified": "2024-04-04T08:50:31Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2022-3342"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w4jx-8cv4-c4v7/GHSA-w4jx-8cv4-c4v7.json b/advisories/unreviewed/2023/10/GHSA-w4jx-8cv4-c4v7/GHSA-w4jx-8cv4-c4v7.json
index dcf5521741f..accf3cf7e2d 100644
--- a/advisories/unreviewed/2023/10/GHSA-w4jx-8cv4-c4v7/GHSA-w4jx-8cv4-c4v7.json
+++ b/advisories/unreviewed/2023/10/GHSA-w4jx-8cv4-c4v7/GHSA-w4jx-8cv4-c4v7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w4jx-8cv4-c4v7",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:43Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4386"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w5w4-gqf5-fh33/GHSA-w5w4-gqf5-fh33.json b/advisories/unreviewed/2023/10/GHSA-w5w4-gqf5-fh33/GHSA-w5w4-gqf5-fh33.json
index 34699093036..e21b3354bcd 100644
--- a/advisories/unreviewed/2023/10/GHSA-w5w4-gqf5-fh33/GHSA-w5w4-gqf5-fh33.json
+++ b/advisories/unreviewed/2023/10/GHSA-w5w4-gqf5-fh33/GHSA-w5w4-gqf5-fh33.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5w4-gqf5-fh33",
- "modified": "2023-10-19T18:30:29Z",
+ "modified": "2024-04-04T08:45:30Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-41713"
@@ -31,7 +31,7 @@
"CWE-259",
"CWE-798"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w5wv-98xr-mhmx/GHSA-w5wv-98xr-mhmx.json b/advisories/unreviewed/2023/10/GHSA-w5wv-98xr-mhmx/GHSA-w5wv-98xr-mhmx.json
index 1df2699ea50..992e632c9ca 100644
--- a/advisories/unreviewed/2023/10/GHSA-w5wv-98xr-mhmx/GHSA-w5wv-98xr-mhmx.json
+++ b/advisories/unreviewed/2023/10/GHSA-w5wv-98xr-mhmx/GHSA-w5wv-98xr-mhmx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5wv-98xr-mhmx",
- "modified": "2023-10-12T09:30:26Z",
+ "modified": "2024-04-04T08:35:13Z",
"published": "2023-10-12T09:30:26Z",
"aliases": [
"CVE-2023-32724"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-732"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T07:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json b/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json
index ac5a0be91b9..9b6866528c7 100644
--- a/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json
+++ b/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w695-r3qx-vgwq",
- "modified": "2023-10-30T18:30:24Z",
+ "modified": "2024-04-04T08:57:39Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40127"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w6rw-h3mq-8rp8/GHSA-w6rw-h3mq-8rp8.json b/advisories/unreviewed/2023/10/GHSA-w6rw-h3mq-8rp8/GHSA-w6rw-h3mq-8rp8.json
index e2433c1d25b..37593f7f03a 100644
--- a/advisories/unreviewed/2023/10/GHSA-w6rw-h3mq-8rp8/GHSA-w6rw-h3mq-8rp8.json
+++ b/advisories/unreviewed/2023/10/GHSA-w6rw-h3mq-8rp8/GHSA-w6rw-h3mq-8rp8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6rw-h3mq-8rp8",
- "modified": "2023-10-19T18:30:27Z",
+ "modified": "2024-04-04T08:38:54Z",
"published": "2023-10-16T00:30:27Z",
"aliases": [
"CVE-2022-48612"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T00:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json b/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json
index 956d5b2cfb5..05f57057783 100644
--- a/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json
+++ b/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w72r-ch4p-xqg3",
- "modified": "2023-10-20T18:30:55Z",
+ "modified": "2024-04-04T08:41:33Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4666"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json b/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json
index d33d59ec674..44cd5549cc4 100644
--- a/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json
+++ b/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w74v-6wvv-qx6w",
- "modified": "2023-10-25T12:30:34Z",
+ "modified": "2024-04-04T08:51:41Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43354"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w7q5-62h8-hhmc/GHSA-w7q5-62h8-hhmc.json b/advisories/unreviewed/2023/10/GHSA-w7q5-62h8-hhmc/GHSA-w7q5-62h8-hhmc.json
index 67cf5921dc0..991e57ab7eb 100644
--- a/advisories/unreviewed/2023/10/GHSA-w7q5-62h8-hhmc/GHSA-w7q5-62h8-hhmc.json
+++ b/advisories/unreviewed/2023/10/GHSA-w7q5-62h8-hhmc/GHSA-w7q5-62h8-hhmc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7q5-62h8-hhmc",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:50Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4920"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-w833-px7j-q64c/GHSA-w833-px7j-q64c.json b/advisories/unreviewed/2023/10/GHSA-w833-px7j-q64c/GHSA-w833-px7j-q64c.json
index 9492328ef24..958f62bcb59 100644
--- a/advisories/unreviewed/2023/10/GHSA-w833-px7j-q64c/GHSA-w833-px7j-q64c.json
+++ b/advisories/unreviewed/2023/10/GHSA-w833-px7j-q64c/GHSA-w833-px7j-q64c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w833-px7j-q64c",
- "modified": "2023-10-19T12:30:23Z",
+ "modified": "2024-04-04T08:47:34Z",
"published": "2023-10-19T12:30:23Z",
"aliases": [
"CVE-2022-26942"
@@ -28,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-763"
+ "CWE-763",
+ "CWE-822"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T10:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wc67-fg6q-qm47/GHSA-wc67-fg6q-qm47.json b/advisories/unreviewed/2023/10/GHSA-wc67-fg6q-qm47/GHSA-wc67-fg6q-qm47.json
index 1d1056e8a2b..42b1908be82 100644
--- a/advisories/unreviewed/2023/10/GHSA-wc67-fg6q-qm47/GHSA-wc67-fg6q-qm47.json
+++ b/advisories/unreviewed/2023/10/GHSA-wc67-fg6q-qm47/GHSA-wc67-fg6q-qm47.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wc67-fg6q-qm47",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:40:04Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45656"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wc9v-c62x-353g/GHSA-wc9v-c62x-353g.json b/advisories/unreviewed/2023/10/GHSA-wc9v-c62x-353g/GHSA-wc9v-c62x-353g.json
index 7e4d276aaeb..3ccca6831d5 100644
--- a/advisories/unreviewed/2023/10/GHSA-wc9v-c62x-353g/GHSA-wc9v-c62x-353g.json
+++ b/advisories/unreviewed/2023/10/GHSA-wc9v-c62x-353g/GHSA-wc9v-c62x-353g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wc9v-c62x-353g",
- "modified": "2023-10-16T09:30:19Z",
+ "modified": "2024-04-04T08:39:50Z",
"published": "2023-10-16T09:30:19Z",
"aliases": [
"CVE-2023-45274"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T09:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wcj6-qwxq-5x5h/GHSA-wcj6-qwxq-5x5h.json b/advisories/unreviewed/2023/10/GHSA-wcj6-qwxq-5x5h/GHSA-wcj6-qwxq-5x5h.json
index d770fe0d85e..8f7062cfcf9 100644
--- a/advisories/unreviewed/2023/10/GHSA-wcj6-qwxq-5x5h/GHSA-wcj6-qwxq-5x5h.json
+++ b/advisories/unreviewed/2023/10/GHSA-wcj6-qwxq-5x5h/GHSA-wcj6-qwxq-5x5h.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wcj6-qwxq-5x5h",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:39Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45758"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wf9m-2866-7623/GHSA-wf9m-2866-7623.json b/advisories/unreviewed/2023/10/GHSA-wf9m-2866-7623/GHSA-wf9m-2866-7623.json
index 24e862f4130..953d842bc8e 100644
--- a/advisories/unreviewed/2023/10/GHSA-wf9m-2866-7623/GHSA-wf9m-2866-7623.json
+++ b/advisories/unreviewed/2023/10/GHSA-wf9m-2866-7623/GHSA-wf9m-2866-7623.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf9m-2866-7623",
- "modified": "2023-10-14T18:30:19Z",
+ "modified": "2024-04-04T08:38:48Z",
"published": "2023-10-14T18:30:19Z",
"aliases": [
"CVE-2023-30994"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-327"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-14T17:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json b/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json
index d5d5ff6b023..3f7ba81eef7 100644
--- a/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json
+++ b/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wfjp-4mpm-mr6x",
- "modified": "2023-10-28T00:30:30Z",
+ "modified": "2024-04-04T08:55:26Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45644"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:33Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wg44-xvpw-f949/GHSA-wg44-xvpw-f949.json b/advisories/unreviewed/2023/10/GHSA-wg44-xvpw-f949/GHSA-wg44-xvpw-f949.json
index 9a46c4cb45b..4d239d1f0e6 100644
--- a/advisories/unreviewed/2023/10/GHSA-wg44-xvpw-f949/GHSA-wg44-xvpw-f949.json
+++ b/advisories/unreviewed/2023/10/GHSA-wg44-xvpw-f949/GHSA-wg44-xvpw-f949.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wg44-xvpw-f949",
- "modified": "2023-10-18T03:30:28Z",
+ "modified": "2024-04-04T08:35:00Z",
"published": "2023-10-11T21:33:25Z",
"aliases": [
"CVE-2023-3781"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-667"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-whjp-vqw5-874c/GHSA-whjp-vqw5-874c.json b/advisories/unreviewed/2023/10/GHSA-whjp-vqw5-874c/GHSA-whjp-vqw5-874c.json
index 80ad030bca7..b6d134fcc44 100644
--- a/advisories/unreviewed/2023/10/GHSA-whjp-vqw5-874c/GHSA-whjp-vqw5-874c.json
+++ b/advisories/unreviewed/2023/10/GHSA-whjp-vqw5-874c/GHSA-whjp-vqw5-874c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whjp-vqw5-874c",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:10Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-43074"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-73"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wj4x-x659-777v/GHSA-wj4x-x659-777v.json b/advisories/unreviewed/2023/10/GHSA-wj4x-x659-777v/GHSA-wj4x-x659-777v.json
index f1116b55c58..d6af086b46e 100644
--- a/advisories/unreviewed/2023/10/GHSA-wj4x-x659-777v/GHSA-wj4x-x659-777v.json
+++ b/advisories/unreviewed/2023/10/GHSA-wj4x-x659-777v/GHSA-wj4x-x659-777v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wj4x-x659-777v",
- "modified": "2023-10-16T03:30:30Z",
+ "modified": "2024-04-04T08:38:58Z",
"published": "2023-10-16T03:30:30Z",
"aliases": [
"CVE-2023-33836"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-798"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T01:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json b/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json
index 76b6ecfd368..7a9e741c6c4 100644
--- a/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json
+++ b/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wj86-wmr8-wpx4",
- "modified": "2023-10-25T12:30:35Z",
+ "modified": "2024-04-04T08:51:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43346"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T23:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wp7p-cgcx-mwrm/GHSA-wp7p-cgcx-mwrm.json b/advisories/unreviewed/2023/10/GHSA-wp7p-cgcx-mwrm/GHSA-wp7p-cgcx-mwrm.json
index 5cd34212fd4..6fb4f1080b4 100644
--- a/advisories/unreviewed/2023/10/GHSA-wp7p-cgcx-mwrm/GHSA-wp7p-cgcx-mwrm.json
+++ b/advisories/unreviewed/2023/10/GHSA-wp7p-cgcx-mwrm/GHSA-wp7p-cgcx-mwrm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp7p-cgcx-mwrm",
- "modified": "2023-10-20T12:31:00Z",
+ "modified": "2024-04-04T08:41:37Z",
"published": "2023-10-16T21:30:26Z",
"aliases": [
"CVE-2023-4725"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wpvc-39pm-wp2r/GHSA-wpvc-39pm-wp2r.json b/advisories/unreviewed/2023/10/GHSA-wpvc-39pm-wp2r/GHSA-wpvc-39pm-wp2r.json
index 44be471cf91..eeb29149a98 100644
--- a/advisories/unreviewed/2023/10/GHSA-wpvc-39pm-wp2r/GHSA-wpvc-39pm-wp2r.json
+++ b/advisories/unreviewed/2023/10/GHSA-wpvc-39pm-wp2r/GHSA-wpvc-39pm-wp2r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpvc-39pm-wp2r",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:53:56Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-25032"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:24Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wq72-w6pg-xxqp/GHSA-wq72-w6pg-xxqp.json b/advisories/unreviewed/2023/10/GHSA-wq72-w6pg-xxqp/GHSA-wq72-w6pg-xxqp.json
index ba6d4f88cdf..be16121527a 100644
--- a/advisories/unreviewed/2023/10/GHSA-wq72-w6pg-xxqp/GHSA-wq72-w6pg-xxqp.json
+++ b/advisories/unreviewed/2023/10/GHSA-wq72-w6pg-xxqp/GHSA-wq72-w6pg-xxqp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq72-w6pg-xxqp",
- "modified": "2023-10-18T00:31:42Z",
+ "modified": "2024-04-04T08:45:27Z",
"published": "2023-10-18T00:31:42Z",
"aliases": [
"CVE-2023-42507"
],
"details": "Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T23:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wqrx-2j54-p3fc/GHSA-wqrx-2j54-p3fc.json b/advisories/unreviewed/2023/10/GHSA-wqrx-2j54-p3fc/GHSA-wqrx-2j54-p3fc.json
index 50a52777fbf..15899780f70 100644
--- a/advisories/unreviewed/2023/10/GHSA-wqrx-2j54-p3fc/GHSA-wqrx-2j54-p3fc.json
+++ b/advisories/unreviewed/2023/10/GHSA-wqrx-2j54-p3fc/GHSA-wqrx-2j54-p3fc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqrx-2j54-p3fc",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:47Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39735"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json b/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json
index 79f440c985e..103eceefbc4 100644
--- a/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json
+++ b/advisories/unreviewed/2023/10/GHSA-wqw5-fg63-857m/GHSA-wqw5-fg63-857m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqw5-fg63-857m",
- "modified": "2023-10-18T00:31:41Z",
+ "modified": "2024-04-04T08:44:18Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22086"
@@ -30,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wr6j-q48c-hx4c/GHSA-wr6j-q48c-hx4c.json b/advisories/unreviewed/2023/10/GHSA-wr6j-q48c-hx4c/GHSA-wr6j-q48c-hx4c.json
index 4454bd4a41f..0f0df733004 100644
--- a/advisories/unreviewed/2023/10/GHSA-wr6j-q48c-hx4c/GHSA-wr6j-q48c-hx4c.json
+++ b/advisories/unreviewed/2023/10/GHSA-wr6j-q48c-hx4c/GHSA-wr6j-q48c-hx4c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wr6j-q48c-hx4c",
- "modified": "2023-10-13T00:30:18Z",
+ "modified": "2024-04-04T08:36:27Z",
"published": "2023-10-13T00:30:18Z",
"aliases": [
"CVE-2023-36839"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-1284"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T23:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wrcg-8gp5-rhrm/GHSA-wrcg-8gp5-rhrm.json b/advisories/unreviewed/2023/10/GHSA-wrcg-8gp5-rhrm/GHSA-wrcg-8gp5-rhrm.json
index 7c38871f403..9ee304ad873 100644
--- a/advisories/unreviewed/2023/10/GHSA-wrcg-8gp5-rhrm/GHSA-wrcg-8gp5-rhrm.json
+++ b/advisories/unreviewed/2023/10/GHSA-wrcg-8gp5-rhrm/GHSA-wrcg-8gp5-rhrm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrcg-8gp5-rhrm",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:57Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45829"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wrh7-xqxc-wghp/GHSA-wrh7-xqxc-wghp.json b/advisories/unreviewed/2023/10/GHSA-wrh7-xqxc-wghp/GHSA-wrh7-xqxc-wghp.json
index 98b0461132c..1b13dc6eb73 100644
--- a/advisories/unreviewed/2023/10/GHSA-wrh7-xqxc-wghp/GHSA-wrh7-xqxc-wghp.json
+++ b/advisories/unreviewed/2023/10/GHSA-wrh7-xqxc-wghp/GHSA-wrh7-xqxc-wghp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrh7-xqxc-wghp",
- "modified": "2023-10-19T18:30:31Z",
+ "modified": "2024-04-04T08:48:32Z",
"published": "2023-10-19T18:30:31Z",
"aliases": [
"CVE-2023-35986"
@@ -31,7 +31,7 @@
"CWE-121",
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T18:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wvm9-mq8w-wrm8/GHSA-wvm9-mq8w-wrm8.json b/advisories/unreviewed/2023/10/GHSA-wvm9-mq8w-wrm8/GHSA-wvm9-mq8w-wrm8.json
index 306832d4303..9becd83c096 100644
--- a/advisories/unreviewed/2023/10/GHSA-wvm9-mq8w-wrm8/GHSA-wvm9-mq8w-wrm8.json
+++ b/advisories/unreviewed/2023/10/GHSA-wvm9-mq8w-wrm8/GHSA-wvm9-mq8w-wrm8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvm9-mq8w-wrm8",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:40Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-3869"
@@ -35,7 +35,7 @@
"CWE-639",
"CWE-862"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wwff-qqfj-cv2g/GHSA-wwff-qqfj-cv2g.json b/advisories/unreviewed/2023/10/GHSA-wwff-qqfj-cv2g/GHSA-wwff-qqfj-cv2g.json
index df8f5918a4f..440b2887639 100644
--- a/advisories/unreviewed/2023/10/GHSA-wwff-qqfj-cv2g/GHSA-wwff-qqfj-cv2g.json
+++ b/advisories/unreviewed/2023/10/GHSA-wwff-qqfj-cv2g/GHSA-wwff-qqfj-cv2g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwff-qqfj-cv2g",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:03Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-28795"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-346"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T14:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wwfp-p79h-2x5v/GHSA-wwfp-p79h-2x5v.json b/advisories/unreviewed/2023/10/GHSA-wwfp-p79h-2x5v/GHSA-wwfp-p79h-2x5v.json
index c4ee3b6437e..660063ca900 100644
--- a/advisories/unreviewed/2023/10/GHSA-wwfp-p79h-2x5v/GHSA-wwfp-p79h-2x5v.json
+++ b/advisories/unreviewed/2023/10/GHSA-wwfp-p79h-2x5v/GHSA-wwfp-p79h-2x5v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwfp-p79h-2x5v",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:52:04Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-38194"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T01:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wx55-4qhm-8qw2/GHSA-wx55-4qhm-8qw2.json b/advisories/unreviewed/2023/10/GHSA-wx55-4qhm-8qw2/GHSA-wx55-4qhm-8qw2.json
index 43b8dc3fd51..09f8a0c9beb 100644
--- a/advisories/unreviewed/2023/10/GHSA-wx55-4qhm-8qw2/GHSA-wx55-4qhm-8qw2.json
+++ b/advisories/unreviewed/2023/10/GHSA-wx55-4qhm-8qw2/GHSA-wx55-4qhm-8qw2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx55-4qhm-8qw2",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:09Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5414"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wxgq-cmv5-57qx/GHSA-wxgq-cmv5-57qx.json b/advisories/unreviewed/2023/10/GHSA-wxgq-cmv5-57qx/GHSA-wxgq-cmv5-57qx.json
index 310fa1a7380..7d1135e620d 100644
--- a/advisories/unreviewed/2023/10/GHSA-wxgq-cmv5-57qx/GHSA-wxgq-cmv5-57qx.json
+++ b/advisories/unreviewed/2023/10/GHSA-wxgq-cmv5-57qx/GHSA-wxgq-cmv5-57qx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxgq-cmv5-57qx",
- "modified": "2023-10-19T21:30:17Z",
+ "modified": "2024-04-04T08:48:47Z",
"published": "2023-10-19T21:30:17Z",
"aliases": [
"CVE-2023-41088"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-319"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T19:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json b/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json
index ccba8eac9d5..143c266e8a5 100644
--- a/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json
+++ b/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxww-3fw5-44w4",
- "modified": "2023-10-20T21:31:00Z",
+ "modified": "2024-04-04T08:37:39Z",
"published": "2023-10-13T12:30:17Z",
"aliases": [
"CVE-2023-43079"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-284"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x529-3p36-rxh5/GHSA-x529-3p36-rxh5.json b/advisories/unreviewed/2023/10/GHSA-x529-3p36-rxh5/GHSA-x529-3p36-rxh5.json
index 08af04e32cc..cb5ac1aed3f 100644
--- a/advisories/unreviewed/2023/10/GHSA-x529-3p36-rxh5/GHSA-x529-3p36-rxh5.json
+++ b/advisories/unreviewed/2023/10/GHSA-x529-3p36-rxh5/GHSA-x529-3p36-rxh5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x529-3p36-rxh5",
- "modified": "2023-10-18T09:30:28Z",
+ "modified": "2024-04-04T08:45:44Z",
"published": "2023-10-18T09:30:28Z",
"aliases": [
"CVE-2023-45049"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T08:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x578-82rc-944x/GHSA-x578-82rc-944x.json b/advisories/unreviewed/2023/10/GHSA-x578-82rc-944x/GHSA-x578-82rc-944x.json
index e499775e231..aa21b5a0f4a 100644
--- a/advisories/unreviewed/2023/10/GHSA-x578-82rc-944x/GHSA-x578-82rc-944x.json
+++ b/advisories/unreviewed/2023/10/GHSA-x578-82rc-944x/GHSA-x578-82rc-944x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x578-82rc-944x",
- "modified": "2023-10-17T12:30:26Z",
+ "modified": "2024-04-04T08:42:52Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-44990"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T10:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x57h-259q-ggjv/GHSA-x57h-259q-ggjv.json b/advisories/unreviewed/2023/10/GHSA-x57h-259q-ggjv/GHSA-x57h-259q-ggjv.json
index 16d649f2531..e3f2eb87c15 100644
--- a/advisories/unreviewed/2023/10/GHSA-x57h-259q-ggjv/GHSA-x57h-259q-ggjv.json
+++ b/advisories/unreviewed/2023/10/GHSA-x57h-259q-ggjv/GHSA-x57h-259q-ggjv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x57h-259q-ggjv",
- "modified": "2023-10-21T09:30:25Z",
+ "modified": "2024-04-04T08:52:29Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-5205"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T08:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x63c-6jx4-44mv/GHSA-x63c-6jx4-44mv.json b/advisories/unreviewed/2023/10/GHSA-x63c-6jx4-44mv/GHSA-x63c-6jx4-44mv.json
index 08fcc72ddcf..0575def50fd 100644
--- a/advisories/unreviewed/2023/10/GHSA-x63c-6jx4-44mv/GHSA-x63c-6jx4-44mv.json
+++ b/advisories/unreviewed/2023/10/GHSA-x63c-6jx4-44mv/GHSA-x63c-6jx4-44mv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x63c-6jx4-44mv",
- "modified": "2023-10-20T09:30:28Z",
+ "modified": "2024-04-04T08:50:15Z",
"published": "2023-10-20T09:30:28Z",
"aliases": [
"CVE-2023-5576"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x7gg-f2xv-xw56/GHSA-x7gg-f2xv-xw56.json b/advisories/unreviewed/2023/10/GHSA-x7gg-f2xv-xw56/GHSA-x7gg-f2xv-xw56.json
index 8c49363543a..8bcf508eb16 100644
--- a/advisories/unreviewed/2023/10/GHSA-x7gg-f2xv-xw56/GHSA-x7gg-f2xv-xw56.json
+++ b/advisories/unreviewed/2023/10/GHSA-x7gg-f2xv-xw56/GHSA-x7gg-f2xv-xw56.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7gg-f2xv-xw56",
- "modified": "2023-10-20T12:31:00Z",
+ "modified": "2024-04-04T08:41:52Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-4862"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T20:15:17Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-x9hv-97wr-x4j8/GHSA-x9hv-97wr-x4j8.json b/advisories/unreviewed/2023/10/GHSA-x9hv-97wr-x4j8/GHSA-x9hv-97wr-x4j8.json
index f1900821183..8e34be603ab 100644
--- a/advisories/unreviewed/2023/10/GHSA-x9hv-97wr-x4j8/GHSA-x9hv-97wr-x4j8.json
+++ b/advisories/unreviewed/2023/10/GHSA-x9hv-97wr-x4j8/GHSA-x9hv-97wr-x4j8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9hv-97wr-x4j8",
- "modified": "2023-10-13T00:30:19Z",
+ "modified": "2024-04-04T08:36:48Z",
"published": "2023-10-13T00:30:19Z",
"aliases": [
"CVE-2023-44183"
@@ -39,7 +39,7 @@
"CWE-20",
"CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-13T00:15:11Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xc8p-j5f8-7w98/GHSA-xc8p-j5f8-7w98.json b/advisories/unreviewed/2023/10/GHSA-xc8p-j5f8-7w98/GHSA-xc8p-j5f8-7w98.json
index e75d6f1a4db..09d32149c82 100644
--- a/advisories/unreviewed/2023/10/GHSA-xc8p-j5f8-7w98/GHSA-xc8p-j5f8-7w98.json
+++ b/advisories/unreviewed/2023/10/GHSA-xc8p-j5f8-7w98/GHSA-xc8p-j5f8-7w98.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xc8p-j5f8-7w98",
- "modified": "2023-10-17T15:30:28Z",
+ "modified": "2024-04-04T08:43:33Z",
"published": "2023-10-17T15:30:28Z",
"aliases": [
"CVE-2023-45907"
],
"details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T14:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json b/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
index 4b890881267..524f88da80b 100644
--- a/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
+++ b/advisories/unreviewed/2023/10/GHSA-xf6j-84wr-6vq4/GHSA-xf6j-84wr-6vq4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf6j-84wr-6vq4",
- "modified": "2023-10-16T06:32:22Z",
+ "modified": "2024-04-04T08:39:05Z",
"published": "2023-10-16T06:32:22Z",
"aliases": [
"CVE-2023-36947"
],
"details": "TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T05:15:49Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xfh2-4rhf-q57x/GHSA-xfh2-4rhf-q57x.json b/advisories/unreviewed/2023/10/GHSA-xfh2-4rhf-q57x/GHSA-xfh2-4rhf-q57x.json
index e6285d88f56..3447be87094 100644
--- a/advisories/unreviewed/2023/10/GHSA-xfh2-4rhf-q57x/GHSA-xfh2-4rhf-q57x.json
+++ b/advisories/unreviewed/2023/10/GHSA-xfh2-4rhf-q57x/GHSA-xfh2-4rhf-q57x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfh2-4rhf-q57x",
- "modified": "2023-10-25T21:30:26Z",
+ "modified": "2024-04-04T08:48:26Z",
"published": "2023-10-19T18:30:29Z",
"aliases": [
"CVE-2022-47583"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-74"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T16:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xfmg-8p5c-72jm/GHSA-xfmg-8p5c-72jm.json b/advisories/unreviewed/2023/10/GHSA-xfmg-8p5c-72jm/GHSA-xfmg-8p5c-72jm.json
index f2fdcf94777..024b55d4c3a 100644
--- a/advisories/unreviewed/2023/10/GHSA-xfmg-8p5c-72jm/GHSA-xfmg-8p5c-72jm.json
+++ b/advisories/unreviewed/2023/10/GHSA-xfmg-8p5c-72jm/GHSA-xfmg-8p5c-72jm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfmg-8p5c-72jm",
- "modified": "2023-10-16T12:33:37Z",
+ "modified": "2024-04-04T08:40:56Z",
"published": "2023-10-16T12:33:37Z",
"aliases": [
"CVE-2023-46066"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T12:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xgf4-vh79-4g7j/GHSA-xgf4-vh79-4g7j.json b/advisories/unreviewed/2023/10/GHSA-xgf4-vh79-4g7j/GHSA-xgf4-vh79-4g7j.json
index 068f6093283..fe744625529 100644
--- a/advisories/unreviewed/2023/10/GHSA-xgf4-vh79-4g7j/GHSA-xgf4-vh79-4g7j.json
+++ b/advisories/unreviewed/2023/10/GHSA-xgf4-vh79-4g7j/GHSA-xgf4-vh79-4g7j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgf4-vh79-4g7j",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:29Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-43892"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-295"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T03:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json b/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json
index 3caf02745bb..fe4c197503c 100644
--- a/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json
+++ b/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgm7-5784-5cxv",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:27Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27376"
@@ -31,7 +31,7 @@
"CWE-287",
"CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:26Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xh9r-6fmf-q43q/GHSA-xh9r-6fmf-q43q.json b/advisories/unreviewed/2023/10/GHSA-xh9r-6fmf-q43q/GHSA-xh9r-6fmf-q43q.json
index cbcb77c97bd..c0899a17699 100644
--- a/advisories/unreviewed/2023/10/GHSA-xh9r-6fmf-q43q/GHSA-xh9r-6fmf-q43q.json
+++ b/advisories/unreviewed/2023/10/GHSA-xh9r-6fmf-q43q/GHSA-xh9r-6fmf-q43q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xh9r-6fmf-q43q",
- "modified": "2023-10-31T18:31:44Z",
+ "modified": "2024-04-04T08:54:59Z",
"published": "2023-10-25T18:32:22Z",
"aliases": [
"CVE-2023-39737"
@@ -34,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:29Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xhm8-r9jc-63fw/GHSA-xhm8-r9jc-63fw.json b/advisories/unreviewed/2023/10/GHSA-xhm8-r9jc-63fw/GHSA-xhm8-r9jc-63fw.json
index 2b0a389aee0..5a369173098 100644
--- a/advisories/unreviewed/2023/10/GHSA-xhm8-r9jc-63fw/GHSA-xhm8-r9jc-63fw.json
+++ b/advisories/unreviewed/2023/10/GHSA-xhm8-r9jc-63fw/GHSA-xhm8-r9jc-63fw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhm8-r9jc-63fw",
- "modified": "2023-10-17T03:32:43Z",
+ "modified": "2024-04-04T08:42:24Z",
"published": "2023-10-17T03:32:43Z",
"aliases": [
"CVE-2022-43889"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T02:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xmxw-j4c5-629g/GHSA-xmxw-j4c5-629g.json b/advisories/unreviewed/2023/10/GHSA-xmxw-j4c5-629g/GHSA-xmxw-j4c5-629g.json
index 19c677668c4..37fde68a3b4 100644
--- a/advisories/unreviewed/2023/10/GHSA-xmxw-j4c5-629g/GHSA-xmxw-j4c5-629g.json
+++ b/advisories/unreviewed/2023/10/GHSA-xmxw-j4c5-629g/GHSA-xmxw-j4c5-629g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xmxw-j4c5-629g",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:55:54Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45772"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:34Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xp27-gwqx-8qx4/GHSA-xp27-gwqx-8qx4.json b/advisories/unreviewed/2023/10/GHSA-xp27-gwqx-8qx4/GHSA-xp27-gwqx-8qx4.json
index c6fb9fb8cd1..cfece5b1031 100644
--- a/advisories/unreviewed/2023/10/GHSA-xp27-gwqx-8qx4/GHSA-xp27-gwqx-8qx4.json
+++ b/advisories/unreviewed/2023/10/GHSA-xp27-gwqx-8qx4/GHSA-xp27-gwqx-8qx4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xp27-gwqx-8qx4",
- "modified": "2023-10-16T12:33:36Z",
+ "modified": "2024-04-04T08:40:37Z",
"published": "2023-10-16T12:33:36Z",
"aliases": [
"CVE-2023-44985"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-16T11:15:44Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xph7-mv6p-642w/GHSA-xph7-mv6p-642w.json b/advisories/unreviewed/2023/10/GHSA-xph7-mv6p-642w/GHSA-xph7-mv6p-642w.json
index 1f48b334fdf..799fbe957b1 100644
--- a/advisories/unreviewed/2023/10/GHSA-xph7-mv6p-642w/GHSA-xph7-mv6p-642w.json
+++ b/advisories/unreviewed/2023/10/GHSA-xph7-mv6p-642w/GHSA-xph7-mv6p-642w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xph7-mv6p-642w",
- "modified": "2023-10-11T21:33:25Z",
+ "modified": "2024-04-04T08:34:55Z",
"published": "2023-10-11T21:33:25Z",
"aliases": [
"CVE-2023-40141"
],
"details": "In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.\n\n",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T20:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xpvj-vm4g-wmjm/GHSA-xpvj-vm4g-wmjm.json b/advisories/unreviewed/2023/10/GHSA-xpvj-vm4g-wmjm/GHSA-xpvj-vm4g-wmjm.json
index ed0c0758434..640c8c376e2 100644
--- a/advisories/unreviewed/2023/10/GHSA-xpvj-vm4g-wmjm/GHSA-xpvj-vm4g-wmjm.json
+++ b/advisories/unreviewed/2023/10/GHSA-xpvj-vm4g-wmjm/GHSA-xpvj-vm4g-wmjm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xpvj-vm4g-wmjm",
- "modified": "2023-10-25T03:30:35Z",
+ "modified": "2024-04-04T08:46:14Z",
"published": "2023-10-18T15:30:24Z",
"aliases": [
"CVE-2023-45608"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-18T13:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xpvx-v3vc-27gc/GHSA-xpvx-v3vc-27gc.json b/advisories/unreviewed/2023/10/GHSA-xpvx-v3vc-27gc/GHSA-xpvx-v3vc-27gc.json
index 06ed1c82f0b..10a337643e0 100644
--- a/advisories/unreviewed/2023/10/GHSA-xpvx-v3vc-27gc/GHSA-xpvx-v3vc-27gc.json
+++ b/advisories/unreviewed/2023/10/GHSA-xpvx-v3vc-27gc/GHSA-xpvx-v3vc-27gc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xpvx-v3vc-27gc",
- "modified": "2023-10-19T15:31:06Z",
+ "modified": "2024-04-04T08:48:11Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-35182"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xq43-hwmx-8g8w/GHSA-xq43-hwmx-8g8w.json b/advisories/unreviewed/2023/10/GHSA-xq43-hwmx-8g8w/GHSA-xq43-hwmx-8g8w.json
index fd98d9bc62b..88af86e3784 100644
--- a/advisories/unreviewed/2023/10/GHSA-xq43-hwmx-8g8w/GHSA-xq43-hwmx-8g8w.json
+++ b/advisories/unreviewed/2023/10/GHSA-xq43-hwmx-8g8w/GHSA-xq43-hwmx-8g8w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq43-hwmx-8g8w",
- "modified": "2023-10-17T06:30:16Z",
+ "modified": "2024-04-04T08:42:31Z",
"published": "2023-10-17T06:30:16Z",
"aliases": [
"CVE-2023-34208"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-22"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T04:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xqpc-wjc5-8chx/GHSA-xqpc-wjc5-8chx.json b/advisories/unreviewed/2023/10/GHSA-xqpc-wjc5-8chx/GHSA-xqpc-wjc5-8chx.json
index 795ad545f95..8eeeba7e373 100644
--- a/advisories/unreviewed/2023/10/GHSA-xqpc-wjc5-8chx/GHSA-xqpc-wjc5-8chx.json
+++ b/advisories/unreviewed/2023/10/GHSA-xqpc-wjc5-8chx/GHSA-xqpc-wjc5-8chx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqpc-wjc5-8chx",
- "modified": "2023-10-20T09:30:29Z",
+ "modified": "2024-04-04T08:50:51Z",
"published": "2023-10-20T09:30:29Z",
"aliases": [
"CVE-2023-4999"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T08:15:12Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xqxc-686p-m2m3/GHSA-xqxc-686p-m2m3.json b/advisories/unreviewed/2023/10/GHSA-xqxc-686p-m2m3/GHSA-xqxc-686p-m2m3.json
index 7f10f2a3b97..2fe09463504 100644
--- a/advisories/unreviewed/2023/10/GHSA-xqxc-686p-m2m3/GHSA-xqxc-686p-m2m3.json
+++ b/advisories/unreviewed/2023/10/GHSA-xqxc-686p-m2m3/GHSA-xqxc-686p-m2m3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqxc-686p-m2m3",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:55Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4937"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:16Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json
index 00292db88d2..985a6abeb15 100644
--- a/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json
+++ b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrwj-6h7r-w997",
- "modified": "2023-10-31T15:30:20Z",
+ "modified": "2024-04-04T08:57:54Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46200"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xrxc-cv69-f3fp/GHSA-xrxc-cv69-f3fp.json b/advisories/unreviewed/2023/10/GHSA-xrxc-cv69-f3fp/GHSA-xrxc-cv69-f3fp.json
index b2c800642bb..85ae10c3f6e 100644
--- a/advisories/unreviewed/2023/10/GHSA-xrxc-cv69-f3fp/GHSA-xrxc-cv69-f3fp.json
+++ b/advisories/unreviewed/2023/10/GHSA-xrxc-cv69-f3fp/GHSA-xrxc-cv69-f3fp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrxc-cv69-f3fp",
- "modified": "2023-10-28T03:30:22Z",
+ "modified": "2024-04-04T08:54:14Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26578"
@@ -31,7 +31,7 @@
"CWE-22",
"CWE-434"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:25Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xv96-5q4x-p79p/GHSA-xv96-5q4x-p79p.json b/advisories/unreviewed/2023/10/GHSA-xv96-5q4x-p79p/GHSA-xv96-5q4x-p79p.json
index be7ead7a909..30b1d10e9fb 100644
--- a/advisories/unreviewed/2023/10/GHSA-xv96-5q4x-p79p/GHSA-xv96-5q4x-p79p.json
+++ b/advisories/unreviewed/2023/10/GHSA-xv96-5q4x-p79p/GHSA-xv96-5q4x-p79p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv96-5q4x-p79p",
- "modified": "2023-10-28T06:30:20Z",
+ "modified": "2024-04-04T08:51:59Z",
"published": "2023-10-21T03:30:17Z",
"aliases": [
"CVE-2023-38193"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-77"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-21T01:15:08Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xvwc-m4qj-9wr9/GHSA-xvwc-m4qj-9wr9.json b/advisories/unreviewed/2023/10/GHSA-xvwc-m4qj-9wr9/GHSA-xvwc-m4qj-9wr9.json
index a8e272ff953..3762e4c9f91 100644
--- a/advisories/unreviewed/2023/10/GHSA-xvwc-m4qj-9wr9/GHSA-xvwc-m4qj-9wr9.json
+++ b/advisories/unreviewed/2023/10/GHSA-xvwc-m4qj-9wr9/GHSA-xvwc-m4qj-9wr9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvwc-m4qj-9wr9",
- "modified": "2023-10-12T15:31:07Z",
+ "modified": "2024-04-04T08:35:28Z",
"published": "2023-10-12T15:31:07Z",
"aliases": [
"CVE-2023-45052"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-12T13:15:10Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xw7q-2j98-xv6p/GHSA-xw7q-2j98-xv6p.json b/advisories/unreviewed/2023/10/GHSA-xw7q-2j98-xv6p/GHSA-xw7q-2j98-xv6p.json
index 0ff17d6d56a..3ed558299a5 100644
--- a/advisories/unreviewed/2023/10/GHSA-xw7q-2j98-xv6p/GHSA-xw7q-2j98-xv6p.json
+++ b/advisories/unreviewed/2023/10/GHSA-xw7q-2j98-xv6p/GHSA-xw7q-2j98-xv6p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xw7q-2j98-xv6p",
- "modified": "2023-10-23T15:30:24Z",
+ "modified": "2024-04-04T08:53:06Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-43065"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-23T15:15:09Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json b/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json
index 2dbeb424d94..1984c4f9d24 100644
--- a/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json
+++ b/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xx33-j3mf-gffc",
- "modified": "2023-10-27T00:30:18Z",
+ "modified": "2024-04-04T08:56:02Z",
"published": "2023-10-25T18:32:24Z",
"aliases": [
"CVE-2023-46523"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:38Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xxc8-gpg2-9w9f/GHSA-xxc8-gpg2-9w9f.json b/advisories/unreviewed/2023/10/GHSA-xxc8-gpg2-9w9f/GHSA-xxc8-gpg2-9w9f.json
index f64e429ea96..32c8318c5d1 100644
--- a/advisories/unreviewed/2023/10/GHSA-xxc8-gpg2-9w9f/GHSA-xxc8-gpg2-9w9f.json
+++ b/advisories/unreviewed/2023/10/GHSA-xxc8-gpg2-9w9f/GHSA-xxc8-gpg2-9w9f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxc8-gpg2-9w9f",
- "modified": "2023-10-20T09:30:27Z",
+ "modified": "2024-04-04T08:49:43Z",
"published": "2023-10-20T09:30:27Z",
"aliases": [
"CVE-2023-4402"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T07:15:15Z"
diff --git a/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json b/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json
index 5c824b66ff6..221a6e62e3e 100644
--- a/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json
+++ b/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxvm-h2mx-9mwj",
- "modified": "2023-10-25T12:30:35Z",
+ "modified": "2024-04-04T08:51:42Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43357"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-20T22:15:10Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json b/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json
index 0d2326aed2b..dd773d54445 100644
--- a/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json
+++ b/advisories/unreviewed/2024/02/GHSA-273x-mxvr-9vx2/GHSA-273x-mxvr-9vx2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-273x-mxvr-9vx2",
- "modified": "2024-02-26T18:30:28Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2022-34357"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230510"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0001"
+ },
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7123154"
diff --git a/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json b/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json
index e57b710c3c3..76aa8ef798a 100644
--- a/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json
+++ b/advisories/unreviewed/2024/02/GHSA-cmph-x6r4-4whr/GHSA-cmph-x6r4-4whr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmph-x6r4-4whr",
- "modified": "2024-02-20T18:30:34Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-02-20T15:31:03Z",
"aliases": [
"CVE-2023-52433"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52433"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/03caf75da1059f0460666c826e9f50e13dfd0017"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2ee52ae94baa"
@@ -26,6 +30,18 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2ee52ae94baabf7ee09cf2a8d854b990dac5d0e4"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9a8c544158f68f656d1734eb5ba00c4f817b76b1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9af7dfb3c9d7985172a240f85e684c5cd33e29ce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c323ed65f66e5387ee0a73452118d49f1dae81b8"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e3213ff99a35"
diff --git a/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json b/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json
index 34ce6ee2c0b..6bd01f77bfa 100644
--- a/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json
+++ b/advisories/unreviewed/2024/02/GHSA-fxmj-6xv8-f3m7/GHSA-fxmj-6xv8-f3m7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxmj-6xv8-f3m7",
- "modified": "2024-02-26T18:30:28Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2023-32344"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/255898"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0002"
+ },
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7123154"
diff --git a/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json b/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json
index 51787f73a45..3fe13d51dcb 100644
--- a/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json
+++ b/advisories/unreviewed/2024/02/GHSA-g9mf-qvgg-vwxr/GHSA-g9mf-qvgg-vwxr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9mf-qvgg-vwxr",
- "modified": "2024-02-27T12:31:09Z",
+ "modified": "2024-04-10T18:30:46Z",
"published": "2024-02-27T12:31:09Z",
"aliases": [
"CVE-2021-46922"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix TPM reservation for seal/unseal\n\nThe original patch 8c657a0590de (\"KEYS: trusted: Reserve TPM for seal\nand unseal operations\") was correct on the mailing list:\n\nhttps://lore.kernel.org/linux-integrity/20210128235621.127925-4-jarkko@kernel.org/\n\nBut somehow got rebased so that the tpm_try_get_ops() in\ntpm2_seal_trusted() got lost. This causes an imbalanced put of the\nTPM ops and causes oopses on TIS based hardware.\n\nThis fix puts back the lost tpm_try_get_ops()",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -22,6 +25,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/39c8d760d44cb3fa0d67e8cd505df81cf4d80999"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9d5171eab462a63e2fbebfccf6026e92be018f20"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/bf84ef2dd2ccdcd8f2658476d34b51455f970ce4"
@@ -31,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-27T10:15:07Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json b/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json
index 8e2d958d39d..030234c9548 100644
--- a/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json
+++ b/advisories/unreviewed/2024/02/GHSA-mj54-2qgh-27pf/GHSA-mj54-2qgh-27pf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj54-2qgh-27pf",
- "modified": "2024-02-26T18:30:28Z",
+ "modified": "2024-04-05T09:30:37Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2023-30996"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/254290"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0004"
+ },
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7123154"
diff --git a/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json b/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json
index ed559f7380d..3ad4bd4a602 100644
--- a/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json
+++ b/advisories/unreviewed/2024/02/GHSA-q52q-f54c-xmvp/GHSA-q52q-f54c-xmvp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q52q-f54c-xmvp",
- "modified": "2024-02-26T18:30:28Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2021-46905"
@@ -18,10 +18,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46905"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0c71d4c89559f72cec2592d078681a843bce570e"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0f000005da31f6947f843ce6b3e3a960540c6e00"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24b699bea7553fc0b98dad9d864befb6005ac7f1"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2ad5692db72874f02b9ad551d26345437ea4f7f3"
@@ -30,6 +38,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/41c44e1f3112d7265dae522c026399b2a42d19ef"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5871761c5f0f20d6e98bf3b6bd7486d857589554"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/5c17cfe155d21954b4c7e2a78fa771cebcd86725"
diff --git a/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json b/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json
index 73185e3db42..f692b39ade3 100644
--- a/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json
+++ b/advisories/unreviewed/2024/02/GHSA-q5mw-2cvx-mjj3/GHSA-q5mw-2cvx-mjj3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5mw-2cvx-mjj3",
- "modified": "2024-02-26T18:30:28Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2023-38359"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260744"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0003"
+ },
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7123154"
diff --git a/advisories/unreviewed/2024/02/GHSA-w6qf-42m7-vh68/GHSA-w6qf-42m7-vh68.json b/advisories/unreviewed/2024/02/GHSA-w6qf-42m7-vh68/GHSA-w6qf-42m7-vh68.json
index c339ba87c23..8509808f12c 100644
--- a/advisories/unreviewed/2024/02/GHSA-w6qf-42m7-vh68/GHSA-w6qf-42m7-vh68.json
+++ b/advisories/unreviewed/2024/02/GHSA-w6qf-42m7-vh68/GHSA-w6qf-42m7-vh68.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6qf-42m7-vh68",
- "modified": "2024-03-22T21:30:56Z",
+ "modified": "2024-04-04T18:30:33Z",
"published": "2024-02-20T00:30:36Z",
"aliases": [
"CVE-2024-1635"
@@ -21,6 +21,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1635"
},
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1674"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1675"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1676"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2024:1677"
+ },
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1635"
diff --git a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
index 05b56ac47b8..f57c041c3b6 100644
--- a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
+++ b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85v9-53x3-q4xp",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52577"
@@ -38,6 +38,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/62c218124fe58372e0e1f60d5b634d21c264b337"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6af289746a636f71f4c0535a9801774118486c7a"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/73be49248a04746096339a48a33fa2f03bd85969"
diff --git a/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json b/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json
index 694a36fb04d..56afa783ce3 100644
--- a/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json
+++ b/advisories/unreviewed/2024/03/GHSA-9hpm-6w4c-hxh2/GHSA-9hpm-6w4c-hxh2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hpm-6w4c-hxh2",
- "modified": "2024-03-14T18:30:30Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:30Z",
"aliases": [
"CVE-2023-32666"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32666"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0010"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00986.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-hv2r-vh4p-hqmp/GHSA-hv2r-vh4p-hqmp.json b/advisories/unreviewed/2024/03/GHSA-hv2r-vh4p-hqmp/GHSA-hv2r-vh4p-hqmp.json
index 666fccafd00..c0c167c908d 100644
--- a/advisories/unreviewed/2024/03/GHSA-hv2r-vh4p-hqmp/GHSA-hv2r-vh4p-hqmp.json
+++ b/advisories/unreviewed/2024/03/GHSA-hv2r-vh4p-hqmp/GHSA-hv2r-vh4p-hqmp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv2r-vh4p-hqmp",
- "modified": "2024-03-14T18:30:30Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:30Z",
"aliases": [
"CVE-2023-22655"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22655"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0006"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00960.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json b/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json
index 235abfb3b37..0a253de92b6 100644
--- a/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json
+++ b/advisories/unreviewed/2024/03/GHSA-j3p2-j2wj-5w6g/GHSA-j3p2-j2wj-5w6g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3p2-j2wj-5w6g",
- "modified": "2024-03-14T18:30:30Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:30Z",
"aliases": [
"CVE-2023-35191"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35191"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0005"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00923.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
index b54f4ea038f..ed3bc1ffbe3 100644
--- a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
+++ b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfw5-pp35-j4h8",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52581"
@@ -18,13 +18,29 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52581"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/09c85f2d21ab6b5acba31a037985b13e8e6565b8"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4aea243b6853d06c1d160a9955b759189aa02b14"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7e5d732e6902eb6a37b35480796838a145ae5f07"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a995a68e8a3b48533e47c856865d109a1f1a9d01"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/cf5000a7787cbc10341091d37245a42c119d26c5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef99506eaf1dc31feff1adfcfd68bc5535a22171"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json b/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json
index e6ac838f8a5..041227d3d48 100644
--- a/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json
+++ b/advisories/unreviewed/2024/03/GHSA-pg2q-wfgh-r323/GHSA-pg2q-wfgh-r323.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-209"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/03/GHSA-pvrq-gg3w-f695/GHSA-pvrq-gg3w-f695.json b/advisories/unreviewed/2024/03/GHSA-pvrq-gg3w-f695/GHSA-pvrq-gg3w-f695.json
index b82c4478da6..13d0ef7c018 100644
--- a/advisories/unreviewed/2024/03/GHSA-pvrq-gg3w-f695/GHSA-pvrq-gg3w-f695.json
+++ b/advisories/unreviewed/2024/03/GHSA-pvrq-gg3w-f695/GHSA-pvrq-gg3w-f695.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvrq-gg3w-f695",
- "modified": "2024-03-14T18:30:30Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:30Z",
"aliases": [
"CVE-2023-39368"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39368"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0007"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00972.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-q99v-mcmh-7x5m/GHSA-q99v-mcmh-7x5m.json b/advisories/unreviewed/2024/03/GHSA-q99v-mcmh-7x5m/GHSA-q99v-mcmh-7x5m.json
index 51cdc5f1540..110396ed69c 100644
--- a/advisories/unreviewed/2024/03/GHSA-q99v-mcmh-7x5m/GHSA-q99v-mcmh-7x5m.json
+++ b/advisories/unreviewed/2024/03/GHSA-q99v-mcmh-7x5m/GHSA-q99v-mcmh-7x5m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q99v-mcmh-7x5m",
- "modified": "2024-03-18T12:30:35Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-18T12:30:35Z",
"aliases": [
"CVE-2024-26639"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/dc904345e3771aa01d0b8358b550802fdc6fe00b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f6564fce256a3944aa1bc76cb3c40e792d97c1eb"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json
index 0f24cac239f..9d4dbed9a43 100644
--- a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json
+++ b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmqf-grh3-9rrr",
- "modified": "2024-03-25T12:30:52Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47178"
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/a20b6eaf4f35046a429cde57bee7eb5f13d6857f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a222d2794c53f8165de20aa91b39e35e4b72bce9"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/03/GHSA-vww6-323c-pxr2/GHSA-vww6-323c-pxr2.json b/advisories/unreviewed/2024/03/GHSA-vww6-323c-pxr2/GHSA-vww6-323c-pxr2.json
index aafd33a0053..b7f975347a7 100644
--- a/advisories/unreviewed/2024/03/GHSA-vww6-323c-pxr2/GHSA-vww6-323c-pxr2.json
+++ b/advisories/unreviewed/2024/03/GHSA-vww6-323c-pxr2/GHSA-vww6-323c-pxr2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vww6-323c-pxr2",
- "modified": "2024-03-14T18:30:31Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:31Z",
"aliases": [
"CVE-2023-43490"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43490"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0009"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01045.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-w5g2-4rxc-h7x8/GHSA-w5g2-4rxc-h7x8.json b/advisories/unreviewed/2024/03/GHSA-w5g2-4rxc-h7x8/GHSA-w5g2-4rxc-h7x8.json
index c14560bc486..294a71d98f5 100644
--- a/advisories/unreviewed/2024/03/GHSA-w5g2-4rxc-h7x8/GHSA-w5g2-4rxc-h7x8.json
+++ b/advisories/unreviewed/2024/03/GHSA-w5g2-4rxc-h7x8/GHSA-w5g2-4rxc-h7x8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5g2-4rxc-h7x8",
- "modified": "2024-03-25T12:30:52Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47179"
@@ -30,6 +30,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a421d218603ffa822a0b8045055c03eae394a7eb"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/aba3c7795f51717ae316f3566442dee7cc3eeccb"
diff --git a/advisories/unreviewed/2024/03/GHSA-x28p-h97m-3347/GHSA-x28p-h97m-3347.json b/advisories/unreviewed/2024/03/GHSA-x28p-h97m-3347/GHSA-x28p-h97m-3347.json
index e024623aee6..b901a5434d8 100644
--- a/advisories/unreviewed/2024/03/GHSA-x28p-h97m-3347/GHSA-x28p-h97m-3347.json
+++ b/advisories/unreviewed/2024/03/GHSA-x28p-h97m-3347/GHSA-x28p-h97m-3347.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x28p-h97m-3347",
- "modified": "2024-03-14T18:30:30Z",
+ "modified": "2024-04-05T09:30:38Z",
"published": "2024-03-14T18:30:30Z",
"aliases": [
"CVE-2023-38575"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38575"
},
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240405-0008"
+ },
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html"
diff --git a/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json b/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json
index 1d54cf468e6..37bd41a30d1 100644
--- a/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json
+++ b/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqf9-qrgq-fxfv",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52525"
@@ -38,6 +38,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/71b1d2b57f145c8469aa9346f0fd57bf59b2b89c"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aef7a0300047e7b4707ea0411dc9597cba108fc8"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b8e260654a29de872e7cb85387d8ab8974694e8e"
diff --git a/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json b/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json
new file mode 100644
index 00000000000..4051d7de3e6
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-2252-87pv-34g4/GHSA-2252-87pv-34g4.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2252-87pv-34g4",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26801"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPIO reset mechanism would\nfree the hci_dev and lead to a use-after-free in hci_error_reset.\n\nHere's the call trace observed on a ChromeOS device with Intel AX201:\n queue_work_on+0x3e/0x6c\n __hci_cmd_sync_sk+0x2ee/0x4c0 [bluetooth ]\n ? init_wait_entry+0x31/0x31\n __hci_cmd_sync+0x16/0x20 [bluetooth ]\n hci_error_reset+0x4f/0xa4 [bluetooth ]\n process_one_work+0x1d8/0x33f\n worker_thread+0x21b/0x373\n kthread+0x13a/0x152\n ? pr_cont_work+0x54/0x54\n ? kthread_blkcg+0x31/0x31\n ret_from_fork+0x1f/0x30\n\nThis patch holds the reference count on the hci_dev while processing\na HCI_EV_HARDWARE_ERROR event to avoid potential crash.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26801"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2449007d3f73b2842c9734f45f0aadb522daf592"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2ab9a19d896f5a0dd386e1f001c5309bc35f433b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/45085686b9559bfbe3a4f41d3d695a520668f5e1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6dd0a9dfa99f8990a08eb8fdd8e79bee31c7d8e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98fb98fd37e42fd4ce13ff657ea64503e24b6090"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/da4569d450b193e39e87119fd316c0291b585d14"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dd594cdc24f2e48dab441732e6dfcafd6b0711d1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e0b278650f07acf2e0932149183458468a731c03"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-25gg-qp55-68p3/GHSA-25gg-qp55-68p3.json b/advisories/unreviewed/2024/04/GHSA-25gg-qp55-68p3/GHSA-25gg-qp55-68p3.json
new file mode 100644
index 00000000000..50b5fb32158
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-25gg-qp55-68p3/GHSA-25gg-qp55-68p3.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-25gg-qp55-68p3",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26797"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Prevent potential buffer overflow in map_hw_resources\n\nAdds a check in the map_hw_resources function to prevent a potential\nbuffer overflow. The function was accessing arrays using an index that\ncould potentially be greater than the size of the arrays, leading to a\nbuffer overflow.\n\nAdds a check to ensure that the index is within the bounds of the\narrays. If the index is out of bounds, an error message is printed and\nbreak it will continue execution with just ignoring extra data early to\nprevent the buffer overflow.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:79 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_stream_id' 6 <= 7\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:81 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_plane_id' 6 <= 7",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26797"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0f8ca019544a252d1afb468ce840c6dcbac73af4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/50a6302cf881f67f1410461a68fe9eabd00ff31d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json b/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json
new file mode 100644
index 00000000000..22e7af419f7
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-29xc-2rhm-5f2q",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-29007"
+ ],
+ "details": "The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29007"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json
new file mode 100644
index 00000000000..01943441748
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2pv2-gg54-r8f4",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26783"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index\n\nWith numa balancing on, when a numa system is running where a numa node\ndoesn't have its local memory so it has no managed zones, the following\noops has been observed. It's because wakeup_kswapd() is called with a\nwrong zone index, -1. Fixed it by checking the index before calling\nwakeup_kswapd().\n\n> BUG: unable to handle page fault for address: 00000000000033f3\n> #PF: supervisor read access in kernel mode\n> #PF: error_code(0x0000) - not-present page\n> PGD 0 P4D 0\n> Oops: 0000 [#1] PREEMPT SMP NOPTI\n> CPU: 2 PID: 895 Comm: masim Not tainted 6.6.0-dirty #255\n> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n> rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n> RIP: 0010:wakeup_kswapd (./linux/mm/vmscan.c:7812)\n> Code: (omitted)\n> RSP: 0000:ffffc90004257d58 EFLAGS: 00010286\n> RAX: ffffffffffffffff RBX: ffff88883fff0480 RCX: 0000000000000003\n> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88883fff0480\n> RBP: ffffffffffffffff R08: ff0003ffffffffff R09: ffffffffffffffff\n> R10: ffff888106c95540 R11: 0000000055555554 R12: 0000000000000003\n> R13: 0000000000000000 R14: 0000000000000000 R15: ffff88883fff0940\n> FS: 00007fc4b8124740(0000) GS:ffff888827c00000(0000) knlGS:0000000000000000\n> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n> CR2: 00000000000033f3 CR3: 000000026cc08004 CR4: 0000000000770ee0\n> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n> PKRU: 55555554\n> Call Trace:\n> \n> ? __die\n> ? page_fault_oops\n> ? __pte_offset_map_lock\n> ? exc_page_fault\n> ? asm_exc_page_fault\n> ? wakeup_kswapd\n> migrate_misplaced_page\n> __handle_mm_fault\n> handle_mm_fault\n> do_user_addr_fault\n> exc_page_fault\n> asm_exc_page_fault\n> RIP: 0033:0x55b897ba0808\n> Code: (omitted)\n> RSP: 002b:00007ffeefa821a0 EFLAGS: 00010287\n> RAX: 000055b89983acd0 RBX: 00007ffeefa823f8 RCX: 000055b89983acd0\n> RDX: 00007fc2f8122010 RSI: 0000000000020000 RDI: 000055b89983acd0\n> RBP: 00007ffeefa821a0 R08: 0000000000000037 R09: 0000000000000075\n> R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000\n> R13: 00007ffeefa82410 R14: 000055b897ba5dd8 R15: 00007fc4b8340000\n> ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26783"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2774f256e7c0219e2b0a0894af1c76bdabc4f974"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bdd21eed8b72f9e28d6c279f6db258e090c79080"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6159bd4c00594249e305bfe02304c67c506264e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json
new file mode 100644
index 00000000000..2433ad9a96f
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2q2v-8vjq-r8m5",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-2115"
+ ],
+ "details": "The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to that of a teacher via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2115"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/changeset/3061953/learnpress/tags/4.0.1/inc/admin/class-lp-admin.php"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/342a4482-f5d3-4cc9-a998-e3abac7142cf?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json
index f2b6bd1a4a6..6a774229c84 100644
--- a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json
+++ b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vp9-gjfg-fmgw",
- "modified": "2024-04-03T15:30:43Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-04-03T15:30:43Z",
"aliases": [
"CVE-2024-26710"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b29b16bd836a838b7690f80e37f8376414c74cbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f1acb109505d983779bbb7e20a1ee6244d2b5736"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json b/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json
new file mode 100644
index 00000000000..9d1d8b2c40e
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-346g-pfrw-wm3v/GHSA-346g-pfrw-wm3v.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-346g-pfrw-wm3v",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25695"
+ ],
+ "details": "There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25695"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3fpg-5xv7-pq63/GHSA-3fpg-5xv7-pq63.json b/advisories/unreviewed/2024/04/GHSA-3fpg-5xv7-pq63/GHSA-3fpg-5xv7-pq63.json
new file mode 100644
index 00000000000..3c45caa5c1c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3fpg-5xv7-pq63/GHSA-3fpg-5xv7-pq63.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3fpg-5xv7-pq63",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-29008"
+ ],
+ "details": "A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM based CloudStack environment, an attacker can exploit this issue to attach host devices such as storage disks, and PCI and USB devices such as network adapters and GPUs, in a regular VM instance that can be further exploited to gain access to the underlying network and storage infrastructure resources, and access any VM instance disks on the local storage.\n\nUsers are advised to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29008"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json b/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json
new file mode 100644
index 00000000000..326c87c4c6e
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3fpg-j8cw-vcjq/GHSA-3fpg-j8cw-vcjq.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3fpg-j8cw-vcjq",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-31081"
+ ],
+ "details": "A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31081"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-31081"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2271998"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-126"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T14:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json b/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json
new file mode 100644
index 00000000000..cc9859f6810
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3h96-p8ww-vw66",
+ "modified": "2024-04-05T15:30:31Z",
+ "published": "2024-04-05T15:30:31Z",
+ "aliases": [
+ "CVE-2024-2499"
+ ],
+ "details": "The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, and including, 0.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2499"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/changeset/3052812/squelch-tabs-and-accordions-shortcodes"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/adf10ad4-38b2-44be-bdc6-ba6b62e9fbe6?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T13:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3mvj-7p7p-x4x5/GHSA-3mvj-7p7p-x4x5.json b/advisories/unreviewed/2024/04/GHSA-3mvj-7p7p-x4x5/GHSA-3mvj-7p7p-x4x5.json
new file mode 100644
index 00000000000..470bcaa83b1
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3mvj-7p7p-x4x5/GHSA-3mvj-7p7p-x4x5.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3mvj-7p7p-x4x5",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-21894"
+ ],
+ "details": "A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21894"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T23:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json b/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json
new file mode 100644
index 00000000000..0b9a3b93dc4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3v83-crv9-cf9p/GHSA-3v83-crv9-cf9p.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3v83-crv9-cf9p",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26793"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix use-after-free and null-ptr-deref in gtp_newlink()\n\nThe gtp_link_ops operations structure for the subsystem must be\nregistered after registering the gtp_net_ops pernet operations structure.\n\nSyzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug:\n\n[ 1010.702740] gtp: GTP module unloaded\n[ 1010.715877] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n[ 1010.715888] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n[ 1010.715895] CPU: 1 PID: 128616 Comm: a.out Not tainted 6.8.0-rc6-std-def-alt1 #1\n[ 1010.715899] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014\n[ 1010.715908] RIP: 0010:gtp_newlink+0x4d7/0x9c0 [gtp]\n[ 1010.715915] Code: 80 3c 02 00 0f 85 41 04 00 00 48 8b bb d8 05 00 00 e8 ed f6 ff ff 48 89 c2 48 89 c5 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 4f 04 00 00 4c 89 e2 4c 8b 6d 00 48 b8 00 00 00\n[ 1010.715920] RSP: 0018:ffff888020fbf180 EFLAGS: 00010203\n[ 1010.715929] RAX: dffffc0000000000 RBX: ffff88800399c000 RCX: 0000000000000000\n[ 1010.715933] RDX: 0000000000000001 RSI: ffffffff84805280 RDI: 0000000000000282\n[ 1010.715938] RBP: 000000000000000d R08: 0000000000000001 R09: 0000000000000000\n[ 1010.715942] R10: 0000000000000001 R11: 0000000000000001 R12: ffff88800399cc80\n[ 1010.715947] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000400\n[ 1010.715953] FS: 00007fd1509ab5c0(0000) GS:ffff88805b300000(0000) knlGS:0000000000000000\n[ 1010.715958] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1010.715962] CR2: 0000000000000000 CR3: 000000001c07a000 CR4: 0000000000750ee0\n[ 1010.715968] PKRU: 55555554\n[ 1010.715972] Call Trace:\n[ 1010.715985] ? __die_body.cold+0x1a/0x1f\n[ 1010.715995] ? die_addr+0x43/0x70\n[ 1010.716002] ? exc_general_protection+0x199/0x2f0\n[ 1010.716016] ? asm_exc_general_protection+0x1e/0x30\n[ 1010.716026] ? gtp_newlink+0x4d7/0x9c0 [gtp]\n[ 1010.716034] ? gtp_net_exit+0x150/0x150 [gtp]\n[ 1010.716042] __rtnl_newlink+0x1063/0x1700\n[ 1010.716051] ? rtnl_setlink+0x3c0/0x3c0\n[ 1010.716063] ? is_bpf_text_address+0xc0/0x1f0\n[ 1010.716070] ? kernel_text_address.part.0+0xbb/0xd0\n[ 1010.716076] ? __kernel_text_address+0x56/0xa0\n[ 1010.716084] ? unwind_get_return_address+0x5a/0xa0\n[ 1010.716091] ? create_prof_cpu_mask+0x30/0x30\n[ 1010.716098] ? arch_stack_walk+0x9e/0xf0\n[ 1010.716106] ? stack_trace_save+0x91/0xd0\n[ 1010.716113] ? stack_trace_consume_entry+0x170/0x170\n[ 1010.716121] ? __lock_acquire+0x15c5/0x5380\n[ 1010.716139] ? mark_held_locks+0x9e/0xe0\n[ 1010.716148] ? kmem_cache_alloc_trace+0x35f/0x3c0\n[ 1010.716155] ? __rtnl_newlink+0x1700/0x1700\n[ 1010.716160] rtnl_newlink+0x69/0xa0\n[ 1010.716166] rtnetlink_rcv_msg+0x43b/0xc50\n[ 1010.716172] ? rtnl_fdb_dump+0x9f0/0x9f0\n[ 1010.716179] ? lock_acquire+0x1fe/0x560\n[ 1010.716188] ? netlink_deliver_tap+0x12f/0xd50\n[ 1010.716196] netlink_rcv_skb+0x14d/0x440\n[ 1010.716202] ? rtnl_fdb_dump+0x9f0/0x9f0\n[ 1010.716208] ? netlink_ack+0xab0/0xab0\n[ 1010.716213] ? netlink_deliver_tap+0x202/0xd50\n[ 1010.716220] ? netlink_deliver_tap+0x218/0xd50\n[ 1010.716226] ? __virt_addr_valid+0x30b/0x590\n[ 1010.716233] netlink_unicast+0x54b/0x800\n[ 1010.716240] ? netlink_attachskb+0x870/0x870\n[ 1010.716248] ? __check_object_size+0x2de/0x3b0\n[ 1010.716254] netlink_sendmsg+0x938/0xe40\n[ 1010.716261] ? netlink_unicast+0x800/0x800\n[ 1010.716269] ? __import_iovec+0x292/0x510\n[ 1010.716276] ? netlink_unicast+0x800/0x800\n[ 1010.716284] __sock_sendmsg+0x159/0x190\n[ 1010.716290] ____sys_sendmsg+0x712/0x880\n[ 1010.716297] ? sock_write_iter+0x3d0/0x3d0\n[ 1010.716304] ? __ia32_sys_recvmmsg+0x270/0x270\n[ 1010.716309] ? lock_acquire+0x1fe/0x560\n[ 1010.716315] ? drain_array_locked+0x90/0x90\n[ 1010.716324] ___sys_sendmsg+0xf8/0x170\n[ 1010.716331] ? sendmsg_copy_msghdr+0x170/0x170\n[ 1010.716337] ? lockdep_init_map\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26793"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/01129059d5141d62fae692f7a336ae3bc712d3eb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5366969a19a8a0d2ffb3d27ef6e8905e5e4216f8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/616d82c3cfa2a2146dd7e3ae47bda7e877ee549e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9376d059a705c5dfaac566c2d09891242013ae16"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/93dd420bc41531c9a31498b9538ca83ba6ec191e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/abd32d7f5c0294c1b2454c5a3b13b18446bac627"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e668b92a3a01429923fd5ca13e99642aab47de69"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ec92aa2cab6f0048f10d6aa4f025c5885cb1a1b6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json
new file mode 100644
index 00000000000..05d6f210ccb
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3xr5-7rvh-x3v2",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25705"
+ ],
+ "details": "There is a cross site scripting vulnerability in the Esri Portal for ArcGIS Experience Builder 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are low. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25705"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json b/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json
new file mode 100644
index 00000000000..43c6d6c52a4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-43fc-v55w-5mx4",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25708"
+ ],
+ "details": "There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25708"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json b/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json
new file mode 100644
index 00000000000..8bbdd9c4825
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-44wr-9xpq-76v2",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26745"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV\n\nWhen kdump kernel tries to copy dump data over SR-IOV, LPAR panics due\nto NULL pointer exception:\n\n Kernel attempted to read user page (0) - exploit attempt? (uid: 0)\n BUG: Kernel NULL pointer dereference on read at 0x00000000\n Faulting instruction address: 0xc000000020847ad4\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: mlx5_core(+) vmx_crypto pseries_wdt papr_scm libnvdimm mlxfw tls psample sunrpc fuse overlay squashfs loop\n CPU: 12 PID: 315 Comm: systemd-udevd Not tainted 6.4.0-Test102+ #12\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c000000020847ad4 LR: c00000002083b2dc CTR: 00000000006cd18c\n REGS: c000000029162ca0 TRAP: 0300 Not tainted (6.4.0-Test102+)\n MSR: 800000000280b033 CR: 48288244 XER: 00000008\n CFAR: c00000002083b2d8 DAR: 0000000000000000 DSISR: 40000000 IRQMASK: 1\n ...\n NIP _find_next_zero_bit+0x24/0x110\n LR bitmap_find_next_zero_area_off+0x5c/0xe0\n Call Trace:\n dev_printk_emit+0x38/0x48 (unreliable)\n iommu_area_alloc+0xc4/0x180\n iommu_range_alloc+0x1e8/0x580\n iommu_alloc+0x60/0x130\n iommu_alloc_coherent+0x158/0x2b0\n dma_iommu_alloc_coherent+0x3c/0x50\n dma_alloc_attrs+0x170/0x1f0\n mlx5_cmd_init+0xc0/0x760 [mlx5_core]\n mlx5_function_setup+0xf0/0x510 [mlx5_core]\n mlx5_init_one+0x84/0x210 [mlx5_core]\n probe_one+0x118/0x2c0 [mlx5_core]\n local_pci_probe+0x68/0x110\n pci_call_probe+0x68/0x200\n pci_device_probe+0xbc/0x1a0\n really_probe+0x104/0x540\n __driver_probe_device+0xb4/0x230\n driver_probe_device+0x54/0x130\n __driver_attach+0x158/0x2b0\n bus_for_each_dev+0xa8/0x130\n driver_attach+0x34/0x50\n bus_add_driver+0x16c/0x300\n driver_register+0xa4/0x1b0\n __pci_register_driver+0x68/0x80\n mlx5_init+0xb8/0x100 [mlx5_core]\n do_one_initcall+0x60/0x300\n do_init_module+0x7c/0x2b0\n\nAt the time of LPAR dump, before kexec hands over control to kdump\nkernel, DDWs (Dynamic DMA Windows) are scanned and added to the FDT.\nFor the SR-IOV case, default DMA window \"ibm,dma-window\" is removed from\nthe FDT and DDW added, for the device.\n\nNow, kexec hands over control to the kdump kernel.\n\nWhen the kdump kernel initializes, PCI busses are scanned and IOMMU\ngroup/tables created, in pci_dma_bus_setup_pSeriesLP(). For the SR-IOV\ncase, there is no \"ibm,dma-window\". The original commit: b1fc44eaa9ba,\nfixes the path where memory is pre-mapped (direct mapped) to the DDW.\nWhen TCEs are direct mapped, there is no need to initialize IOMMU\ntables.\n\niommu_table_setparms_lpar() only considers \"ibm,dma-window\" property\nwhen initiallizing IOMMU table. In the scenario where TCEs are\ndynamically allocated for SR-IOV, newly created IOMMU table is not\ninitialized. Later, when the device driver tries to enter TCEs for the\nSR-IOV device, NULL pointer execption is thrown from iommu_area_alloc().\n\nThe fix is to initialize the IOMMU table with DDW property stored in the\nFDT. There are 2 points to remember:\n\n\t1. For the dedicated adapter, kdump kernel would encounter both\n\t default and DDW in FDT. In this case, DDW property is used to\n\t initialize the IOMMU table.\n\n\t2. A DDW could be direct or dynamic mapped. kdump kernel would\n\t initialize IOMMU table and mark the existing DDW as\n\t \"dynamic\". This works fine since, at the time of table\n\t initialization, iommu_table_clear() makes some space in the\n\t DDW, for some predefined number of TCEs which are needed for\n\t kdump to succeed.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26745"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/09a3c1e46142199adcee372a420b024b4fc61051"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5da6d306f315344af1ca2eff4bd9b10b130f0c28"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7eb95e0af5c9c2e6fad50356eaf32d216d0e7bc3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d4d1e4b1513d975961de7bb4f75e450a92d65ebf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json
new file mode 100644
index 00000000000..51991e5981d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4965-8838-r53x/GHSA-4965-8838-r53x.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4965-8838-r53x",
+ "modified": "2024-04-05T12:31:16Z",
+ "published": "2024-04-05T12:31:16Z",
+ "aliases": [
+ "CVE-2023-6522"
+ ],
+ "details": "Improper Privilege Management vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users.This issue affects Extreme XDS: before 3914.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6522"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-24-0276"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-269"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T12:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4cqm-42fg-6pwv/GHSA-4cqm-42fg-6pwv.json b/advisories/unreviewed/2024/04/GHSA-4cqm-42fg-6pwv/GHSA-4cqm-42fg-6pwv.json
new file mode 100644
index 00000000000..81bf1ff3da3
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4cqm-42fg-6pwv/GHSA-4cqm-42fg-6pwv.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4cqm-42fg-6pwv",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25698"
+ ],
+ "details": "There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25698"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json b/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json
new file mode 100644
index 00000000000..7cc1fcf58df
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4jvv-2c5h-wr97",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26788"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-qdma: init irq after reg initialization\n\nInitialize the qDMA irqs after the registers are configured so that\ninterrupts that may have been pending from a primary kernel don't get\nprocessed by the irq handler before it is ready to and cause panic with\nthe following trace:\n\n Call trace:\n fsl_qdma_queue_handler+0xf8/0x3e8\n __handle_irq_event_percpu+0x78/0x2b0\n handle_irq_event_percpu+0x1c/0x68\n handle_irq_event+0x44/0x78\n handle_fasteoi_irq+0xc8/0x178\n generic_handle_irq+0x24/0x38\n __handle_domain_irq+0x90/0x100\n gic_handle_irq+0x5c/0xb8\n el1_irq+0xb8/0x180\n _raw_spin_unlock_irqrestore+0x14/0x40\n __setup_irq+0x4bc/0x798\n request_threaded_irq+0xd8/0x190\n devm_request_threaded_irq+0x74/0xe8\n fsl_qdma_probe+0x4d4/0xca8\n platform_drv_probe+0x50/0xa0\n really_probe+0xe0/0x3f8\n driver_probe_device+0x64/0x130\n device_driver_attach+0x6c/0x78\n __driver_attach+0xbc/0x158\n bus_for_each_dev+0x5c/0x98\n driver_attach+0x20/0x28\n bus_add_driver+0x158/0x220\n driver_register+0x60/0x110\n __platform_driver_register+0x44/0x50\n fsl_qdma_driver_init+0x18/0x20\n do_one_initcall+0x48/0x258\n kernel_init_freeable+0x1a4/0x23c\n kernel_init+0x10/0xf8\n ret_from_fork+0x10/0x18",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26788"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3cc5fb824c2125aa3740d905b3e5b378c8a09478"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4529c084a320be78ff2c5e64297ae998c6fdf66b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/474d521da890b3e3585335fb80a6044cb2553d99"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/677102a930643c31f1b4c512b041407058bdfef8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87a39071e0b639f45e05d296cc0538eef44ec0bd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9579a21e99fe8dab22a253050ddff28d340d74e1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a69c8bbb946936ac4eb6a6ae1e849435aa8d947d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json
new file mode 100644
index 00000000000..4cf2a124d33
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4q8v-gqw7-8xpx",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26789"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: arm64/neonbs - fix out-of-bounds access on short input\n\nThe bit-sliced implementation of AES-CTR operates on blocks of 128\nbytes, and will fall back to the plain NEON version for tail blocks or\ninputs that are shorter than 128 bytes to begin with.\n\nIt will call straight into the plain NEON asm helper, which performs all\nmemory accesses in granules of 16 bytes (the size of a NEON register).\nFor this reason, the associated plain NEON glue code will copy inputs\nshorter than 16 bytes into a temporary buffer, given that this is a rare\noccurrence and it is not worth the effort to work around this in the asm\ncode.\n\nThe fallback from the bit-sliced NEON version fails to take this into\naccount, potentially resulting in out-of-bounds accesses. So clone the\nsame workaround, and use a temp buffer for short in/outputs.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26789"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/034e2d70b5c7f578200ad09955aeb2aa65d1164a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1291d278b5574819a7266568ce4c28bce9438705"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1c0cf6d19690141002889d72622b90fc01562ce4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9e8ecd4908b53941ab6f0f51584ab80c6c6606c4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json
new file mode 100644
index 00000000000..bd6806a9a16
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4ww3-585w-6p9r",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25706"
+ ],
+ "details": "There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25706"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json b/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json
new file mode 100644
index 00000000000..8c31968b3e1
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4x7j-vfwq-rj38",
+ "modified": "2024-04-04T21:30:32Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-29387"
+ ],
+ "details": "projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29387"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cve.anas-cherni.me/2024/04/04/cve-2024-29387"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-55vp-7jr8-5mm9/GHSA-55vp-7jr8-5mm9.json b/advisories/unreviewed/2024/04/GHSA-55vp-7jr8-5mm9/GHSA-55vp-7jr8-5mm9.json
new file mode 100644
index 00000000000..feb8c18ffa1
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-55vp-7jr8-5mm9/GHSA-55vp-7jr8-5mm9.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-55vp-7jr8-5mm9",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25703"
+ ],
+ "details": "There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25703"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json b/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
new file mode 100644
index 00000000000..e4e9b78d563
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5656-3635-q384",
+ "modified": "2024-04-05T15:30:31Z",
+ "published": "2024-04-05T15:30:31Z",
+ "aliases": [
+ "CVE-2023-49965"
+ ],
+ "details": "SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49965"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hackintoanetwork.com/blog/2023-starlink-router-gen2-xss-eng"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T14:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json b/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json
new file mode 100644
index 00000000000..586359aaa57
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-56m7-9pwj-r76p",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-29863"
+ ],
+ "details": "A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29863"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.qlik.com/t5/Official-Support-Articles/High-Severity-Security-fix-for-QlikView-CVE-2024-29863/ta-p/2432661"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T07:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json b/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json
index 64fafbce2d7..7b7934f7c56 100644
--- a/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json
+++ b/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g26-fc68-x9f2",
- "modified": "2024-04-02T09:30:41Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-04-02T09:30:41Z",
"aliases": [
"CVE-2024-26678"
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26678"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0a962f2fbaa976af9eed21d0306370cded485787"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/1ad55cecf22f05f1c884adf63cc09d3c3e609ebf"
diff --git a/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json b/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json
new file mode 100644
index 00000000000..0167083d7ac
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5h4m-75jp-hg7m",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-31498"
+ ],
+ "details": "ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31498"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.yubico.com/support/security-advisories/ysa-2024-01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T23:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json b/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json
new file mode 100644
index 00000000000..67f125fc8d6
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5mg2-h7qv-m552/GHSA-5mg2-h7qv-m552.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5mg2-h7qv-m552",
+ "modified": "2024-04-10T15:30:32Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-27437"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Disable auto-enable of exclusive INTx IRQ\n\nCurrently for devices requiring masking at the irqchip for INTx, ie.\ndevices without DisINTx support, the IRQ is enabled in request_irq()\nand subsequently disabled as necessary to align with the masked status\nflag. This presents a window where the interrupt could fire between\nthese events, resulting in the IRQ incrementing the disable depth twice.\nThis would be unrecoverable for a user since the masked flag prevents\nnested enables through vfio.\n\nInstead, invert the logic using IRQF_NO_AUTOEN such that exclusive INTx\nis never auto-enabled, then unmask as required.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27437"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/139dfcc4d723ab13469881200c7d80f49d776060"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a4a666c45107206605b7b5bc20545f8aabc4fa2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3b3491ad0f80d913e7d255941d4470f4a4d9bfda"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7a2f0955ffceffadfe098b40b50307431f45438"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bf0bc84a20e6109ab07d5dc072067bd01eb931ec"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fe9a7082684eb059b925c535682e68c34d487d43"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json b/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json
new file mode 100644
index 00000000000..b4f6b69f275
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5qc4-82jh-h385",
+ "modified": "2024-04-04T21:30:31Z",
+ "published": "2024-04-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-27316"
+ ],
+ "details": "HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27316"
+ },
+ {
+ "type": "WEB",
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5rw8-2rrx-mf5m/GHSA-5rw8-2rrx-mf5m.json b/advisories/unreviewed/2024/04/GHSA-5rw8-2rrx-mf5m/GHSA-5rw8-2rrx-mf5m.json
new file mode 100644
index 00000000000..e599746a978
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5rw8-2rrx-mf5m/GHSA-5rw8-2rrx-mf5m.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5rw8-2rrx-mf5m",
+ "modified": "2024-04-04T21:30:30Z",
+ "published": "2024-04-04T21:30:30Z",
+ "aliases": [
+ "CVE-2024-22052"
+ ],
+ "details": "A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22052"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-5xrf-xvwc-pmfg/GHSA-5xrf-xvwc-pmfg.json b/advisories/unreviewed/2024/04/GHSA-5xrf-xvwc-pmfg/GHSA-5xrf-xvwc-pmfg.json
new file mode 100644
index 00000000000..95b5a538f55
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-5xrf-xvwc-pmfg/GHSA-5xrf-xvwc-pmfg.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5xrf-xvwc-pmfg",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2023-36643"
+ ],
+ "details": "Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36643"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/caffeinated-labs/CVE-2023-36643"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json b/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json
new file mode 100644
index 00000000000..a3f8fb1c82e
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-6426-p644-ffcf/GHSA-6426-p644-ffcf.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6426-p644-ffcf",
+ "modified": "2024-04-04T12:30:58Z",
+ "published": "2024-04-04T12:30:58Z",
+ "aliases": [
+ "CVE-2024-3262"
+ ],
+ "details": "Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3262"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/vulnerabilidad-de-exposicion-de-informacion-en-request-tracker-rt"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T10:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json b/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json
new file mode 100644
index 00000000000..d59e592e9c3
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-69h6-fpm9-fc3r/GHSA-69h6-fpm9-fc3r.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-69h6-fpm9-fc3r",
+ "modified": "2024-04-10T15:30:32Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-26813"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/platform: Create persistent IRQ handlers\n\nThe vfio-platform SET_IRQS ioctl currently allows loopback triggering of\nan interrupt before a signaling eventfd has been configured by the user,\nwhich thereby allows a NULL pointer dereference.\n\nRather than register the IRQ relative to a valid trigger, register all\nIRQs in a disabled state in the device open path. This allows mask\noperations on the IRQ to nest within the overall enable state governed\nby a valid eventfd signal. This decouples @masked, protected by the\n@locked spinlock from @trigger, protected via the @igate mutex.\n\nIn doing so, it's guaranteed that changes to @trigger cannot race the\nIRQ handlers because the IRQ handler is synchronously disabled before\nmodifying the trigger, and loopback triggering of the IRQ via ioctl is\nsafe due to serialization with trigger changes via igate.\n\nFor compatibility, request_irq() failures are maintained to be local to\nthe SET_IRQS ioctl rather than a fatal error in the open device path.\nThis allows, for example, a userspace driver with polling mode support\nto continue to work regardless of moving the request_irq() call site.\nThis necessarily blocks all SET_IRQS access to the failed index.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26813"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0f8d8f9c2173a541812dd750529f4a415117eb29"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/62d4e43a569b67929eb3319780be5359694c8086"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/675daf435e9f8e5a5eab140a9864dfad6668b375"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7932db06c82c5b2f42a4d1a849d97dba9ce4a362"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cc5838f19d39a5fef04c468199699d2a4578be3a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6bedd6acc0bcb1e7e010bc046032e47f08d379f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-6gmw-8x48-q8ww/GHSA-6gmw-8x48-q8ww.json b/advisories/unreviewed/2024/04/GHSA-6gmw-8x48-q8ww/GHSA-6gmw-8x48-q8ww.json
new file mode 100644
index 00000000000..e5d906017f9
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-6gmw-8x48-q8ww/GHSA-6gmw-8x48-q8ww.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6gmw-8x48-q8ww",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-26329"
+ ],
+ "details": "Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26329"
+ },
+ {
+ "type": "WEB",
+ "url": "https://x41-dsec.de/lab/advisories/x41-2024-001-chilkat-prng"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T07:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json b/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json
new file mode 100644
index 00000000000..216310de601
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6jfg-4px6-v4c9",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25692"
+ ],
+ "details": "\nThere is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25692"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json b/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
new file mode 100644
index 00000000000..8c802e67268
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6jqp-mm8h-jjgv",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26781"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix possible deadlock in subflow diag\n\nSyzbot and Eric reported a lockdep splat in the subflow diag:\n\n WARNING: possible circular locking dependency detected\n 6.8.0-rc4-syzkaller-00212-g40b9385dd8e6 #0 Not tainted\n\n syz-executor.2/24141 is trying to acquire lock:\n ffff888045870130 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at:\n tcp_diag_put_ulp net/ipv4/tcp_diag.c:100 [inline]\n ffff888045870130 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at:\n tcp_diag_get_aux+0x738/0x830 net/ipv4/tcp_diag.c:137\n\n but task is already holding lock:\n ffffc9000135e488 (&h->lhash2[i].lock){+.+.}-{2:2}, at: spin_lock\n include/linux/spinlock.h:351 [inline]\n ffffc9000135e488 (&h->lhash2[i].lock){+.+.}-{2:2}, at:\n inet_diag_dump_icsk+0x39f/0x1f80 net/ipv4/inet_diag.c:1038\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&h->lhash2[i].lock){+.+.}-{2:2}:\n lock_acquire+0x1e3/0x530 kernel/locking/lockdep.c:5754\n __raw_spin_lock include/linux/spinlock_api_smp.h:133 [inline]\n _raw_spin_lock+0x2e/0x40 kernel/locking/spinlock.c:154\n spin_lock include/linux/spinlock.h:351 [inline]\n __inet_hash+0x335/0xbe0 net/ipv4/inet_hashtables.c:743\n inet_csk_listen_start+0x23a/0x320 net/ipv4/inet_connection_sock.c:1261\n __inet_listen_sk+0x2a2/0x770 net/ipv4/af_inet.c:217\n inet_listen+0xa3/0x110 net/ipv4/af_inet.c:239\n rds_tcp_listen_init+0x3fd/0x5a0 net/rds/tcp_listen.c:316\n rds_tcp_init_net+0x141/0x320 net/rds/tcp.c:577\n ops_init+0x352/0x610 net/core/net_namespace.c:136\n __register_pernet_operations net/core/net_namespace.c:1214 [inline]\n register_pernet_operations+0x2cb/0x660 net/core/net_namespace.c:1283\n register_pernet_device+0x33/0x80 net/core/net_namespace.c:1370\n rds_tcp_init+0x62/0xd0 net/rds/tcp.c:735\n do_one_initcall+0x238/0x830 init/main.c:1236\n do_initcall_level+0x157/0x210 init/main.c:1298\n do_initcalls+0x3f/0x80 init/main.c:1314\n kernel_init_freeable+0x42f/0x5d0 init/main.c:1551\n kernel_init+0x1d/0x2a0 init/main.c:1441\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:242\n\n -> #0 (k-sk_lock-AF_INET6){+.+.}-{0:0}:\n check_prev_add kernel/locking/lockdep.c:3134 [inline]\n check_prevs_add kernel/locking/lockdep.c:3253 [inline]\n validate_chain+0x18ca/0x58e0 kernel/locking/lockdep.c:3869\n __lock_acquire+0x1345/0x1fd0 kernel/locking/lockdep.c:5137\n lock_acquire+0x1e3/0x530 kernel/locking/lockdep.c:5754\n lock_sock_fast include/net/sock.h:1723 [inline]\n subflow_get_info+0x166/0xd20 net/mptcp/diag.c:28\n tcp_diag_put_ulp net/ipv4/tcp_diag.c:100 [inline]\n tcp_diag_get_aux+0x738/0x830 net/ipv4/tcp_diag.c:137\n inet_sk_diag_fill+0x10ed/0x1e00 net/ipv4/inet_diag.c:345\n inet_diag_dump_icsk+0x55b/0x1f80 net/ipv4/inet_diag.c:1061\n __inet_diag_dump+0x211/0x3a0 net/ipv4/inet_diag.c:1263\n inet_diag_dump_compat+0x1c1/0x2d0 net/ipv4/inet_diag.c:1371\n netlink_dump+0x59b/0xc80 net/netlink/af_netlink.c:2264\n __netlink_dump_start+0x5df/0x790 net/netlink/af_netlink.c:2370\n netlink_dump_start include/linux/netlink.h:338 [inline]\n inet_diag_rcv_msg_compat+0x209/0x4c0 net/ipv4/inet_diag.c:1405\n sock_diag_rcv_msg+0xe7/0x410\n netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2543\n sock_diag_rcv+0x2a/0x40 net/core/sock_diag.c:280\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x7ea/0x980 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0xa3b/0xd70 net/netlink/af_netlink.c:1908\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584\n ___sys_sendmsg net/socket.c:2638 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\n\nAs noted by Eric we can break the lock dependency chain avoid\ndumping \n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26781"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70e5b013538d5e4cb421afed431a5fcd2a5d49ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cc32ba2fdf3f8b136619fff551f166ba51ec856d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d487e7ba1bc7444d5f062c4930ef8436c47c7e63"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6a9608af9a75d13243d217f6ce1e30e57d56ffe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f27d319df055629480b84b9288a502337b6f2a2e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa8c776f4c323a9fbc8ddf25edcb962083391430"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-6x3j-xjx9-j84h/GHSA-6x3j-xjx9-j84h.json b/advisories/unreviewed/2024/04/GHSA-6x3j-xjx9-j84h/GHSA-6x3j-xjx9-j84h.json
new file mode 100644
index 00000000000..17f1bb602fd
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-6x3j-xjx9-j84h/GHSA-6x3j-xjx9-j84h.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6x3j-xjx9-j84h",
+ "modified": "2024-04-04T09:30:32Z",
+ "published": "2024-04-04T09:30:32Z",
+ "aliases": [
+ "CVE-2023-25199"
+ ],
+ "details": "A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to execute JavaScript code and obtain sensitive information in a victim's browser.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25199"
+ },
+ {
+ "type": "WEB",
+ "url": "https://summitinfosec.com/blog/x-ray-vision-identifying-cve-2023-25199-and-cve-2023-25200-in-manufacturing-equipment"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T07:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-78h8-m693-fp8x/GHSA-78h8-m693-fp8x.json b/advisories/unreviewed/2024/04/GHSA-78h8-m693-fp8x/GHSA-78h8-m693-fp8x.json
new file mode 100644
index 00000000000..ac4d31d4d06
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-78h8-m693-fp8x/GHSA-78h8-m693-fp8x.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-78h8-m693-fp8x",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2023-36645"
+ ],
+ "details": "SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36645"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/caffeinated-labs/CVE-2023-36645"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json
new file mode 100644
index 00000000000..1fa122e2fab
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7g5r-fqfh-59j6",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26799"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: Fix uninitialized pointer dmactl\n\nIn the case where __lpass_get_dmactl_handle is called and the driver\nid dai_id is invalid the pointer dmactl is not being assigned a value,\nand dmactl contains a garbage value since it has not been initialized\nand so the null check may not work. Fix this to initialize dmactl to\nNULL. One could argue that modern compilers will set this to zero, but\nit is useful to keep this initialized as per the same way in functions\n__lpass_platform_codec_intf_init and lpass_cdc_dma_daiops_hw_params.\n\nCleans up clang scan build warning:\nsound/soc/qcom/lpass-cdc-dma.c:275:7: warning: Branch condition\nevaluates to a garbage value [core.uninitialized.Branch]",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26799"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1382d8b55129875b2e07c4d2a7ebc790183769ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/99adc8b4d2f38bf0d06483ec845bc48f60c3f8cf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d5a7726e6ea62d447b79ab5baeb537ea6bdb225b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json b/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json
new file mode 100644
index 00000000000..cf19a5e97be
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7hfh-vfcv-wfqp",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25699"
+ ],
+ "details": "\nThere is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 through 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially allow a remote, unauthenticated attacker to compromise the confidentiality, integrity, and availability of the software.\n\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25699"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-287"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json b/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json
new file mode 100644
index 00000000000..a5b130a46ac
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-7vqv-4gqw-665q/GHSA-7vqv-4gqw-665q.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7vqv-4gqw-665q",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26791"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: dev-replace: properly validate device names\n\nThere's a syzbot report that device name buffers passed to device\nreplace are not properly checked for string termination which could lead\nto a read out of bounds in getname_kernel().\n\nAdd a helper that validates both source and target device name buffers.\nFor devid as the source initialize the buffer to empty string in case\nsomething tries to read it later.\n\nThis was originally analyzed and fixed in a different way by Edward Adam\nDavis (see links).",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26791"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/11d7a2e429c02d51e2dc90713823ea8b8d3d3a84"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2886fe308a83968dde252302884a1e63351cf16d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/343eecb4ff49a7b1cc1dfe86958a805cf2341cfb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9845664b9ee47ce7ee7ea93caf47d39a9d4552c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ab2d68655d0f04650bef09fee948ff80597c5fb9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b1690ced4d2d8b28868811fb81cd33eee5aefee1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c6652e20d7d783d060fe5f987eac7b5cabe31311"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f590040ce2b712177306b03c2a63b16f7d48d3c8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json b/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json
new file mode 100644
index 00000000000..68da47eaf0b
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-7w6v-jhvx-qx5c/GHSA-7w6v-jhvx-qx5c.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7w6v-jhvx-qx5c",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26792"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix double free of anonymous device after snapshot creation failure\n\nWhen creating a snapshot we may do a double free of an anonymous device\nin case there's an error committing the transaction. The second free may\nresult in freeing an anonymous device number that was allocated by some\nother subsystem in the kernel or another btrfs filesystem.\n\nThe steps that lead to this:\n\n1) At ioctl.c:create_snapshot() we allocate an anonymous device number\n and assign it to pending_snapshot->anon_dev;\n\n2) Then we call btrfs_commit_transaction() and end up at\n transaction.c:create_pending_snapshot();\n\n3) There we call btrfs_get_new_fs_root() and pass it the anonymous device\n number stored in pending_snapshot->anon_dev;\n\n4) btrfs_get_new_fs_root() frees that anonymous device number because\n btrfs_lookup_fs_root() returned a root - someone else did a lookup\n of the new root already, which could some task doing backref walking;\n\n5) After that some error happens in the transaction commit path, and at\n ioctl.c:create_snapshot() we jump to the 'fail' label, and after\n that we free again the same anonymous device number, which in the\n meanwhile may have been reallocated somewhere else, because\n pending_snapshot->anon_dev still has the same value as in step 1.\n\nRecently syzbot ran into this and reported the following trace:\n\n ------------[ cut here ]------------\n ida_free called for id=51 which is not allocated.\n WARNING: CPU: 1 PID: 31038 at lib/idr.c:525 ida_free+0x370/0x420 lib/idr.c:525\n Modules linked in:\n CPU: 1 PID: 31038 Comm: syz-executor.2 Not tainted 6.8.0-rc4-syzkaller-00410-gc02197fc9076 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\n RIP: 0010:ida_free+0x370/0x420 lib/idr.c:525\n Code: 10 42 80 3c 28 (...)\n RSP: 0018:ffffc90015a67300 EFLAGS: 00010246\n RAX: be5130472f5dd000 RBX: 0000000000000033 RCX: 0000000000040000\n RDX: ffffc90009a7a000 RSI: 000000000003ffff RDI: 0000000000040000\n RBP: ffffc90015a673f0 R08: ffffffff81577992 R09: 1ffff92002b4cdb4\n R10: dffffc0000000000 R11: fffff52002b4cdb5 R12: 0000000000000246\n R13: dffffc0000000000 R14: ffffffff8e256b80 R15: 0000000000000246\n FS: 00007fca3f4b46c0(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f167a17b978 CR3: 000000001ed26000 CR4: 0000000000350ef0\n Call Trace:\n \n btrfs_get_root_ref+0xa48/0xaf0 fs/btrfs/disk-io.c:1346\n create_pending_snapshot+0xff2/0x2bc0 fs/btrfs/transaction.c:1837\n create_pending_snapshots+0x195/0x1d0 fs/btrfs/transaction.c:1931\n btrfs_commit_transaction+0xf1c/0x3740 fs/btrfs/transaction.c:2404\n create_snapshot+0x507/0x880 fs/btrfs/ioctl.c:848\n btrfs_mksubvol+0x5d0/0x750 fs/btrfs/ioctl.c:998\n btrfs_mksnapshot+0xb5/0xf0 fs/btrfs/ioctl.c:1044\n __btrfs_ioctl_snap_create+0x387/0x4b0 fs/btrfs/ioctl.c:1306\n btrfs_ioctl_snap_create_v2+0x1ca/0x400 fs/btrfs/ioctl.c:1393\n btrfs_ioctl+0xa74/0xd40\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:871 [inline]\n __se_sys_ioctl+0xfe/0x170 fs/ioctl.c:857\n do_syscall_64+0xfb/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\n RIP: 0033:0x7fca3e67dda9\n Code: 28 00 00 00 (...)\n RSP: 002b:00007fca3f4b40c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 00007fca3e7abf80 RCX: 00007fca3e67dda9\n RDX: 00000000200005c0 RSI: 0000000050009417 RDI: 0000000000000003\n RBP: 00007fca3e6ca47a R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 000000000000000b R14: 00007fca3e7abf80 R15: 00007fff6bf95658\n \n\nWhere we get an explicit message where we attempt to free an anonymous\ndevice number that is not currently allocated. It happens in a different\ncode path from the example below, at btrfs_get_root_ref(), so this change\nmay not fix the case triggered by sy\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26792"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c34adc20b91a8e55e048b18d63f4f4ae003ecf8f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c8ab7521665bd0f8bc4a900244d1d5a7095cc3b9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e2b54eaf28df0c978626c9736b94f003b523b451"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eb3441093aad251418921246fc3b224fd1575701"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
new file mode 100644
index 00000000000..58cac746a9b
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7xpv-78qx-q843",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26805"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: Fix kernel-infoleak-after-free in __skb_datagram_iter\n\nsyzbot reported the following uninit-value access issue [1]:\n\nnetlink_to_full_skb() creates a new `skb` and puts the `skb->data`\npassed as a 1st arg of netlink_to_full_skb() onto new `skb`. The data\nsize is specified as `len` and passed to skb_put_data(). This `len`\nis based on `skb->end` that is not data offset but buffer offset. The\n`skb->end` contains data and tailroom. Since the tailroom is not\ninitialized when the new `skb` created, KMSAN detects uninitialized\nmemory area when copying the data.\n\nThis patch resolved this issue by correct the len from `skb->end` to\n`skb->len`, which is the actual data offset.\n\nBUG: KMSAN: kernel-infoleak-after-free in instrument_copy_to_user include/linux/instrumented.h:114 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in copy_to_user_iter lib/iov_iter.c:24 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_ubuf include/linux/iov_iter.h:29 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance include/linux/iov_iter.h:271 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n instrument_copy_to_user include/linux/instrumented.h:114 [inline]\n copy_to_user_iter lib/iov_iter.c:24 [inline]\n iterate_ubuf include/linux/iov_iter.h:29 [inline]\n iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\n iterate_and_advance include/linux/iov_iter.h:271 [inline]\n _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n copy_to_iter include/linux/uio.h:197 [inline]\n simple_copy_to_iter+0x68/0xa0 net/core/datagram.c:532\n __skb_datagram_iter+0x123/0xdc0 net/core/datagram.c:420\n skb_copy_datagram_iter+0x5c/0x200 net/core/datagram.c:546\n skb_copy_datagram_msg include/linux/skbuff.h:3960 [inline]\n packet_recvmsg+0xd9c/0x2000 net/packet/af_packet.c:3482\n sock_recvmsg_nosec net/socket.c:1044 [inline]\n sock_recvmsg net/socket.c:1066 [inline]\n sock_read_iter+0x467/0x580 net/socket.c:1136\n call_read_iter include/linux/fs.h:2014 [inline]\n new_sync_read fs/read_write.c:389 [inline]\n vfs_read+0x8f6/0xe00 fs/read_write.c:470\n ksys_read+0x20f/0x4c0 fs/read_write.c:613\n __do_sys_read fs/read_write.c:623 [inline]\n __se_sys_read fs/read_write.c:621 [inline]\n __x64_sys_read+0x93/0xd0 fs/read_write.c:621\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was stored to memory at:\n skb_put_data include/linux/skbuff.h:2622 [inline]\n netlink_to_full_skb net/netlink/af_netlink.c:181 [inline]\n __netlink_deliver_tap_skb net/netlink/af_netlink.c:298 [inline]\n __netlink_deliver_tap+0x5be/0xc90 net/netlink/af_netlink.c:325\n netlink_deliver_tap net/netlink/af_netlink.c:338 [inline]\n netlink_deliver_tap_kernel net/netlink/af_netlink.c:347 [inline]\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x10f1/0x1250 net/netlink/af_netlink.c:1368\n netlink_sendmsg+0x1238/0x13d0 net/netlink/af_netlink.c:1910\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n free_pages_prepare mm/page_alloc.c:1087 [inline]\n free_unref_page_prepare+0xb0/0xa40 mm/page_alloc.c:2347\n free_unref_page_list+0xeb/0x1100 mm/page_alloc.c:2533\n release_pages+0x23d3/0x2410 mm/swap.c:1042\n free_pages_and_swap_cache+0xd9/0xf0 mm/swap_state.c:316\n tlb_batch_pages\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26805"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b27bf4c494d61e5663baa34c3edd7ccebf0ea44"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/59fc3e3d049e39e7d0d271f20dd5fb47c57faf1d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/661779e1fcafe1b74b3f3fe8e980c1e207fea1fd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ae51361da43270f4ba0eb924427a07e87e48777"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c71ed29d15b1a1ed6c464f8c3536996963046285"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3ada42e534a83b618bbc1e490d23bf0fdae4736"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ec343a55b687a452f5e87f3b52bf9f155864df65"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f19d1f98e60e68b11fc60839105dd02a30ec0d77"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json b/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
new file mode 100644
index 00000000000..5b225291cfa
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-85q5-wrpf-m53q",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-3217"
+ ],
+ "details": "The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3217"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/browser/wpdirectorykit/trunk/application/controllers/Wdk_frontendajax.php#L72"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/changeset/3064842/wpdirectorykit/trunk/application/controllers/Wdk_frontendajax.php"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09b315e6-d973-467d-8b8d-4b7b4a7ca3f8?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-85r2-29g6-f4w7/GHSA-85r2-29g6-f4w7.json b/advisories/unreviewed/2024/04/GHSA-85r2-29g6-f4w7/GHSA-85r2-29g6-f4w7.json
new file mode 100644
index 00000000000..49e48d183cc
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-85r2-29g6-f4w7/GHSA-85r2-29g6-f4w7.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-85r2-29g6-f4w7",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25693"
+ ],
+ "details": "There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25693"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json
new file mode 100644
index 00000000000..47c33ef18a4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-866j-mv4h-26jh",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26803"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: veth: clear GRO when clearing XDP even when down\n\nveth sets NETIF_F_GRO automatically when XDP is enabled,\nbecause both features use the same NAPI machinery.\n\nThe logic to clear NETIF_F_GRO sits in veth_disable_xdp() which\nis called both on ndo_stop and when XDP is turned off.\nTo avoid the flag from being cleared when the device is brought\ndown, the clearing is skipped when IFF_UP is not set.\nBringing the device down should indeed not modify its features.\n\nUnfortunately, this means that clearing is also skipped when\nXDP is disabled _while_ the device is down. And there's nothing\non the open path to bring the device features back into sync.\nIOW if user enables XDP, disables it and then brings the device\nup we'll end up with a stray GRO flag set but no NAPI instances.\n\nWe don't depend on the GRO flag on the datapath, so the datapath\nwon't crash. We will crash (or hang), however, next time features\nare sync'ed (either by user via ethtool or peer changing its config).\nThe GRO flag will go away, and veth will try to disable the NAPIs.\nBut the open path never created them since XDP was off, the GRO flag\nwas a stray. If NAPI was initialized before we'll hang in napi_disable().\nIf it never was we'll crash trying to stop uninitialized hrtimer.\n\nMove the GRO flag updates to the XDP enable / disable paths,\ninstead of mixing them with the ndo_open / ndo_close paths.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26803"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/16edf51f33f52dff70ed455bc40a6cc443c04664"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7985d73961bbb4e726c1be7b9cd26becc7be8325"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f7a3894e58e6f5d5815533cfde60e3838947941"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f011c103e654d83dc85f057a7d1bd0960d02831c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fe9f801355f0b47668419f30f1fac1cf4539e736"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-8f9g-693j-6rw3/GHSA-8f9g-693j-6rw3.json b/advisories/unreviewed/2024/04/GHSA-8f9g-693j-6rw3/GHSA-8f9g-693j-6rw3.json
new file mode 100644
index 00000000000..35218048941
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-8f9g-693j-6rw3/GHSA-8f9g-693j-6rw3.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8f9g-693j-6rw3",
+ "modified": "2024-04-04T21:30:29Z",
+ "published": "2024-04-04T21:30:29Z",
+ "aliases": [
+ "CVE-2024-25007"
+ ],
+ "details": "\nEricsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25007"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin--ericsson-network-manager-march-2024"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1236"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T19:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json
new file mode 100644
index 00000000000..d999fba1c3d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8fvm-73q4-3j6f",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25709"
+ ],
+ "details": "There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS versions 10.8.1 – 1121 that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item which will potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25709"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json
new file mode 100644
index 00000000000..083b18b6e3c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8vf4-q8g2-79g5",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26787"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmci: stm32: fix DMA API overlapping mappings warning\n\nTurning on CONFIG_DMA_API_DEBUG_SG results in the following warning:\n\nDMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST,\noverlapping mappings aren't supported\nWARNING: CPU: 1 PID: 51 at kernel/dma/debug.c:568\nadd_dma_entry+0x234/0x2f4\nModules linked in:\nCPU: 1 PID: 51 Comm: kworker/1:2 Not tainted 6.1.28 #1\nHardware name: STMicroelectronics STM32MP257F-EV1 Evaluation Board (DT)\nWorkqueue: events_freezable mmc_rescan\nCall trace:\nadd_dma_entry+0x234/0x2f4\ndebug_dma_map_sg+0x198/0x350\n__dma_map_sg_attrs+0xa0/0x110\ndma_map_sg_attrs+0x10/0x2c\nsdmmc_idma_prep_data+0x80/0xc0\nmmci_prep_data+0x38/0x84\nmmci_start_data+0x108/0x2dc\nmmci_request+0xe4/0x190\n__mmc_start_request+0x68/0x140\nmmc_start_request+0x94/0xc0\nmmc_wait_for_req+0x70/0x100\nmmc_send_tuning+0x108/0x1ac\nsdmmc_execute_tuning+0x14c/0x210\nmmc_execute_tuning+0x48/0xec\nmmc_sd_init_uhs_card.part.0+0x208/0x464\nmmc_sd_init_card+0x318/0x89c\nmmc_attach_sd+0xe4/0x180\nmmc_rescan+0x244/0x320\n\nDMA API debug brings to light leaking dma-mappings as dma_map_sg and\ndma_unmap_sg are not correctly balanced.\n\nIf an error occurs in mmci_cmd_irq function, only mmci_dma_error\nfunction is called and as this API is not managed on stm32 variant,\ndma_unmap_sg is never called in this error path.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26787"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0224cbc53ba82b84affa7619b6d1b1a254bc2c53"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/176e66269f0de327375fc0ea51c12c2f5a97e4c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ae5060e17a3fc38e54c3e5bd8abd6b1d5bfae7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6b1ba3f9040be5efc4396d86c9752cdc564730be"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70af82bb9c897faa25a44e4181f36c60312b71ef"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d610a307225951929b9dff807788439454476f85"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json b/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json
new file mode 100644
index 00000000000..44ccce42eb5
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8xc6-54p8-3p65",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26807"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-qspi: fix pointer reference in runtime PM hooks\n\ndev_get_drvdata() gets used to acquire the pointer to cqspi and the SPI\ncontroller. Neither embed the other; this lead to memory corruption.\n\nOn a given platform (Mobileye EyeQ5) the memory corruption is hidden\ninside cqspi->f_pdata. Also, this uninitialised memory is used as a\nmutex (ctlr->bus_lock_mutex) by spi_controller_suspend().",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26807"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/03f1573c9587029730ca68503f5062105b122f61"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/32ce3bb57b6b402de2aec1012511e7ac4e7449dc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/34e1d5c4407c78de0e3473e1fbf8fb74dbe66d03"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json b/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json
new file mode 100644
index 00000000000..8603caf035c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8xr9-89pc-8wcx",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25690"
+ ],
+ "details": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25690"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-80"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json
new file mode 100644
index 00000000000..ccfff2d3a9a
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9243-vfr2-5rcw",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2023-3454"
+ ],
+ "details": "Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3454"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23215"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-78"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T17:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json b/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json
new file mode 100644
index 00000000000..fc7d465e102
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-95rc-29j2-q3vr/GHSA-95rc-29j2-q3vr.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-95rc-29j2-q3vr",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26780"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix task hung while purging oob_skb in GC.\n\nsyzbot reported a task hung; at the same time, GC was looping infinitely\nin list_for_each_entry_safe() for OOB skb. [0]\n\nsyzbot demonstrated that the list_for_each_entry_safe() was not actually\nsafe in this case.\n\nA single skb could have references for multiple sockets. If we free such\na skb in the list_for_each_entry_safe(), the current and next sockets could\nbe unlinked in a single iteration.\n\nunix_notinflight() uses list_del_init() to unlink the socket, so the\nprefetched next socket forms a loop itself and list_for_each_entry_safe()\nnever stops.\n\nHere, we must use while() and make sure we always fetch the first socket.\n\n[0]:\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 5065 Comm: syz-executor236 Not tainted 6.8.0-rc3-syzkaller-00136-g1f719a2f3fa6 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nRIP: 0010:preempt_count arch/x86/include/asm/preempt.h:26 [inline]\nRIP: 0010:check_kcov_mode kernel/kcov.c:173 [inline]\nRIP: 0010:__sanitizer_cov_trace_pc+0xd/0x60 kernel/kcov.c:207\nCode: cc cc cc cc 66 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 65 48 8b 14 25 40 c2 03 00 <65> 8b 05 b4 7c 78 7e a9 00 01 ff 00 48 8b 34 24 74 0f f6 c4 01 74\nRSP: 0018:ffffc900033efa58 EFLAGS: 00000283\nRAX: ffff88807b077800 RBX: ffff88807b077800 RCX: 1ffffffff27b1189\nRDX: ffff88802a5a3b80 RSI: ffffffff8968488d RDI: ffff88807b077f70\nRBP: ffffc900033efbb0 R08: 0000000000000001 R09: fffffbfff27a900c\nR10: ffffffff93d48067 R11: ffffffff8ae000eb R12: ffff88807b077800\nR13: dffffc0000000000 R14: ffff88807b077e40 R15: 0000000000000001\nFS: 0000000000000000(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000564f4fc1e3a8 CR3: 000000000d57a000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n \n \n unix_gc+0x563/0x13b0 net/unix/garbage.c:319\n unix_release_sock+0xa93/0xf80 net/unix/af_unix.c:683\n unix_release+0x91/0xf0 net/unix/af_unix.c:1064\n __sock_release+0xb0/0x270 net/socket.c:659\n sock_close+0x1c/0x30 net/socket.c:1421\n __fput+0x270/0xb80 fs/file_table.c:376\n task_work_run+0x14f/0x250 kernel/task_work.c:180\n exit_task_work include/linux/task_work.h:38 [inline]\n do_exit+0xa8a/0x2ad0 kernel/exit.c:871\n do_group_exit+0xd4/0x2a0 kernel/exit.c:1020\n __do_sys_exit_group kernel/exit.c:1031 [inline]\n __se_sys_exit_group kernel/exit.c:1029 [inline]\n __x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1029\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd5/0x270 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f9d6cbdac09\nCode: Unable to access opcode bytes at 0x7f9d6cbdabdf.\nRSP: 002b:00007fff5952feb8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9d6cbdac09\nRDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000000\nRBP: 00007f9d6cc552b0 R08: ffffffffffffffb8 R09: 0000000000000006\nR10: 0000000000000006 R11: 0000000000000246 R12: 00007f9d6cc552b0\nR13: 0000000000000000 R14: 00007f9d6cc55d00 R15: 00007f9d6cbabe70\n ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26780"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/25236c91b5ab4a26a56ba2e79b8060cf4e047839"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a3d40b4025fcfe51b04924979f1653993b17669"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36f7371de977f805750748e80279be7e370df85c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/69e0f04460f4037e01e29f0d9675544f62aafca3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cb8890318dde26fc89c6ea67d6e9070ab50b6e91"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json b/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json
new file mode 100644
index 00000000000..dc9ec5636c4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json
@@ -0,0 +1,54 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-96rw-9jfw-gw2m",
+ "modified": "2024-04-04T21:30:32Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-3311"
+ ],
+ "details": "A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the function ZipUtils.unZipFiles of the file controller/admin/ThemesController.java. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.3.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259369 was assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3311"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitee.com/iteachyou/dreamer_cms/releases/tag/Latest_Stable_Release_4.1.3.1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitee.com/y1336247431/poc-public/issues/I9BA5R"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259369"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259369"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.303874"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T21:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json
new file mode 100644
index 00000000000..6cb96da199a
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9fvf-9v35-97qv",
+ "modified": "2024-04-04T21:30:30Z",
+ "published": "2024-04-04T21:30:30Z",
+ "aliases": [
+ "CVE-2023-38709"
+ ],
+ "details": "Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.\n\nThis issue affects Apache HTTP Server: through 2.4.58.\n",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38709"
+ },
+ {
+ "type": "WEB",
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json b/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json
new file mode 100644
index 00000000000..1a12668d8b1
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9m65-6pjm-r78p",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-27981"
+ ],
+ "details": "A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.\n\nAffected Products:\nUniFi Network Application (Version 8.0.28 and earlier) .\n \nMitigation:\nUpdate UniFi Network Application to Version 8.1.113 or later.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27981"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-038-038/9d13fead-47de-4372-b2c1-745b8d6b0399"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T23:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json b/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json
new file mode 100644
index 00000000000..fe09d5f7880
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9m7w-p6hr-xv2x/GHSA-9m7w-p6hr-xv2x.json
@@ -0,0 +1,54 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9m7w-p6hr-xv2x",
+ "modified": "2024-04-05T15:30:31Z",
+ "published": "2024-04-05T15:30:30Z",
+ "aliases": [
+ "CVE-2023-5692"
+ ],
+ "details": "WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5692"
+ },
+ {
+ "type": "WEB",
+ "url": "https://core.trac.wordpress.org/changeset/57645"
+ },
+ {
+ "type": "WEB",
+ "url": "https://developer.wordpress.org/reference/functions/is_post_publicly_viewable"
+ },
+ {
+ "type": "WEB",
+ "url": "https://developer.wordpress.org/reference/functions/is_post_type_viewable"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/WordPress/wordpress-develop/blob/6.3/src/wp-includes/canonical.php#L763"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e6f993b-ce09-4050-84a1-cbe9953f36b1?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T13:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json
new file mode 100644
index 00000000000..1157f5983d8
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9rp8-67w7-gf47",
+ "modified": "2024-04-04T12:30:57Z",
+ "published": "2024-04-04T12:30:57Z",
+ "aliases": [
+ "CVE-2024-26808"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain\n\nRemove netdevice from inet/ingress basechain in case NETDEV_UNREGISTER\nevent is reported, otherwise a stale reference to netdevice remains in\nthe hook list.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26808"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/01acb2e8666a6529697141a6017edbf206921913"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36a0a80f32209238469deb481967d777a3d539ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70f17b48c86622217a58d5099d29242fc9adac58"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9489e214ea8f2a90345516016aa51f2db3a8cc2f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af149a46890e8285d1618bd68b8d159bdb87fdb3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e5888acbf1a3d8d021990ce6c6061fd5b2bb21b4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T10:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json b/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json
new file mode 100644
index 00000000000..e736b3e4b72
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9wj5-w226-r39m",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2023-36644"
+ ],
+ "details": "Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36644"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/caffeinated-labs/CVE-2023-36644"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json b/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json
new file mode 100644
index 00000000000..0b78e3b2f67
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c3rj-rhqm-q53c",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25700"
+ ],
+ "details": "There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions <= 11.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in a web map link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json
new file mode 100644
index 00000000000..6fb1cfc1a4c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c4ch-cv96-r58v",
+ "modified": "2024-04-04T21:30:31Z",
+ "published": "2024-04-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-24795"
+ ],
+ "details": "HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.\n\nUsers are recommended to upgrade to version 2.4.59, which fixes this issue.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24795"
+ },
+ {
+ "type": "WEB",
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-cm2m-f7gc-hv64/GHSA-cm2m-f7gc-hv64.json b/advisories/unreviewed/2024/04/GHSA-cm2m-f7gc-hv64/GHSA-cm2m-f7gc-hv64.json
new file mode 100644
index 00000000000..78241d970b3
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-cm2m-f7gc-hv64/GHSA-cm2m-f7gc-hv64.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cm2m-f7gc-hv64",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-31082"
+ ],
+ "details": "A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31082"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-31082"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2271999"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-126"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T14:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json b/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json
new file mode 100644
index 00000000000..e4d36ff65bc
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-cq4r-22pw-4cc7/GHSA-cq4r-22pw-4cc7.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cq4r-22pw-4cc7",
+ "modified": "2024-04-04T21:30:32Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-3314"
+ ],
+ "details": "A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. The manipulation leads to sql injection. The attack may be initiated remotely. The identifier VDB-259385 was assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3314"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259385"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259385"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.309526"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T21:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json b/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json
new file mode 100644
index 00000000000..ada2c79f0c8
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-cxc3-9vgm-w6pp/GHSA-cxc3-9vgm-w6pp.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cxc3-9vgm-w6pp",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-3299"
+ ],
+ "details": "Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT file. NOTE: this vulnerability was SPLIT from CVE-2024-1847.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3299"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.3ds.com/vulnerability/advisories"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T15:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json b/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json
new file mode 100644
index 00000000000..bfec61f567c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-f34w-8j75-rh85/GHSA-f34w-8j75-rh85.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f34w-8j75-rh85",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26795"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Sparse-Memory/vmemmap out-of-bounds fix\n\nOffset vmemmap so that the first page of vmemmap will be mapped\nto the first page of physical memory in order to ensure that\nvmemmap’s bounds will be respected during\npfn_to_page()/page_to_pfn() operations.\nThe conversion macros will produce correct SV39/48/57 addresses\nfor every possible/valid DRAM_BASE inside the physical memory limits.\n\nv2:Address Alex's comments",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26795"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a1728c15ec4f45ed9248ae22f626541c179bfbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5941a90c55d3bfba732b32208d58d997600b44ef"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8310080799b40fd9f2a8b808c657269678c149af"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8af1c121b0102041809bc137ec600d1865eaeedd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a11dd49dcb9376776193e15641f84fcc1e5980c9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a278d5c60f21aa15d540abb2f2da6e6d795c3e6e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-ffgg-5wp9-rrp5/GHSA-ffgg-5wp9-rrp5.json b/advisories/unreviewed/2024/04/GHSA-ffgg-5wp9-rrp5/GHSA-ffgg-5wp9-rrp5.json
new file mode 100644
index 00000000000..552dfe6860d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-ffgg-5wp9-rrp5/GHSA-ffgg-5wp9-rrp5.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ffgg-5wp9-rrp5",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25704"
+ ],
+ "details": "There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions <= 11.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in the Experience Builder Embed widget which when loaded could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25704"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json b/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
new file mode 100644
index 00000000000..51cfd34965b
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fgh4-9fc9-vxgv",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-3298"
+ ],
+ "details": "Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT from CVE-2024-1847.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3298"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.3ds.com/vulnerability/advisories"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T15:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json
new file mode 100644
index 00000000000..1ce4188548c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fp6w-hx4c-x44g",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26782"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix double-free on socket dismantle\n\nwhen MPTCP server accepts an incoming connection, it clones its listener\nsocket. However, the pointer to 'inet_opt' for the new socket has the same\nvalue as the original one: as a consequence, on program exit it's possible\nto observe the following splat:\n\n BUG: KASAN: double-free in inet_sock_destruct+0x54f/0x8b0\n Free of addr ffff888485950880 by task swapper/25/0\n\n CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Not tainted 6.8.0-rc1+ #609\n Hardware name: Supermicro SYS-6027R-72RF/X9DRH-7TF/7F/iTF/iF, BIOS 3.0 07/26/2013\n Call Trace:\n \n dump_stack_lvl+0x32/0x50\n print_report+0xca/0x620\n kasan_report_invalid_free+0x64/0x90\n __kasan_slab_free+0x1aa/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n rcu_do_batch+0x34e/0xd90\n rcu_core+0x559/0xac0\n __do_softirq+0x183/0x5a4\n irq_exit_rcu+0x12d/0x170\n sysvec_apic_timer_interrupt+0x6b/0x80\n \n \n asm_sysvec_apic_timer_interrupt+0x16/0x20\n RIP: 0010:cpuidle_enter_state+0x175/0x300\n Code: 30 00 0f 84 1f 01 00 00 83 e8 01 83 f8 ff 75 e5 48 83 c4 18 44 89 e8 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc fb 45 85 ed <0f> 89 60 ff ff ff 48 c1 e5 06 48 c7 43 18 00 00 00 00 48 83 44 2b\n RSP: 0018:ffff888481cf7d90 EFLAGS: 00000202\n RAX: 0000000000000000 RBX: ffff88887facddc8 RCX: 0000000000000000\n RDX: 1ffff1110ff588b1 RSI: 0000000000000019 RDI: ffff88887fac4588\n RBP: 0000000000000004 R08: 0000000000000002 R09: 0000000000043080\n R10: 0009b02ea273363f R11: ffff88887fabf42b R12: ffffffff932592e0\n R13: 0000000000000004 R14: 0000000000000000 R15: 00000022c880ec80\n cpuidle_enter+0x4a/0xa0\n do_idle+0x310/0x410\n cpu_startup_entry+0x51/0x60\n start_secondary+0x211/0x270\n secondary_startup_64_no_verify+0x184/0x18b\n \n\n Allocated by task 6853:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n __kasan_kmalloc+0xa6/0xb0\n __kmalloc+0x1eb/0x450\n cipso_v4_sock_setattr+0x96/0x360\n netlbl_sock_setattr+0x132/0x1f0\n selinux_netlbl_socket_post_create+0x6c/0x110\n selinux_socket_post_create+0x37b/0x7f0\n security_socket_post_create+0x63/0xb0\n __sock_create+0x305/0x450\n __sys_socket_create.part.23+0xbd/0x130\n __sys_socket+0x37/0xb0\n __x64_sys_socket+0x6f/0xb0\n do_syscall_64+0x83/0x160\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 6858:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x12c/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n subflow_ulp_release+0x1f0/0x250\n tcp_cleanup_ulp+0x6e/0x110\n tcp_v4_destroy_sock+0x5a/0x3a0\n inet_csk_destroy_sock+0x135/0x390\n tcp_fin+0x416/0x5c0\n tcp_data_queue+0x1bc8/0x4310\n tcp_rcv_state_process+0x15a3/0x47b0\n tcp_v4_do_rcv+0x2c1/0x990\n tcp_v4_rcv+0x41fb/0x5ed0\n ip_protocol_deliver_rcu+0x6d/0x9f0\n ip_local_deliver_finish+0x278/0x360\n ip_local_deliver+0x182/0x2c0\n ip_rcv+0xb5/0x1c0\n __netif_receive_skb_one_core+0x16e/0x1b0\n process_backlog+0x1e3/0x650\n __napi_poll+0xa6/0x500\n net_rx_action+0x740/0xbb0\n __do_softirq+0x183/0x5a4\n\n The buggy address belongs to the object at ffff888485950880\n which belongs to the cache kmalloc-64 of size 64\n The buggy address is located 0 bytes inside of\n 64-byte region [ffff888485950880, ffff8884859508c0)\n\n The buggy address belongs to the physical page:\n page:0000000056d1e95e refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888485950700 pfn:0x485950\n flags: 0x57ffffc0000800(slab|node=1|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0057ffffc0000800 ffff88810004c640 ffffea00121b8ac0 dead000000000006\n raw: ffff888485950700 0000000000200019 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888485950780: fa fb fb\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26782"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10048689def7e40a4405acda16fdc6477d4ecc5c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4a4eeb6912538c2d0b158e8d11b62d96c1dada4e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/85933e80d077c9ae2227226beb86c22f464059cc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ce0809ada38dca8d6d41bb57ab40494855c30582"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d93fd40c62397326046902a2c5cb75af50882a85"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f74362a004225df935863dea6eb7d82daaa5b16e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json
new file mode 100644
index 00000000000..1c281ff73fc
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fpf4-cfch-367m",
+ "modified": "2024-04-10T15:30:32Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-26810"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Lock external INTx masking ops\n\nMask operations through config space changes to DisINTx may race INTx\nconfiguration changes via ioctl. Create wrappers that add locking for\npaths outside of the core interrupt code.\n\nIn particular, irq_type is updated holding igate, therefore testing\nis_intx() requires holding igate. For example clearing DisINTx from\nconfig space can otherwise race changes of the interrupt configuration.\n\nThis aligns interfaces which may trigger the INTx eventfd into two\ncamps, one side serialized by igate and the other only enabled while\nINTx is configured. A subsequent patch introduces synchronization for\nthe latter flows.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26810"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/03505e3344b0576fd619416793a31eae9c5b73bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/04a4a017b9ffd7b0f427b8c376688d14cb614651"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3fe0ac10bd117df847c93408a9d428a453cd60e5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6fe478d855b20ac1eb5da724afe16af5a2aaaa40"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/810cd4bb53456d0503cc4e7934e063835152c1b7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json b/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json
new file mode 100644
index 00000000000..06117a72767
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-frw5-678v-439g/GHSA-frw5-678v-439g.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-frw5-678v-439g",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26746"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Ensure safe user copy of completion record\n\nIf CONFIG_HARDENED_USERCOPY is enabled, copying completion record from\nevent log cache to user triggers a kernel bug.\n\n[ 1987.159822] usercopy: Kernel memory exposure attempt detected from SLUB object 'dsa0' (offset 74, size 31)!\n[ 1987.170845] ------------[ cut here ]------------\n[ 1987.176086] kernel BUG at mm/usercopy.c:102!\n[ 1987.180946] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 1987.186866] CPU: 17 PID: 528 Comm: kworker/17:1 Not tainted 6.8.0-rc2+ #5\n[ 1987.194537] Hardware name: Intel Corporation AvenueCity/AvenueCity, BIOS BHSDCRB1.86B.2492.D03.2307181620 07/18/2023\n[ 1987.206405] Workqueue: wq0.0 idxd_evl_fault_work [idxd]\n[ 1987.212338] RIP: 0010:usercopy_abort+0x72/0x90\n[ 1987.217381] Code: 58 65 9c 50 48 c7 c2 17 85 61 9c 57 48 c7 c7 98 fd 6b 9c 48 0f 44 d6 48 c7 c6 b3 08 62 9c 4c 89 d1 49 0f 44 f3 e8 1e 2e d5 ff <0f> 0b 49 c7 c1 9e 42 61 9c 4c 89 cf 4d 89 c8 eb a9 66 66 2e 0f 1f\n[ 1987.238505] RSP: 0018:ff62f5cf20607d60 EFLAGS: 00010246\n[ 1987.244423] RAX: 000000000000005f RBX: 000000000000001f RCX: 0000000000000000\n[ 1987.252480] RDX: 0000000000000000 RSI: ffffffff9c61429e RDI: 00000000ffffffff\n[ 1987.260538] RBP: ff62f5cf20607d78 R08: ff2a6a89ef3fffe8 R09: 00000000fffeffff\n[ 1987.268595] R10: ff2a6a89eed00000 R11: 0000000000000003 R12: ff2a66934849c89a\n[ 1987.276652] R13: 0000000000000001 R14: ff2a66934849c8b9 R15: ff2a66934849c899\n[ 1987.284710] FS: 0000000000000000(0000) GS:ff2a66b22fe40000(0000) knlGS:0000000000000000\n[ 1987.293850] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 1987.300355] CR2: 00007fe291a37000 CR3: 000000010fbd4005 CR4: 0000000000f71ef0\n[ 1987.308413] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 1987.316470] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 1987.324527] PKRU: 55555554\n[ 1987.327622] Call Trace:\n[ 1987.330424] \n[ 1987.332826] ? show_regs+0x6e/0x80\n[ 1987.336703] ? die+0x3c/0xa0\n[ 1987.339988] ? do_trap+0xd4/0xf0\n[ 1987.343662] ? do_error_trap+0x75/0xa0\n[ 1987.347922] ? usercopy_abort+0x72/0x90\n[ 1987.352277] ? exc_invalid_op+0x57/0x80\n[ 1987.356634] ? usercopy_abort+0x72/0x90\n[ 1987.360988] ? asm_exc_invalid_op+0x1f/0x30\n[ 1987.365734] ? usercopy_abort+0x72/0x90\n[ 1987.370088] __check_heap_object+0xb7/0xd0\n[ 1987.374739] __check_object_size+0x175/0x2d0\n[ 1987.379588] idxd_copy_cr+0xa9/0x130 [idxd]\n[ 1987.384341] idxd_evl_fault_work+0x127/0x390 [idxd]\n[ 1987.389878] process_one_work+0x13e/0x300\n[ 1987.394435] ? __pfx_worker_thread+0x10/0x10\n[ 1987.399284] worker_thread+0x2f7/0x420\n[ 1987.403544] ? _raw_spin_unlock_irqrestore+0x2b/0x50\n[ 1987.409171] ? __pfx_worker_thread+0x10/0x10\n[ 1987.414019] kthread+0x107/0x140\n[ 1987.417693] ? __pfx_kthread+0x10/0x10\n[ 1987.421954] ret_from_fork+0x3d/0x60\n[ 1987.426019] ? __pfx_kthread+0x10/0x10\n[ 1987.430281] ret_from_fork_asm+0x1b/0x30\n[ 1987.434744] \n\nThe issue arises because event log cache is created using\nkmem_cache_create() which is not suitable for user copy.\n\nFix the issue by creating event log cache with\nkmem_cache_create_usercopy(), ensuring safe user copy.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26746"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e3022ea42e490a36ec6f2cfa6fc603deb0bace4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bb71e040323175e18c233a9afef32ba14fa64eb7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3ea125df37dc37972d581b74a5d3785c3f283ab"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json b/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json
new file mode 100644
index 00000000000..c39d5041db9
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-gj3p-9jv7-cm49/GHSA-gj3p-9jv7-cm49.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gj3p-9jv7-cm49",
+ "modified": "2024-04-05T03:30:28Z",
+ "published": "2024-04-05T03:30:28Z",
+ "aliases": [
+ "CVE-2024-3321"
+ ],
+ "details": "A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown part of the component Maintenance Module. The manipulation of the argument Subject Code/Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259389 was assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3321"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/qqqyc/vuln/blob/main/eLearning%20System-XSS-04.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259389"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259389"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.310122"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T01:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json b/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json
new file mode 100644
index 00000000000..e5e4f66d625
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-gj98-2c7c-vmc4/GHSA-gj98-2c7c-vmc4.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gj98-2c7c-vmc4",
+ "modified": "2024-04-05T15:30:31Z",
+ "published": "2024-04-05T15:30:31Z",
+ "aliases": [
+ "CVE-2024-31852"
+ ],
+ "details": "LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is \"we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low, because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So, if this function is covered by any testing, the miscompile is most likely to be discovered before the binary is shipped to production.\"",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31852"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/llvm/llvm-project/issues/80287"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/llvmbot/llvm-project/commit/0e16af8e4cf3a66ad5d078d52744ae2776f9c4b2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugs.chromium.org/p/llvm/issues/detail?id=69"
+ },
+ {
+ "type": "WEB",
+ "url": "https://llvm.org/docs/Security.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T15:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-gvmc-5p79-xx55/GHSA-gvmc-5p79-xx55.json b/advisories/unreviewed/2024/04/GHSA-gvmc-5p79-xx55/GHSA-gvmc-5p79-xx55.json
new file mode 100644
index 00000000000..68041bc9969
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-gvmc-5p79-xx55/GHSA-gvmc-5p79-xx55.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gvmc-5p79-xx55",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-30891"
+ ],
+ "details": "A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30891"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Lantern-r/IoT-vuln/blob/main/Tenda/AC18/formexeCommand.md"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json b/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json
index f64c7883446..61cbd1faf0c 100644
--- a/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json
+++ b/advisories/unreviewed/2024/04/GHSA-h2vw-qxx3-m3jv/GHSA-h2vw-qxx3-m3jv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2vw-qxx3-m3jv",
- "modified": "2024-04-03T12:31:05Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-04-02T00:30:47Z",
"aliases": [
"CVE-2024-3141"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/strik3r0x1/Vulns/blob/main/Clavister_E80-RXSS.md"
},
+ {
+ "type": "WEB",
+ "url": "https://my.clavister.com/downloads/?sid=1"
+ },
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.258916"
diff --git a/advisories/unreviewed/2024/04/GHSA-h88c-q974-86mm/GHSA-h88c-q974-86mm.json b/advisories/unreviewed/2024/04/GHSA-h88c-q974-86mm/GHSA-h88c-q974-86mm.json
new file mode 100644
index 00000000000..703712d1b70
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-h88c-q974-86mm/GHSA-h88c-q974-86mm.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h88c-q974-86mm",
+ "modified": "2024-04-05T06:30:46Z",
+ "published": "2024-04-05T06:30:46Z",
+ "aliases": [
+ "CVE-2023-52235"
+ ],
+ "details": "SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52235"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugcrowd.com/disclosures/f529009b-90eb-4bf9-957d-6fe7ea890fa2/starlink-dishy-is-vulnerable-to-csrf-via-dns-rebinding"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T06:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json b/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json
new file mode 100644
index 00000000000..47448df0ae8
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-hg8p-x2hq-57m9/GHSA-hg8p-x2hq-57m9.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hg8p-x2hq-57m9",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-3316"
+ ],
+ "details": "A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/view_category.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259387.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3316"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/adminininin/blob/blob/main/2.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259387"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259387"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.309584"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T22:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json b/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json
new file mode 100644
index 00000000000..9e8bd8d7cbe
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-hhxq-r4w4-4f7m/GHSA-hhxq-r4w4-4f7m.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hhxq-r4w4-4f7m",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26784"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: arm: Fix NULL dereference on scmi_perf_domain removal\n\nOn unloading of the scmi_perf_domain module got the below splat, when in\nthe DT provided to the system under test the '#power-domain-cells' property\nwas missing. Indeed, this particular setup causes the probe to bail out\nearly without giving any error, which leads to the ->remove() callback gets\nto run too, but without all the expected initialized structures in place.\n\nAdd a check and bail out early on remove too.\n\n Call trace:\n scmi_perf_domain_remove+0x28/0x70 [scmi_perf_domain]\n scmi_dev_remove+0x28/0x40 [scmi_core]\n device_remove+0x54/0x90\n device_release_driver_internal+0x1dc/0x240\n driver_detach+0x58/0xa8\n bus_remove_driver+0x78/0x108\n driver_unregister+0x38/0x70\n scmi_driver_unregister+0x28/0x180 [scmi_core]\n scmi_perf_domain_driver_exit+0x18/0xb78 [scmi_perf_domain]\n __arm64_sys_delete_module+0x1a8/0x2c0\n invoke_syscall+0x50/0x128\n el0_svc_common.constprop.0+0x48/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x34/0xb8\n el0t_64_sync_handler+0x100/0x130\n el0t_64_sync+0x190/0x198\n Code: a90153f3 f9403c14 f9414800 955f8a05 (b9400a80)\n ---[ end trace 0000000000000000 ]---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26784"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eb5555d422d0fc325e1574a7353d3c616f82d8b5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f6aaf131e4d4a9a26040ecc018eb70ab8b3d355d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json b/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
new file mode 100644
index 00000000000..6fdcc9908ce
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j2g4-vr97-pwvm",
+ "modified": "2024-04-04T15:30:33Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26750"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Drop oob_skb ref before purging queue in GC.\n\nsyzbot reported another task hung in __unix_gc(). [0]\n\nThe current while loop assumes that all of the left candidates\nhave oob_skb and calling kfree_skb(oob_skb) releases the remaining\ncandidates.\n\nHowever, I missed a case that oob_skb has self-referencing fd and\nanother fd and the latter sk is placed before the former in the\ncandidate list. Then, the while loop never proceeds, resulting\nthe task hung.\n\n__unix_gc() has the same loop just before purging the collected skb,\nso we can call kfree_skb(oob_skb) there and let __skb_queue_purge()\nrelease all inflight sockets.\n\n[0]:\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 2784 Comm: kworker/u4:8 Not tainted 6.8.0-rc4-syzkaller-01028-g71b605d32017 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nWorkqueue: events_unbound __unix_gc\nRIP: 0010:__sanitizer_cov_trace_pc+0x0/0x70 kernel/kcov.c:200\nCode: 89 fb e8 23 00 00 00 48 8b 3d 84 f5 1a 0c 48 89 de 5b e9 43 26 57 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1e fa 48 8b 04 24 65 48 8b 0d 90 52 70 7e 65 8b 15 91 52 70\nRSP: 0018:ffffc9000a17fa78 EFLAGS: 00000287\nRAX: ffffffff8a0a6108 RBX: ffff88802b6c2640 RCX: ffff88802c0b3b80\nRDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000000\nRBP: ffffc9000a17fbf0 R08: ffffffff89383f1d R09: 1ffff1100ee5ff84\nR10: dffffc0000000000 R11: ffffed100ee5ff85 R12: 1ffff110056d84ee\nR13: ffffc9000a17fae0 R14: 0000000000000000 R15: ffffffff8f47b840\nFS: 0000000000000000(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffef5687ff8 CR3: 0000000029b34000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n \n \n __unix_gc+0xe69/0xf40 net/unix/garbage.c:343\n process_one_work kernel/workqueue.c:2633 [inline]\n process_scheduled_works+0x913/0x1420 kernel/workqueue.c:2706\n worker_thread+0xa5f/0x1000 kernel/workqueue.c:2787\n kthread+0x2ef/0x390 kernel/kthread.c:388\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:242\n ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26750"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/43ba9e331559a30000c862eea313248707afa787"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6c480d0f131862645d172ca9e25dc152b1a5c3a6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aa82ac51d63328714645c827775d64dbfd9941f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c4c795b21dd23d9514ae1c6646c3fb2c78b5be60"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e9eac260369d0cf57ea53df95427125725507a0d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-j4vc-q2qg-4hj8/GHSA-j4vc-q2qg-4hj8.json b/advisories/unreviewed/2024/04/GHSA-j4vc-q2qg-4hj8/GHSA-j4vc-q2qg-4hj8.json
new file mode 100644
index 00000000000..3d6a415cdd6
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-j4vc-q2qg-4hj8/GHSA-j4vc-q2qg-4hj8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j4vc-q2qg-4hj8",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-29049"
+ ],
+ "details": "Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29049"
+ },
+ {
+ "type": "WEB",
+ "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29049"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T22:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-j4x2-5qq6-fvpq/GHSA-j4x2-5qq6-fvpq.json b/advisories/unreviewed/2024/04/GHSA-j4x2-5qq6-fvpq/GHSA-j4x2-5qq6-fvpq.json
new file mode 100644
index 00000000000..34c1dde8ce4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-j4x2-5qq6-fvpq/GHSA-j4x2-5qq6-fvpq.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j4x2-5qq6-fvpq",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-29981"
+ ],
+ "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29981"
+ },
+ {
+ "type": "WEB",
+ "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29981"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1021"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T22:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-jf7f-5899-cj5x/GHSA-jf7f-5899-cj5x.json b/advisories/unreviewed/2024/04/GHSA-jf7f-5899-cj5x/GHSA-jf7f-5899-cj5x.json
new file mode 100644
index 00000000000..8ceea36aec0
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-jf7f-5899-cj5x/GHSA-jf7f-5899-cj5x.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jf7f-5899-cj5x",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-27268"
+ ],
+ "details": "IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.3 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27268"
+ },
+ {
+ "type": "WEB",
+ "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/284574"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7145809"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json b/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json
new file mode 100644
index 00000000000..3c4542dfb43
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-jh5x-r89q-r9g4/GHSA-jh5x-r89q-r9g4.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jh5x-r89q-r9g4",
+ "modified": "2024-04-05T00:31:28Z",
+ "published": "2024-04-05T00:31:28Z",
+ "aliases": [
+ "CVE-2024-3320"
+ ],
+ "details": "A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-259388.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3320"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/qqqyc/vuln/blob/main/eLearning%20System-XSS-01.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259388"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259388"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.310103"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T00:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json b/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json
new file mode 100644
index 00000000000..5b5ae174709
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jj9v-ff2v-cgx9",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26804"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: prevent perpetual headroom growth\n\nsyzkaller triggered following kasan splat:\nBUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170\nRead of size 1 at addr ffff88812fb4000e by task syz-executor183/5191\n[..]\n kasan_report+0xda/0x110 mm/kasan/report.c:588\n __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170\n skb_flow_dissect_flow_keys include/linux/skbuff.h:1514 [inline]\n ___skb_get_hash net/core/flow_dissector.c:1791 [inline]\n __skb_get_hash+0xc7/0x540 net/core/flow_dissector.c:1856\n skb_get_hash include/linux/skbuff.h:1556 [inline]\n ip_tunnel_xmit+0x1855/0x33c0 net/ipv4/ip_tunnel.c:748\n ipip_tunnel_xmit+0x3cc/0x4e0 net/ipv4/ipip.c:308\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3564\n __dev_queue_xmit+0x7c1/0x3d60 net/core/dev.c:4349\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n neigh_connected_output+0x42c/0x5d0 net/core/neighbour.c:1592\n ...\n ip_finish_output2+0x833/0x2550 net/ipv4/ip_output.c:235\n ip_finish_output+0x31/0x310 net/ipv4/ip_output.c:323\n ..\n iptunnel_xmit+0x5b4/0x9b0 net/ipv4/ip_tunnel_core.c:82\n ip_tunnel_xmit+0x1dbc/0x33c0 net/ipv4/ip_tunnel.c:831\n ipgre_xmit+0x4a1/0x980 net/ipv4/ip_gre.c:665\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3564\n ...\n\nThe splat occurs because skb->data points past skb->head allocated area.\nThis is because neigh layer does:\n __skb_pull(skb, skb_network_offset(skb));\n\n... but skb_network_offset() returns a negative offset and __skb_pull()\narg is unsigned. IOW, we skb->data gets \"adjusted\" by a huge value.\n\nThe negative value is returned because skb->head and skb->data distance is\nmore than 64k and skb->network_header (u16) has wrapped around.\n\nThe bug is in the ip_tunnel infrastructure, which can cause\ndev->needed_headroom to increment ad infinitum.\n\nThe syzkaller reproducer consists of packets getting routed via a gre\ntunnel, and route of gre encapsulated packets pointing at another (ipip)\ntunnel. The ipip encapsulation finds gre0 as next output device.\n\nThis results in the following pattern:\n\n1). First packet is to be sent out via gre0.\nRoute lookup found an output device, ipip0.\n\n2).\nip_tunnel_xmit for gre0 bumps gre0->needed_headroom based on the future\noutput device, rt.dev->needed_headroom (ipip0).\n\n3).\nip output / start_xmit moves skb on to ipip0. which runs the same\ncode path again (xmit recursion).\n\n4).\nRouting step for the post-gre0-encap packet finds gre0 as output device\nto use for ipip0 encapsulated packet.\n\ntunl0->needed_headroom is then incremented based on the (already bumped)\ngre0 device headroom.\n\nThis repeats for every future packet:\n\ngre0->needed_headroom gets inflated because previous packets' ipip0 step\nincremented rt->dev (gre0) headroom, and ipip0 incremented because gre0\nneeded_headroom was increased.\n\nFor each subsequent packet, gre/ipip0->needed_headroom grows until\npost-expand-head reallocations result in a skb->head/data distance of\nmore than 64k.\n\nOnce that happens, skb->network_header (u16) wraps around when\npskb_expand_head tries to make sure that skb_network_offset() is unchanged\nafter the headroom expansion/reallocation.\n\nAfter this skb_network_offset(skb) returns a different (and negative)\nresult post headroom expansion.\n\nThe next trip to neigh layer (or anything else that would __skb_pull the\nnetwork header) makes skb->data point to a memory location outside\nskb->head area.\n\nv2: Cap the needed_headroom update to an arbitarily chosen upperlimit to\nprevent perpetual increase instead of dropping the headroom increment\ncompletely.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26804"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/049d7989c67e8dd50f07a2096dbafdb41331fb9b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2e95350fe9db9d53c701075060ac8ac883b68aee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ae1e9922bbdbaeb9cfbe91085ab75927488ac0f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0a1db40b23e8ff86dea2786c5ea1470bb23ecb9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ab63de24ebea36fe73ac7121738595d704b66d96"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/afec0c5cd2ed71ca95a8b36a5e6d03333bf34282"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f81e94d2dcd2397137edcb8b85f4c5bed5d22383"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-jv67-jxg9-q8v4/GHSA-jv67-jxg9-q8v4.json b/advisories/unreviewed/2024/04/GHSA-jv67-jxg9-q8v4/GHSA-jv67-jxg9-q8v4.json
new file mode 100644
index 00000000000..31bb635feed
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-jv67-jxg9-q8v4/GHSA-jv67-jxg9-q8v4.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jv67-jxg9-q8v4",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26786"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix iopt_access_list_id overwrite bug\n\nSyzkaller reported the following WARN_ON:\n WARNING: CPU: 1 PID: 4738 at drivers/iommu/iommufd/io_pagetable.c:1360\n\n Call Trace:\n iommufd_access_change_ioas+0x2fe/0x4e0\n iommufd_access_destroy_object+0x50/0xb0\n iommufd_object_remove+0x2a3/0x490\n iommufd_object_destroy_user\n iommufd_access_destroy+0x71/0xb0\n iommufd_test_staccess_release+0x89/0xd0\n __fput+0x272/0xb50\n __fput_sync+0x4b/0x60\n __do_sys_close\n __se_sys_close\n __x64_sys_close+0x8b/0x110\n do_syscall_x64\n\nThe mismatch between the access pointer in the list and the passed-in\npointer is resulting from an overwrite of access->iopt_access_list_id, in\niopt_add_access(). Called from iommufd_access_change_ioas() when\nxa_alloc() succeeds but iopt_calculate_iova_alignment() fails.\n\nAdd a new_id in iopt_add_access() and only update iopt_access_list_id when\nreturning successfully.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26786"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9526a46cc0c378d381560279bea9aa34c84298a0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aeb004c0cd6958e910123a1607634401009c9539"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f1fb745ee0a6fe43f1d84ec369c7e6af2310fda9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-mcfm-cxwv-vq32/GHSA-mcfm-cxwv-vq32.json b/advisories/unreviewed/2024/04/GHSA-mcfm-cxwv-vq32/GHSA-mcfm-cxwv-vq32.json
new file mode 100644
index 00000000000..ed31c3b9f44
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-mcfm-cxwv-vq32/GHSA-mcfm-cxwv-vq32.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mcfm-cxwv-vq32",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-30565"
+ ],
+ "details": "An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30565"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/XiLitter/CMS_vulnerability-discovery/blob/main/SeaCMS_v.12.9.md"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json
index 2f281a3e888..e092a096038 100644
--- a/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json
+++ b/advisories/unreviewed/2024/04/GHSA-mcgw-94j6-6g4q/GHSA-mcgw-94j6-6g4q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcgw-94j6-6g4q",
- "modified": "2024-04-03T12:31:06Z",
+ "modified": "2024-04-04T15:30:33Z",
"published": "2024-04-02T03:30:43Z",
"aliases": [
"CVE-2024-3142"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md"
},
+ {
+ "type": "WEB",
+ "url": "https://my.clavister.com/downloads/?sid=1"
+ },
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.258917"
diff --git a/advisories/unreviewed/2024/04/GHSA-mfj7-pc34-cqm8/GHSA-mfj7-pc34-cqm8.json b/advisories/unreviewed/2024/04/GHSA-mfj7-pc34-cqm8/GHSA-mfj7-pc34-cqm8.json
new file mode 100644
index 00000000000..e22c8c7c8b4
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-mfj7-pc34-cqm8/GHSA-mfj7-pc34-cqm8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mfj7-pc34-cqm8",
+ "modified": "2024-04-04T21:30:30Z",
+ "published": "2024-04-04T21:30:30Z",
+ "aliases": [
+ "CVE-2024-22023"
+ ],
+ "details": "An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22023"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json
new file mode 100644
index 00000000000..a0b83dee307
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mq9r-62m5-pjc2",
+ "modified": "2024-04-05T03:30:28Z",
+ "published": "2024-04-05T03:30:28Z",
+ "aliases": [
+ "CVE-2023-5973"
+ ],
+ "details": "Brocade\n Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not \nproperly represent the portName to the user if the portName contains \nreserved characters. This could allow an authenticated user to alter the\n UI of the Brocade Switch and change ports display.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5973"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23214"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-346"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T03:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json b/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json
new file mode 100644
index 00000000000..f68f8f8930d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-mqqf-4p7r-rf89/GHSA-mqqf-4p7r-rf89.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mqqf-4p7r-rf89",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-31080"
+ ],
+ "details": "A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31080"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-31080"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2271997"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-126"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T14:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json b/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json
new file mode 100644
index 00000000000..b519b65dff2
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p499-wvm3-j86w",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-27575"
+ ],
+ "details": "Directory Traversal vulnerability in INOTEC Sicherheitstechnik GmbH INOTEC Sicherheitstechnik GmbH WebServer CPS220/64 V.3.3.19 allows a remote attacker to execute arbitrary code via the /etc/passwd file.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27575"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/s4fv4n/098bd368bf054d008078e369108c2ebd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.inotec-licht.de"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T13:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json b/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json
new file mode 100644
index 00000000000..a8d1a13dab3
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-p8g6-7v7w-4whg/GHSA-p8g6-7v7w-4whg.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p8g6-7v7w-4whg",
+ "modified": "2024-04-10T15:30:32Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-26812"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Create persistent INTx handler\n\nA vulnerability exists where the eventfd for INTx signaling can be\ndeconfigured, which unregisters the IRQ handler but still allows\neventfds to be signaled with a NULL context through the SET_IRQS ioctl\nor through unmask irqfd if the device interrupt is pending.\n\nIdeally this could be solved with some additional locking; the igate\nmutex serializes the ioctl and config space accesses, and the interrupt\nhandler is unregistered relative to the trigger, but the irqfd path\nruns asynchronous to those. The igate mutex cannot be acquired from the\natomic context of the eventfd wake function. Disabling the irqfd\nrelative to the eventfd registration is potentially incompatible with\nexisting userspace.\n\nAs a result, the solution implemented here moves configuration of the\nINTx interrupt handler to track the lifetime of the INTx context object\nand irq_type configuration, rather than registration of a particular\ntrigger eventfd. Synchronization is added between the ioctl path and\neventfd_signal() wrapper such that the eventfd trigger can be\ndynamically updated relative to in-flight interrupts or irqfd callbacks.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26812"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e09cf81959d9f12b75ad5c6dd53d237432ed034"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/18c198c96a815c962adc2b9b77909eec0be7df4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4c089cefe30924fbe20dd1ee92774ea1f5eca834"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4cb0d7532126d23145329826c38054b4e9a05e7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/69276a555c740acfbff13fb5769ee9c92e1c828e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d29d4c72c1e196cce6969c98072a272d1a703b3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json
new file mode 100644
index 00000000000..09e86a69be5
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pfjp-fv5p-fjx7",
+ "modified": "2024-04-04T12:30:58Z",
+ "published": "2024-04-04T12:30:58Z",
+ "aliases": [
+ "CVE-2024-26809"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: release elements in clone only from destroy path\n\nClone already always provides a current view of the lookup table, use it\nto destroy the set, otherwise it is possible to destroy elements twice.\n\nThis fix requires:\n\n 212ed75dc5fb (\"netfilter: nf_tables: integrate pipapo into commit protocol\")\n\nwhich came after:\n\n 9827a0e6e23b (\"netfilter: nft_set_pipapo: release elements in clone from abort path\").",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26809"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/362508506bf545e9ce18c72a2c48dcbfb891ab9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ad233dc731ab64cdc47b84a5c1f78fff6c024af"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/821e28d5b506e6a73ccc367ff792bd894050d48b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9384b4d85c46ce839f51af01374062ce6318b2f2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0e256f3dd2ba6532f37c5c22e07cb07a36031ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b36b83297ff4910dfc8705402c8abffd4bbf8144"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ff90050771412b91e928093ccd8736ae680063c2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T10:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-pjr2-pwcr-ffrh/GHSA-pjr2-pwcr-ffrh.json b/advisories/unreviewed/2024/04/GHSA-pjr2-pwcr-ffrh/GHSA-pjr2-pwcr-ffrh.json
new file mode 100644
index 00000000000..3184ef58279
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-pjr2-pwcr-ffrh/GHSA-pjr2-pwcr-ffrh.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pjr2-pwcr-ffrh",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26785"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix protection fault in iommufd_test_syz_conv_iova\n\nSyzkaller reported the following bug:\n\n general protection fault, probably for non-canonical address 0xdffffc0000000038: 0000 [#1] SMP KASAN\n KASAN: null-ptr-deref in range [0x00000000000001c0-0x00000000000001c7]\n Call Trace:\n lock_acquire\n lock_acquire+0x1ce/0x4f0\n down_read+0x93/0x4a0\n iommufd_test_syz_conv_iova+0x56/0x1f0\n iommufd_test_access_rw.isra.0+0x2ec/0x390\n iommufd_test+0x1058/0x1e30\n iommufd_fops_ioctl+0x381/0x510\n vfs_ioctl\n __do_sys_ioctl\n __se_sys_ioctl\n __x64_sys_ioctl+0x170/0x1e0\n do_syscall_x64\n do_syscall_64+0x71/0x140\n\nThis is because the new iommufd_access_change_ioas() sets access->ioas to\nNULL during its process, so the lock might be gone in a concurrent racing\ncontext.\n\nFix this by doing the same access->ioas sanity as iommufd_access_rw() and\niommufd_access_pin_pages() functions do.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26785"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cf7c2789822db8b5efa34f5ebcf1621bc0008d48"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc719ecbca45c9c046640d72baddba3d83e0bc0b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-ppf4-83qq-m3fm/GHSA-ppf4-83qq-m3fm.json b/advisories/unreviewed/2024/04/GHSA-ppf4-83qq-m3fm/GHSA-ppf4-83qq-m3fm.json
new file mode 100644
index 00000000000..2efbe06455a
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-ppf4-83qq-m3fm/GHSA-ppf4-83qq-m3fm.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ppf4-83qq-m3fm",
+ "modified": "2024-04-05T09:30:38Z",
+ "published": "2024-04-05T09:30:38Z",
+ "aliases": [
+ "CVE-2024-30849"
+ ],
+ "details": "Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30849"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/wkeyi0x1/vul-report/issues/3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T08:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json b/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
new file mode 100644
index 00000000000..77dbd5b20fb
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q4hp-86wf-hj44",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26800"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix use-after-free on failed backlog decryption\n\nWhen the decrypt request goes to the backlog and crypto_aead_decrypt\nreturns -EBUSY, tls_do_decryption will wait until all async\ndecryptions have completed. If one of them fails, tls_do_decryption\nwill return -EBADMSG and tls_decrypt_sg jumps to the error path,\nreleasing all the pages. But the pages have been passed to the async\ncallback, and have already been released by tls_decrypt_done.\n\nThe only true async case is when crypto_aead_decrypt returns\n -EINPROGRESS. With -EBUSY, we already waited so we can tell\ntls_sw_recvmsg that the data is available for immediate copy, but we\nneed to notify tls_decrypt_sg (via the new ->async_done flag) that the\nmemory has already been released.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26800"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/13114dc5543069f7b97991e3b79937b6da05f5b0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81be85353b0f5a7b660635634b655329b429eefe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f2b85a4cc763841843de693bbd7308fe9a2c4c89"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json b/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json
new file mode 100644
index 00000000000..5270030942b
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-q6w6-rjjj-5p52/GHSA-q6w6-rjjj-5p52.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q6w6-rjjj-5p52",
+ "modified": "2024-04-05T12:31:17Z",
+ "published": "2024-04-05T12:31:17Z",
+ "aliases": [
+ "CVE-2024-31083"
+ ],
+ "details": "A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31083"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-31083"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272000"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T12:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json b/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json
new file mode 100644
index 00000000000..a50d0a70a67
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qfh3-r9xh-mmwf",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2023-25200"
+ ],
+ "details": "An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25200"
+ },
+ {
+ "type": "WEB",
+ "url": "https://summitinfosec.com/blog/x-ray-vision-identifying-cve-2023-25199-and-cve-2023-25200-in-manufacturing-equipment"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T07:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json
new file mode 100644
index 00000000000..50f1d89cea8
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qgf9-6cxx-q2qv",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-29375"
+ ],
+ "details": "CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29375"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ismailcemunver/CVE-2024-29375"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T07:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json b/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json
new file mode 100644
index 00000000000..92fd81c3bc8
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qgpm-9vqg-rgrr",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-2759"
+ ],
+ "details": "Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.\n\n",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cert.pl/en/posts/2024/04/CVE-2024-2759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cert.pl/posts/2024/04/CVE-2024-2759"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T14:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json b/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json
new file mode 100644
index 00000000000..d4848b8192d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qgq8-952v-8jwq",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25696"
+ ],
+ "details": "There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.0 that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to execute this attack are high.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25696"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json b/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json
new file mode 100644
index 00000000000..9e351f68300
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qhq3-q3p4-4fxm/GHSA-qhq3-q3p4-4fxm.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qhq3-q3p4-4fxm",
+ "modified": "2024-04-05T12:31:17Z",
+ "published": "2024-04-05T12:31:17Z",
+ "aliases": [
+ "CVE-2023-6523"
+ ],
+ "details": "Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.This issue affects Extreme XDS: before 3914.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6523"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-24-0276"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-639"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T12:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json
new file mode 100644
index 00000000000..48efbabf90b
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-qv7c-pjpr-grqx/GHSA-qv7c-pjpr-grqx.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qv7c-pjpr-grqx",
+ "modified": "2024-04-04T09:30:35Z",
+ "published": "2024-04-04T09:30:35Z",
+ "aliases": [
+ "CVE-2024-26790"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read\n\nThere is chip (ls1028a) errata:\n\nThe SoC may hang on 16 byte unaligned read transactions by QDMA.\n\nUnaligned read transactions initiated by QDMA may stall in the NOC\n(Network On-Chip), causing a deadlock condition. Stalled transactions will\ntrigger completion timeouts in PCIe controller.\n\nWorkaround:\nEnable prefetch by setting the source descriptor prefetchable bit\n( SD[PF] = 1 ).\n\nImplement this workaround.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26790"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/106c1ac953a66556ec77456c46e818208d3a9bce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/237ecf1afe6c22534fa43abdf2bf0b0f52de0aaa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/518d78b4fac68cac29a263554d7f3b19da99d0da"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5b696e9c388251f1c7373be92293769a489fd367"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9d739bccf261dd93ec1babf82f5c5d71dd4caa3e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad2f8920c314e0a2d9e984fc94b729eca3cda471"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bb3a06e9b9a30e33d96aadc0e077be095a4f8580"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json b/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json
new file mode 100644
index 00000000000..e792ba3ba06
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-r596-ggc2-8m6g/GHSA-r596-ggc2-8m6g.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r596-ggc2-8m6g",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-2103"
+ ],
+ "details": "\nInclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the following Schweitzer Engineering Laboratories relays could allow the relay to behave unpredictably:\nSEL-700BT Motor Bus Transfer Relay, SEL-700G Generator Protection Relay, SEL-710-5 Motor Protection Relay, SEL-751 Feeder Protection Relay, SEL-787-2/-3/-4 Transformer Protection Relay, SEL-787Z High-Impedance Differential Relay\n\n. See product instruction manual appendix A dated 20240308 for more details regarding the SEL-751 Feeder Protection Relay. For more information for the other affected products, see their instruction manuals dated 20240329.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2103"
+ },
+ {
+ "type": "WEB",
+ "url": "https://selinc.com/support/security-notifications/external-reports"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1242"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T16:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json b/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
new file mode 100644
index 00000000000..c620520d991
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r7p6-cff4-g6q4",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26802"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstmmac: Clear variable when destroying workqueue\n\nCurrently when suspending driver and stopping workqueue it is checked whether\nworkqueue is not NULL and if so, it is destroyed.\nFunction destroy_workqueue() does drain queue and does clear variable, but\nit does not set workqueue variable to NULL. This can cause kernel/module\npanic if code attempts to clear workqueue that was not initialized.\n\nThis scenario is possible when resuming suspended driver in stmmac_resume(),\nbecause there is no handling for failed stmmac_hw_setup(),\nwhich can fail and return if DMA engine has failed to initialize,\nand workqueue is initialized after DMA engine.\nShould DMA engine fail to initialize, resume will proceed normally,\nbut interface won't work and TX queue will eventually timeout,\ncausing 'Reset adapter' error.\nThis then does destroy workqueue during reset process.\nAnd since workqueue is initialized after DMA engine and can be skipped,\nit will cause kernel/module panic.\n\nTo secure against this possible crash, set workqueue variable to NULL when\ndestroying workqueue.\n\nLog/backtrace from crash goes as follows:\n[88.031977]------------[ cut here ]------------\n[88.031985]NETDEV WATCHDOG: eth0 (sxgmac): transmit queue 1 timed out\n[88.032017]WARNING: CPU: 0 PID: 0 at net/sched/sch_generic.c:477 dev_watchdog+0x390/0x398\n \n[88.032251]---[ end trace e70de432e4d5c2c0 ]---\n[88.032282]sxgmac 16d88000.ethernet eth0: Reset adapter.\n[88.036359]------------[ cut here ]------------\n[88.036519]Call trace:\n[88.036523] flush_workqueue+0x3e4/0x430\n[88.036528] drain_workqueue+0xc4/0x160\n[88.036533] destroy_workqueue+0x40/0x270\n[88.036537] stmmac_fpe_stop_wq+0x4c/0x70\n[88.036541] stmmac_release+0x278/0x280\n[88.036546] __dev_close_many+0xcc/0x158\n[88.036551] dev_close_many+0xbc/0x190\n[88.036555] dev_close.part.0+0x70/0xc0\n[88.036560] dev_close+0x24/0x30\n[88.036564] stmmac_service_task+0x110/0x140\n[88.036569] process_one_work+0x1d8/0x4a0\n[88.036573] worker_thread+0x54/0x408\n[88.036578] kthread+0x164/0x170\n[88.036583] ret_from_fork+0x10/0x20\n[88.036588]---[ end trace e70de432e4d5c2c1 ]---\n[88.036597]Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26802"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17ccd9798fe0beda3db212cfa3ebe373f605cbd6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/699b103e48ce32d03fc86c35b37ee8ae4288c7e3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8af411bbba1f457c33734795f024d0ef26d0963f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8e99556301172465c8fe33c7f78c39a3d4ce8462"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f72cf22dccc94038cbbaa1029cb575bf52e5cbc8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json b/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json
new file mode 100644
index 00000000000..2d4cf63a47d
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rhvv-h8rg-3gxq",
+ "modified": "2024-04-05T06:30:46Z",
+ "published": "2024-04-05T06:30:46Z",
+ "aliases": [
+ "CVE-2024-29672"
+ ],
+ "details": "Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29672"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/zly2006/reden-is-what-we-made/commit/44c5320f0a1ccaa764dd91df6a12e747f81fe63a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/apple502j/193358682885fe1a6708309ce934e4ed"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T06:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json b/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json
new file mode 100644
index 00000000000..4b1ce636454
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rj8v-47w4-c66w",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-25697"
+ ],
+ "details": "\nThere is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser. The privileges required to execute this attack are low.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25697"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json b/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json
new file mode 100644
index 00000000000..1ff606003b3
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-rm2h-rx39-6fc3/GHSA-rm2h-rx39-6fc3.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rm2h-rx39-6fc3",
+ "modified": "2024-04-10T15:30:32Z",
+ "published": "2024-04-05T09:30:39Z",
+ "aliases": [
+ "CVE-2024-26814"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/fsl-mc: Block calling interrupt handler without trigger\n\nThe eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object is\ninitially NULL and may become NULL if the user sets the trigger\neventfd to -1. The interrupt handler itself is guaranteed that\ntrigger is always valid between request_irq() and free_irq(), but\nthe loopback testing mechanisms to invoke the handler function\nneed to test the trigger. The triggering and setting ioctl paths\nboth make use of igate and are therefore mutually exclusive.\n\nThe vfio-fsl-mc driver does not make use of irqfds, nor does it\nsupport any sort of masking operations, therefore unlike vfio-pci\nand vfio-platform, the flow can remain essentially unchanged.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26814"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/083e750c9f5f4c3bf61161330fb84d7c8e8bb417"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/250219c6a556f8c69c5910fca05a59037e24147d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ec0d88166dac43f29e96801c0927d514f17add9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7447d911af699a15f8d050dfcb7c680a86f87012"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de87511fb0404d23b6da5f4660383b6ed095e28d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ee0bd4ad780dfbb60355b99f25063357ab488267"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json b/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
new file mode 100644
index 00000000000..8eb764d917c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rmrx-q6x5-whjx",
+ "modified": "2024-04-04T21:30:32Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-3315"
+ ],
+ "details": "A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file classes/user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259386 is the identifier assigned to this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3315"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/adminininin/blob/blob/main/README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.259386"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.259386"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.309575"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T21:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-rqhw-p5r2-7vq4/GHSA-rqhw-p5r2-7vq4.json b/advisories/unreviewed/2024/04/GHSA-rqhw-p5r2-7vq4/GHSA-rqhw-p5r2-7vq4.json
index 0a303d3f04d..e26f72af30b 100644
--- a/advisories/unreviewed/2024/04/GHSA-rqhw-p5r2-7vq4/GHSA-rqhw-p5r2-7vq4.json
+++ b/advisories/unreviewed/2024/04/GHSA-rqhw-p5r2-7vq4/GHSA-rqhw-p5r2-7vq4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqhw-p5r2-7vq4",
- "modified": "2024-04-03T12:31:06Z",
+ "modified": "2024-04-05T15:30:31Z",
"published": "2024-04-03T12:31:06Z",
"aliases": [
"CVE-2024-31390"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31390"
},
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakdance-builder?_s_id=cve"
+ },
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/breakdance/wordpress-breakdance-plugin-1-7-0-authenticated-remote-code-execution-rce-vulnerability?_s_id=cve"
diff --git a/advisories/unreviewed/2024/04/GHSA-rr4c-9mp9-8wp6/GHSA-rr4c-9mp9-8wp6.json b/advisories/unreviewed/2024/04/GHSA-rr4c-9mp9-8wp6/GHSA-rr4c-9mp9-8wp6.json
new file mode 100644
index 00000000000..afca71bbfff
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-rr4c-9mp9-8wp6/GHSA-rr4c-9mp9-8wp6.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rr4c-9mp9-8wp6",
+ "modified": "2024-04-04T21:30:32Z",
+ "published": "2024-04-04T21:30:32Z",
+ "aliases": [
+ "CVE-2024-29386"
+ ],
+ "details": "projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29386"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cve.anas-cherni.me/2024/04/04/cve-2024-29386"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json b/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json
new file mode 100644
index 00000000000..c55899a24f9
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vm4m-6mf9-8885",
+ "modified": "2024-04-05T15:30:30Z",
+ "published": "2024-04-05T15:30:30Z",
+ "aliases": [
+ "CVE-2024-2380"
+ ],
+ "details": "Stored XSS in graph rendering in Checkmk <2.3.0b4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2380"
+ },
+ {
+ "type": "WEB",
+ "url": "https://checkmk.com/werk/16618"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-80"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T13:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-vmgj-7wpp-x799/GHSA-vmgj-7wpp-x799.json b/advisories/unreviewed/2024/04/GHSA-vmgj-7wpp-x799/GHSA-vmgj-7wpp-x799.json
new file mode 100644
index 00000000000..cf017c4e049
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-vmgj-7wpp-x799/GHSA-vmgj-7wpp-x799.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vmgj-7wpp-x799",
+ "modified": "2024-04-04T21:30:31Z",
+ "published": "2024-04-04T21:30:31Z",
+ "aliases": [
+ "CVE-2024-22053"
+ ],
+ "details": "A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x\n 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory. ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22053"
+ },
+ {
+ "type": "WEB",
+ "url": "https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T20:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-vqhg-mqww-h64x/GHSA-vqhg-mqww-h64x.json b/advisories/unreviewed/2024/04/GHSA-vqhg-mqww-h64x/GHSA-vqhg-mqww-h64x.json
new file mode 100644
index 00000000000..843d5bbc995
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-vqhg-mqww-h64x/GHSA-vqhg-mqww-h64x.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vqhg-mqww-h64x",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2020-25730"
+ ],
+ "details": "Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25730"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ZoneMinder/zoneminder/commit/9268db14a79c4ccd444c2bf8d24e62b13207b413"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json b/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json
new file mode 100644
index 00000000000..8ddb5a4858e
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w322-w9fv-rx3m/GHSA-w322-w9fv-rx3m.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w322-w9fv-rx3m",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T15:30:34Z",
+ "aliases": [
+ "CVE-2024-3296"
+ ],
+ "details": "A timing-based side-channel exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3296"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-3296"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2269723"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-203"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T14:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
new file mode 100644
index 00000000000..50219fa317a
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w59w-35q3-vcg7",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-29006"
+ ],
+ "details": "By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29006"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.apache.org/thread/82f46pv7mvh95ybto5hn8wlo6g8jhjvp"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-290"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json
new file mode 100644
index 00000000000..4e9767152cc
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w5wq-cvfc-3r8g",
+ "modified": "2024-04-08T18:30:47Z",
+ "published": "2024-04-05T06:30:46Z",
+ "aliases": [
+ "CVE-2024-2509"
+ ],
+ "details": "The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2509"
+ },
+ {
+ "type": "WEB",
+ "url": "https://research.cleantalk.org/cve-2024-2509"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wpscan.com/vulnerability/dec4a632-e04b-4fdd-86e4-48304b892a4f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-05T05:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json b/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json
new file mode 100644
index 00000000000..206c9f8b39c
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w68v-jm79-7cvv/GHSA-w68v-jm79-7cvv.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w68v-jm79-7cvv",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-20800"
+ ],
+ "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution within the context of the victim's browser.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20800"
+ },
+ {
+ "type": "WEB",
+ "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
new file mode 100644
index 00000000000..9d7e5d2953e
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w94f-xh79-q24v",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26806"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks\n\nThe ->runtime_suspend() and ->runtime_resume() callbacks are not\nexpected to call spi_controller_suspend() and spi_controller_resume().\nRemove calls to those in the cadence-qspi driver.\n\nThose helpers have two roles currently:\n - They stop/start the queue, including dealing with the kworker.\n - They toggle the SPI controller SPI_CONTROLLER_SUSPENDED flag. It\n requires acquiring ctlr->bus_lock_mutex.\n\nStep one is irrelevant because cadence-qspi is not queued. Step two\nhowever has two implications:\n - A deadlock occurs, because ->runtime_resume() is called in a context\n where the lock is already taken (in the ->exec_op() callback, where\n the usage count is incremented).\n - It would disallow all operations once the device is auto-suspended.\n\nHere is a brief call tree highlighting the mutex deadlock:\n\nspi_mem_exec_op()\n ...\n spi_mem_access_start()\n mutex_lock(&ctlr->bus_lock_mutex)\n\n cqspi_exec_mem_op()\n pm_runtime_resume_and_get()\n cqspi_resume()\n spi_controller_resume()\n mutex_lock(&ctlr->bus_lock_mutex)\n ...\n\n spi_mem_access_end()\n mutex_unlock(&ctlr->bus_lock_mutex)\n ...",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26806"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/041562ebc4759c9932b59a06527f8753b86da365"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/959043afe53ae80633e810416cee6076da6e91c6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json b/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json
new file mode 100644
index 00000000000..f70ddfaf145
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w9gh-mc2w-wrg3",
+ "modified": "2024-04-04T18:30:33Z",
+ "published": "2024-04-04T18:30:33Z",
+ "aliases": [
+ "CVE-2024-28787"
+ ],
+ "details": "IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28787"
+ },
+ {
+ "type": "WEB",
+ "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/286584"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7145828"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-650"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T18:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json b/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json
new file mode 100644
index 00000000000..a17750db0ef
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w9qr-vr3p-gqmx",
+ "modified": "2024-04-04T15:30:34Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26794"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race between ordered extent completion and fiemap\n\nFor fiemap we recently stopped locking the target extent range for the\nwhole duration of the fiemap call, in order to avoid a deadlock in a\nscenario where the fiemap buffer happens to be a memory mapped range of\nthe same file. This use case is very unlikely to be useful in practice but\nit may be triggered by fuzz testing (syzbot, etc).\n\nHowever by not locking the target extent range for the whole duration of\nthe fiemap call we can race with an ordered extent. This happens like\nthis:\n\n1) The fiemap task finishes processing a file extent item that covers\n the file range [512K, 1M[, and that file extent item is the last item\n in the leaf currently being processed;\n\n2) And ordered extent for the file range [768K, 2M[, in COW mode,\n completes (btrfs_finish_one_ordered()) and the file extent item\n covering the range [512K, 1M[ is trimmed to cover the range\n [512K, 768K[ and then a new file extent item for the range [768K, 2M[\n is inserted in the inode's subvolume tree;\n\n3) The fiemap task calls fiemap_next_leaf_item(), which then calls\n btrfs_next_leaf() to find the next leaf / item. This finds that the\n the next key following the one we previously processed (its type is\n BTRFS_EXTENT_DATA_KEY and its offset is 512K), is the key corresponding\n to the new file extent item inserted by the ordered extent, which has\n a type of BTRFS_EXTENT_DATA_KEY and an offset of 768K;\n\n4) Later the fiemap code ends up at emit_fiemap_extent() and triggers\n the warning:\n\n if (cache->offset + cache->len > offset) {\n WARN_ON(1);\n return -EINVAL;\n }\n\n Since we get 1M > 768K, because the previously emitted entry for the\n old extent covering the file range [512K, 1M[ ends at an offset that\n is greater than the new extent's start offset (768K). This makes fiemap\n fail with -EINVAL besides triggering the warning that produces a stack\n trace like the following:\n\n [1621.677651] ------------[ cut here ]------------\n [1621.677656] WARNING: CPU: 1 PID: 204366 at fs/btrfs/extent_io.c:2492 emit_fiemap_extent+0x84/0x90 [btrfs]\n [1621.677899] Modules linked in: btrfs blake2b_generic (...)\n [1621.677951] CPU: 1 PID: 204366 Comm: pool Not tainted 6.8.0-rc5-btrfs-next-151+ #1\n [1621.677954] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n [1621.677956] RIP: 0010:emit_fiemap_extent+0x84/0x90 [btrfs]\n [1621.678033] Code: 2b 4c 89 63 (...)\n [1621.678035] RSP: 0018:ffffab16089ffd20 EFLAGS: 00010206\n [1621.678037] RAX: 00000000004fa000 RBX: ffffab16089ffe08 RCX: 0000000000009000\n [1621.678039] RDX: 00000000004f9000 RSI: 00000000004f1000 RDI: ffffab16089ffe90\n [1621.678040] RBP: 00000000004f9000 R08: 0000000000001000 R09: 0000000000000000\n [1621.678041] R10: 0000000000000000 R11: 0000000000001000 R12: 0000000041d78000\n [1621.678043] R13: 0000000000001000 R14: 0000000000000000 R15: ffff9434f0b17850\n [1621.678044] FS: 00007fa6e20006c0(0000) GS:ffff943bdfa40000(0000) knlGS:0000000000000000\n [1621.678046] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [1621.678048] CR2: 00007fa6b0801000 CR3: 000000012d404002 CR4: 0000000000370ef0\n [1621.678053] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n [1621.678055] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n [1621.678056] Call Trace:\n [1621.678074] \n [1621.678076] ? __warn+0x80/0x130\n [1621.678082] ? emit_fiemap_extent+0x84/0x90 [btrfs]\n [1621.678159] ? report_bug+0x1f4/0x200\n [1621.678164] ? handle_bug+0x42/0x70\n [1621.678167] ? exc_invalid_op+0x14/0x70\n [1621.678170] ? asm_exc_invalid_op+0x16/0x20\n [1621.678178] ? emit_fiemap_extent+0x84/0x90 [btrfs]\n [1621.678253] extent_fiemap+0x766\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26794"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/31d07a757c6d3430e03cc22799921569999b9a12"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a1a4a9ca77f143c00fce69c1239887ff8b813bec"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d43f8e58f10a44df8c08e7f7076f3288352cd168"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json
new file mode 100644
index 00000000000..5884aaddb4a
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wm99-2g28-jp5m",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26798"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: always restore the old font data in fbcon_do_set_font()\n\nCommit a5a923038d70 (fbdev: fbcon: Properly revert changes when\nvc_resize() failed) started restoring old font data upon failure (of\nvc_resize()). But it performs so only for user fonts. It means that the\n\"system\"/internal fonts are not restored at all. So in result, the very\nfirst call to fbcon_do_set_font() performs no restore at all upon\nfailing vc_resize().\n\nThis can be reproduced by Syzkaller to crash the system on the next\ninvocation of font_get(). It's rather hard to hit the allocation failure\nin vc_resize() on the first font_set(), but not impossible. Esp. if\nfault injection is used to aid the execution/failure. It was\ndemonstrated by Sirius:\n BUG: unable to handle page fault for address: fffffffffffffff8\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD cb7b067 P4D cb7b067 PUD cb7d067 PMD 0\n Oops: 0000 [#1] PREEMPT SMP KASAN\n CPU: 1 PID: 8007 Comm: poc Not tainted 6.7.0-g9d1694dc91ce #20\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:fbcon_get_font+0x229/0x800 drivers/video/fbdev/core/fbcon.c:2286\n Call Trace:\n \n con_font_get drivers/tty/vt/vt.c:4558 [inline]\n con_font_op+0x1fc/0xf20 drivers/tty/vt/vt.c:4673\n vt_k_ioctl drivers/tty/vt/vt_ioctl.c:474 [inline]\n vt_ioctl+0x632/0x2ec0 drivers/tty/vt/vt_ioctl.c:752\n tty_ioctl+0x6f8/0x1570 drivers/tty/tty_io.c:2803\n vfs_ioctl fs/ioctl.c:51 [inline]\n ...\n\nSo restore the font data in any case, not only for user fonts. Note the\nlater 'if' is now protected by 'old_userfont' and not 'old_data' as the\nlatter is always set now. (And it is supposed to be non-NULL. Otherwise\nwe would see the bug above again.)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26798"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/00d6a284fcf3fad1b7e1b5bc3cd87cbfb60ce03f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/20a4b5214f7bee13c897477168c77bbf79683c3d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f91a96b892fab2f2543b4a55740c5bee36b1a6b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/73a6bd68a1342f3a44cac9dffad81ad6a003e520"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a2c881413dcc5d801bdc9535e51270cc88cb9cd8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-wxqf-qvrv-xr8r/GHSA-wxqf-qvrv-xr8r.json b/advisories/unreviewed/2024/04/GHSA-wxqf-qvrv-xr8r/GHSA-wxqf-qvrv-xr8r.json
new file mode 100644
index 00000000000..2cbb3a99182
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-wxqf-qvrv-xr8r/GHSA-wxqf-qvrv-xr8r.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wxqf-qvrv-xr8r",
+ "modified": "2024-04-04T09:30:34Z",
+ "published": "2024-04-04T09:30:34Z",
+ "aliases": [
+ "CVE-2024-25503"
+ ],
+ "details": "Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25503"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/EQSTLab/PoC/tree/main/2024/XSS/CVE-2024-25503"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T08:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
new file mode 100644
index 00000000000..9b5cde45131
--- /dev/null
+++ b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x4pp-356g-v2qr",
+ "modified": "2024-04-04T09:30:36Z",
+ "published": "2024-04-04T09:30:36Z",
+ "aliases": [
+ "CVE-2024-26796"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: ctr_get_width function for legacy is not defined\n\nWith parameters CONFIG_RISCV_PMU_LEGACY=y and CONFIG_RISCV_PMU_SBI=n\nlinux kernel crashes when you try perf record:\n\n$ perf record ls\n[ 46.749286] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[ 46.750199] Oops [#1]\n[ 46.750342] Modules linked in:\n[ 46.750608] CPU: 0 PID: 107 Comm: perf-exec Not tainted 6.6.0 #2\n[ 46.750906] Hardware name: riscv-virtio,qemu (DT)\n[ 46.751184] epc : 0x0\n[ 46.751430] ra : arch_perf_update_userpage+0x54/0x13e\n[ 46.751680] epc : 0000000000000000 ra : ffffffff8072ee52 sp : ff2000000022b8f0\n[ 46.751958] gp : ffffffff81505988 tp : ff6000000290d400 t0 : ff2000000022b9c0\n[ 46.752229] t1 : 0000000000000001 t2 : 0000000000000003 s0 : ff2000000022b930\n[ 46.752451] s1 : ff600000028fb000 a0 : 0000000000000000 a1 : ff600000028fb000\n[ 46.752673] a2 : 0000000ae2751268 a3 : 00000000004fb708 a4 : 0000000000000004\n[ 46.752895] a5 : 0000000000000000 a6 : 000000000017ffe3 a7 : 00000000000000d2\n[ 46.753117] s2 : ff600000028fb000 s3 : 0000000ae2751268 s4 : 0000000000000000\n[ 46.753338] s5 : ffffffff8153e290 s6 : ff600000863b9000 s7 : ff60000002961078\n[ 46.753562] s8 : ff60000002961048 s9 : ff60000002961058 s10: 0000000000000001\n[ 46.753783] s11: 0000000000000018 t3 : ffffffffffffffff t4 : ffffffffffffffff\n[ 46.754005] t5 : ff6000000292270c t6 : ff2000000022bb30\n[ 46.754179] status: 0000000200000100 badaddr: 0000000000000000 cause: 000000000000000c\n[ 46.754653] Code: Unable to access instruction at 0xffffffffffffffec.\n[ 46.754939] ---[ end trace 0000000000000000 ]---\n[ 46.755131] note: perf-exec[107] exited with irqs disabled\n[ 46.755546] note: perf-exec[107] exited with preempt_count 4\n\nThis happens because in the legacy case the ctr_get_width function was not\ndefined, but it is used in arch_perf_update_userpage.\n\nAlso remove extra check in riscv_pmu_ctr_get_width_mask",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26796"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/682dc133f83e0194796e6ea72eb642df1c03dfbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e0d17ee872cf8d0f51cc561329b8e1a0aa792bbb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e4f50e85de5a6b21dfdc0d7ca435eba4f62935c3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-04-04T09:15:08Z"
+ }
+}
\ No newline at end of file