Publish Advisories

GHSA-wvg9-27w3-xhh7
GHSA-354q-38f3-jh4j
GHSA-cpmq-crvm-2w5p
GHSA-c8cv-8gr5-5v2w
GHSA-j7hm-p94x-q9pw
GHSA-qv79-48vx-52fw
GHSA-g8c4-rhfw-rcpw
GHSA-fjv7-prxm-hm8g
GHSA-hvph-2g5j-p2c9
GHSA-jvxf-w5f4-25gh
GHSA-pq6p-fc96-wc5w
GHSA-r6m2-cj32-wg84
GHSA-w228-frcg-5x99
GHSA-9jpv-w64v-mgr2
GHSA-vgh3-mwxq-rcp8
This commit is contained in:
advisory-database[bot]
2024-02-01 03:31:45 +00:00
parent 09c88b23d8
commit 9369de1351
15 changed files with 110 additions and 24 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvg9-27w3-xhh7",
"modified": "2022-05-24T17:17:10Z",
"modified": "2024-02-01T03:30:23Z",
"published": "2022-05-24T17:17:10Z",
"aliases": [
"CVE-2020-12659"
],
"details": "An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -57,7 +60,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-354q-38f3-jh4j",
"modified": "2023-05-05T15:30:59Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-04-25T21:30:29Z",
"aliases": [
"CVE-2023-2269"
@@ -29,6 +29,18 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63AJUCJTZCII2JMAF7MGZEM66KY7IALT/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FBLBKW2WM5YSTS6OGEU5SYHXSJ5EWSTV/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IXHBLWYNSUBS77TYPOJTADPDXKBH2F4U/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63AJUCJTZCII2JMAF7MGZEM66KY7IALT/"
@@ -41,6 +53,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXHBLWYNSUBS77TYPOJTADPDXKBH2F4U/"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/ZD1xyZxb3rHot8PV%40redhat.com/t/"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/ZD1xyZxb3rHot8PV@redhat.com/t/"
@@ -63,7 +79,7 @@
"CWE-413",
"CWE-667"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-25T21:15:10Z"
@@ -33,6 +33,18 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HU4PKLUVB5CTMOVQ2GV33TNUNMJCBGD/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBXEXL2ZQBWCBLNUP6P67FHECXQWSK3L/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GM66PNHGCXZU66LQCTP2FSJLFF6CVMSI/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HU4PKLUVB5CTMOVQ2GV33TNUNMJCBGD/"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8cv-8gr5-5v2w",
"modified": "2023-06-02T03:30:22Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-05-27T00:30:19Z",
"aliases": [
"CVE-2023-2898"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/linux-f2fs-devel/20230522124203.3838360-1-chao%40kernel.org/"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/linux-f2fs-devel/20230522124203.3838360-1-chao@kernel.org/"
@@ -47,7 +51,7 @@
"CWE-362",
"CWE-476"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-26T22:15:14Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7hm-p94x-q9pw",
"modified": "2023-05-10T15:30:19Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-05-03T12:30:41Z",
"aliases": [
"CVE-2022-40302"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-03T12:16:27Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qv79-48vx-52fw",
"modified": "2023-08-08T15:33:39Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-08-03T00:30:15Z",
"aliases": [
"CVE-2023-1437"
@@ -31,7 +31,7 @@
"CWE-119",
"CWE-822"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-02T23:15:10Z"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5084"
},
{
"type": "WEB",
"url": "https://github.com/hestiacp/hestiacp/pull/4013/commits/5131f5a966759df77477fdf7f29daa2bda93b1ff"
},
{
"type": "WEB",
"url": "https://github.com/hestiacp/hestiacp/commit/5131f5a966759df77477fdf7f29daa2bda93b1ff"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fjv7-prxm-hm8g",
"modified": "2023-10-16T18:30:27Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-11T12:30:27Z",
"aliases": [
"CVE-2023-44109"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-74"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-11T11:15:14Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvph-2g5j-p2c9",
"modified": "2023-10-10T06:30:30Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-10T06:30:29Z",
"aliases": [
"CVE-2023-5467"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-10T05:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvxf-w5f4-25gh",
"modified": "2023-10-18T00:31:41Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22074"
@@ -24,13 +24,17 @@
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175352/Oracle-19c-21c-Sharding-Component-Password-Hash-Exposure.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:13Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq6p-fc96-wc5w",
"modified": "2023-11-16T03:30:19Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-26T21:30:22Z",
"aliases": [
"CVE-2023-46747"
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-288"
"CWE-288",
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6m2-cj32-wg84",
"modified": "2023-10-13T21:30:18Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-09T09:30:42Z",
"aliases": [
"CVE-2023-39854"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-09T07:15:24Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w228-frcg-5x99",
"modified": "2023-10-11T09:34:01Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-10-04T21:30:22Z",
"aliases": [
"CVE-2023-5391"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-04T19:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jpv-w64v-mgr2",
"modified": "2023-11-28T12:31:25Z",
"modified": "2024-02-01T03:30:22Z",
"published": "2023-11-02T09:30:18Z",
"aliases": [
"CVE-2023-46595"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgh3-mwxq-rcp8",
"modified": "2024-02-01T03:30:22Z",
"published": "2024-02-01T03:30:22Z",
"aliases": [
"CVE-2024-0831"
],
"details": "Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0831"
},
{
"type": "WEB",
"url": "https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration"
},
{
"type": "WEB",
"url": "https://link-to-discuss"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T02:15:46Z"
}
}