From 96c297bfe7de63a8e372168412a02b7b8720764d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 23 Jan 2024 18:32:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r62w-x9pp-jrqp.json | 78 +++++++++++++++++++ .../GHSA-8jvf-jqg4-r6h2.json | 7 +- .../GHSA-6fjw-fw76-494w.json | 7 +- .../GHSA-4wcp-phx2-2w2x.json | 7 +- .../GHSA-4hh4-3rxm-gq3h.json | 7 +- .../GHSA-4jpm-qv63-23qh.json | 9 ++- .../GHSA-5mwc-rp6j-mw6r.json | 9 ++- .../GHSA-8v5c-chfg-fcjx.json | 7 +- .../GHSA-8v6g-rf54-42cg.json | 13 +++- .../GHSA-g7vh-w82q-6c7j.json | 11 ++- .../GHSA-ghvr-mww9-3hrg.json | 10 ++- .../GHSA-hf4m-wpq9-6c3x.json | 9 ++- .../GHSA-p75r-f57h-pg5w.json | 11 ++- .../GHSA-r62w-x9pp-jrqp.json | 63 --------------- .../GHSA-rqw4-wgg4-99m9.json | 7 +- .../GHSA-v8v4-4v92-48h2.json | 10 ++- .../GHSA-vqmx-64jh-5r2h.json | 8 +- .../GHSA-6hrq-pjj8-qgcg.json | 8 +- .../GHSA-37m7-jq3g-46vx.json | 11 ++- .../GHSA-7pxw-wr4x-29hm.json | 31 ++++++++ .../GHSA-833g-hhhp-wggv.json | 11 ++- .../GHSA-8mgx-wgjw-q32g.json | 11 ++- .../GHSA-95ph-5wpx-w6gq.json | 11 ++- .../GHSA-9m8r-h264-rvx5.json | 11 ++- .../GHSA-c74w-77jp-9c48.json | 11 ++- .../GHSA-cj4r-mxq9-xgx5.json | 11 ++- .../GHSA-fqc4-ffq5-4r98.json | 3 +- .../GHSA-grw9-xhr2-wcp3.json | 11 ++- .../GHSA-h57w-vh34-f8cw.json | 11 ++- .../GHSA-hc66-p838-6xfp.json | 38 +++++++++ .../GHSA-hw85-hp8p-j3g9.json | 9 ++- .../GHSA-mg9f-ffx6-x997.json | 11 ++- .../GHSA-mx5q-46h2-qqfw.json | 11 ++- .../GHSA-pgcw-8wrq-74f3.json | 39 ++++++++++ .../GHSA-pr27-mhpp-2ccr.json | 2 +- .../GHSA-v435-pfj6-68r3.json | 35 +++++++++ .../GHSA-v9wr-2xrg-v7w8.json | 35 +++++++++ .../GHSA-xr6f-9r29-5gq3.json | 38 +++++++++ .../GHSA-xw8x-r2rg-vmq9.json | 38 +++++++++ 39 files changed, 516 insertions(+), 154 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7pxw-wr4x-29hm/GHSA-7pxw-wr4x-29hm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hc66-p838-6xfp/GHSA-hc66-p838-6xfp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pgcw-8wrq-74f3/GHSA-pgcw-8wrq-74f3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v435-pfj6-68r3/GHSA-v435-pfj6-68r3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v9wr-2xrg-v7w8/GHSA-v9wr-2xrg-v7w8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xr6f-9r29-5gq3/GHSA-xr6f-9r29-5gq3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xw8x-r2rg-vmq9/GHSA-xw8x-r2rg-vmq9.json diff --git a/advisories/github-reviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json b/advisories/github-reviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json new file mode 100644 index 00000000000..4e363b01155 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json @@ -0,0 +1,78 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r62w-x9pp-jrqp", + "modified": "2024-01-23T18:30:44Z", + "published": "2022-05-02T03:26:40Z", + "aliases": [ + "CVE-2009-1595" + ], + "summary": "Ignite Realtime Openfire Allows Users to Change Passwords of Arbitrary Accounts", + "details": "The `jabber:iq:auth` implementation in `IQAuthHandler.java` in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a `passwd_change` action.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.igniterealtime.openfire:parent" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.6.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-1595" + }, + { + "type": "WEB", + "url": "https://github.com/igniterealtime/Openfire/commit/97e1f08cf72e430f5cca5ba94cd20703dadb5ce5" + }, + { + "type": "WEB", + "url": "https://download.igniterealtime.org/openfire/docs/latest/changelog.html#3.6.4" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50292" + }, + { + "type": "PACKAGE", + "url": "https://github.com/igniterealtime/Openfire" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090518061336/http://www.igniterealtime.org/issues/browse/JM-1531" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140901211944/http://www.securityfocus.com/bid/34804" + }, + { + "type": "WEB", + "url": "http://www.igniterealtime.org/community/message/190280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-23T18:30:44Z", + "nvd_published_at": "2009-05-11T14:30:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2021/12/GHSA-8jvf-jqg4-r6h2/GHSA-8jvf-jqg4-r6h2.json b/advisories/unreviewed/2021/12/GHSA-8jvf-jqg4-r6h2/GHSA-8jvf-jqg4-r6h2.json index 070e65eae92..7f5e0e635b2 100644 --- a/advisories/unreviewed/2021/12/GHSA-8jvf-jqg4-r6h2/GHSA-8jvf-jqg4-r6h2.json +++ b/advisories/unreviewed/2021/12/GHSA-8jvf-jqg4-r6h2/GHSA-8jvf-jqg4-r6h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jvf-jqg4-r6h2", - "modified": "2021-12-21T00:01:25Z", + "modified": "2024-01-23T18:31:10Z", "published": "2021-12-16T00:02:12Z", "aliases": [ "CVE-2021-20330" ], "details": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.25; MongoDB Server v4.2 versions prior to 4.2.14; MongoDB Server v4.4 versions prior to 4.4.6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/01/GHSA-6fjw-fw76-494w/GHSA-6fjw-fw76-494w.json b/advisories/unreviewed/2022/01/GHSA-6fjw-fw76-494w/GHSA-6fjw-fw76-494w.json index 5051141121e..d5b6c047631 100644 --- a/advisories/unreviewed/2022/01/GHSA-6fjw-fw76-494w/GHSA-6fjw-fw76-494w.json +++ b/advisories/unreviewed/2022/01/GHSA-6fjw-fw76-494w/GHSA-6fjw-fw76-494w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fjw-fw76-494w", - "modified": "2022-01-27T00:03:02Z", + "modified": "2024-01-23T18:31:10Z", "published": "2022-01-21T00:00:47Z", "aliases": [ "CVE-2021-32039" ], "details": "Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/02/GHSA-4wcp-phx2-2w2x/GHSA-4wcp-phx2-2w2x.json b/advisories/unreviewed/2022/02/GHSA-4wcp-phx2-2w2x/GHSA-4wcp-phx2-2w2x.json index 495f67162ca..ac37dc4cbda 100644 --- a/advisories/unreviewed/2022/02/GHSA-4wcp-phx2-2w2x/GHSA-4wcp-phx2-2w2x.json +++ b/advisories/unreviewed/2022/02/GHSA-4wcp-phx2-2w2x/GHSA-4wcp-phx2-2w2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wcp-phx2-2w2x", - "modified": "2022-02-10T00:00:42Z", + "modified": "2024-01-23T18:31:10Z", "published": "2022-02-10T00:00:42Z", "aliases": [ "CVE-2021-32036" ], "details": "An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4hh4-3rxm-gq3h/GHSA-4hh4-3rxm-gq3h.json b/advisories/unreviewed/2022/05/GHSA-4hh4-3rxm-gq3h/GHSA-4hh4-3rxm-gq3h.json index 25387e14a73..f57faa98c5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hh4-3rxm-gq3h/GHSA-4hh4-3rxm-gq3h.json +++ b/advisories/unreviewed/2022/05/GHSA-4hh4-3rxm-gq3h/GHSA-4hh4-3rxm-gq3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hh4-3rxm-gq3h", - "modified": "2022-05-24T17:41:54Z", + "modified": "2024-01-23T18:31:09Z", "published": "2022-05-24T17:41:54Z", "aliases": [ "CVE-2021-20335" ], "details": "For MongoDB Ops Manager 4.2.X with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager 4.4.X triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster. This issue is temporary and eventually corrects itself after MongoDB Ops Manager instances have finished upgrading to MongoDB Ops Manager 4.4. In addition, customers must be running with clientCertificateMode=OPTIONAL / allowConnectionsWithoutCertificates=true to be impacted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4jpm-qv63-23qh/GHSA-4jpm-qv63-23qh.json b/advisories/unreviewed/2022/05/GHSA-4jpm-qv63-23qh/GHSA-4jpm-qv63-23qh.json index b9fa55e950e..289a8b66f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jpm-qv63-23qh/GHSA-4jpm-qv63-23qh.json +++ b/advisories/unreviewed/2022/05/GHSA-4jpm-qv63-23qh/GHSA-4jpm-qv63-23qh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jpm-qv63-23qh", - "modified": "2022-05-24T22:01:28Z", + "modified": "2024-01-23T18:31:09Z", "published": "2022-05-24T22:01:28Z", "aliases": [ "CVE-2020-7929" ], "details": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects: MongoDB Inc. MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-185" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5mwc-rp6j-mw6r/GHSA-5mwc-rp6j-mw6r.json b/advisories/unreviewed/2022/05/GHSA-5mwc-rp6j-mw6r/GHSA-5mwc-rp6j-mw6r.json index 045f7ae1dc3..23b439f8bdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mwc-rp6j-mw6r/GHSA-5mwc-rp6j-mw6r.json +++ b/advisories/unreviewed/2022/05/GHSA-5mwc-rp6j-mw6r/GHSA-5mwc-rp6j-mw6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mwc-rp6j-mw6r", - "modified": "2022-05-24T17:34:50Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T17:34:50Z", "aliases": [ "CVE-2020-7928" ], "details": "A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects: MongoDB Inc. MongoDB Server v4.5 versions prior to 4.5.1; v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-158" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-8v5c-chfg-fcjx/GHSA-8v5c-chfg-fcjx.json b/advisories/unreviewed/2022/05/GHSA-8v5c-chfg-fcjx/GHSA-8v5c-chfg-fcjx.json index 4f41af390b2..93f0881dae0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v5c-chfg-fcjx/GHSA-8v5c-chfg-fcjx.json +++ b/advisories/unreviewed/2022/05/GHSA-8v5c-chfg-fcjx/GHSA-8v5c-chfg-fcjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v5c-chfg-fcjx", - "modified": "2022-05-24T19:21:17Z", + "modified": "2024-01-23T18:31:10Z", "published": "2022-05-24T19:21:17Z", "aliases": [ "CVE-2021-32037" ], "details": "An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8v6g-rf54-42cg/GHSA-8v6g-rf54-42cg.json b/advisories/unreviewed/2022/05/GHSA-8v6g-rf54-42cg/GHSA-8v6g-rf54-42cg.json index 8525a059eec..5384ba58fc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v6g-rf54-42cg/GHSA-8v6g-rf54-42cg.json +++ b/advisories/unreviewed/2022/05/GHSA-8v6g-rf54-42cg/GHSA-8v6g-rf54-42cg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v6g-rf54-42cg", - "modified": "2022-05-24T17:34:50Z", + "modified": "2024-01-23T18:31:09Z", "published": "2022-05-24T17:34:50Z", "aliases": [ "CVE-2020-7927" ], "details": "Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions 4.2.0-4.2.17, v4.3 versions 4.3.0-4.3.9 and v4.4 versions 4.4.0-4.4.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -21,11 +24,15 @@ { "type": "WEB", "url": "https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3" + }, + { + "type": "WEB", + "url": "https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-4.4.3" } ], "database_specific": { "cwe_ids": [ - + "CWE-648" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-g7vh-w82q-6c7j/GHSA-g7vh-w82q-6c7j.json b/advisories/unreviewed/2022/05/GHSA-g7vh-w82q-6c7j/GHSA-g7vh-w82q-6c7j.json index bea1840c489..bb00b83b489 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7vh-w82q-6c7j/GHSA-g7vh-w82q-6c7j.json +++ b/advisories/unreviewed/2022/05/GHSA-g7vh-w82q-6c7j/GHSA-g7vh-w82q-6c7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7vh-w82q-6c7j", - "modified": "2022-05-24T16:53:23Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T16:53:23Z", "aliases": [ "CVE-2016-10885" ], "details": "The wp-editor plugin before 1.2.6 for WordPress has CSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-08-14T16:15:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-ghvr-mww9-3hrg/GHSA-ghvr-mww9-3hrg.json b/advisories/unreviewed/2022/05/GHSA-ghvr-mww9-3hrg/GHSA-ghvr-mww9-3hrg.json index 5ed85b595e0..80d58d126d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghvr-mww9-3hrg/GHSA-ghvr-mww9-3hrg.json +++ b/advisories/unreviewed/2022/05/GHSA-ghvr-mww9-3hrg/GHSA-ghvr-mww9-3hrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghvr-mww9-3hrg", - "modified": "2022-05-24T19:09:06Z", + "modified": "2024-01-23T18:31:10Z", "published": "2022-05-24T19:09:06Z", "aliases": [ "CVE-2021-20333" ], "details": "Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21; MongoDB Server v4.2 versions prior to 4.2.10;", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-117" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hf4m-wpq9-6c3x/GHSA-hf4m-wpq9-6c3x.json b/advisories/unreviewed/2022/05/GHSA-hf4m-wpq9-6c3x/GHSA-hf4m-wpq9-6c3x.json index aa5782e536e..9c5b46d25e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf4m-wpq9-6c3x/GHSA-hf4m-wpq9-6c3x.json +++ b/advisories/unreviewed/2022/05/GHSA-hf4m-wpq9-6c3x/GHSA-hf4m-wpq9-6c3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf4m-wpq9-6c3x", - "modified": "2022-05-24T16:53:23Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T16:53:23Z", "aliases": [ "CVE-2016-10886" ], "details": "The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-08-14T16:15:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-p75r-f57h-pg5w/GHSA-p75r-f57h-pg5w.json b/advisories/unreviewed/2022/05/GHSA-p75r-f57h-pg5w/GHSA-p75r-f57h-pg5w.json index 8532e4ebbfc..39dc756587e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p75r-f57h-pg5w/GHSA-p75r-f57h-pg5w.json +++ b/advisories/unreviewed/2022/05/GHSA-p75r-f57h-pg5w/GHSA-p75r-f57h-pg5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p75r-f57h-pg5w", - "modified": "2022-05-24T17:13:58Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T17:13:58Z", "aliases": [ "CVE-2020-7922" ], "details": "X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are unaffected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-04-09T18:15:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json b/advisories/unreviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json deleted file mode 100644 index 5cc4134319c..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-r62w-x9pp-jrqp/GHSA-r62w-x9pp-jrqp.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-r62w-x9pp-jrqp", - "modified": "2022-05-02T03:26:40Z", - "published": "2022-05-02T03:26:40Z", - "aliases": [ - "CVE-2009-1595" - ], - "details": "The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-1595" - }, - { - "type": "WEB", - "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50292" - }, - { - "type": "WEB", - "url": "http://osvdb.org/54189" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/34976" - }, - { - "type": "WEB", - "url": "http://www.igniterealtime.org/builds/openfire/docs/latest/changelog.html" - }, - { - "type": "WEB", - "url": "http://www.igniterealtime.org/community/message/190280" - }, - { - "type": "WEB", - "url": "http://www.igniterealtime.org/issues/browse/JM-1531" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/34804" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/1237" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-287" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2009-05-11T14:30:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-rqw4-wgg4-99m9/GHSA-rqw4-wgg4-99m9.json b/advisories/unreviewed/2022/05/GHSA-rqw4-wgg4-99m9/GHSA-rqw4-wgg4-99m9.json index bb5fedc5d6c..d09b74dafd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqw4-wgg4-99m9/GHSA-rqw4-wgg4-99m9.json +++ b/advisories/unreviewed/2022/05/GHSA-rqw4-wgg4-99m9/GHSA-rqw4-wgg4-99m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqw4-wgg4-99m9", - "modified": "2022-05-24T17:34:50Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T17:34:50Z", "aliases": [ "CVE-2020-7926" ], "details": "A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects: MongoDB Server version 4.4 prior to 4.4.1. Versions before 4.4 are not affected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v8v4-4v92-48h2/GHSA-v8v4-4v92-48h2.json b/advisories/unreviewed/2022/05/GHSA-v8v4-4v92-48h2/GHSA-v8v4-4v92-48h2.json index a1a2b2dc7e7..e435d183c48 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8v4-4v92-48h2/GHSA-v8v4-4v92-48h2.json +++ b/advisories/unreviewed/2022/05/GHSA-v8v4-4v92-48h2/GHSA-v8v4-4v92-48h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8v4-4v92-48h2", - "modified": "2022-05-24T17:34:50Z", + "modified": "2024-01-23T18:31:08Z", "published": "2022-05-24T17:34:50Z", "aliases": [ "CVE-2020-7925" ], "details": "Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc12; v4.2 versions prior to 4.2.9.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-475" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vqmx-64jh-5r2h/GHSA-vqmx-64jh-5r2h.json b/advisories/unreviewed/2022/05/GHSA-vqmx-64jh-5r2h/GHSA-vqmx-64jh-5r2h.json index 4c05120226d..7f108d5226b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqmx-64jh-5r2h/GHSA-vqmx-64jh-5r2h.json +++ b/advisories/unreviewed/2022/05/GHSA-vqmx-64jh-5r2h/GHSA-vqmx-64jh-5r2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqmx-64jh-5r2h", - "modified": "2022-05-24T17:49:18Z", + "modified": "2024-01-23T18:31:10Z", "published": "2022-05-24T17:49:18Z", "aliases": [ "CVE-2021-20326" ], "details": "A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-732" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/08/GHSA-6hrq-pjj8-qgcg/GHSA-6hrq-pjj8-qgcg.json b/advisories/unreviewed/2023/08/GHSA-6hrq-pjj8-qgcg/GHSA-6hrq-pjj8-qgcg.json index ad6cb7c366e..48d89c682ff 100644 --- a/advisories/unreviewed/2023/08/GHSA-6hrq-pjj8-qgcg/GHSA-6hrq-pjj8-qgcg.json +++ b/advisories/unreviewed/2023/08/GHSA-6hrq-pjj8-qgcg/GHSA-6hrq-pjj8-qgcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hrq-pjj8-qgcg", - "modified": "2023-08-11T18:31:48Z", + "modified": "2024-01-23T18:31:10Z", "published": "2023-08-09T12:30:26Z", "aliases": [ "CVE-2023-32781" @@ -28,13 +28,17 @@ { "type": "WEB", "url": "https://www.paessler.com/prtg/history/stable" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176677/PRTG-Authenticated-Remote-Code-Execution.html" } ], "database_specific": { "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-09T12:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-37m7-jq3g-46vx/GHSA-37m7-jq3g-46vx.json b/advisories/unreviewed/2024/01/GHSA-37m7-jq3g-46vx/GHSA-37m7-jq3g-46vx.json index dd20cb232b6..38e12f6dbd2 100644 --- a/advisories/unreviewed/2024/01/GHSA-37m7-jq3g-46vx/GHSA-37m7-jq3g-46vx.json +++ b/advisories/unreviewed/2024/01/GHSA-37m7-jq3g-46vx/GHSA-37m7-jq3g-46vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37m7-jq3g-46vx", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-7125" ], "details": "The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:14Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7pxw-wr4x-29hm/GHSA-7pxw-wr4x-29hm.json b/advisories/unreviewed/2024/01/GHSA-7pxw-wr4x-29hm/GHSA-7pxw-wr4x-29hm.json new file mode 100644 index 00000000000..4f4695f4068 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7pxw-wr4x-29hm/GHSA-7pxw-wr4x-29hm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pxw-wr4x-29hm", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2024-23854" + ], + "details": "Rejected reason: This CVE ID was unused by the CNA.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23854" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-833g-hhhp-wggv/GHSA-833g-hhhp-wggv.json b/advisories/unreviewed/2024/01/GHSA-833g-hhhp-wggv/GHSA-833g-hhhp-wggv.json index ddbc310ebfc..e011ea9af9b 100644 --- a/advisories/unreviewed/2024/01/GHSA-833g-hhhp-wggv/GHSA-833g-hhhp-wggv.json +++ b/advisories/unreviewed/2024/01/GHSA-833g-hhhp-wggv/GHSA-833g-hhhp-wggv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-833g-hhhp-wggv", - "modified": "2024-01-16T18:31:08Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24559" ], "details": "The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json b/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json index cccc644c832..0c790809035 100644 --- a/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json +++ b/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mgx-wgjw-q32g", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2024-0239" ], "details": "The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:14Z" diff --git a/advisories/unreviewed/2024/01/GHSA-95ph-5wpx-w6gq/GHSA-95ph-5wpx-w6gq.json b/advisories/unreviewed/2024/01/GHSA-95ph-5wpx-w6gq/GHSA-95ph-5wpx-w6gq.json index f4394342f1a..675613a02ae 100644 --- a/advisories/unreviewed/2024/01/GHSA-95ph-5wpx-w6gq/GHSA-95ph-5wpx-w6gq.json +++ b/advisories/unreviewed/2024/01/GHSA-95ph-5wpx-w6gq/GHSA-95ph-5wpx-w6gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95ph-5wpx-w6gq", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-4969" ], "details": "A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json b/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json index 17ba18a3813..151adf9bdcc 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json +++ b/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m8r-h264-rvx5", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2024-0187" ], "details": "The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:14Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c74w-77jp-9c48/GHSA-c74w-77jp-9c48.json b/advisories/unreviewed/2024/01/GHSA-c74w-77jp-9c48/GHSA-c74w-77jp-9c48.json index 9700791a3a7..b1086903ebc 100644 --- a/advisories/unreviewed/2024/01/GHSA-c74w-77jp-9c48/GHSA-c74w-77jp-9c48.json +++ b/advisories/unreviewed/2024/01/GHSA-c74w-77jp-9c48/GHSA-c74w-77jp-9c48.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c74w-77jp-9c48", - "modified": "2024-01-16T03:30:20Z", + "modified": "2024-01-23T18:31:10Z", "published": "2024-01-16T03:30:20Z", "aliases": [ "CVE-2023-51257" ], "details": "An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T02:15:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cj4r-mxq9-xgx5/GHSA-cj4r-mxq9-xgx5.json b/advisories/unreviewed/2024/01/GHSA-cj4r-mxq9-xgx5/GHSA-cj4r-mxq9-xgx5.json index f4b73427a70..682be80aa5c 100644 --- a/advisories/unreviewed/2024/01/GHSA-cj4r-mxq9-xgx5/GHSA-cj4r-mxq9-xgx5.json +++ b/advisories/unreviewed/2024/01/GHSA-cj4r-mxq9-xgx5/GHSA-cj4r-mxq9-xgx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj4r-mxq9-xgx5", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-4757" ], "details": "The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:13Z" diff --git a/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json b/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json index 5df19599d9c..4661b00069f 100644 --- a/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json +++ b/advisories/unreviewed/2024/01/GHSA-fqc4-ffq5-4r98/GHSA-fqc4-ffq5-4r98.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-338" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json b/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json index e3e940b84a3..c74a64fa73c 100644 --- a/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json +++ b/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grw9-xhr2-wcp3", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-0079" ], "details": "The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-h57w-vh34-f8cw/GHSA-h57w-vh34-f8cw.json b/advisories/unreviewed/2024/01/GHSA-h57w-vh34-f8cw/GHSA-h57w-vh34-f8cw.json index 8dd358e9b01..40c5aee6551 100644 --- a/advisories/unreviewed/2024/01/GHSA-h57w-vh34-f8cw/GHSA-h57w-vh34-f8cw.json +++ b/advisories/unreviewed/2024/01/GHSA-h57w-vh34-f8cw/GHSA-h57w-vh34-f8cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h57w-vh34-f8cw", - "modified": "2024-01-16T03:30:20Z", + "modified": "2024-01-23T18:31:10Z", "published": "2024-01-16T03:30:20Z", "aliases": [ "CVE-2023-51282" ], "details": "An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T02:15:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-hc66-p838-6xfp/GHSA-hc66-p838-6xfp.json b/advisories/unreviewed/2024/01/GHSA-hc66-p838-6xfp/GHSA-hc66-p838-6xfp.json new file mode 100644 index 00000000000..00d8e4dded1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hc66-p838-6xfp/GHSA-hc66-p838-6xfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc66-p838-6xfp", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2023-50275" + ], + "details": "HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50275" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04586en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hw85-hp8p-j3g9/GHSA-hw85-hp8p-j3g9.json b/advisories/unreviewed/2024/01/GHSA-hw85-hp8p-j3g9/GHSA-hw85-hp8p-j3g9.json index bf422c13b3c..b6cb4c4443a 100644 --- a/advisories/unreviewed/2024/01/GHSA-hw85-hp8p-j3g9/GHSA-hw85-hp8p-j3g9.json +++ b/advisories/unreviewed/2024/01/GHSA-hw85-hp8p-j3g9/GHSA-hw85-hp8p-j3g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw85-hp8p-j3g9", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-6824" ], "details": "The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:13Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mg9f-ffx6-x997/GHSA-mg9f-ffx6-x997.json b/advisories/unreviewed/2024/01/GHSA-mg9f-ffx6-x997/GHSA-mg9f-ffx6-x997.json index 47036c66d0e..7ee7b6ea828 100644 --- a/advisories/unreviewed/2024/01/GHSA-mg9f-ffx6-x997/GHSA-mg9f-ffx6-x997.json +++ b/advisories/unreviewed/2024/01/GHSA-mg9f-ffx6-x997/GHSA-mg9f-ffx6-x997.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mg9f-ffx6-x997", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-7151" ], "details": "The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:14Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json b/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json index 62e25de7865..449df3b3fd4 100644 --- a/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json +++ b/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5q-46h2-qqfw", - "modified": "2024-01-16T18:31:10Z", + "modified": "2024-01-23T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-7154" ], "details": "The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:14Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pgcw-8wrq-74f3/GHSA-pgcw-8wrq-74f3.json b/advisories/unreviewed/2024/01/GHSA-pgcw-8wrq-74f3/GHSA-pgcw-8wrq-74f3.json new file mode 100644 index 00000000000..a7bdc031897 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pgcw-8wrq-74f3/GHSA-pgcw-8wrq-74f3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgcw-8wrq-74f3", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2023-45889" + ], + "details": "A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45889" + }, + { + "type": "WEB", + "url": "https://blog.zerdle.net/classlink/" + }, + { + "type": "WEB", + "url": "https://blog.zerdle.net/classlink2/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pr27-mhpp-2ccr/GHSA-pr27-mhpp-2ccr.json b/advisories/unreviewed/2024/01/GHSA-pr27-mhpp-2ccr/GHSA-pr27-mhpp-2ccr.json index 44dafb597cd..c246dde3d70 100644 --- a/advisories/unreviewed/2024/01/GHSA-pr27-mhpp-2ccr/GHSA-pr27-mhpp-2ccr.json +++ b/advisories/unreviewed/2024/01/GHSA-pr27-mhpp-2ccr/GHSA-pr27-mhpp-2ccr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr27-mhpp-2ccr", - "modified": "2024-01-17T15:30:27Z", + "modified": "2024-01-23T18:31:10Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45231" diff --git a/advisories/unreviewed/2024/01/GHSA-v435-pfj6-68r3/GHSA-v435-pfj6-68r3.json b/advisories/unreviewed/2024/01/GHSA-v435-pfj6-68r3/GHSA-v435-pfj6-68r3.json new file mode 100644 index 00000000000..a7a011ab4a9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v435-pfj6-68r3/GHSA-v435-pfj6-68r3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v435-pfj6-68r3", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2024-22496" + ], + "details": "Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22496" + }, + { + "type": "WEB", + "url": "https://github.com/cui2shark/security/blob/main/%28JFinalcms%20admin-login-username%29%20.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v9wr-2xrg-v7w8/GHSA-v9wr-2xrg-v7w8.json b/advisories/unreviewed/2024/01/GHSA-v9wr-2xrg-v7w8/GHSA-v9wr-2xrg-v7w8.json new file mode 100644 index 00000000000..1deaffefeb5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v9wr-2xrg-v7w8/GHSA-v9wr-2xrg-v7w8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9wr-2xrg-v7w8", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2024-22490" + ], + "details": "Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22490" + }, + { + "type": "WEB", + "url": "https://github.com/cui2shark/security/blob/main/beetl-bbs%20-%20A%20reflected%20cross-site%20scripting%20%28XSS%29%20vulnerability%20was%20discovered%20in%20the%20search%20box.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xr6f-9r29-5gq3/GHSA-xr6f-9r29-5gq3.json b/advisories/unreviewed/2024/01/GHSA-xr6f-9r29-5gq3/GHSA-xr6f-9r29-5gq3.json new file mode 100644 index 00000000000..b0b48b72e31 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xr6f-9r29-5gq3/GHSA-xr6f-9r29-5gq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr6f-9r29-5gq3", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2023-50274" + ], + "details": "HPE OneView may allow command injection with local privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50274" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04586en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xw8x-r2rg-vmq9/GHSA-xw8x-r2rg-vmq9.json b/advisories/unreviewed/2024/01/GHSA-xw8x-r2rg-vmq9/GHSA-xw8x-r2rg-vmq9.json new file mode 100644 index 00000000000..4b5584bbd6c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xw8x-r2rg-vmq9/GHSA-xw8x-r2rg-vmq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw8x-r2rg-vmq9", + "modified": "2024-01-23T18:31:11Z", + "published": "2024-01-23T18:31:11Z", + "aliases": [ + "CVE-2023-6573" + ], + "details": "HPE OneView may have a missing passphrase during restore.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6573" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04586en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-23T18:15:18Z" + } +} \ No newline at end of file