Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-05 12:31:39 +00:00
parent 19295ac3ca
commit 9ba2cfe33b
46 changed files with 893 additions and 81 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fccv-jmmp-qg76",
"modified": "2023-12-21T22:01:39Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2023-11-28T18:30:23Z",
"aliases": [
"CVE-2023-46589"
@@ -197,6 +197,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231214-0009/"
@@ -42,6 +42,10 @@
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20211112-0002/"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210923-0001/"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210923-0001/"
@@ -56,6 +60,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-170",
"CWE-20"
],
"severity": "CRITICAL",
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210917-0003/"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
@@ -29,9 +29,17 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2168631"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-02"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22j2-mxcq-m52p",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32874"
],
"details": "In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:07Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33rw-cjxq-8rgp",
"modified": "2024-01-05T12:30:21Z",
"published": "2024-01-05T12:30:21Z",
"aliases": [
"CVE-2023-51538"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support WordPress HelpDesk & Support Plugin.This issue affects Awesome Support WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51538"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/awesome-support/wordpress-awesome-support-plugin-6-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T10:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mhp-935g-p95j",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32879"
],
"details": "In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308064.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:08Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5f2c-q448-h62x",
"modified": "2024-01-05T12:30:21Z",
"published": "2024-01-05T12:30:21Z",
"aliases": [
"CVE-2023-50991"
],
"details": "Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50991"
},
{
"type": "WEB",
"url": "https://github.com/ef4tless/vuln/blob/master/iot/i29/pingSet.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T10:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5ghg-77c4-pg6g",
"modified": "2024-01-05T12:30:24Z",
"published": "2024-01-05T12:30:24Z",
"aliases": [
"CVE-2023-51678"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51678"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/doofinder-for-woocommerce/wordpress-doofinder-wp-woocommerce-search-plugin-2-0-33-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T10:15:12Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w6w-j982-cggq",
"modified": "2024-01-05T12:30:22Z",
"published": "2024-01-05T12:30:22Z",
"aliases": [
"CVE-2023-51539"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51539"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/apollo13-framework-extensions/wordpress-apollo13-framework-extensions-plugin-1-9-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T10:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pjw-2w28-39xc",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32878"
],
"details": "In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74pj-4459-77rw",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32885"
],
"details": "In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c6f-5v4h-x27j",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32872"
],
"details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08308607.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:07Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hf2-cmmw-j42p",
"modified": "2024-01-05T12:30:25Z",
"published": "2024-01-05T12:30:25Z",
"aliases": [
"CVE-2023-52148"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52148"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/affiliates-manager/wordpress-affiliates-manager-plugin-2-9-30-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T11:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jwp-9wj7-pp6x",
"modified": "2024-01-05T12:30:25Z",
"published": "2024-01-05T12:30:25Z",
"aliases": [
"CVE-2023-52151"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator Automate everything with the #1 no-code automation and integration plugin: from n/a through 5.1.0.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52151"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/uncanny-automator/wordpress-uncanny-automator-plugin-5-1-0-2-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T11:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q5q-c932-cm9r",
"modified": "2024-01-02T03:30:30Z",
"modified": "2024-01-05T12:30:19Z",
"published": "2024-01-02T03:30:30Z",
"aliases": [
"CVE-2023-32880"
],
"details": "In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T03:15:08Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8284-h6g2-x964",
"modified": "2024-01-05T12:30:25Z",
"published": "2024-01-05T12:30:25Z",
"aliases": [
"CVE-2023-52124"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs Responsive Tabs Plugin for WordPress: from n/a through 2.2.0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52124"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/wp-expand-tabs-free/wordpress-wp-tabs-responsive-tabs-plugin-for-wordpress-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T12:15:09Z"
}
}

Some files were not shown because too many files have changed in this diff Show More