From 9d9c0d32216240963d5a96fdf714cd06a4120914 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 22 Dec 2022 18:31:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4hgp-5v89-5fhw.json | 6 +++- .../GHSA-jf26-p43w-867v.json | 4 +++ .../GHSA-76r5-xvfg-3gj2.json | 4 +++ .../GHSA-g397-g5h4-jrx6.json | 4 +++ .../GHSA-hcgg-5q2q-c9qf.json | 4 +++ .../GHSA-hjfq-c3jw-r92p.json | 5 +++ .../GHSA-hvrc-p628-rmrc.json | 4 +++ .../GHSA-hx6h-vxvg-2g6w.json | 4 +++ .../GHSA-mfp9-chmw-53h7.json | 4 +++ .../GHSA-phx5-p62q-ppqc.json | 4 +++ .../GHSA-w8wm-5qpx-c8j6.json | 4 +++ .../GHSA-395q-7j8c-c3j7.json | 9 +++-- .../GHSA-429v-rpg5-8469.json | 9 +++-- .../GHSA-44mv-gf6j-pvgx.json | 9 +++-- .../GHSA-463f-2q49-4chc.json | 9 +++-- .../GHSA-49gf-23c6-vwj7.json | 36 +++++++++++++++++++ .../GHSA-56mg-c7p2-w99m.json | 9 +++-- .../GHSA-664m-3r2m-mxpx.json | 11 +++--- .../GHSA-6gg7-q37j-4gwp.json | 9 +++-- .../GHSA-6wmx-298j-589v.json | 11 +++--- .../GHSA-76w3-2xmj-8wr3.json | 33 +++++++++++++++++ .../GHSA-7mxg-cx88-pj6r.json | 4 +++ .../GHSA-84pv-wjmq-7chc.json | 9 +++-- .../GHSA-93wq-f3m6-f4w4.json | 9 +++-- .../GHSA-999r-r2f8-xm55.json | 11 +++--- .../GHSA-9wxc-wwm3-4wvf.json | 9 +++-- .../GHSA-cmgp-w7hp-vqr7.json | 4 +++ .../GHSA-cw83-h4x5-m8mv.json | 11 +++--- .../GHSA-f22x-pp6j-8h8j.json | 11 +++--- .../GHSA-f685-h8p2-vgf5.json | 9 +++-- .../GHSA-ff4v-crmx-qh7v.json | 4 +++ .../GHSA-g3wc-xv93-445q.json | 9 +++-- .../GHSA-g5jc-hc65-x4vm.json | 9 +++-- .../GHSA-ghhc-93hq-6rqv.json | 4 +++ .../GHSA-h8mf-8qf9-cg8w.json | 9 +++-- .../GHSA-jj3f-6mrw-wgq6.json | 9 +++-- .../GHSA-mcxp-g82x-32fg.json | 33 +++++++++++++++++ .../GHSA-p377-qm42-6xph.json | 33 +++++++++++++++++ .../GHSA-pmj2-vwxv-3w98.json | 4 +++ .../GHSA-pv34-c9m7-5qqm.json | 9 +++-- .../GHSA-pvrf-2wf8-jrqv.json | 4 +++ .../GHSA-q8cm-r6w4-28gm.json | 4 +++ .../GHSA-rvqq-fwff-p2v4.json | 11 +++--- .../GHSA-w4w3-58wp-7gmq.json | 11 +++--- .../GHSA-w7r9-9mj3-89fp.json | 9 +++-- .../GHSA-w8rr-xg77-6mj9.json | 9 +++-- .../GHSA-x7wf-5vvq-hf3f.json | 11 +++--- .../GHSA-xj46-w22p-wj4j.json | 9 +++-- 48 files changed, 373 insertions(+), 87 deletions(-) create mode 100644 advisories/unreviewed/2022/12/GHSA-49gf-23c6-vwj7/GHSA-49gf-23c6-vwj7.json create mode 100644 advisories/unreviewed/2022/12/GHSA-76w3-2xmj-8wr3/GHSA-76w3-2xmj-8wr3.json create mode 100644 advisories/unreviewed/2022/12/GHSA-mcxp-g82x-32fg/GHSA-mcxp-g82x-32fg.json create mode 100644 advisories/unreviewed/2022/12/GHSA-p377-qm42-6xph/GHSA-p377-qm42-6xph.json diff --git a/advisories/unreviewed/2022/08/GHSA-4hgp-5v89-5fhw/GHSA-4hgp-5v89-5fhw.json b/advisories/unreviewed/2022/08/GHSA-4hgp-5v89-5fhw/GHSA-4hgp-5v89-5fhw.json index 63e8771ee94..20b4af317d2 100644 --- a/advisories/unreviewed/2022/08/GHSA-4hgp-5v89-5fhw/GHSA-4hgp-5v89-5fhw.json +++ b/advisories/unreviewed/2022/08/GHSA-4hgp-5v89-5fhw/GHSA-4hgp-5v89-5fhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-4hgp-5v89-5fhw", - "modified": "2022-08-26T00:03:35Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-08-24T00:00:29Z", "aliases": [ "CVE-2021-3759" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1999675" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/linux-mm/1626333284-1404-1-git-send-email-nglaive@gmail.com/" diff --git a/advisories/unreviewed/2022/09/GHSA-jf26-p43w-867v/GHSA-jf26-p43w-867v.json b/advisories/unreviewed/2022/09/GHSA-jf26-p43w-867v/GHSA-jf26-p43w-867v.json index 4c4825515ce..683c8e24074 100644 --- a/advisories/unreviewed/2022/09/GHSA-jf26-p43w-867v/GHSA-jf26-p43w-867v.json +++ b/advisories/unreviewed/2022/09/GHSA-jf26-p43w-867v/GHSA-jf26-p43w-867v.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://bugzilla.kernel.org/show_bug.cgi?id=214771" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-76r5-xvfg-3gj2/GHSA-76r5-xvfg-3gj2.json b/advisories/unreviewed/2022/10/GHSA-76r5-xvfg-3gj2/GHSA-76r5-xvfg-3gj2.json index b8c9d5949a7..ec3cdcf3bb9 100644 --- a/advisories/unreviewed/2022/10/GHSA-76r5-xvfg-3gj2/GHSA-76r5-xvfg-3gj2.json +++ b/advisories/unreviewed/2022/10/GHSA-76r5-xvfg-3gj2/GHSA-76r5-xvfg-3gj2.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec7eede369fe5b0d085ac51fdbb95184f87bfc6c" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211018" diff --git a/advisories/unreviewed/2022/10/GHSA-g397-g5h4-jrx6/GHSA-g397-g5h4-jrx6.json b/advisories/unreviewed/2022/10/GHSA-g397-g5h4-jrx6/GHSA-g397-g5h4-jrx6.json index 6d7ea9e5f9e..7bbd6bb69ed 100644 --- a/advisories/unreviewed/2022/10/GHSA-g397-g5h4-jrx6/GHSA-g397-g5h4-jrx6.json +++ b/advisories/unreviewed/2022/10/GHSA-g397-g5h4-jrx6/GHSA-g397-g5h4-jrx6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3c52c6bb831f6335c176a0fc7214e26f43adbd11" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211021" diff --git a/advisories/unreviewed/2022/10/GHSA-hcgg-5q2q-c9qf/GHSA-hcgg-5q2q-c9qf.json b/advisories/unreviewed/2022/10/GHSA-hcgg-5q2q-c9qf/GHSA-hcgg-5q2q-c9qf.json index ab7b924f148..5834ba4b812 100644 --- a/advisories/unreviewed/2022/10/GHSA-hcgg-5q2q-c9qf/GHSA-hcgg-5q2q-c9qf.json +++ b/advisories/unreviewed/2022/10/GHSA-hcgg-5q2q-c9qf/GHSA-hcgg-5q2q-c9qf.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3435" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY/" diff --git a/advisories/unreviewed/2022/10/GHSA-hjfq-c3jw-r92p/GHSA-hjfq-c3jw-r92p.json b/advisories/unreviewed/2022/10/GHSA-hjfq-c3jw-r92p/GHSA-hjfq-c3jw-r92p.json index d3d217ff28c..9b290f28077 100644 --- a/advisories/unreviewed/2022/10/GHSA-hjfq-c3jw-r92p/GHSA-hjfq-c3jw-r92p.json +++ b/advisories/unreviewed/2022/10/GHSA-hjfq-c3jw-r92p/GHSA-hjfq-c3jw-r92p.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=89f9f3cb86b1c63badaf392a83dd661d56cc50b1" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211087" @@ -32,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-hvrc-p628-rmrc/GHSA-hvrc-p628-rmrc.json b/advisories/unreviewed/2022/10/GHSA-hvrc-p628-rmrc/GHSA-hvrc-p628-rmrc.json index a7ed478981f..4b051c1f2b7 100644 --- a/advisories/unreviewed/2022/10/GHSA-hvrc-p628-rmrc/GHSA-hvrc-p628-rmrc.json +++ b/advisories/unreviewed/2022/10/GHSA-hvrc-p628-rmrc/GHSA-hvrc-p628-rmrc.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41850" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20220904193115.GA28134@ubuntu/t/#u" diff --git a/advisories/unreviewed/2022/10/GHSA-hx6h-vxvg-2g6w/GHSA-hx6h-vxvg-2g6w.json b/advisories/unreviewed/2022/10/GHSA-hx6h-vxvg-2g6w/GHSA-hx6h-vxvg-2g6w.json index 3d3381dc60e..5ba079e6021 100644 --- a/advisories/unreviewed/2022/10/GHSA-hx6h-vxvg-2g6w/GHSA-hx6h-vxvg-2g6w.json +++ b/advisories/unreviewed/2022/10/GHSA-hx6h-vxvg-2g6w/GHSA-hx6h-vxvg-2g6w.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=42cf46dea905a80f6de218e837ba4d4cc33d6979" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DGOIRR72OAFE53XZRUDZDP7INGLIC3E3/" diff --git a/advisories/unreviewed/2022/10/GHSA-mfp9-chmw-53h7/GHSA-mfp9-chmw-53h7.json b/advisories/unreviewed/2022/10/GHSA-mfp9-chmw-53h7/GHSA-mfp9-chmw-53h7.json index de424b5d0c7..bccc958ac87 100644 --- a/advisories/unreviewed/2022/10/GHSA-mfp9-chmw-53h7/GHSA-mfp9-chmw-53h7.json +++ b/advisories/unreviewed/2022/10/GHSA-mfp9-chmw-53h7/GHSA-mfp9-chmw-53h7.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41849" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20220925133243.GA383897@ubuntu/T/" diff --git a/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json b/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json index f6484e7a5cb..4c7bc8c3463 100644 --- a/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json +++ b/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=93e2be344a7db169b7119de21ac1bf253b8c6907" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211363" diff --git a/advisories/unreviewed/2022/10/GHSA-w8wm-5qpx-c8j6/GHSA-w8wm-5qpx-c8j6.json b/advisories/unreviewed/2022/10/GHSA-w8wm-5qpx-c8j6/GHSA-w8wm-5qpx-c8j6.json index 255dfe3d195..16466c33d6b 100644 --- a/advisories/unreviewed/2022/10/GHSA-w8wm-5qpx-c8j6/GHSA-w8wm-5qpx-c8j6.json +++ b/advisories/unreviewed/2022/10/GHSA-w8wm-5qpx-c8j6/GHSA-w8wm-5qpx-c8j6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=2568a7e0832ee30b0a351016d03062ab4e0e0a3f" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://vuldb.com/?id.211088" diff --git a/advisories/unreviewed/2022/12/GHSA-395q-7j8c-c3j7/GHSA-395q-7j8c-c3j7.json b/advisories/unreviewed/2022/12/GHSA-395q-7j8c-c3j7/GHSA-395q-7j8c-c3j7.json index 81bce9c3370..5c6ae36cbe5 100644 --- a/advisories/unreviewed/2022/12/GHSA-395q-7j8c-c3j7/GHSA-395q-7j8c-c3j7.json +++ b/advisories/unreviewed/2022/12/GHSA-395q-7j8c-c3j7/GHSA-395q-7j8c-c3j7.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-395q-7j8c-c3j7", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4598" ], "details": "A vulnerability has been found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/api/theme-edit/ of the component Announcement Handler. The manipulation of the argument Text/Mobile Text leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-216193 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-429v-rpg5-8469/GHSA-429v-rpg5-8469.json b/advisories/unreviewed/2022/12/GHSA-429v-rpg5-8469/GHSA-429v-rpg5-8469.json index 80d0cbd3f20..5b197fa033a 100644 --- a/advisories/unreviewed/2022/12/GHSA-429v-rpg5-8469/GHSA-429v-rpg5-8469.json +++ b/advisories/unreviewed/2022/12/GHSA-429v-rpg5-8469/GHSA-429v-rpg5-8469.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-429v-rpg5-8469", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4601" ], "details": "A vulnerability was found in Shoplazza LifeStyle 1.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/api/theme-edit/ of the component Shipping/Member Discount/Icon. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216196.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json b/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json index dfe41651531..5af0e53a7b4 100644 --- a/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json +++ b/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-44mv-gf6j-pvgx", - "modified": "2022-12-18T06:31:09Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-18T06:31:09Z", "aliases": [ "CVE-2022-47515" ], "details": "An issue was discovered in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a long message in a TCP request that leads to std::length_error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-463f-2q49-4chc/GHSA-463f-2q49-4chc.json b/advisories/unreviewed/2022/12/GHSA-463f-2q49-4chc/GHSA-463f-2q49-4chc.json index 884a7b78722..f101f7da69c 100644 --- a/advisories/unreviewed/2022/12/GHSA-463f-2q49-4chc/GHSA-463f-2q49-4chc.json +++ b/advisories/unreviewed/2022/12/GHSA-463f-2q49-4chc/GHSA-463f-2q49-4chc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-463f-2q49-4chc", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4602" ], "details": "A vulnerability was found in Shoplazza LifeStyle 1.1. It has been rated as problematic. This issue affects some unknown processing of the file /admin/api/theme-edit/ of the component Review Flow Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-216197 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-49gf-23c6-vwj7/GHSA-49gf-23c6-vwj7.json b/advisories/unreviewed/2022/12/GHSA-49gf-23c6-vwj7/GHSA-49gf-23c6-vwj7.json new file mode 100644 index 00000000000..ccafe9734cf --- /dev/null +++ b/advisories/unreviewed/2022/12/GHSA-49gf-23c6-vwj7/GHSA-49gf-23c6-vwj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-49gf-23c6-vwj7", + "modified": "2022-12-22T18:30:25Z", + "published": "2022-12-22T18:30:25Z", + "aliases": [ + "CVE-2022-44510" + ], + "details": "Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44510" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-56mg-c7p2-w99m/GHSA-56mg-c7p2-w99m.json b/advisories/unreviewed/2022/12/GHSA-56mg-c7p2-w99m/GHSA-56mg-c7p2-w99m.json index a08853dc2b3..46e3b725873 100644 --- a/advisories/unreviewed/2022/12/GHSA-56mg-c7p2-w99m/GHSA-56mg-c7p2-w99m.json +++ b/advisories/unreviewed/2022/12/GHSA-56mg-c7p2-w99m/GHSA-56mg-c7p2-w99m.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-56mg-c7p2-w99m", - "modified": "2022-12-16T21:30:44Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-16T21:30:44Z", "aliases": [ "CVE-2022-4566" ], "details": "A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to sql injection. The name of the patch is 167970e5c4da7bb46217f576dc50622b83f32b40. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215975.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json b/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json index ede90618757..6a8deb7178d 100644 --- a/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json +++ b/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-664m-3r2m-mxpx", - "modified": "2022-12-17T00:30:20Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-17T00:30:20Z", "aliases": [ "CVE-2022-38756" ], "details": "A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-6gg7-q37j-4gwp/GHSA-6gg7-q37j-4gwp.json b/advisories/unreviewed/2022/12/GHSA-6gg7-q37j-4gwp/GHSA-6gg7-q37j-4gwp.json index 26c7e784392..ccbd57127d9 100644 --- a/advisories/unreviewed/2022/12/GHSA-6gg7-q37j-4gwp/GHSA-6gg7-q37j-4gwp.json +++ b/advisories/unreviewed/2022/12/GHSA-6gg7-q37j-4gwp/GHSA-6gg7-q37j-4gwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-6gg7-q37j-4gwp", - "modified": "2022-12-18T09:31:01Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-18T09:31:01Z", "aliases": [ "CVE-2022-4594" ], "details": "A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the function deployWar of the file 1.x/src/rogatkin/web/WarRoller.java. The manipulation leads to path traversal. The attack can be launched remotely. The name of the patch is 1bac15c496ec54efe21ad7fab4e17633778582fc. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216187.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-6wmx-298j-589v/GHSA-6wmx-298j-589v.json b/advisories/unreviewed/2022/12/GHSA-6wmx-298j-589v/GHSA-6wmx-298j-589v.json index 264351adcf0..c36e4d78d46 100644 --- a/advisories/unreviewed/2022/12/GHSA-6wmx-298j-589v/GHSA-6wmx-298j-589v.json +++ b/advisories/unreviewed/2022/12/GHSA-6wmx-298j-589v/GHSA-6wmx-298j-589v.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-6wmx-298j-589v", - "modified": "2022-12-17T00:30:21Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-26580" ], "details": "PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 was discovered to be vulnerable to command injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-76w3-2xmj-8wr3/GHSA-76w3-2xmj-8wr3.json b/advisories/unreviewed/2022/12/GHSA-76w3-2xmj-8wr3/GHSA-76w3-2xmj-8wr3.json new file mode 100644 index 00000000000..ed80838685c --- /dev/null +++ b/advisories/unreviewed/2022/12/GHSA-76w3-2xmj-8wr3/GHSA-76w3-2xmj-8wr3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-76w3-2xmj-8wr3", + "modified": "2022-12-22T18:30:24Z", + "published": "2022-12-22T18:30:24Z", + "aliases": [ + "CVE-2022-46101" + ], + "details": "AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46101" + }, + { + "type": "WEB", + "url": "https://github.com/loadream/AyaCMS/issues/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-7mxg-cx88-pj6r/GHSA-7mxg-cx88-pj6r.json b/advisories/unreviewed/2022/12/GHSA-7mxg-cx88-pj6r/GHSA-7mxg-cx88-pj6r.json index bc13602090a..1f53acb6e0d 100644 --- a/advisories/unreviewed/2022/12/GHSA-7mxg-cx88-pj6r/GHSA-7mxg-cx88-pj6r.json +++ b/advisories/unreviewed/2022/12/GHSA-7mxg-cx88-pj6r/GHSA-7mxg-cx88-pj6r.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42328" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-424.txt" diff --git a/advisories/unreviewed/2022/12/GHSA-84pv-wjmq-7chc/GHSA-84pv-wjmq-7chc.json b/advisories/unreviewed/2022/12/GHSA-84pv-wjmq-7chc/GHSA-84pv-wjmq-7chc.json index 0f31b4b6fc1..0dc061470c1 100644 --- a/advisories/unreviewed/2022/12/GHSA-84pv-wjmq-7chc/GHSA-84pv-wjmq-7chc.json +++ b/advisories/unreviewed/2022/12/GHSA-84pv-wjmq-7chc/GHSA-84pv-wjmq-7chc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-84pv-wjmq-7chc", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4599" ], "details": "A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/api/theme-edit/ of the component Product Handler. The manipulation of the argument Subheading/Heading/Text/Button Text/Label leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-216194 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-93wq-f3m6-f4w4/GHSA-93wq-f3m6-f4w4.json b/advisories/unreviewed/2022/12/GHSA-93wq-f3m6-f4w4/GHSA-93wq-f3m6-f4w4.json index a8ec1ae3ae4..239849368e9 100644 --- a/advisories/unreviewed/2022/12/GHSA-93wq-f3m6-f4w4/GHSA-93wq-f3m6-f4w4.json +++ b/advisories/unreviewed/2022/12/GHSA-93wq-f3m6-f4w4/GHSA-93wq-f3m6-f4w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-93wq-f3m6-f4w4", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4600" ], "details": "A vulnerability was found in Shoplazza LifeStyle 1.1. It has been classified as problematic. This affects an unknown part of the file /admin/api/theme-edit/ of the component Product Carousel Handler. The manipulation of the argument Heading/Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-216195.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json b/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json index 3a4a4c685d6..1ebc03eb980 100644 --- a/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json +++ b/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-999r-r2f8-xm55", - "modified": "2022-12-17T00:30:21Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-37832" ], "details": "Mutiny 7.2.0-10788 suffers from Hardcoded root password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-9wxc-wwm3-4wvf/GHSA-9wxc-wwm3-4wvf.json b/advisories/unreviewed/2022/12/GHSA-9wxc-wwm3-4wvf/GHSA-9wxc-wwm3-4wvf.json index 8c7f137db28..5439e4f6716 100644 --- a/advisories/unreviewed/2022/12/GHSA-9wxc-wwm3-4wvf/GHSA-9wxc-wwm3-4wvf.json +++ b/advisories/unreviewed/2022/12/GHSA-9wxc-wwm3-4wvf/GHSA-9wxc-wwm3-4wvf.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-9wxc-wwm3-4wvf", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4597" ], "details": "A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown function of the file /admin/api/admin/v2_products of the component Create Product Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216192.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-cmgp-w7hp-vqr7/GHSA-cmgp-w7hp-vqr7.json b/advisories/unreviewed/2022/12/GHSA-cmgp-w7hp-vqr7/GHSA-cmgp-w7hp-vqr7.json index b6750244a9d..d6b2cf7bc0d 100644 --- a/advisories/unreviewed/2022/12/GHSA-cmgp-w7hp-vqr7/GHSA-cmgp-w7hp-vqr7.json +++ b/advisories/unreviewed/2022/12/GHSA-cmgp-w7hp-vqr7/GHSA-cmgp-w7hp-vqr7.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3643" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-423.txt" diff --git a/advisories/unreviewed/2022/12/GHSA-cw83-h4x5-m8mv/GHSA-cw83-h4x5-m8mv.json b/advisories/unreviewed/2022/12/GHSA-cw83-h4x5-m8mv/GHSA-cw83-h4x5-m8mv.json index 6b29160dc73..15e3e12acb8 100644 --- a/advisories/unreviewed/2022/12/GHSA-cw83-h4x5-m8mv/GHSA-cw83-h4x5-m8mv.json +++ b/advisories/unreviewed/2022/12/GHSA-cw83-h4x5-m8mv/GHSA-cw83-h4x5-m8mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-cw83-h4x5-m8mv", - "modified": "2022-12-17T00:30:21Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-26581" ], "details": "The ADB daemon in PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 allows the execution of the systool utility in production mode, allowing unauthenticated attackers to perform privileged actions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-f22x-pp6j-8h8j/GHSA-f22x-pp6j-8h8j.json b/advisories/unreviewed/2022/12/GHSA-f22x-pp6j-8h8j/GHSA-f22x-pp6j-8h8j.json index 19d93169251..7109ee39d59 100644 --- a/advisories/unreviewed/2022/12/GHSA-f22x-pp6j-8h8j/GHSA-f22x-pp6j-8h8j.json +++ b/advisories/unreviewed/2022/12/GHSA-f22x-pp6j-8h8j/GHSA-f22x-pp6j-8h8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-f22x-pp6j-8h8j", - "modified": "2022-12-17T00:30:21Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-26579" ], "details": "PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 allows root privileged attackers to install an unsigned application by copying the APK to /data/app, setting the appropriate permissions and rebooting the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-f685-h8p2-vgf5/GHSA-f685-h8p2-vgf5.json b/advisories/unreviewed/2022/12/GHSA-f685-h8p2-vgf5/GHSA-f685-h8p2-vgf5.json index d718677998b..853945f8024 100644 --- a/advisories/unreviewed/2022/12/GHSA-f685-h8p2-vgf5/GHSA-f685-h8p2-vgf5.json +++ b/advisories/unreviewed/2022/12/GHSA-f685-h8p2-vgf5/GHSA-f685-h8p2-vgf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-f685-h8p2-vgf5", - "modified": "2022-12-18T09:31:01Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T09:31:01Z", "aliases": [ "CVE-2022-4593" ], "details": "A vulnerability was found in retra-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a6d94ab88f4a6f631a14c59b72461140fb57ae1f. It is recommended to apply a patch to fix this issue. VDB-216186 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json b/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json index e575129f59f..77b7bb739c2 100644 --- a/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json +++ b/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/0cdfa9e6f0915e3d243e2393bfa8a22e12d553b0" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-5-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-g3wc-xv93-445q/GHSA-g3wc-xv93-445q.json b/advisories/unreviewed/2022/12/GHSA-g3wc-xv93-445q/GHSA-g3wc-xv93-445q.json index 0fdc6fdc35b..d5a840d1e40 100644 --- a/advisories/unreviewed/2022/12/GHSA-g3wc-xv93-445q/GHSA-g3wc-xv93-445q.json +++ b/advisories/unreviewed/2022/12/GHSA-g3wc-xv93-445q/GHSA-g3wc-xv93-445q.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-g3wc-xv93-445q", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2021-4248" ], "details": "A vulnerability was found in kapetan dns up to 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file DNS/Protocol/Request.cs. The manipulation leads to insufficient entropy in prng. The attack may be launched remotely. Upgrading to version 7.0.0 is able to address this issue. The name of the patch is cf7105aa2aae90d6656088fe5a8ee1d5730773b6. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216188.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-330" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-g5jc-hc65-x4vm/GHSA-g5jc-hc65-x4vm.json b/advisories/unreviewed/2022/12/GHSA-g5jc-hc65-x4vm/GHSA-g5jc-hc65-x4vm.json index 0fa1b72bb17..806a2161468 100644 --- a/advisories/unreviewed/2022/12/GHSA-g5jc-hc65-x4vm/GHSA-g5jc-hc65-x4vm.json +++ b/advisories/unreviewed/2022/12/GHSA-g5jc-hc65-x4vm/GHSA-g5jc-hc65-x4vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-g5jc-hc65-x4vm", - "modified": "2022-12-17T21:30:28Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-12-17T21:30:28Z", "aliases": [ "CVE-2021-4246" ], "details": "A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack may be launched remotely. The name of the patch is 29e1ead3bb1c1fad53b77dfc14534496421c5b5d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216176.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-ghhc-93hq-6rqv/GHSA-ghhc-93hq-6rqv.json b/advisories/unreviewed/2022/12/GHSA-ghhc-93hq-6rqv/GHSA-ghhc-93hq-6rqv.json index 4228602c8bc..1f14bed02a8 100644 --- a/advisories/unreviewed/2022/12/GHSA-ghhc-93hq-6rqv/GHSA-ghhc-93hq-6rqv.json +++ b/advisories/unreviewed/2022/12/GHSA-ghhc-93hq-6rqv/GHSA-ghhc-93hq-6rqv.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42329" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-424.txt" diff --git a/advisories/unreviewed/2022/12/GHSA-h8mf-8qf9-cg8w/GHSA-h8mf-8qf9-cg8w.json b/advisories/unreviewed/2022/12/GHSA-h8mf-8qf9-cg8w/GHSA-h8mf-8qf9-cg8w.json index 2b17882f7d0..582a682fe93 100644 --- a/advisories/unreviewed/2022/12/GHSA-h8mf-8qf9-cg8w/GHSA-h8mf-8qf9-cg8w.json +++ b/advisories/unreviewed/2022/12/GHSA-h8mf-8qf9-cg8w/GHSA-h8mf-8qf9-cg8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-h8mf-8qf9-cg8w", - "modified": "2022-12-18T09:31:01Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T09:31:01Z", "aliases": [ "CVE-2022-4592" ], "details": "A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/comment/commentdelete of the file index.php. The manipulation leads to sql injection. The attack may be initiated remotely. The name of the patch is 8c62d274986137d6a1d06958a6f75c3553f45f8f. It is recommended to apply a patch to fix this issue. The identifier VDB-216185 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-jj3f-6mrw-wgq6/GHSA-jj3f-6mrw-wgq6.json b/advisories/unreviewed/2022/12/GHSA-jj3f-6mrw-wgq6/GHSA-jj3f-6mrw-wgq6.json index 1105b6ebfce..a6c4226e264 100644 --- a/advisories/unreviewed/2022/12/GHSA-jj3f-6mrw-wgq6/GHSA-jj3f-6mrw-wgq6.json +++ b/advisories/unreviewed/2022/12/GHSA-jj3f-6mrw-wgq6/GHSA-jj3f-6mrw-wgq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-jj3f-6mrw-wgq6", - "modified": "2022-12-17T21:30:27Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-17T21:30:27Z", "aliases": [ "CVE-2022-4590" ], "details": "A vulnerability was found in mschaef toto up to 1.4.20. It has been classified as problematic. This affects an unknown part of the component Todo List Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.21 is able to address this issue. The name of the patch is fdc825ac5249f40683377e8a526a06cdc6870125. It is recommended to upgrade the affected component. The identifier VDB-216177 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-mcxp-g82x-32fg/GHSA-mcxp-g82x-32fg.json b/advisories/unreviewed/2022/12/GHSA-mcxp-g82x-32fg/GHSA-mcxp-g82x-32fg.json new file mode 100644 index 00000000000..60bec2941c5 --- /dev/null +++ b/advisories/unreviewed/2022/12/GHSA-mcxp-g82x-32fg/GHSA-mcxp-g82x-32fg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-mcxp-g82x-32fg", + "modified": "2022-12-22T18:30:24Z", + "published": "2022-12-22T18:30:24Z", + "aliases": [ + "CVE-2022-47926" + ], + "details": "AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47926" + }, + { + "type": "WEB", + "url": "https://github.com/loadream/AyaCMS/issues/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-p377-qm42-6xph/GHSA-p377-qm42-6xph.json b/advisories/unreviewed/2022/12/GHSA-p377-qm42-6xph/GHSA-p377-qm42-6xph.json new file mode 100644 index 00000000000..3939e9c698d --- /dev/null +++ b/advisories/unreviewed/2022/12/GHSA-p377-qm42-6xph/GHSA-p377-qm42-6xph.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p377-qm42-6xph", + "modified": "2022-12-22T18:30:24Z", + "published": "2022-12-22T18:30:24Z", + "aliases": [ + "CVE-2022-46102" + ], + "details": "AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46102" + }, + { + "type": "WEB", + "url": "https://github.com/loadream/AyaCMS/issues/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json b/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json index b654075b33e..b379ede5289 100644 --- a/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json +++ b/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/cd21d99e595ec1d8721e1058dcdd4f1f7de1d793" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-2-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-pv34-c9m7-5qqm/GHSA-pv34-c9m7-5qqm.json b/advisories/unreviewed/2022/12/GHSA-pv34-c9m7-5qqm/GHSA-pv34-c9m7-5qqm.json index d739815974e..278210d2c37 100644 --- a/advisories/unreviewed/2022/12/GHSA-pv34-c9m7-5qqm/GHSA-pv34-c9m7-5qqm.json +++ b/advisories/unreviewed/2022/12/GHSA-pv34-c9m7-5qqm/GHSA-pv34-c9m7-5qqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-pv34-c9m7-5qqm", - "modified": "2022-12-17T21:30:27Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-17T21:30:27Z", "aliases": [ "CVE-2022-4591" ], "details": "A vulnerability was found in mschaef toto up to 1.4.20. It has been declared as problematic. This vulnerability affects unknown code of the component Email Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.4.21 is able to address this issue. The name of the patch is 1f27f37c1a06f54a76971f70eaa6139dc139bdf9. It is recommended to upgrade the affected component. VDB-216178 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json b/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json index 379b2845bcb..091365cd697 100644 --- a/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json +++ b/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/051ae669e4505abbe05165bebf6be7922de11f41" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-3-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json b/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json index 87c097d77c5..0d29b1c1650 100644 --- a/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json +++ b/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/f9b62f9843c7b0afdaecabbcebf1dbba18599408" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-4-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-rvqq-fwff-p2v4/GHSA-rvqq-fwff-p2v4.json b/advisories/unreviewed/2022/12/GHSA-rvqq-fwff-p2v4/GHSA-rvqq-fwff-p2v4.json index 7036d7b771f..d7d153c8200 100644 --- a/advisories/unreviewed/2022/12/GHSA-rvqq-fwff-p2v4/GHSA-rvqq-fwff-p2v4.json +++ b/advisories/unreviewed/2022/12/GHSA-rvqq-fwff-p2v4/GHSA-rvqq-fwff-p2v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-rvqq-fwff-p2v4", - "modified": "2022-12-18T06:31:09Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T06:31:09Z", "aliases": [ "CVE-2022-47514" ], "details": "An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-w4w3-58wp-7gmq/GHSA-w4w3-58wp-7gmq.json b/advisories/unreviewed/2022/12/GHSA-w4w3-58wp-7gmq/GHSA-w4w3-58wp-7gmq.json index 93c52de90a5..bdb13d10df0 100644 --- a/advisories/unreviewed/2022/12/GHSA-w4w3-58wp-7gmq/GHSA-w4w3-58wp-7gmq.json +++ b/advisories/unreviewed/2022/12/GHSA-w4w3-58wp-7gmq/GHSA-w4w3-58wp-7gmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-w4w3-58wp-7gmq", - "modified": "2022-12-17T00:30:21Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-26582" ], "details": "The systool_server in PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 fails to check for dollar signs or backticks in user supplied commands, leading to to arbitrary command execution as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-w7r9-9mj3-89fp/GHSA-w7r9-9mj3-89fp.json b/advisories/unreviewed/2022/12/GHSA-w7r9-9mj3-89fp/GHSA-w7r9-9mj3-89fp.json index 842cc2bca6f..6830d775e5d 100644 --- a/advisories/unreviewed/2022/12/GHSA-w7r9-9mj3-89fp/GHSA-w7r9-9mj3-89fp.json +++ b/advisories/unreviewed/2022/12/GHSA-w7r9-9mj3-89fp/GHSA-w7r9-9mj3-89fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-w7r9-9mj3-89fp", - "modified": "2022-12-18T12:30:20Z", + "modified": "2022-12-22T18:30:25Z", "published": "2022-12-18T12:30:20Z", "aliases": [ "CVE-2022-4595" ], "details": "A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is a6223a1150d60cd036106ba6a8e676c1bfc3cc85. It is recommended to apply a patch to fix this issue. The identifier VDB-216189 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-w8rr-xg77-6mj9/GHSA-w8rr-xg77-6mj9.json b/advisories/unreviewed/2022/12/GHSA-w8rr-xg77-6mj9/GHSA-w8rr-xg77-6mj9.json index 1b6bf1d5f32..79a23ad312c 100644 --- a/advisories/unreviewed/2022/12/GHSA-w8rr-xg77-6mj9/GHSA-w8rr-xg77-6mj9.json +++ b/advisories/unreviewed/2022/12/GHSA-w8rr-xg77-6mj9/GHSA-w8rr-xg77-6mj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-w8rr-xg77-6mj9", - "modified": "2022-12-17T15:30:24Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-12-17T15:30:24Z", "aliases": [ "CVE-2022-4587" ], "details": "A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the argument username leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 3296ebd61e7fe49e93b5755d5d7766d6e94a7667. It is recommended to apply a patch to fix this issue. The identifier VDB-216173 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-x7wf-5vvq-hf3f/GHSA-x7wf-5vvq-hf3f.json b/advisories/unreviewed/2022/12/GHSA-x7wf-5vvq-hf3f/GHSA-x7wf-5vvq-hf3f.json index cde13688a40..d56cc6a24fe 100644 --- a/advisories/unreviewed/2022/12/GHSA-x7wf-5vvq-hf3f/GHSA-x7wf-5vvq-hf3f.json +++ b/advisories/unreviewed/2022/12/GHSA-x7wf-5vvq-hf3f/GHSA-x7wf-5vvq-hf3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-x7wf-5vvq-hf3f", - "modified": "2022-12-16T21:30:44Z", + "modified": "2022-12-22T18:30:24Z", "published": "2022-12-16T21:30:44Z", "aliases": [ "CVE-2022-46670" ], "details": "Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/12/GHSA-xj46-w22p-wj4j/GHSA-xj46-w22p-wj4j.json b/advisories/unreviewed/2022/12/GHSA-xj46-w22p-wj4j/GHSA-xj46-w22p-wj4j.json index 3de24acaa39..414f7ae33ec 100644 --- a/advisories/unreviewed/2022/12/GHSA-xj46-w22p-wj4j/GHSA-xj46-w22p-wj4j.json +++ b/advisories/unreviewed/2022/12/GHSA-xj46-w22p-wj4j/GHSA-xj46-w22p-wj4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-xj46-w22p-wj4j", - "modified": "2022-12-17T15:30:23Z", + "modified": "2022-12-22T18:30:26Z", "published": "2022-12-17T15:30:23Z", "aliases": [ "CVE-2022-4588" ], "details": "A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.2.0. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 85.0.0 is able to address this issue. The name of the patch is 6523bb17d889e2ab13d767f38afefdb37083f1d0. It is recommended to upgrade the affected component. VDB-216174 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file