diff --git a/advisories/unreviewed/2022/05/GHSA-rq28-x6fq-j954/GHSA-rq28-x6fq-j954.json b/advisories/unreviewed/2022/05/GHSA-rq28-x6fq-j954/GHSA-rq28-x6fq-j954.json index bfd0bd91fd3..0095b057dcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq28-x6fq-j954/GHSA-rq28-x6fq-j954.json +++ b/advisories/unreviewed/2022/05/GHSA-rq28-x6fq-j954/GHSA-rq28-x6fq-j954.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rq28-x6fq-j954", - "modified": "2022-05-24T22:28:57Z", + "modified": "2023-12-18T18:30:18Z", "published": "2022-05-24T22:28:57Z", "aliases": [ "CVE-2021-38342" ], "details": "The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38342" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2021/08/nested-pages-pat%E2%80%A6on-vulnerability/" + }, { "type": "WEB", "url": "https://www.wordfence.com/blog/2021/08/nested-pages-pat…on-vulnerability/" diff --git a/advisories/unreviewed/2022/05/GHSA-wg24-7m7r-fcx2/GHSA-wg24-7m7r-fcx2.json b/advisories/unreviewed/2022/05/GHSA-wg24-7m7r-fcx2/GHSA-wg24-7m7r-fcx2.json index 6f9c773ad63..43fdcafd663 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg24-7m7r-fcx2/GHSA-wg24-7m7r-fcx2.json +++ b/advisories/unreviewed/2022/05/GHSA-wg24-7m7r-fcx2/GHSA-wg24-7m7r-fcx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg24-7m7r-fcx2", - "modified": "2022-05-24T22:29:02Z", + "modified": "2023-12-18T18:30:18Z", "published": "2022-05-24T22:29:02Z", "aliases": [ "CVE-2021-38343" ], "details": "The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38343" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2021/08/nested-pages-pat%E2%80%A6on-vulnerability/" + }, { "type": "WEB", "url": "https://www.wordfence.com/blog/2021/08/nested-pages-pat…on-vulnerability/" diff --git a/advisories/unreviewed/2023/05/GHSA-3mwx-cqmc-fxfr/GHSA-3mwx-cqmc-fxfr.json b/advisories/unreviewed/2023/05/GHSA-3mwx-cqmc-fxfr/GHSA-3mwx-cqmc-fxfr.json index a3388d9fb05..a3bc31a79fe 100644 --- a/advisories/unreviewed/2023/05/GHSA-3mwx-cqmc-fxfr/GHSA-3mwx-cqmc-fxfr.json +++ b/advisories/unreviewed/2023/05/GHSA-3mwx-cqmc-fxfr/GHSA-3mwx-cqmc-fxfr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mwx-cqmc-fxfr", - "modified": "2023-05-31T06:30:39Z", + "modified": "2023-12-18T18:30:18Z", "published": "2023-05-31T06:30:39Z", "aliases": [ "CVE-2023-2434" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-31T04:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-25jx-3xgv-hqfq/GHSA-25jx-3xgv-hqfq.json b/advisories/unreviewed/2023/12/GHSA-25jx-3xgv-hqfq/GHSA-25jx-3xgv-hqfq.json new file mode 100644 index 00000000000..b29fbb00bd8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-25jx-3xgv-hqfq/GHSA-25jx-3xgv-hqfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25jx-3xgv-hqfq", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-47789" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47789" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-shipping-canada-post/wordpress-woocommerce-canada-post-shipping-plugin-2-8-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2h9m-7wj7-h654/GHSA-2h9m-7wj7-h654.json b/advisories/unreviewed/2023/12/GHSA-2h9m-7wj7-h654/GHSA-2h9m-7wj7-h654.json new file mode 100644 index 00000000000..8a603ec7fc4 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2h9m-7wj7-h654/GHSA-2h9m-7wj7-h654.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h9m-7wj7-h654", + "modified": "2023-12-18T18:30:20Z", + "published": "2023-12-18T18:30:20Z", + "aliases": [ + "CVE-2023-46177" + ], + "details": "IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46177" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/269536" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7091235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-35xx-3fgf-hr8m/GHSA-35xx-3fgf-hr8m.json b/advisories/unreviewed/2023/12/GHSA-35xx-3fgf-hr8m/GHSA-35xx-3fgf-hr8m.json new file mode 100644 index 00000000000..d0841f1dee6 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-35xx-3fgf-hr8m/GHSA-35xx-3fgf-hr8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35xx-3fgf-hr8m", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-33214" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/taggbox-widget/wordpress-taggbox-ugc-galleries-social-media-widgets-user-reviews-analytics-plugin-2-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json b/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json new file mode 100644 index 00000000000..b169c37c72e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49q5-wf3p-7xv2", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-49853" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PayTR Ödeme ve Elektronik Para Kurulu?u A.?. PayTR Taksit Tablosu – WooCommerce.This issue affects PayTR Taksit Tablosu – WooCommerce: from n/a through 1.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49853" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/paytr-taksit-tablosu-woocommerce/wordpress-paytr-taksit-tablosu-woocommerce-plugin-1-3-1-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4g5f-w3mh-w99m/GHSA-4g5f-w3mh-w99m.json b/advisories/unreviewed/2023/12/GHSA-4g5f-w3mh-w99m/GHSA-4g5f-w3mh-w99m.json index 1ab81584360..d52627b65b3 100644 --- a/advisories/unreviewed/2023/12/GHSA-4g5f-w3mh-w99m/GHSA-4g5f-w3mh-w99m.json +++ b/advisories/unreviewed/2023/12/GHSA-4g5f-w3mh-w99m/GHSA-4g5f-w3mh-w99m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g5f-w3mh-w99m", - "modified": "2023-12-13T18:31:04Z", + "modified": "2023-12-18T18:30:20Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50769" ], "details": "Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T18:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-4gfc-72gw-v385/GHSA-4gfc-72gw-v385.json b/advisories/unreviewed/2023/12/GHSA-4gfc-72gw-v385/GHSA-4gfc-72gw-v385.json index 03ecc8dcc90..37834b08adc 100644 --- a/advisories/unreviewed/2023/12/GHSA-4gfc-72gw-v385/GHSA-4gfc-72gw-v385.json +++ b/advisories/unreviewed/2023/12/GHSA-4gfc-72gw-v385/GHSA-4gfc-72gw-v385.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gfc-72gw-v385", - "modified": "2023-12-13T18:31:04Z", + "modified": "2023-12-18T18:30:20Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50766" ], "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T18:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-6rwq-h5r6-wjc7/GHSA-6rwq-h5r6-wjc7.json b/advisories/unreviewed/2023/12/GHSA-6rwq-h5r6-wjc7/GHSA-6rwq-h5r6-wjc7.json new file mode 100644 index 00000000000..cae4e0d1474 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-6rwq-h5r6-wjc7/GHSA-6rwq-h5r6-wjc7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rwq-h5r6-wjc7", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-49843" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49843" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/first-order-discount-woocommerce/wordpress-first-order-discount-woocommerce-plugin-1-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7jvc-97hq-cq55/GHSA-7jvc-97hq-cq55.json b/advisories/unreviewed/2023/12/GHSA-7jvc-97hq-cq55/GHSA-7jvc-97hq-cq55.json new file mode 100644 index 00000000000..d62626c676e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7jvc-97hq-cq55/GHSA-7jvc-97hq-cq55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jvc-97hq-cq55", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-46617" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46617" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/adfoxly/wordpress-adfoxly-ad-manager-adsense-ads-ads-txt-plugin-1-8-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7xpc-vjjj-p5jm/GHSA-7xpc-vjjj-p5jm.json b/advisories/unreviewed/2023/12/GHSA-7xpc-vjjj-p5jm/GHSA-7xpc-vjjj-p5jm.json new file mode 100644 index 00000000000..58d9a41f736 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7xpc-vjjj-p5jm/GHSA-7xpc-vjjj-p5jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xpc-vjjj-p5jm", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-48755" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/teachpress/wordpress-teachpress-plugin-9-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-82wr-wm9r-pf6p/GHSA-82wr-wm9r-pf6p.json b/advisories/unreviewed/2023/12/GHSA-82wr-wm9r-pf6p/GHSA-82wr-wm9r-pf6p.json index c66420adf5b..816d57a1b80 100644 --- a/advisories/unreviewed/2023/12/GHSA-82wr-wm9r-pf6p/GHSA-82wr-wm9r-pf6p.json +++ b/advisories/unreviewed/2023/12/GHSA-82wr-wm9r-pf6p/GHSA-82wr-wm9r-pf6p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82wr-wm9r-pf6p", - "modified": "2023-12-13T18:31:04Z", + "modified": "2023-12-18T18:30:20Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-49363" ], "details": "Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T18:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9vrm-747r-668v/GHSA-9vrm-747r-668v.json b/advisories/unreviewed/2023/12/GHSA-9vrm-747r-668v/GHSA-9vrm-747r-668v.json index 222d6306566..d89b1615060 100644 --- a/advisories/unreviewed/2023/12/GHSA-9vrm-747r-668v/GHSA-9vrm-747r-668v.json +++ b/advisories/unreviewed/2023/12/GHSA-9vrm-747r-668v/GHSA-9vrm-747r-668v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vrm-747r-668v", - "modified": "2023-12-13T18:31:04Z", + "modified": "2023-12-18T18:30:20Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50767" ], "details": "Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T18:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-cpv7-rc64-25fh/GHSA-cpv7-rc64-25fh.json b/advisories/unreviewed/2023/12/GHSA-cpv7-rc64-25fh/GHSA-cpv7-rc64-25fh.json new file mode 100644 index 00000000000..7c9e4d66f47 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-cpv7-rc64-25fh/GHSA-cpv7-rc64-25fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpv7-rc64-25fh", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-49844" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTester: from n/a through 2.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49844" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpperformancetester/wordpress-wpperformancetester-plugin-2-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-g9v6-6343-cxw5/GHSA-g9v6-6343-cxw5.json b/advisories/unreviewed/2023/12/GHSA-g9v6-6343-cxw5/GHSA-g9v6-6343-cxw5.json new file mode 100644 index 00000000000..809b3c6c8a6 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-g9v6-6343-cxw5/GHSA-g9v6-6343-cxw5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9v6-6343-cxw5", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-6778" + ], + "details": "Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6778" + }, + { + "type": "WEB", + "url": "https://github.com/allegroai/clearml-server/commit/4684fd5b74af582c894b67a0a06e865c948b763a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5f3fffac-0358-48e6-a500-81bac13e0e2b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gc9j-5mpv-699g/GHSA-gc9j-5mpv-699g.json b/advisories/unreviewed/2023/12/GHSA-gc9j-5mpv-699g/GHSA-gc9j-5mpv-699g.json new file mode 100644 index 00000000000..1e6e90fcd86 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gc9j-5mpv-699g/GHSA-gc9j-5mpv-699g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc9j-5mpv-699g", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-6920" + ], + "details": "Rejected reason: This flaw was found to be a duplicate of CVE-2023-6927. Please see https://access.redhat.com/security/cve/CVE-2023-6927 for information about affected products and security errata.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6920" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json b/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json new file mode 100644 index 00000000000..bb66aa8dde9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-j5r4-2mjg-6xcc/GHSA-j5r4-2mjg-6xcc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r4-2mjg-6xcc", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-6817" + ], + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nThe function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free.\n\nWe recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6817" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=317eb9685095678f2c9f5a8189de698c5354316a" + }, + { + "type": "WEB", + "url": "https://kernel.dance/317eb9685095678f2c9f5a8189de698c5354316a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-mf7f-pmf6-v68p/GHSA-mf7f-pmf6-v68p.json b/advisories/unreviewed/2023/12/GHSA-mf7f-pmf6-v68p/GHSA-mf7f-pmf6-v68p.json index 4eaa23508b7..0e18ea9c25a 100644 --- a/advisories/unreviewed/2023/12/GHSA-mf7f-pmf6-v68p/GHSA-mf7f-pmf6-v68p.json +++ b/advisories/unreviewed/2023/12/GHSA-mf7f-pmf6-v68p/GHSA-mf7f-pmf6-v68p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-mwjm-p6g5-rfvf/GHSA-mwjm-p6g5-rfvf.json b/advisories/unreviewed/2023/12/GHSA-mwjm-p6g5-rfvf/GHSA-mwjm-p6g5-rfvf.json new file mode 100644 index 00000000000..39b0ed221be --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mwjm-p6g5-rfvf/GHSA-mwjm-p6g5-rfvf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwjm-p6g5-rfvf", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-49840" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wc-multi-currency/wordpress-multi-currency-for-woocommerce-plugin-1-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-p848-73m6-23xf/GHSA-p848-73m6-23xf.json b/advisories/unreviewed/2023/12/GHSA-p848-73m6-23xf/GHSA-p848-73m6-23xf.json new file mode 100644 index 00000000000..a3eb1421a6a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-p848-73m6-23xf/GHSA-p848-73m6-23xf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p848-73m6-23xf", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-48762" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jet-elements/wordpress-jetelements-for-elementor-plugin-2-6-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-phjq-7xqp-2526/GHSA-phjq-7xqp-2526.json b/advisories/unreviewed/2023/12/GHSA-phjq-7xqp-2526/GHSA-phjq-7xqp-2526.json index 824bdcdb512..0ab466838c7 100644 --- a/advisories/unreviewed/2023/12/GHSA-phjq-7xqp-2526/GHSA-phjq-7xqp-2526.json +++ b/advisories/unreviewed/2023/12/GHSA-phjq-7xqp-2526/GHSA-phjq-7xqp-2526.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phjq-7xqp-2526", - "modified": "2023-12-13T18:31:04Z", + "modified": "2023-12-18T18:30:20Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50768" ], "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T18:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r3gf-pg53-xqph/GHSA-r3gf-pg53-xqph.json b/advisories/unreviewed/2023/12/GHSA-r3gf-pg53-xqph/GHSA-r3gf-pg53-xqph.json index 02f1145e610..7cb1d1d866f 100644 --- a/advisories/unreviewed/2023/12/GHSA-r3gf-pg53-xqph/GHSA-r3gf-pg53-xqph.json +++ b/advisories/unreviewed/2023/12/GHSA-r3gf-pg53-xqph/GHSA-r3gf-pg53-xqph.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rqxc-rjhg-cprx/GHSA-rqxc-rjhg-cprx.json b/advisories/unreviewed/2023/12/GHSA-rqxc-rjhg-cprx/GHSA-rqxc-rjhg-cprx.json new file mode 100644 index 00000000000..c07a323c585 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rqxc-rjhg-cprx/GHSA-rqxc-rjhg-cprx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqxc-rjhg-cprx", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-48766" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SVGator SVGator – Add Animated SVG Easily.This issue affects SVGator – Add Animated SVG Easily: from n/a through 1.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/svgator/wordpress-svgator-add-animated-svg-easily-plugin-1-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rw93-j8h9-pfx7/GHSA-rw93-j8h9-pfx7.json b/advisories/unreviewed/2023/12/GHSA-rw93-j8h9-pfx7/GHSA-rw93-j8h9-pfx7.json new file mode 100644 index 00000000000..bacd8ecb901 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rw93-j8h9-pfx7/GHSA-rw93-j8h9-pfx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw93-j8h9-pfx7", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-47806" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a through 1.3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/disable-user-login/wordpress-disable-user-login-plugin-1-3-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vx34-745v-7g3g/GHSA-vx34-745v-7g3g.json b/advisories/unreviewed/2023/12/GHSA-vx34-745v-7g3g/GHSA-vx34-745v-7g3g.json new file mode 100644 index 00000000000..3a778566ab1 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vx34-745v-7g3g/GHSA-vx34-745v-7g3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx34-745v-7g3g", + "modified": "2023-12-18T18:30:20Z", + "published": "2023-12-18T18:30:20Z", + "aliases": [ + "CVE-2022-40312" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-25-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-x6q7-3r54-hvf2/GHSA-x6q7-3r54-hvf2.json b/advisories/unreviewed/2023/12/GHSA-x6q7-3r54-hvf2/GHSA-x6q7-3r54-hvf2.json new file mode 100644 index 00000000000..b83c29ee7e3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-x6q7-3r54-hvf2/GHSA-x6q7-3r54-hvf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6q7-3r54-hvf2", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-6691" + ], + "details": "\nCambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6691" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xmw2-9fv2-vx29/GHSA-xmw2-9fv2-vx29.json b/advisories/unreviewed/2023/12/GHSA-xmw2-9fv2-vx29/GHSA-xmw2-9fv2-vx29.json new file mode 100644 index 00000000000..9cd024c0a85 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xmw2-9fv2-vx29/GHSA-xmw2-9fv2-vx29.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmw2-9fv2-vx29", + "modified": "2023-12-18T18:30:21Z", + "published": "2023-12-18T18:30:21Z", + "aliases": [ + "CVE-2023-47787" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-bookings/wordpress-woocommerce-bookings-plugin-2-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T16:15:10Z" + } +} \ No newline at end of file