From a240c7e72716bd57d67c5b4a313a71878c89775a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Dec 2023 21:44:46 +0000 Subject: [PATCH] Publish Advisories GHSA-g4xm-5mqm-8m32 GHSA-jqr2-7f24-xrgc GHSA-v9w3-34xq-hrjg --- .../2023/12/GHSA-g4xm-5mqm-8m32/GHSA-g4xm-5mqm-8m32.json | 7 +++++-- .../2023/12/GHSA-jqr2-7f24-xrgc/GHSA-jqr2-7f24-xrgc.json | 9 ++++++--- .../2023/12/GHSA-v9w3-34xq-hrjg/GHSA-v9w3-34xq-hrjg.json | 7 +++++-- 3 files changed, 16 insertions(+), 7 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-g4xm-5mqm-8m32/GHSA-g4xm-5mqm-8m32.json b/advisories/github-reviewed/2023/12/GHSA-g4xm-5mqm-8m32/GHSA-g4xm-5mqm-8m32.json index 6a1c49702d4..cca9a3e926d 100644 --- a/advisories/github-reviewed/2023/12/GHSA-g4xm-5mqm-8m32/GHSA-g4xm-5mqm-8m32.json +++ b/advisories/github-reviewed/2023/12/GHSA-g4xm-5mqm-8m32/GHSA-g4xm-5mqm-8m32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4xm-5mqm-8m32", - "modified": "2023-12-13T19:44:46Z", + "modified": "2023-12-18T21:44:04Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50778" @@ -9,7 +9,10 @@ "summary": "Cross-Site Request Forgery in Jenkins PaaSLane Estimate Plugin", "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2023/12/GHSA-jqr2-7f24-xrgc/GHSA-jqr2-7f24-xrgc.json b/advisories/github-reviewed/2023/12/GHSA-jqr2-7f24-xrgc/GHSA-jqr2-7f24-xrgc.json index b38c1c09d21..abbaf0ca2bd 100644 --- a/advisories/github-reviewed/2023/12/GHSA-jqr2-7f24-xrgc/GHSA-jqr2-7f24-xrgc.json +++ b/advisories/github-reviewed/2023/12/GHSA-jqr2-7f24-xrgc/GHSA-jqr2-7f24-xrgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqr2-7f24-xrgc", - "modified": "2023-12-13T19:45:06Z", + "modified": "2023-12-18T21:44:26Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50779" @@ -9,7 +9,10 @@ "summary": "Missing permission check in Jenkins PaaSLane Estimate Plugin", "details": "PaaSLane Estimate Plugin 1.0.4 and earlier does not perform permission checks in several HTTP endpoints. This allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ { @@ -52,7 +55,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/12/GHSA-v9w3-34xq-hrjg/GHSA-v9w3-34xq-hrjg.json b/advisories/github-reviewed/2023/12/GHSA-v9w3-34xq-hrjg/GHSA-v9w3-34xq-hrjg.json index 905ed6cd76e..029e6585d6b 100644 --- a/advisories/github-reviewed/2023/12/GHSA-v9w3-34xq-hrjg/GHSA-v9w3-34xq-hrjg.json +++ b/advisories/github-reviewed/2023/12/GHSA-v9w3-34xq-hrjg/GHSA-v9w3-34xq-hrjg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9w3-34xq-hrjg", - "modified": "2023-12-13T23:15:24Z", + "modified": "2023-12-18T21:43:29Z", "published": "2023-12-13T18:31:04Z", "aliases": [ "CVE-2023-50777" @@ -9,7 +9,10 @@ "summary": "Tokens stored in plain text by PaaSLane Estimate Plugin ", "details": "Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ {