Publish Advisories

GHSA-53v4-42fg-g287
GHSA-62jr-84gf-wmg4
GHSA-f4qf-m5gf-8jm8
GHSA-c4g9-53v4-f2qg
GHSA-f24p-3hqr-7g3q
GHSA-chgx-7cw3-hr55
GHSA-jx3x-j983-74m3
GHSA-c4w5-6p37-2vp9
GHSA-h54p-v85c-f69r
GHSA-jmh8-4h3g-x5g5
GHSA-4766-3xqh-rp5x
GHSA-p6rw-gvvh-q8v4
GHSA-rj8q-prqp-jwfg
GHSA-rr4v-xrwq-7rhx
GHSA-244g-mc48-hxgx
GHSA-95h5-gp28-rjvc
GHSA-mqhm-2f26-c69c
GHSA-rq54-4p92-2jhj
This commit is contained in:
advisory-database[bot]
2024-02-16 15:31:51 +00:00
parent eee8b791d2
commit a55ee2a69c
18 changed files with 136 additions and 26 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53v4-42fg-g287",
"modified": "2023-12-05T21:55:49Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2023-11-28T18:30:23Z",
"aliases": [
"CVE-2022-41678"
@@ -79,6 +79,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/7g17kwbtjl011mm4tr8bn1vnoq9wh4sl"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0004"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/28/1"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62jr-84gf-wmg4",
"modified": "2024-01-16T15:24:41Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-16T15:24:41Z",
"aliases": [
"CVE-2024-22207"
@@ -51,6 +51,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/fastify/fastify-swagger-ui"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0002"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4qf-m5gf-8jm8",
"modified": "2024-02-01T21:03:23Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-19T12:30:18Z",
"aliases": [
"CVE-2024-21733"
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0005"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4g9-53v4-f2qg",
"modified": "2022-04-30T18:18:16Z",
"modified": "2024-02-16T15:30:25Z",
"published": "2022-04-30T18:18:16Z",
"aliases": [
"CVE-2001-1559"
],
"details": "The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f24p-3hqr-7g3q",
"modified": "2022-05-01T02:31:32Z",
"modified": "2024-02-16T15:30:25Z",
"published": "2022-05-01T02:31:32Z",
"aliases": [
"CVE-2005-4868"
],
"details": "Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -45,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-732"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chgx-7cw3-hr55",
"modified": "2023-11-14T15:30:23Z",
"modified": "2024-02-16T15:30:25Z",
"published": "2023-08-11T15:30:45Z",
"aliases": [
"CVE-2023-39418"
@@ -51,7 +51,7 @@
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230915-0002/"
"url": "https://security.netapp.com/advisory/ntap-20230915-0002"
},
{
"type": "WEB",
@@ -59,7 +59,7 @@
},
{
"type": "WEB",
"url": "https://www.postgresql.org/support/security/CVE-2023-39418/"
"url": "https://www.postgresql.org/support/security/CVE-2023-39418"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx3x-j983-74m3",
"modified": "2023-11-14T15:30:23Z",
"modified": "2024-02-16T15:30:25Z",
"published": "2023-08-11T15:30:45Z",
"aliases": [
"CVE-2023-39417"
@@ -119,7 +119,7 @@
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230915-0002/"
"url": "https://security.netapp.com/advisory/ntap-20230915-0002"
},
{
"type": "WEB",
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h54p-v85c-f69r",
"modified": "2023-11-14T12:30:26Z",
"modified": "2024-02-16T15:30:25Z",
"published": "2023-09-14T18:32:40Z",
"aliases": [
"CVE-2023-41032"
@@ -31,7 +31,7 @@
},
{
"type": "WEB",
"url": "https://www.bentley.com/advisories/be-2023-0004/"
"url": "https://www.bentley.com/advisories/be-2023-0004"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmh8-4h3g-x5g5",
"modified": "2023-11-02T18:30:24Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2023-10-25T21:30:32Z",
"aliases": [
"CVE-2023-42852"
@@ -23,15 +23,15 @@
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2/"
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM/"
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/"
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K"
},
{
"type": "WEB",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4766-3xqh-rp5x",
"modified": "2024-01-16T15:30:27Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-09T03:30:22Z",
"aliases": [
"CVE-2023-49238"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://security.gradle.com/advisory/2023-01"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0003"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6rw-gvvh-q8v4",
"modified": "2024-02-15T09:30:35Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-31T15:30:20Z",
"aliases": [
"CVE-2023-6246"
@@ -41,6 +41,10 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202402-01"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0007"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/01/30/6"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rj8q-prqp-jwfg",
"modified": "2024-01-24T00:30:31Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-09T18:30:27Z",
"aliases": [
"CVE-2023-6129"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0009"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20240109.txt"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr4v-xrwq-7rhx",
"modified": "2024-01-15T12:30:20Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-01-15T12:30:20Z",
"aliases": [
"CVE-2023-4001"
@@ -53,6 +53,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHLZQ47HM64NDOHMHYO7VIJFYD5ZPPYN"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0006"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/15/3"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-244g-mc48-hxgx",
"modified": "2024-02-10T09:30:21Z",
"modified": "2024-02-16T15:30:26Z",
"published": "2024-02-10T09:30:21Z",
"aliases": [
"CVE-2024-23517"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95h5-gp28-rjvc",
"modified": "2024-02-16T15:30:27Z",
"published": "2024-02-16T15:30:27Z",
"aliases": [
"CVE-2024-25320"
],
"details": "Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25320"
},
{
"type": "WEB",
"url": "https://github.com/cqliuke/cve/blob/main/sql.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-16T15:15:08Z"
}
}
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-23"
],
"severity": "LOW",
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq54-4p92-2jhj",
"modified": "2024-02-16T15:30:27Z",
"published": "2024-02-16T15:30:27Z",
"aliases": [
"CVE-2024-21775"
],
"details": "Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21775"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/products/exchange-reports/advisory/CVE-2024-21775.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-16T15:15:08Z"
}
}