From a741dd979eefa6069e95a3e8b6c4f89cd1632188 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Apr 2023 18:31:40 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mfh2-p8f8-6h65.json | 4 ++ .../GHSA-22wj-5rv2-cqf6.json | 42 ++++++++++++++++ .../GHSA-2j4f-52m8-xq9h.json | 38 ++++++++++++++ .../GHSA-2pgq-w6mw-xjv4.json | 9 ++-- .../GHSA-2qhq-8vjf-73j8.json | 9 ++-- .../GHSA-3288-5p9j-wphm.json | 9 ++-- .../GHSA-333g-r8qf-r22c.json | 39 +++++++++++++++ .../GHSA-3482-49mc-jhqp.json | 9 ++-- .../GHSA-34w5-49cc-qp8r.json | 38 ++++++++++++++ .../GHSA-3797-g9f6-3qf2.json | 9 ++-- .../GHSA-3874-v58r-hmr4.json | 9 ++-- .../GHSA-3rwq-2648-vg59.json | 9 ++-- .../GHSA-5cx2-vq3h-x52c.json | 42 ++++++++++++++++ .../GHSA-6f6p-f4c4-22jj.json | 9 ++-- .../GHSA-6qw9-cqm2-283v.json | 38 ++++++++++++++ .../GHSA-83w8-56qx-9vq7.json | 2 +- .../GHSA-88qf-5f3v-pm6m.json | 47 +++++++++++++++++ .../GHSA-8m5p-37vm-f6cv.json | 50 +++++++++++++++++++ .../GHSA-96v9-qjfg-m4gr.json | 9 ++-- .../GHSA-9f4g-pmfg-4p4q.json | 9 ++-- .../GHSA-9g43-4p8p-g9g5.json | 9 ++-- .../GHSA-9w4w-2cpw-g65c.json | 2 +- .../GHSA-c6gg-q5f6-74fh.json | 10 ++-- .../GHSA-c727-w428-q3f5.json | 39 +++++++++++++++ .../GHSA-cgg5-8gwc-3f9x.json | 50 +++++++++++++++++++ .../GHSA-fc8j-8whg-6jmp.json | 9 ++-- .../GHSA-fmcm-3vcv-q39p.json | 2 +- .../GHSA-fpx6-4jxg-6422.json | 2 +- .../GHSA-fwxm-w6rg-c4gp.json | 2 +- .../GHSA-g87p-p63w-9573.json | 42 ++++++++++++++++ .../GHSA-g8qc-7wxv-m3gf.json | 9 ++-- .../GHSA-gh3f-7cgq-5c59.json | 42 ++++++++++++++++ .../GHSA-gwwh-g689-9jvg.json | 9 ++-- .../GHSA-h6pv-hpfp-q558.json | 2 +- .../GHSA-h95q-46mc-6g3w.json | 9 ++-- .../GHSA-h9v3-m6cc-qpv3.json | 9 ++-- .../GHSA-hv4g-mmv9-qwrp.json | 9 ++-- .../GHSA-jfjp-c9jg-cqcx.json | 9 ++-- .../GHSA-jjm3-jcr6-f9w4.json | 9 ++-- .../GHSA-jrc6-6mxc-2rw2.json | 9 ++-- .../GHSA-jvhx-vw8m-6v64.json | 9 ++-- .../GHSA-mqgr-4p27-366c.json | 9 ++-- .../GHSA-p68q-j5xf-h247.json | 9 ++-- .../GHSA-p9w4-8hh8-crcx.json | 9 ++-- .../GHSA-pgrj-wm9q-gw8p.json | 42 ++++++++++++++++ .../GHSA-pxwf-m68q-gmw8.json | 7 ++- .../GHSA-q9h2-893q-85gq.json | 38 ++++++++++++++ .../GHSA-qq2j-hq57-9rpr.json | 9 ++-- .../GHSA-qvq2-2xfw-f6x6.json | 7 ++- .../GHSA-r83q-3rfr-hgfg.json | 9 ++-- .../GHSA-r976-44r3-hm6v.json | 42 ++++++++++++++++ .../GHSA-rfpr-2mwv-6gc8.json | 2 +- .../GHSA-rm84-x485-ppvh.json | 7 ++- .../GHSA-vvgj-r4cg-78rh.json | 2 +- .../GHSA-w347-2542-wgjq.json | 9 ++-- .../GHSA-wq8f-xmq3-5vq9.json | 39 +++++++++++++++ .../GHSA-x4hx-qqp4-qp78.json | 8 ++- .../GHSA-xhc7-32vm-6c85.json | 9 ++-- .../GHSA-xqqm-4xjp-r9cv.json | 9 ++-- 59 files changed, 882 insertions(+), 106 deletions(-) create mode 100644 advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json create mode 100644 advisories/unreviewed/2023/04/GHSA-2j4f-52m8-xq9h/GHSA-2j4f-52m8-xq9h.json create mode 100644 advisories/unreviewed/2023/04/GHSA-333g-r8qf-r22c/GHSA-333g-r8qf-r22c.json create mode 100644 advisories/unreviewed/2023/04/GHSA-34w5-49cc-qp8r/GHSA-34w5-49cc-qp8r.json create mode 100644 advisories/unreviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json create mode 100644 advisories/unreviewed/2023/04/GHSA-6qw9-cqm2-283v/GHSA-6qw9-cqm2-283v.json create mode 100644 advisories/unreviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json create mode 100644 advisories/unreviewed/2023/04/GHSA-8m5p-37vm-f6cv/GHSA-8m5p-37vm-f6cv.json create mode 100644 advisories/unreviewed/2023/04/GHSA-c727-w428-q3f5/GHSA-c727-w428-q3f5.json create mode 100644 advisories/unreviewed/2023/04/GHSA-cgg5-8gwc-3f9x/GHSA-cgg5-8gwc-3f9x.json create mode 100644 advisories/unreviewed/2023/04/GHSA-g87p-p63w-9573/GHSA-g87p-p63w-9573.json create mode 100644 advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json create mode 100644 advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json create mode 100644 advisories/unreviewed/2023/04/GHSA-q9h2-893q-85gq/GHSA-q9h2-893q-85gq.json create mode 100644 advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json create mode 100644 advisories/unreviewed/2023/04/GHSA-wq8f-xmq3-5vq9/GHSA-wq8f-xmq3-5vq9.json diff --git a/advisories/unreviewed/2022/05/GHSA-mfh2-p8f8-6h65/GHSA-mfh2-p8f8-6h65.json b/advisories/unreviewed/2022/05/GHSA-mfh2-p8f8-6h65/GHSA-mfh2-p8f8-6h65.json index f5b8d881589..86f8d270794 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfh2-p8f8-6h65/GHSA-mfh2-p8f8-6h65.json +++ b/advisories/unreviewed/2022/05/GHSA-mfh2-p8f8-6h65/GHSA-mfh2-p8f8-6h65.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://www.thalesgroup.com/en/markets/digital-identity-and-security/iot/resources/security-updates-cinterion-iot-modules" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171978/Telit-Cinterion-IoT-Traversal-Escalation-Bypass-Heap-Overflow.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Apr/11" diff --git a/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json b/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json new file mode 100644 index 00000000000..5e2dbf1af79 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22wj-5rv2-cqf6", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26097" + ], + "details": "An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behaviour may not be blocked.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26097" + }, + { + "type": "WEB", + "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-26097" + }, + { + "type": "WEB", + "url": "https://www.telindus.lu/fr/produits/apsal" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-2j4f-52m8-xq9h/GHSA-2j4f-52m8-xq9h.json b/advisories/unreviewed/2023/04/GHSA-2j4f-52m8-xq9h/GHSA-2j4f-52m8-xq9h.json new file mode 100644 index 00000000000..77df8731259 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-2j4f-52m8-xq9h/GHSA-2j4f-52m8-xq9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j4f-52m8-xq9h", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-27991" + ], + "details": "The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27991" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-2pgq-w6mw-xjv4/GHSA-2pgq-w6mw-xjv4.json b/advisories/unreviewed/2023/04/GHSA-2pgq-w6mw-xjv4/GHSA-2pgq-w6mw-xjv4.json index 78971751ae4..5c96152fd1c 100644 --- a/advisories/unreviewed/2023/04/GHSA-2pgq-w6mw-xjv4/GHSA-2pgq-w6mw-xjv4.json +++ b/advisories/unreviewed/2023/04/GHSA-2pgq-w6mw-xjv4/GHSA-2pgq-w6mw-xjv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pgq-w6mw-xjv4", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-33297" ], "details": "Information disclosure due to buffer overread in Linux sensors", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-2qhq-8vjf-73j8/GHSA-2qhq-8vjf-73j8.json b/advisories/unreviewed/2023/04/GHSA-2qhq-8vjf-73j8/GHSA-2qhq-8vjf-73j8.json index 92918722502..5085f1431a8 100644 --- a/advisories/unreviewed/2023/04/GHSA-2qhq-8vjf-73j8/GHSA-2qhq-8vjf-73j8.json +++ b/advisories/unreviewed/2023/04/GHSA-2qhq-8vjf-73j8/GHSA-2qhq-8vjf-73j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhq-8vjf-73j8", - "modified": "2023-04-15T09:30:23Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T09:30:23Z", "aliases": [ "CVE-2023-2089" ], "details": "A vulnerability was found in SourceCodester Complaint Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/userprofile.php of the component GET Parameter Handler. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226097 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T08:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-3288-5p9j-wphm/GHSA-3288-5p9j-wphm.json b/advisories/unreviewed/2023/04/GHSA-3288-5p9j-wphm/GHSA-3288-5p9j-wphm.json index 94e2e18b3f8..09c8d6ba989 100644 --- a/advisories/unreviewed/2023/04/GHSA-3288-5p9j-wphm/GHSA-3288-5p9j-wphm.json +++ b/advisories/unreviewed/2023/04/GHSA-3288-5p9j-wphm/GHSA-3288-5p9j-wphm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3288-5p9j-wphm", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-25745" ], "details": "Memory corruption in modem due to improper input validation while handling the incoming CoAP message", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-670" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-333g-r8qf-r22c/GHSA-333g-r8qf-r22c.json b/advisories/unreviewed/2023/04/GHSA-333g-r8qf-r22c/GHSA-333g-r8qf-r22c.json new file mode 100644 index 00000000000..cbc8589469f --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-333g-r8qf-r22c/GHSA-333g-r8qf-r22c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-333g-r8qf-r22c", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26865" + ], + "details": "SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26865" + }, + { + "type": "WEB", + "url": "https://bdroppy.com/dropshipping-apps-integrations-bdroppy/" + }, + { + "type": "WEB", + "url": "https://friends-of-presta.github.io/security-advisories/modules/2023/04/20/bdroppy.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-3482-49mc-jhqp/GHSA-3482-49mc-jhqp.json b/advisories/unreviewed/2023/04/GHSA-3482-49mc-jhqp/GHSA-3482-49mc-jhqp.json index 8de733290f4..41e8bedb063 100644 --- a/advisories/unreviewed/2023/04/GHSA-3482-49mc-jhqp/GHSA-3482-49mc-jhqp.json +++ b/advisories/unreviewed/2023/04/GHSA-3482-49mc-jhqp/GHSA-3482-49mc-jhqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3482-49mc-jhqp", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2096" ], "details": "A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/service_requests/manage_inventory.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226104.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T11:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-34w5-49cc-qp8r/GHSA-34w5-49cc-qp8r.json b/advisories/unreviewed/2023/04/GHSA-34w5-49cc-qp8r/GHSA-34w5-49cc-qp8r.json new file mode 100644 index 00000000000..b394e8c8a2d --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-34w5-49cc-qp8r/GHSA-34w5-49cc-qp8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34w5-49cc-qp8r", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-22916" + ], + "details": "The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22916" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-3797-g9f6-3qf2/GHSA-3797-g9f6-3qf2.json b/advisories/unreviewed/2023/04/GHSA-3797-g9f6-3qf2/GHSA-3797-g9f6-3qf2.json index 717e12c19cc..52791afeb91 100644 --- a/advisories/unreviewed/2023/04/GHSA-3797-g9f6-3qf2/GHSA-3797-g9f6-3qf2.json +++ b/advisories/unreviewed/2023/04/GHSA-3797-g9f6-3qf2/GHSA-3797-g9f6-3qf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3797-g9f6-3qf2", - "modified": "2023-04-14T00:31:38Z", + "modified": "2023-04-24T18:30:28Z", "published": "2023-04-14T00:31:38Z", "aliases": [ "CVE-2023-30637" ], "details": "Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-3874-v58r-hmr4/GHSA-3874-v58r-hmr4.json b/advisories/unreviewed/2023/04/GHSA-3874-v58r-hmr4/GHSA-3874-v58r-hmr4.json index b672e5b6287..327102e134c 100644 --- a/advisories/unreviewed/2023/04/GHSA-3874-v58r-hmr4/GHSA-3874-v58r-hmr4.json +++ b/advisories/unreviewed/2023/04/GHSA-3874-v58r-hmr4/GHSA-3874-v58r-hmr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3874-v58r-hmr4", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2094" ], "details": "A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226102 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T11:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-3rwq-2648-vg59/GHSA-3rwq-2648-vg59.json b/advisories/unreviewed/2023/04/GHSA-3rwq-2648-vg59/GHSA-3rwq-2648-vg59.json index 70a0f0550f5..35b9744f302 100644 --- a/advisories/unreviewed/2023/04/GHSA-3rwq-2648-vg59/GHSA-3rwq-2648-vg59.json +++ b/advisories/unreviewed/2023/04/GHSA-3rwq-2648-vg59/GHSA-3rwq-2648-vg59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rwq-2648-vg59", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-33302" ], "details": "Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json b/advisories/unreviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json new file mode 100644 index 00000000000..a8ffe73cb66 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cx2-vq3h-x52c", + "modified": "2023-04-24T18:30:30Z", + "published": "2023-04-24T18:30:30Z", + "aliases": [ + "CVE-2023-27524" + ], + "details": "Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27524" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/n0ftx60sllf527j7g11kmt24wvof8xyk" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/04/24/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-6f6p-f4c4-22jj/GHSA-6f6p-f4c4-22jj.json b/advisories/unreviewed/2023/04/GHSA-6f6p-f4c4-22jj/GHSA-6f6p-f4c4-22jj.json index d3887f2fd0c..a30fb35dc44 100644 --- a/advisories/unreviewed/2023/04/GHSA-6f6p-f4c4-22jj/GHSA-6f6p-f4c4-22jj.json +++ b/advisories/unreviewed/2023/04/GHSA-6f6p-f4c4-22jj/GHSA-6f6p-f4c4-22jj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f6p-f4c4-22jj", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:28Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33269" ], "details": "Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-6qw9-cqm2-283v/GHSA-6qw9-cqm2-283v.json b/advisories/unreviewed/2023/04/GHSA-6qw9-cqm2-283v/GHSA-6qw9-cqm2-283v.json new file mode 100644 index 00000000000..dd695e5f32b --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-6qw9-cqm2-283v/GHSA-6qw9-cqm2-283v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qw9-cqm2-283v", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-27990" + ], + "details": "The XSS vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27990" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json b/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json index 443585dd560..87c0c3fa821 100644 --- a/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json +++ b/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json b/advisories/unreviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json new file mode 100644 index 00000000000..780cff0dcb8 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88qf-5f3v-pm6m", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-29566" + ], + "details": "huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29566" + }, + { + "type": "WEB", + "url": "https://github.com/rona-dinihari/dawnsparks-node-tesseract/commit/81d1664f0b9fe521534acfae1d5b9c40127b36c1" + }, + { + "type": "WEB", + "url": "https://github.com/omnitaint/Vulnerability-Reports/blob/ec3645003c7f8996459b5b24c722474adc2d599f/reports/dawnsparks-node-tesseract/report.md" + }, + { + "type": "WEB", + "url": "https://github.com/rona-dinihari/dawnsparks-node-tesseract" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/dawnsparks-node-tesseract" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-8m5p-37vm-f6cv/GHSA-8m5p-37vm-f6cv.json b/advisories/unreviewed/2023/04/GHSA-8m5p-37vm-f6cv/GHSA-8m5p-37vm-f6cv.json new file mode 100644 index 00000000000..0a85b9bc515 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-8m5p-37vm-f6cv/GHSA-8m5p-37vm-f6cv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m5p-37vm-f6cv", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2012-10013" + ], + "details": "A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the file backend_localization.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.0 is able to address this issue. The name of the patch is 43dc96defd7944da12ff116476a6890acd7dd24b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227231.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-10013" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/kau-boys-backend-localization/commit/43dc96defd7944da12ff116476a6890acd7dd24b" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/kau-boys-backend-localization/releases/tag/2.0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.227231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.227231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-96v9-qjfg-m4gr/GHSA-96v9-qjfg-m4gr.json b/advisories/unreviewed/2023/04/GHSA-96v9-qjfg-m4gr/GHSA-96v9-qjfg-m4gr.json index 0db5b3843a1..b7ef06ea4e1 100644 --- a/advisories/unreviewed/2023/04/GHSA-96v9-qjfg-m4gr/GHSA-96v9-qjfg-m4gr.json +++ b/advisories/unreviewed/2023/04/GHSA-96v9-qjfg-m4gr/GHSA-96v9-qjfg-m4gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96v9-qjfg-m4gr", - "modified": "2023-04-15T12:30:15Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:15Z", "aliases": [ "CVE-2023-2099" ], "details": "A vulnerability classified as problematic has been found in SourceCodester Vehicle Service Management System 1.0. This affects an unknown part of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226107.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-9f4g-pmfg-4p4q/GHSA-9f4g-pmfg-4p4q.json b/advisories/unreviewed/2023/04/GHSA-9f4g-pmfg-4p4q/GHSA-9f4g-pmfg-4p4q.json index c4f5148f7a0..f868e472933 100644 --- a/advisories/unreviewed/2023/04/GHSA-9f4g-pmfg-4p4q/GHSA-9f4g-pmfg-4p4q.json +++ b/advisories/unreviewed/2023/04/GHSA-9f4g-pmfg-4p4q/GHSA-9f4g-pmfg-4p4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f4g-pmfg-4p4q", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T18:30:28Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-33298" ], "details": "Memory corruption due to use after free in Modem while modem initialization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-9g43-4p8p-g9g5/GHSA-9g43-4p8p-g9g5.json b/advisories/unreviewed/2023/04/GHSA-9g43-4p8p-g9g5/GHSA-9g43-4p8p-g9g5.json index 5cd32d6c998..3229fe8932f 100644 --- a/advisories/unreviewed/2023/04/GHSA-9g43-4p8p-g9g5/GHSA-9g43-4p8p-g9g5.json +++ b/advisories/unreviewed/2023/04/GHSA-9g43-4p8p-g9g5/GHSA-9g43-4p8p-g9g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g43-4p8p-g9g5", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-25597" ], "details": "A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit could allow access to sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json b/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json index 44f562f76b4..dba080f691e 100644 --- a/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json +++ b/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-c6gg-q5f6-74fh/GHSA-c6gg-q5f6-74fh.json b/advisories/unreviewed/2023/04/GHSA-c6gg-q5f6-74fh/GHSA-c6gg-q5f6-74fh.json index 11e4589eb60..e350846a437 100644 --- a/advisories/unreviewed/2023/04/GHSA-c6gg-q5f6-74fh/GHSA-c6gg-q5f6-74fh.json +++ b/advisories/unreviewed/2023/04/GHSA-c6gg-q5f6-74fh/GHSA-c6gg-q5f6-74fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6gg-q5f6-74fh", - "modified": "2023-04-12T21:30:20Z", + "modified": "2023-04-24T18:30:26Z", "published": "2023-04-12T21:30:20Z", "aliases": [ "CVE-2023-24513" ], "details": "On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125", + "CWE-126" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-c727-w428-q3f5/GHSA-c727-w428-q3f5.json b/advisories/unreviewed/2023/04/GHSA-c727-w428-q3f5/GHSA-c727-w428-q3f5.json new file mode 100644 index 00000000000..8035839e3dc --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-c727-w428-q3f5/GHSA-c727-w428-q3f5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c727-w428-q3f5", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-27849" + ], + "details": "rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27849" + }, + { + "type": "WEB", + "url": "https://github.com/omnitaint/Vulnerability-Reports/blob/2211ea4712f24d20b7f223fb737910fdfb041edb/reports/rails-routes-to-json/report.md" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/rails-routes-to-json" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-cgg5-8gwc-3f9x/GHSA-cgg5-8gwc-3f9x.json b/advisories/unreviewed/2023/04/GHSA-cgg5-8gwc-3f9x/GHSA-cgg5-8gwc-3f9x.json new file mode 100644 index 00000000000..f08c5e7e3ac --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-cgg5-8gwc-3f9x/GHSA-cgg5-8gwc-3f9x.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgg5-8gwc-3f9x", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2012-10014" + ], + "details": "A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affected is the function backend_localization_admin_settings/backend_localization_save_setting/backend_localization_login_form/localize_backend of the file backend_localization.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.1 is able to address this issue. The name of the patch is 36f457ee16dd114e510fd91a3ea9fbb3c1f87184. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227232.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-10014" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/kau-boys-backend-localization/commit/36f457ee16dd114e510fd91a3ea9fbb3c1f87184" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/kau-boys-backend-localization/releases/tag/2.0.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.227232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.227232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fc8j-8whg-6jmp/GHSA-fc8j-8whg-6jmp.json b/advisories/unreviewed/2023/04/GHSA-fc8j-8whg-6jmp/GHSA-fc8j-8whg-6jmp.json index 8afb3d7dbfd..659fa34479e 100644 --- a/advisories/unreviewed/2023/04/GHSA-fc8j-8whg-6jmp/GHSA-fc8j-8whg-6jmp.json +++ b/advisories/unreviewed/2023/04/GHSA-fc8j-8whg-6jmp/GHSA-fc8j-8whg-6jmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc8j-8whg-6jmp", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33282" ], "details": "Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json b/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json index 52aa89bee40..585feef0bd5 100644 --- a/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json +++ b/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json b/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json index ce0a0059ec5..05c2e36b9dd 100644 --- a/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json +++ b/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fwxm-w6rg-c4gp/GHSA-fwxm-w6rg-c4gp.json b/advisories/unreviewed/2023/04/GHSA-fwxm-w6rg-c4gp/GHSA-fwxm-w6rg-c4gp.json index 28cf12bcbe5..5c29eae0fd7 100644 --- a/advisories/unreviewed/2023/04/GHSA-fwxm-w6rg-c4gp/GHSA-fwxm-w6rg-c4gp.json +++ b/advisories/unreviewed/2023/04/GHSA-fwxm-w6rg-c4gp/GHSA-fwxm-w6rg-c4gp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-g87p-p63w-9573/GHSA-g87p-p63w-9573.json b/advisories/unreviewed/2023/04/GHSA-g87p-p63w-9573/GHSA-g87p-p63w-9573.json new file mode 100644 index 00000000000..d63f5381ac3 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-g87p-p63w-9573/GHSA-g87p-p63w-9573.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g87p-p63w-9573", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26059" + ], + "details": "An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26059" + }, + { + "type": "WEB", + "url": "https://nokia.com" + }, + { + "type": "WEB", + "url": "https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2022-03/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-g8qc-7wxv-m3gf/GHSA-g8qc-7wxv-m3gf.json b/advisories/unreviewed/2023/04/GHSA-g8qc-7wxv-m3gf/GHSA-g8qc-7wxv-m3gf.json index 712539a1f21..a569b137ab8 100644 --- a/advisories/unreviewed/2023/04/GHSA-g8qc-7wxv-m3gf/GHSA-g8qc-7wxv-m3gf.json +++ b/advisories/unreviewed/2023/04/GHSA-g8qc-7wxv-m3gf/GHSA-g8qc-7wxv-m3gf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8qc-7wxv-m3gf", - "modified": "2023-04-15T15:30:15Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T15:30:15Z", "aliases": [ "CVE-2023-2100" ], "details": "A vulnerability classified as problematic was found in SourceCodester Vehicle Service Management System 1.0. This vulnerability affects unknown code of the file /admin/report/index.php. The manipulation of the argument date_end leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226108.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T13:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json b/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json new file mode 100644 index 00000000000..a601026328a --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh3f-7cgq-5c59", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26061" + ], + "details": "An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a scheduled task. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26061" + }, + { + "type": "WEB", + "url": "https://nokia.com" + }, + { + "type": "WEB", + "url": "https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2022-05/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-gwwh-g689-9jvg/GHSA-gwwh-g689-9jvg.json b/advisories/unreviewed/2023/04/GHSA-gwwh-g689-9jvg/GHSA-gwwh-g689-9jvg.json index 017d980151a..b7159983163 100644 --- a/advisories/unreviewed/2023/04/GHSA-gwwh-g689-9jvg/GHSA-gwwh-g689-9jvg.json +++ b/advisories/unreviewed/2023/04/GHSA-gwwh-g689-9jvg/GHSA-gwwh-g689-9jvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwwh-g689-9jvg", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-25739" ], "details": "Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json b/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json index 35f8b0e1b42..f1c84bdd09f 100644 --- a/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json +++ b/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-h95q-46mc-6g3w/GHSA-h95q-46mc-6g3w.json b/advisories/unreviewed/2023/04/GHSA-h95q-46mc-6g3w/GHSA-h95q-46mc-6g3w.json index 4f1f8699221..d2c5f4a5daa 100644 --- a/advisories/unreviewed/2023/04/GHSA-h95q-46mc-6g3w/GHSA-h95q-46mc-6g3w.json +++ b/advisories/unreviewed/2023/04/GHSA-h95q-46mc-6g3w/GHSA-h95q-46mc-6g3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h95q-46mc-6g3w", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-40503" ], "details": "Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-h9v3-m6cc-qpv3/GHSA-h9v3-m6cc-qpv3.json b/advisories/unreviewed/2023/04/GHSA-h9v3-m6cc-qpv3/GHSA-h9v3-m6cc-qpv3.json index 85f7214b3ec..98c0d5d606c 100644 --- a/advisories/unreviewed/2023/04/GHSA-h9v3-m6cc-qpv3/GHSA-h9v3-m6cc-qpv3.json +++ b/advisories/unreviewed/2023/04/GHSA-h9v3-m6cc-qpv3/GHSA-h9v3-m6cc-qpv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9v3-m6cc-qpv3", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:28Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33231" ], "details": "Memory corruption due to double free in core while initializing the encryption key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-hv4g-mmv9-qwrp/GHSA-hv4g-mmv9-qwrp.json b/advisories/unreviewed/2023/04/GHSA-hv4g-mmv9-qwrp/GHSA-hv4g-mmv9-qwrp.json index 6363c9cb95f..9cde58444f0 100644 --- a/advisories/unreviewed/2023/04/GHSA-hv4g-mmv9-qwrp/GHSA-hv4g-mmv9-qwrp.json +++ b/advisories/unreviewed/2023/04/GHSA-hv4g-mmv9-qwrp/GHSA-hv4g-mmv9-qwrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hv4g-mmv9-qwrp", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-33301" ], "details": "Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-704" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-jfjp-c9jg-cqcx/GHSA-jfjp-c9jg-cqcx.json b/advisories/unreviewed/2023/04/GHSA-jfjp-c9jg-cqcx/GHSA-jfjp-c9jg-cqcx.json index f593c8c4159..c879157cf9f 100644 --- a/advisories/unreviewed/2023/04/GHSA-jfjp-c9jg-cqcx/GHSA-jfjp-c9jg-cqcx.json +++ b/advisories/unreviewed/2023/04/GHSA-jfjp-c9jg-cqcx/GHSA-jfjp-c9jg-cqcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jfjp-c9jg-cqcx", - "modified": "2023-04-11T21:31:01Z", + "modified": "2023-04-24T18:30:26Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-25409" ], "details": "Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-jjm3-jcr6-f9w4/GHSA-jjm3-jcr6-f9w4.json b/advisories/unreviewed/2023/04/GHSA-jjm3-jcr6-f9w4/GHSA-jjm3-jcr6-f9w4.json index f4bd6439793..6169f3406b3 100644 --- a/advisories/unreviewed/2023/04/GHSA-jjm3-jcr6-f9w4/GHSA-jjm3-jcr6-f9w4.json +++ b/advisories/unreviewed/2023/04/GHSA-jjm3-jcr6-f9w4/GHSA-jjm3-jcr6-f9w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjm3-jcr6-f9w4", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2093" ], "details": "A vulnerability, which was classified as critical, was found in SourceCodester Vehicle Service Management System 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226101 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T10:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-jrc6-6mxc-2rw2/GHSA-jrc6-6mxc-2rw2.json b/advisories/unreviewed/2023/04/GHSA-jrc6-6mxc-2rw2/GHSA-jrc6-6mxc-2rw2.json index fcd338024b6..6a0f9268c9f 100644 --- a/advisories/unreviewed/2023/04/GHSA-jrc6-6mxc-2rw2/GHSA-jrc6-6mxc-2rw2.json +++ b/advisories/unreviewed/2023/04/GHSA-jrc6-6mxc-2rw2/GHSA-jrc6-6mxc-2rw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrc6-6mxc-2rw2", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33270" ], "details": "Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-jvhx-vw8m-6v64/GHSA-jvhx-vw8m-6v64.json b/advisories/unreviewed/2023/04/GHSA-jvhx-vw8m-6v64/GHSA-jvhx-vw8m-6v64.json index 79746af5e62..a688943128b 100644 --- a/advisories/unreviewed/2023/04/GHSA-jvhx-vw8m-6v64/GHSA-jvhx-vw8m-6v64.json +++ b/advisories/unreviewed/2023/04/GHSA-jvhx-vw8m-6v64/GHSA-jvhx-vw8m-6v64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvhx-vw8m-6v64", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2097" ], "details": "A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226105 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-mqgr-4p27-366c/GHSA-mqgr-4p27-366c.json b/advisories/unreviewed/2023/04/GHSA-mqgr-4p27-366c/GHSA-mqgr-4p27-366c.json index f9539b0a0d3..bc0eadcfb33 100644 --- a/advisories/unreviewed/2023/04/GHSA-mqgr-4p27-366c/GHSA-mqgr-4p27-366c.json +++ b/advisories/unreviewed/2023/04/GHSA-mqgr-4p27-366c/GHSA-mqgr-4p27-366c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqgr-4p27-366c", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2092" ], "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Vehicle Service Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226100.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T10:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-p68q-j5xf-h247/GHSA-p68q-j5xf-h247.json b/advisories/unreviewed/2023/04/GHSA-p68q-j5xf-h247/GHSA-p68q-j5xf-h247.json index 2acaf54de9a..4b62a0590eb 100644 --- a/advisories/unreviewed/2023/04/GHSA-p68q-j5xf-h247/GHSA-p68q-j5xf-h247.json +++ b/advisories/unreviewed/2023/04/GHSA-p68q-j5xf-h247/GHSA-p68q-j5xf-h247.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p68q-j5xf-h247", - "modified": "2023-04-15T09:30:23Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T09:30:23Z", "aliases": [ "CVE-2023-2091" ], "details": "A vulnerability classified as critical was found in KylinSoft youker-assistant. Affected by this vulnerability is the function adjust_cpufreq_scaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.4.13 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-226099.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T09:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-p9w4-8hh8-crcx/GHSA-p9w4-8hh8-crcx.json b/advisories/unreviewed/2023/04/GHSA-p9w4-8hh8-crcx/GHSA-p9w4-8hh8-crcx.json index 968f563e41d..f7f180744b6 100644 --- a/advisories/unreviewed/2023/04/GHSA-p9w4-8hh8-crcx/GHSA-p9w4-8hh8-crcx.json +++ b/advisories/unreviewed/2023/04/GHSA-p9w4-8hh8-crcx/GHSA-p9w4-8hh8-crcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9w4-8hh8-crcx", - "modified": "2023-04-15T00:30:37Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T00:30:37Z", "aliases": [ "CVE-2023-29383" ], "details": "In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \\n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \\r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that \"cat /etc/passwd\" shows a rogue user account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json b/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json new file mode 100644 index 00000000000..edca109ae8c --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgrj-wm9q-gw8p", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26060" + ], + "details": "An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during creation of the working set. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26060" + }, + { + "type": "WEB", + "url": "https://nokia.com" + }, + { + "type": "WEB", + "url": "https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2022-04/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-pxwf-m68q-gmw8/GHSA-pxwf-m68q-gmw8.json b/advisories/unreviewed/2023/04/GHSA-pxwf-m68q-gmw8/GHSA-pxwf-m68q-gmw8.json index a969c3642ce..76c00b6e381 100644 --- a/advisories/unreviewed/2023/04/GHSA-pxwf-m68q-gmw8/GHSA-pxwf-m68q-gmw8.json +++ b/advisories/unreviewed/2023/04/GHSA-pxwf-m68q-gmw8/GHSA-pxwf-m68q-gmw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxwf-m68q-gmw8", - "modified": "2023-04-14T21:30:22Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-14T21:30:22Z", "aliases": [ "CVE-2023-2004" ], "details": "An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-q9h2-893q-85gq/GHSA-q9h2-893q-85gq.json b/advisories/unreviewed/2023/04/GHSA-q9h2-893q-85gq/GHSA-q9h2-893q-85gq.json new file mode 100644 index 00000000000..1f07ea28c4e --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-q9h2-893q-85gq/GHSA-q9h2-893q-85gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9h2-893q-85gq", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-22918" + ], + "details": "A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22918" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-qq2j-hq57-9rpr/GHSA-qq2j-hq57-9rpr.json b/advisories/unreviewed/2023/04/GHSA-qq2j-hq57-9rpr/GHSA-qq2j-hq57-9rpr.json index 42fa5a07cc7..26f2dd1b33d 100644 --- a/advisories/unreviewed/2023/04/GHSA-qq2j-hq57-9rpr/GHSA-qq2j-hq57-9rpr.json +++ b/advisories/unreviewed/2023/04/GHSA-qq2j-hq57-9rpr/GHSA-qq2j-hq57-9rpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qq2j-hq57-9rpr", - "modified": "2023-04-14T21:30:24Z", + "modified": "2023-04-24T18:30:28Z", "published": "2023-04-14T21:30:24Z", "aliases": [ "CVE-2023-2073" ], "details": "A vulnerability was found in Campcodes Online Traffic Offense Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Login.php. The manipulation of the argument password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226051.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-14T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-qvq2-2xfw-f6x6/GHSA-qvq2-2xfw-f6x6.json b/advisories/unreviewed/2023/04/GHSA-qvq2-2xfw-f6x6/GHSA-qvq2-2xfw-f6x6.json index c873297913a..a44fd833ff4 100644 --- a/advisories/unreviewed/2023/04/GHSA-qvq2-2xfw-f6x6/GHSA-qvq2-2xfw-f6x6.json +++ b/advisories/unreviewed/2023/04/GHSA-qvq2-2xfw-f6x6/GHSA-qvq2-2xfw-f6x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvq2-2xfw-f6x6", - "modified": "2023-04-14T21:30:22Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-14T21:30:22Z", "aliases": [ "CVE-2023-2008" ], "details": "A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-r83q-3rfr-hgfg/GHSA-r83q-3rfr-hgfg.json b/advisories/unreviewed/2023/04/GHSA-r83q-3rfr-hgfg/GHSA-r83q-3rfr-hgfg.json index 8d6f80de5d5..3b29bde87fc 100644 --- a/advisories/unreviewed/2023/04/GHSA-r83q-3rfr-hgfg/GHSA-r83q-3rfr-hgfg.json +++ b/advisories/unreviewed/2023/04/GHSA-r83q-3rfr-hgfg/GHSA-r83q-3rfr-hgfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r83q-3rfr-hgfg", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2098" ], "details": "A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /inc/topBarNav.php. The manipulation of the argument search leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-226106 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json b/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json new file mode 100644 index 00000000000..69f2d33e983 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r976-44r3-hm6v", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-26099" + ], + "details": "An issue was discovered in Telindus Apsal 3.14.2022.235 b. The consultation permission is insecure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26099" + }, + { + "type": "WEB", + "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-26099" + }, + { + "type": "WEB", + "url": "https://www.telindus.lu/fr/produits/apsal" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json b/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json index 39e740eca53..84a77a3d3b4 100644 --- a/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json +++ b/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-rm84-x485-ppvh/GHSA-rm84-x485-ppvh.json b/advisories/unreviewed/2023/04/GHSA-rm84-x485-ppvh/GHSA-rm84-x485-ppvh.json index 307f0624bdd..569984212f2 100644 --- a/advisories/unreviewed/2023/04/GHSA-rm84-x485-ppvh/GHSA-rm84-x485-ppvh.json +++ b/advisories/unreviewed/2023/04/GHSA-rm84-x485-ppvh/GHSA-rm84-x485-ppvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rm84-x485-ppvh", - "modified": "2023-04-14T21:30:24Z", + "modified": "2023-04-24T18:30:29Z", "published": "2023-04-14T21:30:24Z", "aliases": [ "CVE-2023-27654" ], "details": "An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json b/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json index 60a7263af5f..0a7517384f6 100644 --- a/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json +++ b/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-w347-2542-wgjq/GHSA-w347-2542-wgjq.json b/advisories/unreviewed/2023/04/GHSA-w347-2542-wgjq/GHSA-w347-2542-wgjq.json index 116faa2fa99..b47e2642e7c 100644 --- a/advisories/unreviewed/2023/04/GHSA-w347-2542-wgjq/GHSA-w347-2542-wgjq.json +++ b/advisories/unreviewed/2023/04/GHSA-w347-2542-wgjq/GHSA-w347-2542-wgjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w347-2542-wgjq", - "modified": "2023-04-12T15:30:44Z", + "modified": "2023-04-24T18:30:26Z", "published": "2023-04-12T15:30:44Z", "aliases": [ "CVE-2023-27830" ], "details": "TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wq8f-xmq3-5vq9/GHSA-wq8f-xmq3-5vq9.json b/advisories/unreviewed/2023/04/GHSA-wq8f-xmq3-5vq9/GHSA-wq8f-xmq3-5vq9.json new file mode 100644 index 00000000000..e94f1771ff3 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-wq8f-xmq3-5vq9/GHSA-wq8f-xmq3-5vq9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq8f-xmq3-5vq9", + "modified": "2023-04-24T18:30:31Z", + "published": "2023-04-24T18:30:31Z", + "aliases": [ + "CVE-2023-27848" + ], + "details": "broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27848" + }, + { + "type": "WEB", + "url": "https://github.com/omnitaint/Vulnerability-Reports/blob/9d65add2bca71ed6d6b2e281ee6790a12504ff8e/reports/broccoli-compass/report.md" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/broccoli-compass" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-x4hx-qqp4-qp78/GHSA-x4hx-qqp4-qp78.json b/advisories/unreviewed/2023/04/GHSA-x4hx-qqp4-qp78/GHSA-x4hx-qqp4-qp78.json index b8ff3ac780f..752f9d6e7ba 100644 --- a/advisories/unreviewed/2023/04/GHSA-x4hx-qqp4-qp78/GHSA-x4hx-qqp4-qp78.json +++ b/advisories/unreviewed/2023/04/GHSA-x4hx-qqp4-qp78/GHSA-x4hx-qqp4-qp78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4hx-qqp4-qp78", - "modified": "2023-04-15T09:30:24Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T09:30:24Z", "aliases": [ "CVE-2023-2027" ], "details": "The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-288" ], "severity": null, diff --git a/advisories/unreviewed/2023/04/GHSA-xhc7-32vm-6c85/GHSA-xhc7-32vm-6c85.json b/advisories/unreviewed/2023/04/GHSA-xhc7-32vm-6c85/GHSA-xhc7-32vm-6c85.json index a539bd3bd5b..92dd71e923f 100644 --- a/advisories/unreviewed/2023/04/GHSA-xhc7-32vm-6c85/GHSA-xhc7-32vm-6c85.json +++ b/advisories/unreviewed/2023/04/GHSA-xhc7-32vm-6c85/GHSA-xhc7-32vm-6c85.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhc7-32vm-6c85", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T18:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-25730" ], "details": "Information disclosure in modem due to improper check of IP type while processing DNS server query", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-xqqm-4xjp-r9cv/GHSA-xqqm-4xjp-r9cv.json b/advisories/unreviewed/2023/04/GHSA-xqqm-4xjp-r9cv/GHSA-xqqm-4xjp-r9cv.json index cd01b212455..2bc3e95afa9 100644 --- a/advisories/unreviewed/2023/04/GHSA-xqqm-4xjp-r9cv/GHSA-xqqm-4xjp-r9cv.json +++ b/advisories/unreviewed/2023/04/GHSA-xqqm-4xjp-r9cv/GHSA-xqqm-4xjp-r9cv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqqm-4xjp-r9cv", - "modified": "2023-04-15T12:30:16Z", + "modified": "2023-04-24T18:30:30Z", "published": "2023-04-15T12:30:16Z", "aliases": [ "CVE-2023-2095" ], "details": "A vulnerability was found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226103.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-15T11:15:00Z"