diff --git a/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json b/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json index b5f145d0298..f1eefa54f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json +++ b/advisories/unreviewed/2022/05/GHSA-683g-4vqr-5fqc/GHSA-683g-4vqr-5fqc.json @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2" }, + { + "type": "WEB", + "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7314e613d5ff9f0934f7a0f74ed7973b903315d1" + }, { "type": "WEB", "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7314e613d5ff9f0934f7a0f74ed7973b903315d1" diff --git a/advisories/unreviewed/2023/05/GHSA-6fc4-88rc-xvr2/GHSA-6fc4-88rc-xvr2.json b/advisories/unreviewed/2023/05/GHSA-6fc4-88rc-xvr2/GHSA-6fc4-88rc-xvr2.json index 13b6ea8da59..b7b3d9a9c35 100644 --- a/advisories/unreviewed/2023/05/GHSA-6fc4-88rc-xvr2/GHSA-6fc4-88rc-xvr2.json +++ b/advisories/unreviewed/2023/05/GHSA-6fc4-88rc-xvr2/GHSA-6fc4-88rc-xvr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fc4-88rc-xvr2", - "modified": "2023-06-08T03:30:15Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-05-31T21:31:10Z", "aliases": [ "CVE-2022-48502" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-31T20:15:10Z" diff --git a/advisories/unreviewed/2023/07/GHSA-229r-cp46-m292/GHSA-229r-cp46-m292.json b/advisories/unreviewed/2023/07/GHSA-229r-cp46-m292/GHSA-229r-cp46-m292.json index 9ee927de680..a7133254cc9 100644 --- a/advisories/unreviewed/2023/07/GHSA-229r-cp46-m292/GHSA-229r-cp46-m292.json +++ b/advisories/unreviewed/2023/07/GHSA-229r-cp46-m292/GHSA-229r-cp46-m292.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-229r-cp46-m292", - "modified": "2023-07-27T18:30:32Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-07-18T00:31:08Z", "aliases": [ "CVE-2023-38431" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T00:15:09Z" diff --git a/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json b/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json index e56c5e0c2c0..f04a72c4e09 100644 --- a/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json +++ b/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5gp-9w8f-f2p2", - "modified": "2023-07-27T18:30:32Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-07-18T00:31:08Z", "aliases": [ "CVE-2023-38428" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T00:15:09Z" diff --git a/advisories/unreviewed/2023/08/GHSA-p8vw-m6qq-w42v/GHSA-p8vw-m6qq-w42v.json b/advisories/unreviewed/2023/08/GHSA-p8vw-m6qq-w42v/GHSA-p8vw-m6qq-w42v.json index 7266f2e457a..95fba95b2e6 100644 --- a/advisories/unreviewed/2023/08/GHSA-p8vw-m6qq-w42v/GHSA-p8vw-m6qq-w42v.json +++ b/advisories/unreviewed/2023/08/GHSA-p8vw-m6qq-w42v/GHSA-p8vw-m6qq-w42v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8vw-m6qq-w42v", - "modified": "2023-08-26T03:30:32Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2022-48564" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-22T19:16:31Z" diff --git a/advisories/unreviewed/2023/08/GHSA-v76x-qfmc-m88p/GHSA-v76x-qfmc-m88p.json b/advisories/unreviewed/2023/08/GHSA-v76x-qfmc-m88p/GHSA-v76x-qfmc-m88p.json index cb2332a10ab..eb51d938b4c 100644 --- a/advisories/unreviewed/2023/08/GHSA-v76x-qfmc-m88p/GHSA-v76x-qfmc-m88p.json +++ b/advisories/unreviewed/2023/08/GHSA-v76x-qfmc-m88p/GHSA-v76x-qfmc-m88p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v76x-qfmc-m88p", - "modified": "2023-08-21T03:30:15Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-08-02T06:30:20Z", "aliases": [ "CVE-2023-4016" @@ -35,7 +35,7 @@ "CWE-122", "CWE-787" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T05:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json b/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json index 52333f088dd..e72d8b856e1 100644 --- a/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json +++ b/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/pkp/pkp-lib/issues/9464" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176255/PKP-WAL-3.4.0-3-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json b/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json new file mode 100644 index 00000000000..cd3ef99197c --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pqp-qx7r-vppf", + "modified": "2023-12-15T18:30:29Z", + "published": "2023-12-15T18:30:29Z", + "aliases": [ + "CVE-2023-50917" + ], + "details": "MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50917" + }, + { + "type": "WEB", + "url": "https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178" + }, + { + "type": "WEB", + "url": "https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3vp4-9jc4-q799/GHSA-3vp4-9jc4-q799.json b/advisories/unreviewed/2023/12/GHSA-3vp4-9jc4-q799/GHSA-3vp4-9jc4-q799.json new file mode 100644 index 00000000000..cb1191f1c91 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3vp4-9jc4-q799/GHSA-3vp4-9jc4-q799.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vp4-9jc4-q799", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-5512" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5512" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2194607" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/427827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-46jg-h552-883r/GHSA-46jg-h552-883r.json b/advisories/unreviewed/2023/12/GHSA-46jg-h552-883r/GHSA-46jg-h552-883r.json new file mode 100644 index 00000000000..ac6f0031208 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-46jg-h552-883r/GHSA-46jg-h552-883r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46jg-h552-883r", + "modified": "2023-12-15T18:30:29Z", + "published": "2023-12-15T18:30:29Z", + "aliases": [ + "CVE-2023-50089" + ], + "details": "A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50089" + }, + { + "type": "WEB", + "url": "https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4v5v-pg2w-hjcf/GHSA-4v5v-pg2w-hjcf.json b/advisories/unreviewed/2023/12/GHSA-4v5v-pg2w-hjcf/GHSA-4v5v-pg2w-hjcf.json new file mode 100644 index 00000000000..1c9b50ad3c5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4v5v-pg2w-hjcf/GHSA-4v5v-pg2w-hjcf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v5v-pg2w-hjcf", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49767" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Stored XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49767" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/biteship/wordpress-biteship-plugin-2-2-22-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-5p8c-5878-m3xr/GHSA-5p8c-5878-m3xr.json b/advisories/unreviewed/2023/12/GHSA-5p8c-5878-m3xr/GHSA-5p8c-5878-m3xr.json new file mode 100644 index 00000000000..17cd2881fc0 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-5p8c-5878-m3xr/GHSA-5p8c-5878-m3xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p8c-5878-m3xr", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49191" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49191" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gdpr-compliance-by-supsystic/wordpress-gdpr-cookie-consent-by-supsystic-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-625m-28mg-rq98/GHSA-625m-28mg-rq98.json b/advisories/unreviewed/2023/12/GHSA-625m-28mg-rq98/GHSA-625m-28mg-rq98.json new file mode 100644 index 00000000000..35f1e36feeb --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-625m-28mg-rq98/GHSA-625m-28mg-rq98.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-625m-28mg-rq98", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-3904" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3904" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2053154" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/418226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-69m3-5g7g-x3r7/GHSA-69m3-5g7g-x3r7.json b/advisories/unreviewed/2023/12/GHSA-69m3-5g7g-x3r7/GHSA-69m3-5g7g-x3r7.json new file mode 100644 index 00000000000..9bca0b4b3f9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-69m3-5g7g-x3r7/GHSA-69m3-5g7g-x3r7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69m3-5g7g-x3r7", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49823" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bold-page-builder/wordpress-bold-page-builder-plugin-4-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-75fj-hhgg-q745/GHSA-75fj-hhgg-q745.json b/advisories/unreviewed/2023/12/GHSA-75fj-hhgg-q745/GHSA-75fj-hhgg-q745.json new file mode 100644 index 00000000000..a7e829a7e3e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-75fj-hhgg-q745/GHSA-75fj-hhgg-q745.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75fj-hhgg-q745", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49190" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49190" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/site-offline/wordpress-site-offline-or-coming-soon-or-maintenance-mode-plugin-1-5-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json b/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json new file mode 100644 index 00000000000..103caafd477 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rmv-77v4-hrpv", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49747" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.This issue affects Guest Author: from n/a through 2.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/guest-author/wordpress-guest-author-plugin-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json b/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json new file mode 100644 index 00000000000..dc49df4b5c4 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c948-477j-77c3/GHSA-c948-477j-77c3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c948-477j-77c3", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-5310" + ], + "details": "\nA denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5310" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/gecko_sdk/releases" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000005E7EIAU?%20operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json index 69c5d934e47..724c8b85436 100644 --- a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json +++ b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2hj-x395-x532", - "modified": "2023-12-12T12:30:54Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46284" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-fv75-q8rq-39gj/GHSA-fv75-q8rq-39gj.json b/advisories/unreviewed/2023/12/GHSA-fv75-q8rq-39gj/GHSA-fv75-q8rq-39gj.json new file mode 100644 index 00000000000..f536328da9e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-fv75-q8rq-39gj/GHSA-fv75-q8rq-39gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv75-q8rq-39gj", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49189" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49189" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-share-buttons-analytics-by-getsocial/wordpress-social-share-buttons-analytics-plugin-getsocial-io-plugin-4-3-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-ghrj-rqcw-5xqp/GHSA-ghrj-rqcw-5xqp.json b/advisories/unreviewed/2023/12/GHSA-ghrj-rqcw-5xqp/GHSA-ghrj-rqcw-5xqp.json new file mode 100644 index 00000000000..d99ef054b57 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-ghrj-rqcw-5xqp/GHSA-ghrj-rqcw-5xqp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghrj-rqcw-5xqp", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-3511" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3511" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2046752" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/416961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gp3h-jq5w-chrc/GHSA-gp3h-jq5w-chrc.json b/advisories/unreviewed/2023/12/GHSA-gp3h-jq5w-chrc/GHSA-gp3h-jq5w-chrc.json new file mode 100644 index 00000000000..3554f3aa1e5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gp3h-jq5w-chrc/GHSA-gp3h-jq5w-chrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp3h-jq5w-chrc", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49159" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through 3.0.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49159" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/commentluv/wordpress-commentluv-plugin-3-0-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json b/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json index 71f305dbc99..151d79701ed 100644 --- a/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json +++ b/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrh7-rq69-242h", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2020-12615" ], "details": "An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T13:15:06Z" diff --git a/advisories/unreviewed/2023/12/GHSA-j69j-38vv-w2h9/GHSA-j69j-38vv-w2h9.json b/advisories/unreviewed/2023/12/GHSA-j69j-38vv-w2h9/GHSA-j69j-38vv-w2h9.json index 4a4a8267d07..4513b819047 100644 --- a/advisories/unreviewed/2023/12/GHSA-j69j-38vv-w2h9/GHSA-j69j-38vv-w2h9.json +++ b/advisories/unreviewed/2023/12/GHSA-j69j-38vv-w2h9/GHSA-j69j-38vv-w2h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j69j-38vv-w2h9", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-15T18:30:27Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2020-12612" ], "details": "An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFiles(x86)% environment variable. However, when this same policy gets pushed to a 32bit machine, this environment variable does not exist. Therefore, since the standard user can create a user level environment variable, they can repoint this variable to any folder the user has full control of. Then, the folder structure can be created in such a way that a rule matches and arbitrary code runs elevated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json b/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json new file mode 100644 index 00000000000..9edbdac3a6e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh7x-8j8h-xvj8", + "modified": "2023-12-15T18:30:29Z", + "published": "2023-12-15T18:30:29Z", + "aliases": [ + "CVE-2023-50918" + ], + "details": "app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50918" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/commit/92888b1376246c0f20c256aaa3c57b6f12115fa1" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/compare/v2.4.181...v2.4.182" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-pq7v-xh7j-pwmx/GHSA-pq7v-xh7j-pwmx.json b/advisories/unreviewed/2023/12/GHSA-pq7v-xh7j-pwmx/GHSA-pq7v-xh7j-pwmx.json new file mode 100644 index 00000000000..f8851303b9f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-pq7v-xh7j-pwmx/GHSA-pq7v-xh7j-pwmx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq7v-xh7j-pwmx", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-6051" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 15.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6051" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2237165" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/431345" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q8x8-6c79-7jxf/GHSA-q8x8-6c79-7jxf.json b/advisories/unreviewed/2023/12/GHSA-q8x8-6c79-7jxf/GHSA-q8x8-6c79-7jxf.json new file mode 100644 index 00000000000..d6245099ef4 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-q8x8-6c79-7jxf/GHSA-q8x8-6c79-7jxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8x8-6c79-7jxf", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49197" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49197" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dofollow-case-by-case/wordpress-dofollow-case-by-case-plugin-3-4-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rjgg-r474-38m3/GHSA-rjgg-r474-38m3.json b/advisories/unreviewed/2023/12/GHSA-rjgg-r474-38m3/GHSA-rjgg-r474-38m3.json new file mode 100644 index 00000000000..51d0f950c58 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rjgg-r474-38m3/GHSA-rjgg-r474-38m3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjgg-r474-38m3", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49749" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!.This issue affects SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!: from n/a through 1.0.23.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/suretriggers/wordpress-suretriggers-plugin-1-0-23-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-v64g-f7qf-63xm/GHSA-v64g-f7qf-63xm.json b/advisories/unreviewed/2023/12/GHSA-v64g-f7qf-63xm/GHSA-v64g-f7qf-63xm.json new file mode 100644 index 00000000000..e566b8c8c92 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v64g-f7qf-63xm/GHSA-v64g-f7qf-63xm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v64g-f7qf-63xm", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-5061" + ], + "details": "An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5061" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2125189" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/425521" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-w683-cc8r-prr2/GHSA-w683-cc8r-prr2.json b/advisories/unreviewed/2023/12/GHSA-w683-cc8r-prr2/GHSA-w683-cc8r-prr2.json new file mode 100644 index 00000000000..7877c7aedd3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-w683-cc8r-prr2/GHSA-w683-cc8r-prr2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w683-cc8r-prr2", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49744" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through 2.21.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gift-up/wordpress-gift-up-gift-cards-for-wordpress-and-woocommerce-plugin-2-21-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-w864-g84v-8h25/GHSA-w864-g84v-8h25.json b/advisories/unreviewed/2023/12/GHSA-w864-g84v-8h25/GHSA-w864-g84v-8h25.json new file mode 100644 index 00000000000..27045b5262b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-w864-g84v-8h25/GHSA-w864-g84v-8h25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w864-g84v-8h25", + "modified": "2023-12-15T18:30:28Z", + "published": "2023-12-15T18:30:28Z", + "aliases": [ + "CVE-2023-49829" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49829" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tutor/wordpress-tutor-lms-plugin-2-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wpj8-2grx-f965/GHSA-wpj8-2grx-f965.json b/advisories/unreviewed/2023/12/GHSA-wpj8-2grx-f965/GHSA-wpj8-2grx-f965.json new file mode 100644 index 00000000000..3819622b923 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wpj8-2grx-f965/GHSA-wpj8-2grx-f965.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpj8-2grx-f965", + "modified": "2023-12-15T18:30:29Z", + "published": "2023-12-15T18:30:29Z", + "aliases": [ + "CVE-2023-6680" + ], + "details": "An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6680" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/421607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-15T16:15:46Z" + } +} \ No newline at end of file