From b0fe9dc6b1c6fe0023e475022875c8825e8e72f1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 22 May 2023 00:31:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6rq2-x93p-cpmq.json | 5 ++ .../GHSA-7h7h-4rmp-2qm5.json | 11 ++++- .../GHSA-8rcg-5g7w-gw95.json | 11 ++++- .../GHSA-x4wg-g4fv-f8m6.json | 7 ++- .../GHSA-9882-476q-39vf.json | 4 ++ .../GHSA-jvxq-fmg4-p4w2.json | 4 ++ .../GHSA-xcgm-pvwf-mjq7.json | 4 ++ .../GHSA-4rv9-8872-9582.json | 4 ++ .../GHSA-5c63-m98j-vx6v.json | 4 ++ .../GHSA-jr52-cgg9-p2ph.json | 4 ++ .../GHSA-rrjx-7fgp-4597.json | 4 ++ .../GHSA-2xw7-44j9-24rv.json | 4 ++ .../GHSA-6w7p-46mm-c2fc.json | 11 ++++- .../GHSA-c8wv-qwwc-6j73.json | 11 ++++- .../GHSA-h7pp-5ppj-95mv.json | 11 ++++- .../GHSA-j7ww-g7m2-fpcg.json | 4 ++ .../GHSA-xwm9-c4jc-crcp.json | 5 ++ .../GHSA-4p85-gw46-324c.json | 4 ++ .../GHSA-jjr9-g78r-wg8r.json | 4 ++ .../GHSA-3m69-hv34-fc7r.json | 7 ++- .../GHSA-5xc6-pmr2-qj78.json | 7 ++- .../GHSA-cxqq-h5hh-jgq2.json | 7 ++- .../GHSA-h3r7-x4mp-2c39.json | 4 ++ .../GHSA-x6xv-j46p-v597.json | 6 ++- .../GHSA-3cqw-cf93-mf47.json | 4 ++ .../GHSA-4jqr-r4vf-pqw6.json | 4 ++ .../GHSA-5xg2-mrpw-8wm7.json | 4 ++ .../GHSA-gmch-57w2-pj7q.json | 4 ++ .../GHSA-w4mm-gfhc-2p52.json | 4 ++ .../GHSA-wv3p-jvhj-v4jc.json | 4 ++ .../GHSA-7prr-xcc8-8wpv.json | 47 +++++++++++++++++++ .../GHSA-pj74-hxf7-xf99.json | 35 ++++++++++++++ .../GHSA-xp5g-jhg3-3rg2.json | 39 +++++++++++++++ 33 files changed, 277 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2023/05/GHSA-7prr-xcc8-8wpv/GHSA-7prr-xcc8-8wpv.json create mode 100644 advisories/unreviewed/2023/05/GHSA-pj74-hxf7-xf99/GHSA-pj74-hxf7-xf99.json create mode 100644 advisories/unreviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json diff --git a/advisories/unreviewed/2021/11/GHSA-6rq2-x93p-cpmq/GHSA-6rq2-x93p-cpmq.json b/advisories/unreviewed/2021/11/GHSA-6rq2-x93p-cpmq/GHSA-6rq2-x93p-cpmq.json index b449bc82e12..82c6dc43623 100644 --- a/advisories/unreviewed/2021/11/GHSA-6rq2-x93p-cpmq/GHSA-6rq2-x93p-cpmq.json +++ b/advisories/unreviewed/2021/11/GHSA-6rq2-x93p-cpmq/GHSA-6rq2-x93p-cpmq.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1349" @@ -44,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2021/12/GHSA-7h7h-4rmp-2qm5/GHSA-7h7h-4rmp-2qm5.json b/advisories/unreviewed/2021/12/GHSA-7h7h-4rmp-2qm5/GHSA-7h7h-4rmp-2qm5.json index 0e8b2775c07..efcb7afd15c 100644 --- a/advisories/unreviewed/2021/12/GHSA-7h7h-4rmp-2qm5/GHSA-7h7h-4rmp-2qm5.json +++ b/advisories/unreviewed/2021/12/GHSA-7h7h-4rmp-2qm5/GHSA-7h7h-4rmp-2qm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h7h-4rmp-2qm5", - "modified": "2021-12-30T00:00:35Z", + "modified": "2023-05-22T00:30:18Z", "published": "2021-12-21T00:00:46Z", "aliases": [ "CVE-2021-44858" ], "details": "An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -22,6 +25,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T297322" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ" diff --git a/advisories/unreviewed/2021/12/GHSA-8rcg-5g7w-gw95/GHSA-8rcg-5g7w-gw95.json b/advisories/unreviewed/2021/12/GHSA-8rcg-5g7w-gw95/GHSA-8rcg-5g7w-gw95.json index bc6c8befc7e..2dc52838317 100644 --- a/advisories/unreviewed/2021/12/GHSA-8rcg-5g7w-gw95/GHSA-8rcg-5g7w-gw95.json +++ b/advisories/unreviewed/2021/12/GHSA-8rcg-5g7w-gw95/GHSA-8rcg-5g7w-gw95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rcg-5g7w-gw95", - "modified": "2021-12-22T00:01:38Z", + "modified": "2023-05-22T00:30:18Z", "published": "2021-12-18T00:01:08Z", "aliases": [ "CVE-2021-45038" ], "details": "An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -22,6 +25,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T297574" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ" diff --git a/advisories/unreviewed/2021/12/GHSA-x4wg-g4fv-f8m6/GHSA-x4wg-g4fv-f8m6.json b/advisories/unreviewed/2021/12/GHSA-x4wg-g4fv-f8m6/GHSA-x4wg-g4fv-f8m6.json index 5d6edeefb49..ebc8f30f2ec 100644 --- a/advisories/unreviewed/2021/12/GHSA-x4wg-g4fv-f8m6/GHSA-x4wg-g4fv-f8m6.json +++ b/advisories/unreviewed/2021/12/GHSA-x4wg-g4fv-f8m6/GHSA-x4wg-g4fv-f8m6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T297322" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ" @@ -32,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/02/GHSA-9882-476q-39vf/GHSA-9882-476q-39vf.json b/advisories/unreviewed/2022/02/GHSA-9882-476q-39vf/GHSA-9882-476q-39vf.json index 3dafea20f24..e8c5247b5e2 100644 --- a/advisories/unreviewed/2022/02/GHSA-9882-476q-39vf/GHSA-9882-476q-39vf.json +++ b/advisories/unreviewed/2022/02/GHSA-9882-476q-39vf/GHSA-9882-476q-39vf.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5077" diff --git a/advisories/unreviewed/2022/02/GHSA-jvxq-fmg4-p4w2/GHSA-jvxq-fmg4-p4w2.json b/advisories/unreviewed/2022/02/GHSA-jvxq-fmg4-p4w2/GHSA-jvxq-fmg4-p4w2.json index 15e6a8cfd7f..423a9bf514f 100644 --- a/advisories/unreviewed/2022/02/GHSA-jvxq-fmg4-p4w2/GHSA-jvxq-fmg4-p4w2.json +++ b/advisories/unreviewed/2022/02/GHSA-jvxq-fmg4-p4w2/GHSA-jvxq-fmg4-p4w2.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5077" diff --git a/advisories/unreviewed/2022/02/GHSA-xcgm-pvwf-mjq7/GHSA-xcgm-pvwf-mjq7.json b/advisories/unreviewed/2022/02/GHSA-xcgm-pvwf-mjq7/GHSA-xcgm-pvwf-mjq7.json index dc89e8fd9b4..cdffb98476c 100644 --- a/advisories/unreviewed/2022/02/GHSA-xcgm-pvwf-mjq7/GHSA-xcgm-pvwf-mjq7.json +++ b/advisories/unreviewed/2022/02/GHSA-xcgm-pvwf-mjq7/GHSA-xcgm-pvwf-mjq7.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5077" diff --git a/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json b/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json index 86701ff1f3f..47694f61004 100644 --- a/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json +++ b/advisories/unreviewed/2022/03/GHSA-4rv9-8872-9582/GHSA-4rv9-8872-9582.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T304126" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json b/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json index edfb40a111c..d0d94eb32ab 100644 --- a/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json +++ b/advisories/unreviewed/2022/03/GHSA-5c63-m98j-vx6v/GHSA-5c63-m98j-vx6v.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T297543" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5246" diff --git a/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json b/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json index 95ea3feb77c..fb347a8a0d1 100644 --- a/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json +++ b/advisories/unreviewed/2022/03/GHSA-jr52-cgg9-p2ph/GHSA-jr52-cgg9-p2ph.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T294256" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json b/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json index b77d3286979..f670cd8b332 100644 --- a/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json +++ b/advisories/unreviewed/2022/03/GHSA-rrjx-7fgp-4597/GHSA-rrjx-7fgp-4597.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T302248" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-2xw7-44j9-24rv/GHSA-2xw7-44j9-24rv.json b/advisories/unreviewed/2022/05/GHSA-2xw7-44j9-24rv/GHSA-2xw7-44j9-24rv.json index 3f119290d51..84f95cd1087 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xw7-44j9-24rv/GHSA-2xw7-44j9-24rv.json +++ b/advisories/unreviewed/2022/05/GHSA-2xw7-44j9-24rv/GHSA-2xw7-44j9-24rv.json @@ -48,6 +48,10 @@ { "type": "WEB", "url": "https://portswigger.net/daily-swig/waf-bypass-severe-owasp-modsecurity-core-rule-set-bug-was-present-for-several-years" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-25" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-6w7p-46mm-c2fc/GHSA-6w7p-46mm-c2fc.json b/advisories/unreviewed/2022/05/GHSA-6w7p-46mm-c2fc/GHSA-6w7p-46mm-c2fc.json index 0c9e3994494..4f68f127beb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w7p-46mm-c2fc/GHSA-6w7p-46mm-c2fc.json +++ b/advisories/unreviewed/2022/05/GHSA-6w7p-46mm-c2fc/GHSA-6w7p-46mm-c2fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6w7p-46mm-c2fc", - "modified": "2022-05-24T19:17:14Z", + "modified": "2023-05-22T00:30:17Z", "published": "2022-05-24T19:17:14Z", "aliases": [ "CVE-2021-41798" ], "details": "MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,6 +36,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T285515" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-c8wv-qwwc-6j73/GHSA-c8wv-qwwc-6j73.json b/advisories/unreviewed/2022/05/GHSA-c8wv-qwwc-6j73/GHSA-c8wv-qwwc-6j73.json index 2eff6be5a1f..8571269c583 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8wv-qwwc-6j73/GHSA-c8wv-qwwc-6j73.json +++ b/advisories/unreviewed/2022/05/GHSA-c8wv-qwwc-6j73/GHSA-c8wv-qwwc-6j73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8wv-qwwc-6j73", - "modified": "2022-05-24T19:17:14Z", + "modified": "2023-05-22T00:30:18Z", "published": "2022-05-24T19:17:14Z", "aliases": [ "CVE-2021-41800" ], "details": "MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -41,6 +44,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T284419" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-h7pp-5ppj-95mv/GHSA-h7pp-5ppj-95mv.json b/advisories/unreviewed/2022/05/GHSA-h7pp-5ppj-95mv/GHSA-h7pp-5ppj-95mv.json index b9ec0a727d8..1b4174b894a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7pp-5ppj-95mv/GHSA-h7pp-5ppj-95mv.json +++ b/advisories/unreviewed/2022/05/GHSA-h7pp-5ppj-95mv/GHSA-h7pp-5ppj-95mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7pp-5ppj-95mv", - "modified": "2022-05-24T19:17:14Z", + "modified": "2023-05-22T00:30:18Z", "published": "2022-05-24T19:17:14Z", "aliases": [ "CVE-2021-41799" ], "details": "MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,6 +40,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T290394" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-j7ww-g7m2-fpcg/GHSA-j7ww-g7m2-fpcg.json b/advisories/unreviewed/2022/05/GHSA-j7ww-g7m2-fpcg/GHSA-j7ww-g7m2-fpcg.json index d1207909e9b..3cb0df41c27 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7ww-g7m2-fpcg/GHSA-j7ww-g7m2-fpcg.json +++ b/advisories/unreviewed/2022/05/GHSA-j7ww-g7m2-fpcg/GHSA-j7ww-g7m2-fpcg.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1351" diff --git a/advisories/unreviewed/2022/05/GHSA-xwm9-c4jc-crcp/GHSA-xwm9-c4jc-crcp.json b/advisories/unreviewed/2022/05/GHSA-xwm9-c4jc-crcp/GHSA-xwm9-c4jc-crcp.json index 2ed7ea9fcea..5661fecf7fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwm9-c4jc-crcp/GHSA-xwm9-c4jc-crcp.json +++ b/advisories/unreviewed/2022/05/GHSA-xwm9-c4jc-crcp/GHSA-xwm9-c4jc-crcp.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-26" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1350" @@ -44,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-4p85-gw46-324c/GHSA-4p85-gw46-324c.json b/advisories/unreviewed/2022/07/GHSA-4p85-gw46-324c/GHSA-4p85-gw46-324c.json index 75ad64e9df0..d324cf09d83 100644 --- a/advisories/unreviewed/2022/07/GHSA-4p85-gw46-324c/GHSA-4p85-gw46-324c.json +++ b/advisories/unreviewed/2022/07/GHSA-4p85-gw46-324c/GHSA-4p85-gw46-324c.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T308473" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5246" diff --git a/advisories/unreviewed/2022/07/GHSA-jjr9-g78r-wg8r/GHSA-jjr9-g78r-wg8r.json b/advisories/unreviewed/2022/07/GHSA-jjr9-g78r-wg8r/GHSA-jjr9-g78r-wg8r.json index 88169ac290d..3479d5e524f 100644 --- a/advisories/unreviewed/2022/07/GHSA-jjr9-g78r-wg8r/GHSA-jjr9-g78r-wg8r.json +++ b/advisories/unreviewed/2022/07/GHSA-jjr9-g78r-wg8r/GHSA-jjr9-g78r-wg8r.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://phabricator.wikimedia.org/T308471" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" + }, { "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5246" diff --git a/advisories/unreviewed/2022/09/GHSA-3m69-hv34-fc7r/GHSA-3m69-hv34-fc7r.json b/advisories/unreviewed/2022/09/GHSA-3m69-hv34-fc7r/GHSA-3m69-hv34-fc7r.json index e15041b333f..3b1d345360d 100644 --- a/advisories/unreviewed/2022/09/GHSA-3m69-hv34-fc7r/GHSA-3m69-hv34-fc7r.json +++ b/advisories/unreviewed/2022/09/GHSA-3m69-hv34-fc7r/GHSA-3m69-hv34-fc7r.json @@ -40,11 +40,16 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-25" } ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-5xc6-pmr2-qj78/GHSA-5xc6-pmr2-qj78.json b/advisories/unreviewed/2022/09/GHSA-5xc6-pmr2-qj78/GHSA-5xc6-pmr2-qj78.json index 6185a3099fc..b07d07ee4bc 100644 --- a/advisories/unreviewed/2022/09/GHSA-5xc6-pmr2-qj78/GHSA-5xc6-pmr2-qj78.json +++ b/advisories/unreviewed/2022/09/GHSA-5xc6-pmr2-qj78/GHSA-5xc6-pmr2-qj78.json @@ -40,11 +40,16 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-25" } ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-cxqq-h5hh-jgq2/GHSA-cxqq-h5hh-jgq2.json b/advisories/unreviewed/2022/09/GHSA-cxqq-h5hh-jgq2/GHSA-cxqq-h5hh-jgq2.json index e8f0cd676b6..c7b325626d7 100644 --- a/advisories/unreviewed/2022/09/GHSA-cxqq-h5hh-jgq2/GHSA-cxqq-h5hh-jgq2.json +++ b/advisories/unreviewed/2022/09/GHSA-cxqq-h5hh-jgq2/GHSA-cxqq-h5hh-jgq2.json @@ -40,11 +40,16 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-25" } ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-693" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-h3r7-x4mp-2c39/GHSA-h3r7-x4mp-2c39.json b/advisories/unreviewed/2022/09/GHSA-h3r7-x4mp-2c39/GHSA-h3r7-x4mp-2c39.json index 68bc157a646..d0ea23cfbd7 100644 --- a/advisories/unreviewed/2022/09/GHSA-h3r7-x4mp-2c39/GHSA-h3r7-x4mp-2c39.json +++ b/advisories/unreviewed/2022/09/GHSA-h3r7-x4mp-2c39/GHSA-h3r7-x4mp-2c39.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://github.com/tinyproxy/tinyproxy/blob/84f203fb1c4733608c7283bbe794005a469c4b00/src/reqs.c#L346" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-27" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-x6xv-j46p-v597/GHSA-x6xv-j46p-v597.json b/advisories/unreviewed/2022/09/GHSA-x6xv-j46p-v597/GHSA-x6xv-j46p-v597.json index a349869918d..33cc0098741 100644 --- a/advisories/unreviewed/2022/09/GHSA-x6xv-j46p-v597/GHSA-x6xv-j46p-v597.json +++ b/advisories/unreviewed/2022/09/GHSA-x6xv-j46p-v597/GHSA-x6xv-j46p-v597.json @@ -40,11 +40,15 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-25" } ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-3cqw-cf93-mf47/GHSA-3cqw-cf93-mf47.json b/advisories/unreviewed/2022/12/GHSA-3cqw-cf93-mf47/GHSA-3cqw-cf93-mf47.json index 00ee3b66db6..cebc0d76d41 100644 --- a/advisories/unreviewed/2022/12/GHSA-3cqw-cf93-mf47/GHSA-3cqw-cf93-mf47.json +++ b/advisories/unreviewed/2022/12/GHSA-3cqw-cf93-mf47/GHSA-3cqw-cf93-mf47.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T293589" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json b/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json index d0e92a59e3a..2b1c6d766d4 100644 --- a/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json +++ b/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T316304" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-5xg2-mrpw-8wm7/GHSA-5xg2-mrpw-8wm7.json b/advisories/unreviewed/2022/12/GHSA-5xg2-mrpw-8wm7/GHSA-5xg2-mrpw-8wm7.json index e53ec67a1ff..4604d618c6c 100644 --- a/advisories/unreviewed/2022/12/GHSA-5xg2-mrpw-8wm7/GHSA-5xg2-mrpw-8wm7.json +++ b/advisories/unreviewed/2022/12/GHSA-5xg2-mrpw-8wm7/GHSA-5xg2-mrpw-8wm7.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T309894" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-gmch-57w2-pj7q/GHSA-gmch-57w2-pj7q.json b/advisories/unreviewed/2022/12/GHSA-gmch-57w2-pj7q/GHSA-gmch-57w2-pj7q.json index d22c3e07bf2..fd92c07ba82 100644 --- a/advisories/unreviewed/2022/12/GHSA-gmch-57w2-pj7q/GHSA-gmch-57w2-pj7q.json +++ b/advisories/unreviewed/2022/12/GHSA-gmch-57w2-pj7q/GHSA-gmch-57w2-pj7q.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T271037" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json b/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json index 8d711828ab7..cf4d163bac4 100644 --- a/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json +++ b/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T292763" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json index 6ae791c9716..6b4b5cdcd03 100644 --- a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json +++ b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://phabricator.wikimedia.org/T322637" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202305-24" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-7prr-xcc8-8wpv/GHSA-7prr-xcc8-8wpv.json b/advisories/unreviewed/2023/05/GHSA-7prr-xcc8-8wpv/GHSA-7prr-xcc8-8wpv.json new file mode 100644 index 00000000000..51fd737eca2 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-7prr-xcc8-8wpv/GHSA-7prr-xcc8-8wpv.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7prr-xcc8-8wpv", + "modified": "2023-05-22T00:30:20Z", + "published": "2023-05-22T00:30:20Z", + "aliases": [ + "CVE-2020-36694" + ], + "details": "An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36694" + }, + { + "type": "WEB", + "url": "https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10" + }, + { + "type": "WEB", + "url": "https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc00bcaa589914096edef7fb87ca5cee4a166b5c" + }, + { + "type": "WEB", + "url": "https://syzkaller.appspot.com/bug?id=0c4fd9c6aa04ec116d01e915d3b186f71a212cb2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-pj74-hxf7-xf99/GHSA-pj74-hxf7-xf99.json b/advisories/unreviewed/2023/05/GHSA-pj74-hxf7-xf99/GHSA-pj74-hxf7-xf99.json new file mode 100644 index 00000000000..966f22c294d --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-pj74-hxf7-xf99/GHSA-pj74-hxf7-xf99.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj74-hxf7-xf99", + "modified": "2023-05-22T00:30:20Z", + "published": "2023-05-22T00:30:20Z", + "aliases": [ + "CVE-2023-33254" + ], + "details": "There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33254" + }, + { + "type": "WEB", + "url": "https://www.stevencampbell.info/KACE-LDAP-Bind-Credential-Exposure/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json b/advisories/unreviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json new file mode 100644 index 00000000000..2e5bbe198db --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp5g-jhg3-3rg2", + "modified": "2023-05-22T00:30:20Z", + "published": "2023-05-22T00:30:20Z", + "aliases": [ + "CVE-2023-33252" + ], + "details": "iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33252" + }, + { + "type": "WEB", + "url": "https://github.com/iden3/snarkjs/commits/master/src/groth16_verify.js" + }, + { + "type": "WEB", + "url": "https://github.com/iden3/snarkjs/tags" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file