From b4a8102e161d93981d01c81559f3d5f53ee02f55 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 28 Feb 2024 01:13:29 +0000 Subject: [PATCH] Publish Advisories GHSA-3f54-fhj6-g7ff GHSA-3g68-hg24-4xxq GHSA-3q9p-f48q-wjcp GHSA-5qcf-4cgw-f76m GHSA-g6j7-vgxw-qg28 GHSA-mx27-jhrp-2gfm GHSA-w978-mmpv-hphg --- .../04/GHSA-3f54-fhj6-g7ff/GHSA-3f54-fhj6-g7ff.json | 11 +++++++---- .../04/GHSA-3g68-hg24-4xxq/GHSA-3g68-hg24-4xxq.json | 11 +++++++---- .../04/GHSA-3q9p-f48q-wjcp/GHSA-3q9p-f48q-wjcp.json | 11 +++++++---- .../04/GHSA-5qcf-4cgw-f76m/GHSA-5qcf-4cgw-f76m.json | 11 +++++++---- .../04/GHSA-g6j7-vgxw-qg28/GHSA-g6j7-vgxw-qg28.json | 11 +++++++---- .../04/GHSA-mx27-jhrp-2gfm/GHSA-mx27-jhrp-2gfm.json | 11 +++++++---- .../04/GHSA-w978-mmpv-hphg/GHSA-w978-mmpv-hphg.json | 11 +++++++---- 7 files changed, 49 insertions(+), 28 deletions(-) diff --git a/advisories/unreviewed/2022/04/GHSA-3f54-fhj6-g7ff/GHSA-3f54-fhj6-g7ff.json b/advisories/unreviewed/2022/04/GHSA-3f54-fhj6-g7ff/GHSA-3f54-fhj6-g7ff.json index a97ff4baa9e..19522c6155f 100644 --- a/advisories/unreviewed/2022/04/GHSA-3f54-fhj6-g7ff/GHSA-3f54-fhj6-g7ff.json +++ b/advisories/unreviewed/2022/04/GHSA-3f54-fhj6-g7ff/GHSA-3f54-fhj6-g7ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f54-fhj6-g7ff", - "modified": "2022-04-21T01:57:47Z", + "modified": "2024-02-28T01:10:55Z", "published": "2022-04-21T01:57:47Z", "aliases": [ "CVE-2010-3665" ], "details": "TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-04T22:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-3g68-hg24-4xxq/GHSA-3g68-hg24-4xxq.json b/advisories/unreviewed/2022/04/GHSA-3g68-hg24-4xxq/GHSA-3g68-hg24-4xxq.json index b469f036f45..7dd436bdbd0 100644 --- a/advisories/unreviewed/2022/04/GHSA-3g68-hg24-4xxq/GHSA-3g68-hg24-4xxq.json +++ b/advisories/unreviewed/2022/04/GHSA-3g68-hg24-4xxq/GHSA-3g68-hg24-4xxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g68-hg24-4xxq", - "modified": "2022-04-21T01:57:46Z", + "modified": "2024-02-28T01:10:53Z", "published": "2022-04-21T01:57:46Z", "aliases": [ "CVE-2010-2783" ], "details": "IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-10-31T21:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-3q9p-f48q-wjcp/GHSA-3q9p-f48q-wjcp.json b/advisories/unreviewed/2022/04/GHSA-3q9p-f48q-wjcp/GHSA-3q9p-f48q-wjcp.json index 49bf9f15997..24b9b517773 100644 --- a/advisories/unreviewed/2022/04/GHSA-3q9p-f48q-wjcp/GHSA-3q9p-f48q-wjcp.json +++ b/advisories/unreviewed/2022/04/GHSA-3q9p-f48q-wjcp/GHSA-3q9p-f48q-wjcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q9p-f48q-wjcp", - "modified": "2022-04-21T01:57:51Z", + "modified": "2024-02-28T01:12:11Z", "published": "2022-04-21T01:57:51Z", "aliases": [ "CVE-2010-4177" ], "details": "mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-12T23:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-5qcf-4cgw-f76m/GHSA-5qcf-4cgw-f76m.json b/advisories/unreviewed/2022/04/GHSA-5qcf-4cgw-f76m/GHSA-5qcf-4cgw-f76m.json index 61d37ef2af2..e0adaa91086 100644 --- a/advisories/unreviewed/2022/04/GHSA-5qcf-4cgw-f76m/GHSA-5qcf-4cgw-f76m.json +++ b/advisories/unreviewed/2022/04/GHSA-5qcf-4cgw-f76m/GHSA-5qcf-4cgw-f76m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qcf-4cgw-f76m", - "modified": "2022-04-21T01:57:48Z", + "modified": "2024-02-28T01:12:04Z", "published": "2022-04-21T01:57:48Z", "aliases": [ "CVE-2010-2446" ], "details": "Rbot Reaction plugin allows command execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-06T17:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-g6j7-vgxw-qg28/GHSA-g6j7-vgxw-qg28.json b/advisories/unreviewed/2022/04/GHSA-g6j7-vgxw-qg28/GHSA-g6j7-vgxw-qg28.json index 3c07c93995b..1354a0ddc11 100644 --- a/advisories/unreviewed/2022/04/GHSA-g6j7-vgxw-qg28/GHSA-g6j7-vgxw-qg28.json +++ b/advisories/unreviewed/2022/04/GHSA-g6j7-vgxw-qg28/GHSA-g6j7-vgxw-qg28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6j7-vgxw-qg28", - "modified": "2022-04-21T01:57:52Z", + "modified": "2024-02-28T01:12:53Z", "published": "2022-04-21T01:57:52Z", "aliases": [ "CVE-2010-4817" ], "details": "pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-13T22:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-mx27-jhrp-2gfm/GHSA-mx27-jhrp-2gfm.json b/advisories/unreviewed/2022/04/GHSA-mx27-jhrp-2gfm/GHSA-mx27-jhrp-2gfm.json index 2453f62271f..71004429477 100644 --- a/advisories/unreviewed/2022/04/GHSA-mx27-jhrp-2gfm/GHSA-mx27-jhrp-2gfm.json +++ b/advisories/unreviewed/2022/04/GHSA-mx27-jhrp-2gfm/GHSA-mx27-jhrp-2gfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mx27-jhrp-2gfm", - "modified": "2022-04-21T01:57:51Z", + "modified": "2024-02-28T01:12:20Z", "published": "2022-04-21T01:57:51Z", "aliases": [ "CVE-2010-4657" ], "details": "PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-772" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-13T21:15:00Z" diff --git a/advisories/unreviewed/2022/04/GHSA-w978-mmpv-hphg/GHSA-w978-mmpv-hphg.json b/advisories/unreviewed/2022/04/GHSA-w978-mmpv-hphg/GHSA-w978-mmpv-hphg.json index 9fe6e3106a5..83d3aae09f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-w978-mmpv-hphg/GHSA-w978-mmpv-hphg.json +++ b/advisories/unreviewed/2022/04/GHSA-w978-mmpv-hphg/GHSA-w978-mmpv-hphg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w978-mmpv-hphg", - "modified": "2022-04-21T01:57:46Z", + "modified": "2024-02-28T01:10:51Z", "published": "2022-04-21T01:57:46Z", "aliases": [ "CVE-2010-2548" ], "details": "IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-10-31T21:15:00Z"