Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-12-19 18:31:49 +00:00
parent d91e0a3963
commit b6a8feefd9
52 changed files with 1139 additions and 47 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7v3-vgf4-xqcc",
"modified": "2022-05-24T16:49:57Z",
"modified": "2023-12-19T18:30:29Z",
"published": "2022-05-24T16:49:57Z",
"aliases": [
"CVE-2019-0330"
],
"details": "The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-07-10T20:15:00Z"
@@ -48,6 +48,10 @@
{
"type": "WEB",
"url": "https://www.securityweek.com/exploitation-of-critical-confluence-vulnerability-begins/"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html"
}
],
"database_specific": {
@@ -25,6 +25,14 @@
"type": "WEB",
"url": "https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7876"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40661"
@@ -25,6 +25,14 @@
"type": "WEB",
"url": "https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7876"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40660"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/OpenSC/OpenSC/commit/f1993dc4e0b33050b8f72a3558ee88b24c4063b2"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-4535"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-295v-38xm-x24r",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-19T18:30:30Z",
"aliases": [
"CVE-2023-44983"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44983"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/aruba-hispeed-cache/wordpress-aruba-hispeed-cache-plugin-2-0-6-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2f28-c6gf-w62p",
"modified": "2023-12-19T18:30:31Z",
"published": "2023-12-19T18:30:31Z",
"aliases": [
"CVE-2023-46223"
],
"details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46223"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2ff7-p4h3-cfp8",
"modified": "2023-12-14T15:30:22Z",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-14T15:30:22Z",
"aliases": [
"CVE-2022-45365"
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-306",
"CWE-862"
],
"severity": "HIGH",
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37h3-969w-7ph2",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-19T18:30:30Z",
"aliases": [
"CVE-2023-41727"
],
"details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41727"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j4p-qc5m-wqgh",
"modified": "2023-12-14T06:30:44Z",
"modified": "2023-12-19T18:30:29Z",
"published": "2023-12-14T06:30:44Z",
"aliases": [
"CVE-2023-49938"
],
"details": "An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T05:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mgx-28wc-mhmx",
"modified": "2023-12-15T15:30:28Z",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-15T15:30:28Z",
"aliases": [
"CVE-2023-48765"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q3v-9mp5-cqff",
"modified": "2023-12-19T18:30:31Z",
"published": "2023-12-19T18:30:31Z",
"aliases": [
"CVE-2023-46263"
],
"details": "An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46263"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3v63-qv3r-29hp",
"modified": "2023-12-19T18:30:31Z",
"published": "2023-12-19T18:30:31Z",
"aliases": [
"CVE-2023-46257"
],
"details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46257"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42rj-c8ww-p58f",
"modified": "2023-12-19T18:30:32Z",
"published": "2023-12-19T18:30:32Z",
"aliases": [
"CVE-2023-50272"
],
"details": "A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50272"
},
{
"type": "WEB",
"url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04584en_us"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gxg-f9jp-6c4f",
"modified": "2023-12-14T09:30:19Z",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-14T09:30:19Z",
"aliases": [
"CVE-2023-40657"
],
"details": "A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T09:15:41Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hq7-4r72-pxrp",
"modified": "2023-12-19T18:30:31Z",
"published": "2023-12-19T18:30:31Z",
"aliases": [
"CVE-2023-46266"
],
"details": "An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46266"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mqm-8w5p-8gjq",
"modified": "2023-12-19T18:30:30Z",
"published": "2023-12-19T18:30:30Z",
"aliases": [
"CVE-2023-44991"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files (Manual, Auto & AI).This issue affects Media File Renamer: Rename Files (Manual, Auto & AI): from n/a through 5.6.9.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44991"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/media-file-renamer/wordpress-media-file-renamer-plugin-5-6-9-sensitive-data-exposure-via-debug-log-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4x6r-c8c8-x44h",
"modified": "2023-12-19T18:30:31Z",
"published": "2023-12-19T18:30:31Z",
"aliases": [
"CVE-2023-46264"
],
"details": "An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46264"
},
{
"type": "WEB",
"url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-19T16:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5947-p758-5g99",
"modified": "2023-12-14T00:30:26Z",
"modified": "2023-12-19T18:30:29Z",
"published": "2023-12-14T00:30:26Z",
"aliases": [
"CVE-2023-41618"
],
"details": "Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T00:15:43Z"

Some files were not shown because too many files have changed in this diff Show More