From b6a8feefd93ec0435a516428d0dba1b3ed9635d1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Dec 2023 18:31:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-w7v3-vgf4-xqcc.json | 11 ++++-- .../GHSA-8prx-84h6-4fr5.json | 4 ++ .../GHSA-2c2j-2pgv-gfgc.json | 8 ++++ .../GHSA-7635-x5f9-5458.json | 8 ++++ .../GHSA-phh2-j3h6-vqr9.json | 4 ++ .../GHSA-295v-38xm-x24r.json | 38 +++++++++++++++++++ .../GHSA-2f28-c6gf-w62p.json | 38 +++++++++++++++++++ .../GHSA-2ff7-p4h3-cfp8.json | 2 +- .../GHSA-2jqj-w7h9-j4g2.json | 1 + .../GHSA-37h3-969w-7ph2.json | 38 +++++++++++++++++++ .../GHSA-3j4p-qc5m-wqgh.json | 9 +++-- .../GHSA-3mgx-28wc-mhmx.json | 2 +- .../GHSA-3q3v-9mp5-cqff.json | 38 +++++++++++++++++++ .../GHSA-3v63-qv3r-29hp.json | 38 +++++++++++++++++++ .../GHSA-42rj-c8ww-p58f.json | 38 +++++++++++++++++++ .../GHSA-4gxg-f9jp-6c4f.json | 9 +++-- .../GHSA-4hq7-4r72-pxrp.json | 38 +++++++++++++++++++ .../GHSA-4mqm-8w5p-8gjq.json | 38 +++++++++++++++++++ .../GHSA-4x6r-c8c8-x44h.json | 38 +++++++++++++++++++ .../GHSA-5947-p758-5g99.json | 11 ++++-- .../GHSA-63cq-qp74-7w56.json | 38 +++++++++++++++++++ .../GHSA-63vr-qwf8-72qv.json | 2 +- .../GHSA-678p-2fg5-j3m2.json | 2 +- .../GHSA-75vw-45w8-6h3g.json | 9 +++-- .../GHSA-769x-q5v4-m549.json | 38 +++++++++++++++++++ .../GHSA-9jhh-hw56-3jhj.json | 9 +++-- .../GHSA-9v38-vjvh-5jr4.json | 9 +++-- .../GHSA-c7vp-x3hm-mmrp.json | 38 +++++++++++++++++++ .../GHSA-c89h-4r84-43j7.json | 38 +++++++++++++++++++ .../GHSA-cf4w-jr22-49m6.json | 1 + .../GHSA-cvfr-v5hr-8952.json | 38 +++++++++++++++++++ .../GHSA-g5gh-w2mq-pjxv.json | 9 +++-- .../GHSA-gmf5-m5h7-48v7.json | 38 +++++++++++++++++++ .../GHSA-gqvf-3hgp-5hxv.json | 3 +- .../GHSA-hj3r-2hqm-4f6w.json | 38 +++++++++++++++++++ .../GHSA-hqx2-wc2c-3843.json | 38 +++++++++++++++++++ .../GHSA-jjp4-6rrm-wrm6.json | 38 +++++++++++++++++++ .../GHSA-jr37-c5mp-55w3.json | 9 +++-- .../GHSA-jvg2-h67f-h9rw.json | 9 +++-- .../GHSA-m2v4-c7w8-gcjq.json | 38 +++++++++++++++++++ .../GHSA-m69c-xr2j-q82p.json | 9 +++-- .../GHSA-mh7x-8j8h-xvj8.json | 9 +++-- .../GHSA-mwj6-6ghh-97gx.json | 38 +++++++++++++++++++ .../GHSA-prgf-7pc3-3h2j.json | 9 +++-- .../GHSA-rfhr-9grr-mhwq.json | 2 +- .../GHSA-v4rx-vw37-jhmq.json | 38 +++++++++++++++++++ .../GHSA-vr3j-fq3j-prvj.json | 38 +++++++++++++++++++ .../GHSA-vv3w-p5xw-r8c3.json | 38 +++++++++++++++++++ .../GHSA-w425-226c-79r3.json | 38 +++++++++++++++++++ .../GHSA-wmh6-wh26-4mj9.json | 38 +++++++++++++++++++ .../GHSA-wphm-hq4w-gwj8.json | 38 +++++++++++++++++++ .../GHSA-xv5g-cq95-4rcm.json | 38 +++++++++++++++++++ 52 files changed, 1139 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2023/12/GHSA-295v-38xm-x24r/GHSA-295v-38xm-x24r.json create mode 100644 advisories/unreviewed/2023/12/GHSA-2f28-c6gf-w62p/GHSA-2f28-c6gf-w62p.json create mode 100644 advisories/unreviewed/2023/12/GHSA-37h3-969w-7ph2/GHSA-37h3-969w-7ph2.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3q3v-9mp5-cqff/GHSA-3q3v-9mp5-cqff.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3v63-qv3r-29hp/GHSA-3v63-qv3r-29hp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4hq7-4r72-pxrp/GHSA-4hq7-4r72-pxrp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4mqm-8w5p-8gjq/GHSA-4mqm-8w5p-8gjq.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4x6r-c8c8-x44h/GHSA-4x6r-c8c8-x44h.json create mode 100644 advisories/unreviewed/2023/12/GHSA-63cq-qp74-7w56/GHSA-63cq-qp74-7w56.json create mode 100644 advisories/unreviewed/2023/12/GHSA-769x-q5v4-m549/GHSA-769x-q5v4-m549.json create mode 100644 advisories/unreviewed/2023/12/GHSA-c7vp-x3hm-mmrp/GHSA-c7vp-x3hm-mmrp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-c89h-4r84-43j7/GHSA-c89h-4r84-43j7.json create mode 100644 advisories/unreviewed/2023/12/GHSA-cvfr-v5hr-8952/GHSA-cvfr-v5hr-8952.json create mode 100644 advisories/unreviewed/2023/12/GHSA-gmf5-m5h7-48v7/GHSA-gmf5-m5h7-48v7.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hj3r-2hqm-4f6w/GHSA-hj3r-2hqm-4f6w.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hqx2-wc2c-3843/GHSA-hqx2-wc2c-3843.json create mode 100644 advisories/unreviewed/2023/12/GHSA-jjp4-6rrm-wrm6/GHSA-jjp4-6rrm-wrm6.json create mode 100644 advisories/unreviewed/2023/12/GHSA-m2v4-c7w8-gcjq/GHSA-m2v4-c7w8-gcjq.json create mode 100644 advisories/unreviewed/2023/12/GHSA-mwj6-6ghh-97gx/GHSA-mwj6-6ghh-97gx.json create mode 100644 advisories/unreviewed/2023/12/GHSA-v4rx-vw37-jhmq/GHSA-v4rx-vw37-jhmq.json create mode 100644 advisories/unreviewed/2023/12/GHSA-vr3j-fq3j-prvj/GHSA-vr3j-fq3j-prvj.json create mode 100644 advisories/unreviewed/2023/12/GHSA-vv3w-p5xw-r8c3/GHSA-vv3w-p5xw-r8c3.json create mode 100644 advisories/unreviewed/2023/12/GHSA-w425-226c-79r3/GHSA-w425-226c-79r3.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wphm-hq4w-gwj8/GHSA-wphm-hq4w-gwj8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-xv5g-cq95-4rcm/GHSA-xv5g-cq95-4rcm.json diff --git a/advisories/unreviewed/2022/05/GHSA-w7v3-vgf4-xqcc/GHSA-w7v3-vgf4-xqcc.json b/advisories/unreviewed/2022/05/GHSA-w7v3-vgf4-xqcc/GHSA-w7v3-vgf4-xqcc.json index 6de5bf5c4cf..a477c6e31a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7v3-vgf4-xqcc/GHSA-w7v3-vgf4-xqcc.json +++ b/advisories/unreviewed/2022/05/GHSA-w7v3-vgf4-xqcc/GHSA-w7v3-vgf4-xqcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7v3-vgf4-xqcc", - "modified": "2022-05-24T16:49:57Z", + "modified": "2023-12-19T18:30:29Z", "published": "2022-05-24T16:49:57Z", "aliases": [ "CVE-2019-0330" ], "details": "The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-10T20:15:00Z" diff --git a/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json b/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json index 0ad27dd7463..c5e3dde9259 100644 --- a/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json +++ b/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json @@ -48,6 +48,10 @@ { "type": "WEB", "url": "https://www.securityweek.com/exploitation-of-critical-confluence-vulnerability-begins/" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json b/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json index e58d8126536..23e09dca94b 100644 --- a/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json +++ b/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7876" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7879" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40661" diff --git a/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json b/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json index 8f5ebb697d5..027c02844bc 100644 --- a/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json +++ b/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7876" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7879" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40660" diff --git a/advisories/unreviewed/2023/11/GHSA-phh2-j3h6-vqr9/GHSA-phh2-j3h6-vqr9.json b/advisories/unreviewed/2023/11/GHSA-phh2-j3h6-vqr9/GHSA-phh2-j3h6-vqr9.json index fe0c0e2a179..84951939858 100644 --- a/advisories/unreviewed/2023/11/GHSA-phh2-j3h6-vqr9/GHSA-phh2-j3h6-vqr9.json +++ b/advisories/unreviewed/2023/11/GHSA-phh2-j3h6-vqr9/GHSA-phh2-j3h6-vqr9.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/OpenSC/OpenSC/commit/f1993dc4e0b33050b8f72a3558ee88b24c4063b2" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7879" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4535" diff --git a/advisories/unreviewed/2023/12/GHSA-295v-38xm-x24r/GHSA-295v-38xm-x24r.json b/advisories/unreviewed/2023/12/GHSA-295v-38xm-x24r/GHSA-295v-38xm-x24r.json new file mode 100644 index 00000000000..1add9d1093f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-295v-38xm-x24r/GHSA-295v-38xm-x24r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-295v-38xm-x24r", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-44983" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44983" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/aruba-hispeed-cache/wordpress-aruba-hispeed-cache-plugin-2-0-6-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2f28-c6gf-w62p/GHSA-2f28-c6gf-w62p.json b/advisories/unreviewed/2023/12/GHSA-2f28-c6gf-w62p/GHSA-2f28-c6gf-w62p.json new file mode 100644 index 00000000000..ab6f89593f5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2f28-c6gf-w62p/GHSA-2f28-c6gf-w62p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f28-c6gf-w62p", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46223" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46223" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2ff7-p4h3-cfp8/GHSA-2ff7-p4h3-cfp8.json b/advisories/unreviewed/2023/12/GHSA-2ff7-p4h3-cfp8/GHSA-2ff7-p4h3-cfp8.json index 21160e877a8..a81cc43de71 100644 --- a/advisories/unreviewed/2023/12/GHSA-2ff7-p4h3-cfp8/GHSA-2ff7-p4h3-cfp8.json +++ b/advisories/unreviewed/2023/12/GHSA-2ff7-p4h3-cfp8/GHSA-2ff7-p4h3-cfp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2ff7-p4h3-cfp8", - "modified": "2023-12-14T15:30:22Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T15:30:22Z", "aliases": [ "CVE-2022-45365" diff --git a/advisories/unreviewed/2023/12/GHSA-2jqj-w7h9-j4g2/GHSA-2jqj-w7h9-j4g2.json b/advisories/unreviewed/2023/12/GHSA-2jqj-w7h9-j4g2/GHSA-2jqj-w7h9-j4g2.json index e39dc4cb212..c8c3f986f7f 100644 --- a/advisories/unreviewed/2023/12/GHSA-2jqj-w7h9-j4g2/GHSA-2jqj-w7h9-j4g2.json +++ b/advisories/unreviewed/2023/12/GHSA-2jqj-w7h9-j4g2/GHSA-2jqj-w7h9-j4g2.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-37h3-969w-7ph2/GHSA-37h3-969w-7ph2.json b/advisories/unreviewed/2023/12/GHSA-37h3-969w-7ph2/GHSA-37h3-969w-7ph2.json new file mode 100644 index 00000000000..4dbfaea3abd --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-37h3-969w-7ph2/GHSA-37h3-969w-7ph2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37h3-969w-7ph2", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-41727" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41727" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3j4p-qc5m-wqgh/GHSA-3j4p-qc5m-wqgh.json b/advisories/unreviewed/2023/12/GHSA-3j4p-qc5m-wqgh/GHSA-3j4p-qc5m-wqgh.json index 6d41cff191c..4d861c71380 100644 --- a/advisories/unreviewed/2023/12/GHSA-3j4p-qc5m-wqgh/GHSA-3j4p-qc5m-wqgh.json +++ b/advisories/unreviewed/2023/12/GHSA-3j4p-qc5m-wqgh/GHSA-3j4p-qc5m-wqgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j4p-qc5m-wqgh", - "modified": "2023-12-14T06:30:44Z", + "modified": "2023-12-19T18:30:29Z", "published": "2023-12-14T06:30:44Z", "aliases": [ "CVE-2023-49938" ], "details": "An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T05:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-3mgx-28wc-mhmx/GHSA-3mgx-28wc-mhmx.json b/advisories/unreviewed/2023/12/GHSA-3mgx-28wc-mhmx/GHSA-3mgx-28wc-mhmx.json index 8e33a559796..11ee7f34baa 100644 --- a/advisories/unreviewed/2023/12/GHSA-3mgx-28wc-mhmx/GHSA-3mgx-28wc-mhmx.json +++ b/advisories/unreviewed/2023/12/GHSA-3mgx-28wc-mhmx/GHSA-3mgx-28wc-mhmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mgx-28wc-mhmx", - "modified": "2023-12-15T15:30:28Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-15T15:30:28Z", "aliases": [ "CVE-2023-48765" diff --git a/advisories/unreviewed/2023/12/GHSA-3q3v-9mp5-cqff/GHSA-3q3v-9mp5-cqff.json b/advisories/unreviewed/2023/12/GHSA-3q3v-9mp5-cqff/GHSA-3q3v-9mp5-cqff.json new file mode 100644 index 00000000000..c732274a2cf --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3q3v-9mp5-cqff/GHSA-3q3v-9mp5-cqff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q3v-9mp5-cqff", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46263" + ], + "details": "An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46263" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3v63-qv3r-29hp/GHSA-3v63-qv3r-29hp.json b/advisories/unreviewed/2023/12/GHSA-3v63-qv3r-29hp/GHSA-3v63-qv3r-29hp.json new file mode 100644 index 00000000000..5c9790e6906 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3v63-qv3r-29hp/GHSA-3v63-qv3r-29hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v63-qv3r-29hp", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46257" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46257" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json b/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json new file mode 100644 index 00000000000..31142eff618 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42rj-c8ww-p58f", + "modified": "2023-12-19T18:30:32Z", + "published": "2023-12-19T18:30:32Z", + "aliases": [ + "CVE-2023-50272" + ], + "details": "A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50272" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04584en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4gxg-f9jp-6c4f/GHSA-4gxg-f9jp-6c4f.json b/advisories/unreviewed/2023/12/GHSA-4gxg-f9jp-6c4f/GHSA-4gxg-f9jp-6c4f.json index 05a69c73770..99580cfd890 100644 --- a/advisories/unreviewed/2023/12/GHSA-4gxg-f9jp-6c4f/GHSA-4gxg-f9jp-6c4f.json +++ b/advisories/unreviewed/2023/12/GHSA-4gxg-f9jp-6c4f/GHSA-4gxg-f9jp-6c4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxg-f9jp-6c4f", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40657" ], "details": "A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-4hq7-4r72-pxrp/GHSA-4hq7-4r72-pxrp.json b/advisories/unreviewed/2023/12/GHSA-4hq7-4r72-pxrp/GHSA-4hq7-4r72-pxrp.json new file mode 100644 index 00000000000..fdbc72104fb --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4hq7-4r72-pxrp/GHSA-4hq7-4r72-pxrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hq7-4r72-pxrp", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46266" + ], + "details": "An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46266" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4mqm-8w5p-8gjq/GHSA-4mqm-8w5p-8gjq.json b/advisories/unreviewed/2023/12/GHSA-4mqm-8w5p-8gjq/GHSA-4mqm-8w5p-8gjq.json new file mode 100644 index 00000000000..67a6070f4b8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4mqm-8w5p-8gjq/GHSA-4mqm-8w5p-8gjq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mqm-8w5p-8gjq", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-44991" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files (Manual, Auto & AI).This issue affects Media File Renamer: Rename Files (Manual, Auto & AI): from n/a through 5.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44991" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/media-file-renamer/wordpress-media-file-renamer-plugin-5-6-9-sensitive-data-exposure-via-debug-log-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4x6r-c8c8-x44h/GHSA-4x6r-c8c8-x44h.json b/advisories/unreviewed/2023/12/GHSA-4x6r-c8c8-x44h/GHSA-4x6r-c8c8-x44h.json new file mode 100644 index 00000000000..ca4a0d2de4a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4x6r-c8c8-x44h/GHSA-4x6r-c8c8-x44h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x6r-c8c8-x44h", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46264" + ], + "details": "An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46264" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-5947-p758-5g99/GHSA-5947-p758-5g99.json b/advisories/unreviewed/2023/12/GHSA-5947-p758-5g99/GHSA-5947-p758-5g99.json index aaf8e8fe608..806d3f06047 100644 --- a/advisories/unreviewed/2023/12/GHSA-5947-p758-5g99/GHSA-5947-p758-5g99.json +++ b/advisories/unreviewed/2023/12/GHSA-5947-p758-5g99/GHSA-5947-p758-5g99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5947-p758-5g99", - "modified": "2023-12-14T00:30:26Z", + "modified": "2023-12-19T18:30:29Z", "published": "2023-12-14T00:30:26Z", "aliases": [ "CVE-2023-41618" ], "details": "Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T00:15:43Z" diff --git a/advisories/unreviewed/2023/12/GHSA-63cq-qp74-7w56/GHSA-63cq-qp74-7w56.json b/advisories/unreviewed/2023/12/GHSA-63cq-qp74-7w56/GHSA-63cq-qp74-7w56.json new file mode 100644 index 00000000000..3df49947cd3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-63cq-qp74-7w56/GHSA-63cq-qp74-7w56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63cq-qp74-7w56", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46259" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46259" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-63vr-qwf8-72qv/GHSA-63vr-qwf8-72qv.json b/advisories/unreviewed/2023/12/GHSA-63vr-qwf8-72qv/GHSA-63vr-qwf8-72qv.json index ed946c2ad6b..7baa50c11e3 100644 --- a/advisories/unreviewed/2023/12/GHSA-63vr-qwf8-72qv/GHSA-63vr-qwf8-72qv.json +++ b/advisories/unreviewed/2023/12/GHSA-63vr-qwf8-72qv/GHSA-63vr-qwf8-72qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63vr-qwf8-72qv", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-6366" diff --git a/advisories/unreviewed/2023/12/GHSA-678p-2fg5-j3m2/GHSA-678p-2fg5-j3m2.json b/advisories/unreviewed/2023/12/GHSA-678p-2fg5-j3m2/GHSA-678p-2fg5-j3m2.json index fb4675293d5..eae68b5ff5e 100644 --- a/advisories/unreviewed/2023/12/GHSA-678p-2fg5-j3m2/GHSA-678p-2fg5-j3m2.json +++ b/advisories/unreviewed/2023/12/GHSA-678p-2fg5-j3m2/GHSA-678p-2fg5-j3m2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-678p-2fg5-j3m2", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-6365" diff --git a/advisories/unreviewed/2023/12/GHSA-75vw-45w8-6h3g/GHSA-75vw-45w8-6h3g.json b/advisories/unreviewed/2023/12/GHSA-75vw-45w8-6h3g/GHSA-75vw-45w8-6h3g.json index 5825172fa74..48fd0722eb4 100644 --- a/advisories/unreviewed/2023/12/GHSA-75vw-45w8-6h3g/GHSA-75vw-45w8-6h3g.json +++ b/advisories/unreviewed/2023/12/GHSA-75vw-45w8-6h3g/GHSA-75vw-45w8-6h3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75vw-45w8-6h3g", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-47261" ], "details": "Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T17:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-769x-q5v4-m549/GHSA-769x-q5v4-m549.json b/advisories/unreviewed/2023/12/GHSA-769x-q5v4-m549/GHSA-769x-q5v4-m549.json new file mode 100644 index 00000000000..de3ad9245ac --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-769x-q5v4-m549/GHSA-769x-q5v4-m549.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-769x-q5v4-m549", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-25715" + ], + "details": "Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25715" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gamipress/wordpress-gamipress-plugin-2-5-6-missing-authorization-leading-to-points-manipulation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9jhh-hw56-3jhj/GHSA-9jhh-hw56-3jhj.json b/advisories/unreviewed/2023/12/GHSA-9jhh-hw56-3jhj/GHSA-9jhh-hw56-3jhj.json index 15f8e77c0f3..1eed127809c 100644 --- a/advisories/unreviewed/2023/12/GHSA-9jhh-hw56-3jhj/GHSA-9jhh-hw56-3jhj.json +++ b/advisories/unreviewed/2023/12/GHSA-9jhh-hw56-3jhj/GHSA-9jhh-hw56-3jhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jhh-hw56-3jhj", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-49707" ], "details": "SQLi vulnerability in S5 Register module for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:42Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9v38-vjvh-5jr4/GHSA-9v38-vjvh-5jr4.json b/advisories/unreviewed/2023/12/GHSA-9v38-vjvh-5jr4/GHSA-9v38-vjvh-5jr4.json index 220301868b4..3b4f18a1a06 100644 --- a/advisories/unreviewed/2023/12/GHSA-9v38-vjvh-5jr4/GHSA-9v38-vjvh-5jr4.json +++ b/advisories/unreviewed/2023/12/GHSA-9v38-vjvh-5jr4/GHSA-9v38-vjvh-5jr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v38-vjvh-5jr4", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40658" ], "details": "A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-c7vp-x3hm-mmrp/GHSA-c7vp-x3hm-mmrp.json b/advisories/unreviewed/2023/12/GHSA-c7vp-x3hm-mmrp/GHSA-c7vp-x3hm-mmrp.json new file mode 100644 index 00000000000..d24c33b7b91 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c7vp-x3hm-mmrp/GHSA-c7vp-x3hm-mmrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7vp-x3hm-mmrp", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46224" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46224" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c89h-4r84-43j7/GHSA-c89h-4r84-43j7.json b/advisories/unreviewed/2023/12/GHSA-c89h-4r84-43j7/GHSA-c89h-4r84-43j7.json new file mode 100644 index 00000000000..5dd6ac3bf2a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c89h-4r84-43j7/GHSA-c89h-4r84-43j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c89h-4r84-43j7", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46222" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46222" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-cf4w-jr22-49m6/GHSA-cf4w-jr22-49m6.json b/advisories/unreviewed/2023/12/GHSA-cf4w-jr22-49m6/GHSA-cf4w-jr22-49m6.json index 4ff2c59cfa1..db8a3b6db32 100644 --- a/advisories/unreviewed/2023/12/GHSA-cf4w-jr22-49m6/GHSA-cf4w-jr22-49m6.json +++ b/advisories/unreviewed/2023/12/GHSA-cf4w-jr22-49m6/GHSA-cf4w-jr22-49m6.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-cvfr-v5hr-8952/GHSA-cvfr-v5hr-8952.json b/advisories/unreviewed/2023/12/GHSA-cvfr-v5hr-8952/GHSA-cvfr-v5hr-8952.json new file mode 100644 index 00000000000..e82773e7b11 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-cvfr-v5hr-8952/GHSA-cvfr-v5hr-8952.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvfr-v5hr-8952", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46803" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46803" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-g5gh-w2mq-pjxv/GHSA-g5gh-w2mq-pjxv.json b/advisories/unreviewed/2023/12/GHSA-g5gh-w2mq-pjxv/GHSA-g5gh-w2mq-pjxv.json index 088f8b9a91f..525ae952ead 100644 --- a/advisories/unreviewed/2023/12/GHSA-g5gh-w2mq-pjxv/GHSA-g5gh-w2mq-pjxv.json +++ b/advisories/unreviewed/2023/12/GHSA-g5gh-w2mq-pjxv/GHSA-g5gh-w2mq-pjxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5gh-w2mq-pjxv", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40655" ], "details": "A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-gmf5-m5h7-48v7/GHSA-gmf5-m5h7-48v7.json b/advisories/unreviewed/2023/12/GHSA-gmf5-m5h7-48v7/GHSA-gmf5-m5h7-48v7.json new file mode 100644 index 00000000000..147d2a834ce --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gmf5-m5h7-48v7/GHSA-gmf5-m5h7-48v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmf5-m5h7-48v7", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46225" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46225" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gqvf-3hgp-5hxv/GHSA-gqvf-3hgp-5hxv.json b/advisories/unreviewed/2023/12/GHSA-gqvf-3hgp-5hxv/GHSA-gqvf-3hgp-5hxv.json index b37c4a68efc..c62e00e64b5 100644 --- a/advisories/unreviewed/2023/12/GHSA-gqvf-3hgp-5hxv/GHSA-gqvf-3hgp-5hxv.json +++ b/advisories/unreviewed/2023/12/GHSA-gqvf-3hgp-5hxv/GHSA-gqvf-3hgp-5hxv.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-hj3r-2hqm-4f6w/GHSA-hj3r-2hqm-4f6w.json b/advisories/unreviewed/2023/12/GHSA-hj3r-2hqm-4f6w/GHSA-hj3r-2hqm-4f6w.json new file mode 100644 index 00000000000..d8282fc3da3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hj3r-2hqm-4f6w/GHSA-hj3r-2hqm-4f6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj3r-2hqm-4f6w", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46262" + ], + "details": "An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46262" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hqx2-wc2c-3843/GHSA-hqx2-wc2c-3843.json b/advisories/unreviewed/2023/12/GHSA-hqx2-wc2c-3843/GHSA-hqx2-wc2c-3843.json new file mode 100644 index 00000000000..e1bfdfacedf --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hqx2-wc2c-3843/GHSA-hqx2-wc2c-3843.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqx2-wc2c-3843", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-46217" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46217" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jjp4-6rrm-wrm6/GHSA-jjp4-6rrm-wrm6.json b/advisories/unreviewed/2023/12/GHSA-jjp4-6rrm-wrm6/GHSA-jjp4-6rrm-wrm6.json new file mode 100644 index 00000000000..4c281a5caac --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-jjp4-6rrm-wrm6/GHSA-jjp4-6rrm-wrm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjp4-6rrm-wrm6", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-46216" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46216" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jr37-c5mp-55w3/GHSA-jr37-c5mp-55w3.json b/advisories/unreviewed/2023/12/GHSA-jr37-c5mp-55w3/GHSA-jr37-c5mp-55w3.json index 69abb8eeecb..9b4c6b53741 100644 --- a/advisories/unreviewed/2023/12/GHSA-jr37-c5mp-55w3/GHSA-jr37-c5mp-55w3.json +++ b/advisories/unreviewed/2023/12/GHSA-jr37-c5mp-55w3/GHSA-jr37-c5mp-55w3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr37-c5mp-55w3", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-49708" ], "details": "SQLi vulnerability in Starshop component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:42Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jvg2-h67f-h9rw/GHSA-jvg2-h67f-h9rw.json b/advisories/unreviewed/2023/12/GHSA-jvg2-h67f-h9rw/GHSA-jvg2-h67f-h9rw.json index eab2116dff3..281e2584cc8 100644 --- a/advisories/unreviewed/2023/12/GHSA-jvg2-h67f-h9rw/GHSA-jvg2-h67f-h9rw.json +++ b/advisories/unreviewed/2023/12/GHSA-jvg2-h67f-h9rw/GHSA-jvg2-h67f-h9rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvg2-h67f-h9rw", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40659" ], "details": "A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-m2v4-c7w8-gcjq/GHSA-m2v4-c7w8-gcjq.json b/advisories/unreviewed/2023/12/GHSA-m2v4-c7w8-gcjq/GHSA-m2v4-c7w8-gcjq.json new file mode 100644 index 00000000000..34bfdb3555f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-m2v4-c7w8-gcjq/GHSA-m2v4-c7w8-gcjq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2v4-c7w8-gcjq", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46260" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46260" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-m69c-xr2j-q82p/GHSA-m69c-xr2j-q82p.json b/advisories/unreviewed/2023/12/GHSA-m69c-xr2j-q82p/GHSA-m69c-xr2j-q82p.json index 5c62fdc91c9..5ef6e6cd280 100644 --- a/advisories/unreviewed/2023/12/GHSA-m69c-xr2j-q82p/GHSA-m69c-xr2j-q82p.json +++ b/advisories/unreviewed/2023/12/GHSA-m69c-xr2j-q82p/GHSA-m69c-xr2j-q82p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m69c-xr2j-q82p", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:29Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40629" ], "details": "SQLi vulnerability in LMS Lite component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json b/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json index 9edbdac3a6e..2a4de533c54 100644 --- a/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json +++ b/advisories/unreviewed/2023/12/GHSA-mh7x-8j8h-xvj8/GHSA-mh7x-8j8h-xvj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh7x-8j8h-xvj8", - "modified": "2023-12-15T18:30:29Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-15T18:30:29Z", "aliases": [ "CVE-2023-50918" ], "details": "app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-15T18:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mwj6-6ghh-97gx/GHSA-mwj6-6ghh-97gx.json b/advisories/unreviewed/2023/12/GHSA-mwj6-6ghh-97gx/GHSA-mwj6-6ghh-97gx.json new file mode 100644 index 00000000000..c37d2944b59 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mwj6-6ghh-97gx/GHSA-mwj6-6ghh-97gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwj6-6ghh-97gx", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46261" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46261" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-prgf-7pc3-3h2j/GHSA-prgf-7pc3-3h2j.json b/advisories/unreviewed/2023/12/GHSA-prgf-7pc3-3h2j/GHSA-prgf-7pc3-3h2j.json index 4377f3a278c..f96f30798e4 100644 --- a/advisories/unreviewed/2023/12/GHSA-prgf-7pc3-3h2j/GHSA-prgf-7pc3-3h2j.json +++ b/advisories/unreviewed/2023/12/GHSA-prgf-7pc3-3h2j/GHSA-prgf-7pc3-3h2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prgf-7pc3-3h2j", - "modified": "2023-12-14T09:30:19Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-40656" ], "details": "A reflected XSS vulnerability was discovered in the Quickform component for Joomla.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-14T09:15:41Z" diff --git a/advisories/unreviewed/2023/12/GHSA-rfhr-9grr-mhwq/GHSA-rfhr-9grr-mhwq.json b/advisories/unreviewed/2023/12/GHSA-rfhr-9grr-mhwq/GHSA-rfhr-9grr-mhwq.json index c44509d79f4..e889d912834 100644 --- a/advisories/unreviewed/2023/12/GHSA-rfhr-9grr-mhwq/GHSA-rfhr-9grr-mhwq.json +++ b/advisories/unreviewed/2023/12/GHSA-rfhr-9grr-mhwq/GHSA-rfhr-9grr-mhwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfhr-9grr-mhwq", - "modified": "2023-12-14T18:30:21Z", + "modified": "2023-12-19T18:30:30Z", "published": "2023-12-14T18:30:21Z", "aliases": [ "CVE-2023-6367" diff --git a/advisories/unreviewed/2023/12/GHSA-v4rx-vw37-jhmq/GHSA-v4rx-vw37-jhmq.json b/advisories/unreviewed/2023/12/GHSA-v4rx-vw37-jhmq/GHSA-v4rx-vw37-jhmq.json new file mode 100644 index 00000000000..69659af6335 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v4rx-vw37-jhmq/GHSA-v4rx-vw37-jhmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4rx-vw37-jhmq", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46220" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46220" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vr3j-fq3j-prvj/GHSA-vr3j-fq3j-prvj.json b/advisories/unreviewed/2023/12/GHSA-vr3j-fq3j-prvj/GHSA-vr3j-fq3j-prvj.json new file mode 100644 index 00000000000..a5e6dc3984a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vr3j-fq3j-prvj/GHSA-vr3j-fq3j-prvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr3j-fq3j-prvj", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46258" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46258" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vv3w-p5xw-r8c3/GHSA-vv3w-p5xw-r8c3.json b/advisories/unreviewed/2023/12/GHSA-vv3w-p5xw-r8c3/GHSA-vv3w-p5xw-r8c3.json new file mode 100644 index 00000000000..fc6e1ce3f38 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vv3w-p5xw-r8c3/GHSA-vv3w-p5xw-r8c3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv3w-p5xw-r8c3", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2023-37390" + ], + "details": "Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37390" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themesflat-addons-for-elementor/wordpress-themesflat-addons-for-elementor-plugin-2-0-0-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-w425-226c-79r3/GHSA-w425-226c-79r3.json b/advisories/unreviewed/2023/12/GHSA-w425-226c-79r3/GHSA-w425-226c-79r3.json new file mode 100644 index 00000000000..509c32b827f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-w425-226c-79r3/GHSA-w425-226c-79r3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w425-226c-79r3", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46221" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46221" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json b/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json new file mode 100644 index 00000000000..fa257780d47 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmh6-wh26-4mj9", + "modified": "2023-12-19T18:30:31Z", + "published": "2023-12-19T18:30:31Z", + "aliases": [ + "CVE-2023-46265" + ], + "details": "An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46265" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wphm-hq4w-gwj8/GHSA-wphm-hq4w-gwj8.json b/advisories/unreviewed/2023/12/GHSA-wphm-hq4w-gwj8/GHSA-wphm-hq4w-gwj8.json new file mode 100644 index 00000000000..01fe98ce1ab --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wphm-hq4w-gwj8/GHSA-wphm-hq4w-gwj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wphm-hq4w-gwj8", + "modified": "2023-12-19T18:30:30Z", + "published": "2023-12-19T18:30:30Z", + "aliases": [ + "CVE-2021-22962" + ], + "details": "An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22962" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xv5g-cq95-4rcm/GHSA-xv5g-cq95-4rcm.json b/advisories/unreviewed/2023/12/GHSA-xv5g-cq95-4rcm/GHSA-xv5g-cq95-4rcm.json new file mode 100644 index 00000000000..91566f60b74 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xv5g-cq95-4rcm/GHSA-xv5g-cq95-4rcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv5g-cq95-4rcm", + "modified": "2023-12-19T18:30:32Z", + "published": "2023-12-19T18:30:32Z", + "aliases": [ + "CVE-2023-46804" + ], + "details": "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46804" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-19T16:15:12Z" + } +} \ No newline at end of file