diff --git a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json index d8a30841871..2b31cd645f0 100644 --- a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json +++ b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0423" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0580" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34966" diff --git a/advisories/unreviewed/2023/07/GHSA-786x-44fx-qqh8/GHSA-786x-44fx-qqh8.json b/advisories/unreviewed/2023/07/GHSA-786x-44fx-qqh8/GHSA-786x-44fx-qqh8.json index 133f6d3f4c6..afba3350737 100644 --- a/advisories/unreviewed/2023/07/GHSA-786x-44fx-qqh8/GHSA-786x-44fx-qqh8.json +++ b/advisories/unreviewed/2023/07/GHSA-786x-44fx-qqh8/GHSA-786x-44fx-qqh8.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0404" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0569" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3019" diff --git a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json index 464daecdc30..27392eef60d 100644 --- a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json +++ b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x98-4rw8-872g", - "modified": "2024-01-25T21:32:11Z", + "modified": "2024-01-30T18:30:18Z", "published": "2023-07-25T18:30:32Z", "aliases": [ "CVE-2023-3772" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0412" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0575" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3772" diff --git a/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json b/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json index e2b19288ba3..6f4c5e1ffa9 100644 --- a/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json +++ b/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0423" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0580" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34967" diff --git a/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json b/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json index 168742b52c3..92e0c2ee686 100644 --- a/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json +++ b/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0423" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0580" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34968" diff --git a/advisories/unreviewed/2023/07/GHSA-cgvp-6hhh-fqwh/GHSA-cgvp-6hhh-fqwh.json b/advisories/unreviewed/2023/07/GHSA-cgvp-6hhh-fqwh/GHSA-cgvp-6hhh-fqwh.json index b07b85b1957..1d48b79afb8 100644 --- a/advisories/unreviewed/2023/07/GHSA-cgvp-6hhh-fqwh/GHSA-cgvp-6hhh-fqwh.json +++ b/advisories/unreviewed/2023/07/GHSA-cgvp-6hhh-fqwh/GHSA-cgvp-6hhh-fqwh.json @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0448" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0575" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3567" diff --git a/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json b/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json index bfa0159c6d1..6fbb7588089 100644 --- a/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json +++ b/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0423" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0580" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2022-2127" diff --git a/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json b/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json index 42197784e2e..16c63651649 100644 --- a/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json +++ b/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4mv-7g6h-5vh8", - "modified": "2024-01-30T06:30:22Z", + "modified": "2024-01-30T18:30:18Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-3812" @@ -85,6 +85,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0554" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0562" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0563" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0575" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0593" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3812" diff --git a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json index 173f43c3454..88f827402d3 100644 --- a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json +++ b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7077" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0575" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4132" diff --git a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json index 66eb6d86ffb..c2d4b0c4cf2 100644 --- a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json +++ b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json @@ -105,6 +105,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0461" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0562" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0563" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0593" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-42753" diff --git a/advisories/unreviewed/2023/11/GHSA-xr9j-c7v6-7542/GHSA-xr9j-c7v6-7542.json b/advisories/unreviewed/2023/11/GHSA-xr9j-c7v6-7542/GHSA-xr9j-c7v6-7542.json index 5569efda6b3..7eb9682fcab 100644 --- a/advisories/unreviewed/2023/11/GHSA-xr9j-c7v6-7542/GHSA-xr9j-c7v6-7542.json +++ b/advisories/unreviewed/2023/11/GHSA-xr9j-c7v6-7542/GHSA-xr9j-c7v6-7542.json @@ -89,6 +89,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0554" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0575" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5178" diff --git a/advisories/unreviewed/2024/01/GHSA-2m5x-r2g7-72x8/GHSA-2m5x-r2g7-72x8.json b/advisories/unreviewed/2024/01/GHSA-2m5x-r2g7-72x8/GHSA-2m5x-r2g7-72x8.json new file mode 100644 index 00000000000..11f92b952dc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2m5x-r2g7-72x8/GHSA-2m5x-r2g7-72x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m5x-r2g7-72x8", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2023-46230" + ], + "details": "In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46230" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-0111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-33p8-v8q2-mx53/GHSA-33p8-v8q2-mx53.json b/advisories/unreviewed/2024/01/GHSA-33p8-v8q2-mx53/GHSA-33p8-v8q2-mx53.json index a6d7610bc36..0c660b89b6f 100644 --- a/advisories/unreviewed/2024/01/GHSA-33p8-v8q2-mx53/GHSA-33p8-v8q2-mx53.json +++ b/advisories/unreviewed/2024/01/GHSA-33p8-v8q2-mx53/GHSA-33p8-v8q2-mx53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-33p8-v8q2-mx53", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47196" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47197.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json b/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json index a97473e2604..51013267f94 100644 --- a/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json +++ b/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3568-h36m-7jmf", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0749" ], "details": "A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json index 4143639a1d7..83f5f837626 100644 --- a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json +++ b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h6x-952r-xr8p", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23213" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. Processing web content may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json b/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json new file mode 100644 index 00000000000..72778ee6cae --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rhq-47cj-h9g4", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2024-21388" + ], + "details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21388" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21388" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json index 90239d2bce3..fcbfc5601d3 100644 --- a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json +++ b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4287-v2hm-q9f2", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23214" ], "details": "Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json b/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json index 5654b28cf56..55396aaef9f 100644 --- a/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json +++ b/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46g9-6366-qgqc", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23211" ], "details": "A privacy issue was addressed with improved handling of user preferences. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. A user's private browsing activity may be visible in Settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json index c1d49493131..7067cd638b5 100644 --- a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json +++ b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/30/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-6jhr-xfqr-826m/GHSA-6jhr-xfqr-826m.json b/advisories/unreviewed/2024/01/GHSA-6jhr-xfqr-826m/GHSA-6jhr-xfqr-826m.json index 176d34a1ea8..c39fa693215 100644 --- a/advisories/unreviewed/2024/01/GHSA-6jhr-xfqr-826m/GHSA-6jhr-xfqr-826m.json +++ b/advisories/unreviewed/2024/01/GHSA-6jhr-xfqr-826m/GHSA-6jhr-xfqr-826m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jhr-xfqr-826m", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-47200" ], "details": "A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47201.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json b/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json index dc659115421..d994cce3e90 100644 --- a/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json +++ b/advisories/unreviewed/2024/01/GHSA-7299-g634-x782/GHSA-7299-g634-x782.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7299-g634-x782", - "modified": "2024-01-23T12:30:30Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T12:30:30Z", "aliases": [ "CVE-2024-22076" ], "details": "MyQ Print Server before 8.2 patch 43 allows Unauthenticated Remote Code Execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T11:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7jq7-8r3x-pjjq/GHSA-7jq7-8r3x-pjjq.json b/advisories/unreviewed/2024/01/GHSA-7jq7-8r3x-pjjq/GHSA-7jq7-8r3x-pjjq.json index ee5b9683390..e09119eadc6 100644 --- a/advisories/unreviewed/2024/01/GHSA-7jq7-8r3x-pjjq/GHSA-7jq7-8r3x-pjjq.json +++ b/advisories/unreviewed/2024/01/GHSA-7jq7-8r3x-pjjq/GHSA-7jq7-8r3x-pjjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jq7-8r3x-pjjq", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0753" ], "details": "In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7pvg-hvr4-rj6w/GHSA-7pvg-hvr4-rj6w.json b/advisories/unreviewed/2024/01/GHSA-7pvg-hvr4-rj6w/GHSA-7pvg-hvr4-rj6w.json new file mode 100644 index 00000000000..9de7e9281d5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7pvg-hvr4-rj6w/GHSA-7pvg-hvr4-rj6w.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pvg-hvr4-rj6w", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2024-1036" + ], + "details": "A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the component Icon Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252311.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1036" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/X1ASzPP5rHel" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252311" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252311" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7qfc-6cw5-2ppm/GHSA-7qfc-6cw5-2ppm.json b/advisories/unreviewed/2024/01/GHSA-7qfc-6cw5-2ppm/GHSA-7qfc-6cw5-2ppm.json index a16e1daaadf..6551334e86a 100644 --- a/advisories/unreviewed/2024/01/GHSA-7qfc-6cw5-2ppm/GHSA-7qfc-6cw5-2ppm.json +++ b/advisories/unreviewed/2024/01/GHSA-7qfc-6cw5-2ppm/GHSA-7qfc-6cw5-2ppm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7qfc-6cw5-2ppm", - "modified": "2024-01-19T18:30:28Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-19T18:30:28Z", "aliases": [ "CVE-2023-47033" ], "details": "MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-19T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json index 0526ccb65a4..c2243eb9e3d 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json +++ b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g27-wpjg-5vv9", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23217" ], "details": "A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. An app may be able to bypass certain Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8j8p-j2w4-2qvh/GHSA-8j8p-j2w4-2qvh.json b/advisories/unreviewed/2024/01/GHSA-8j8p-j2w4-2qvh/GHSA-8j8p-j2w4-2qvh.json index 059c79a0a08..464decb5a7a 100644 --- a/advisories/unreviewed/2024/01/GHSA-8j8p-j2w4-2qvh/GHSA-8j8p-j2w4-2qvh.json +++ b/advisories/unreviewed/2024/01/GHSA-8j8p-j2w4-2qvh/GHSA-8j8p-j2w4-2qvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j8p-j2w4-2qvh", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47192" ], "details": "An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-93gv-w5cx-phvx/GHSA-93gv-w5cx-phvx.json b/advisories/unreviewed/2024/01/GHSA-93gv-w5cx-phvx/GHSA-93gv-w5cx-phvx.json index 450b4e39668..9aa6d0c8f99 100644 --- a/advisories/unreviewed/2024/01/GHSA-93gv-w5cx-phvx/GHSA-93gv-w5cx-phvx.json +++ b/advisories/unreviewed/2024/01/GHSA-93gv-w5cx-phvx/GHSA-93gv-w5cx-phvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93gv-w5cx-phvx", - "modified": "2024-01-23T15:30:57Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:57Z", "aliases": [ "CVE-2024-0745" ], "details": "The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9fhq-2p6p-h9p8/GHSA-9fhq-2p6p-h9p8.json b/advisories/unreviewed/2024/01/GHSA-9fhq-2p6p-h9p8/GHSA-9fhq-2p6p-h9p8.json new file mode 100644 index 00000000000..6f0b7d8fad8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9fhq-2p6p-h9p8/GHSA-9fhq-2p6p-h9p8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhq-2p6p-h9p8", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2024-1035" + ], + "details": "A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252310 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1035" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/AIbnbytIW9Bq" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252310" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252310" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9gjc-h498-ff34/GHSA-9gjc-h498-ff34.json b/advisories/unreviewed/2024/01/GHSA-9gjc-h498-ff34/GHSA-9gjc-h498-ff34.json index c0bea285ab0..c9fa2e3e0be 100644 --- a/advisories/unreviewed/2024/01/GHSA-9gjc-h498-ff34/GHSA-9gjc-h498-ff34.json +++ b/advisories/unreviewed/2024/01/GHSA-9gjc-h498-ff34/GHSA-9gjc-h498-ff34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gjc-h498-ff34", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52094" ], "details": "An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json b/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json index a05bb1c2d90..df54c24a529 100644 --- a/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json +++ b/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8vm-23j7-pf2r", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23218" ], "details": "A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f96h-7c9x-735r/GHSA-f96h-7c9x-735r.json b/advisories/unreviewed/2024/01/GHSA-f96h-7c9x-735r/GHSA-f96h-7c9x-735r.json index f8769f45489..f0a1c08f7cc 100644 --- a/advisories/unreviewed/2024/01/GHSA-f96h-7c9x-735r/GHSA-f96h-7c9x-735r.json +++ b/advisories/unreviewed/2024/01/GHSA-f96h-7c9x-735r/GHSA-f96h-7c9x-735r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f96h-7c9x-735r", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47193" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47194.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json index a8133ac3a67..738624d294e 100644 --- a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json +++ b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json @@ -64,6 +64,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/30/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-g78p-m98v-8prx/GHSA-g78p-m98v-8prx.json b/advisories/unreviewed/2024/01/GHSA-g78p-m98v-8prx/GHSA-g78p-m98v-8prx.json new file mode 100644 index 00000000000..b474ca58a87 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g78p-m98v-8prx/GHSA-g78p-m98v-8prx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g78p-m98v-8prx", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2023-46231" + ], + "details": "In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46231" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-0110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json b/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json index 2d29bb2a72d..c92daa69b4d 100644 --- a/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json +++ b/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3x8-jx27-7vw4", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23210" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to view a user's phone number in system logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json b/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json index 2a1d7069148..beb574e4b97 100644 --- a/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json +++ b/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6xq-j8xx-3fv4", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0754" ], "details": "Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-j2wh-3mg8-x62m/GHSA-j2wh-3mg8-x62m.json b/advisories/unreviewed/2024/01/GHSA-j2wh-3mg8-x62m/GHSA-j2wh-3mg8-x62m.json index 31b42aa545e..1875c249a4b 100644 --- a/advisories/unreviewed/2024/01/GHSA-j2wh-3mg8-x62m/GHSA-j2wh-3mg8-x62m.json +++ b/advisories/unreviewed/2024/01/GHSA-j2wh-3mg8-x62m/GHSA-j2wh-3mg8-x62m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2wh-3mg8-x62m", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:20Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47198" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47199.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json new file mode 100644 index 00000000000..dda92213d8e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3rg-72x7-gm5r", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2023-37518" + ], + "details": "HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37518" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110202" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jm27-8g8p-3jmp/GHSA-jm27-8g8p-3jmp.json b/advisories/unreviewed/2024/01/GHSA-jm27-8g8p-3jmp/GHSA-jm27-8g8p-3jmp.json index 49ce71bff97..995ead1d8f8 100644 --- a/advisories/unreviewed/2024/01/GHSA-jm27-8g8p-3jmp/GHSA-jm27-8g8p-3jmp.json +++ b/advisories/unreviewed/2024/01/GHSA-jm27-8g8p-3jmp/GHSA-jm27-8g8p-3jmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm27-8g8p-3jmp", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47194" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47195.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json b/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json index 384edc59b83..53c39051325 100644 --- a/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json +++ b/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx5w-px6r-88w4", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0747" ], "details": "When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mff6-fp66-7vrp/GHSA-mff6-fp66-7vrp.json b/advisories/unreviewed/2024/01/GHSA-mff6-fp66-7vrp/GHSA-mff6-fp66-7vrp.json index 5558b2124d9..9a1dfa7bae3 100644 --- a/advisories/unreviewed/2024/01/GHSA-mff6-fp66-7vrp/GHSA-mff6-fp66-7vrp.json +++ b/advisories/unreviewed/2024/01/GHSA-mff6-fp66-7vrp/GHSA-mff6-fp66-7vrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mff6-fp66-7vrp", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0752" ], "details": "A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mgr5-ggf9-pgjr/GHSA-mgr5-ggf9-pgjr.json b/advisories/unreviewed/2024/01/GHSA-mgr5-ggf9-pgjr/GHSA-mgr5-ggf9-pgjr.json index ad9b76b5f68..b5cfdc0afd0 100644 --- a/advisories/unreviewed/2024/01/GHSA-mgr5-ggf9-pgjr/GHSA-mgr5-ggf9-pgjr.json +++ b/advisories/unreviewed/2024/01/GHSA-mgr5-ggf9-pgjr/GHSA-mgr5-ggf9-pgjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgr5-ggf9-pgjr", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47195" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47196.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mmx8-j2r4-x8r6/GHSA-mmx8-j2r4-x8r6.json b/advisories/unreviewed/2024/01/GHSA-mmx8-j2r4-x8r6/GHSA-mmx8-j2r4-x8r6.json index 579c20a6c61..883d12a9f4f 100644 --- a/advisories/unreviewed/2024/01/GHSA-mmx8-j2r4-x8r6/GHSA-mmx8-j2r4-x8r6.json +++ b/advisories/unreviewed/2024/01/GHSA-mmx8-j2r4-x8r6/GHSA-mmx8-j2r4-x8r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmx8-j2r4-x8r6", - "modified": "2024-01-19T18:30:29Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-19T18:30:29Z", "aliases": [ "CVE-2023-47034" ], "details": "A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-19T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mvvq-wfcg-vq6m/GHSA-mvvq-wfcg-vq6m.json b/advisories/unreviewed/2024/01/GHSA-mvvq-wfcg-vq6m/GHSA-mvvq-wfcg-vq6m.json index 12a8a0c1ee2..8fbdc5c8bca 100644 --- a/advisories/unreviewed/2024/01/GHSA-mvvq-wfcg-vq6m/GHSA-mvvq-wfcg-vq6m.json +++ b/advisories/unreviewed/2024/01/GHSA-mvvq-wfcg-vq6m/GHSA-mvvq-wfcg-vq6m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvvq-wfcg-vq6m", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0751" ], "details": "A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json b/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json index 881782a16ee..dcd132ffae5 100644 --- a/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json +++ b/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json @@ -25,6 +25,26 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0320" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0557" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0558" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0597" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0607" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0614" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6816" diff --git a/advisories/unreviewed/2024/01/GHSA-phf3-25c6-93hv/GHSA-phf3-25c6-93hv.json b/advisories/unreviewed/2024/01/GHSA-phf3-25c6-93hv/GHSA-phf3-25c6-93hv.json new file mode 100644 index 00000000000..f171dcaad0a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-phf3-25c6-93hv/GHSA-phf3-25c6-93hv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phf3-25c6-93hv", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2023-6258" + ], + "details": "A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6258" + }, + { + "type": "WEB", + "url": "https://github.com/latchset/pkcs11-provider/pull/308" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2251062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1300" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pw8j-6xcp-c453/GHSA-pw8j-6xcp-c453.json b/advisories/unreviewed/2024/01/GHSA-pw8j-6xcp-c453/GHSA-pw8j-6xcp-c453.json index 36a34b2d1b3..776b6d5e118 100644 --- a/advisories/unreviewed/2024/01/GHSA-pw8j-6xcp-c453/GHSA-pw8j-6xcp-c453.json +++ b/advisories/unreviewed/2024/01/GHSA-pw8j-6xcp-c453/GHSA-pw8j-6xcp-c453.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw8j-6xcp-c453", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0750" ], "details": "A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json b/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json index 74ee3f6142e..fab6e66cbc8 100644 --- a/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json +++ b/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh5h-jvwg-m9xw", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23215" ], "details": "An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json b/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json index ae51595727f..86256dad1e8 100644 --- a/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json +++ b/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwm3-5pgj-28qh", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23212" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -79,7 +82,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json b/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json index 0b4a5af508a..8b4539e3628 100644 --- a/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json +++ b/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2mg-qw96-w89q", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23208" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rf89-gmj8-r696/GHSA-rf89-gmj8-r696.json b/advisories/unreviewed/2024/01/GHSA-rf89-gmj8-r696/GHSA-rf89-gmj8-r696.json index a2d410b84d7..783f89ade98 100644 --- a/advisories/unreviewed/2024/01/GHSA-rf89-gmj8-r696/GHSA-rf89-gmj8-r696.json +++ b/advisories/unreviewed/2024/01/GHSA-rf89-gmj8-r696/GHSA-rf89-gmj8-r696.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf89-gmj8-r696", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-47197" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47198.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-vw65-ccrc-xmfw/GHSA-vw65-ccrc-xmfw.json b/advisories/unreviewed/2024/01/GHSA-vw65-ccrc-xmfw/GHSA-vw65-ccrc-xmfw.json index 5568e9e8376..973135eda67 100644 --- a/advisories/unreviewed/2024/01/GHSA-vw65-ccrc-xmfw/GHSA-vw65-ccrc-xmfw.json +++ b/advisories/unreviewed/2024/01/GHSA-vw65-ccrc-xmfw/GHSA-vw65-ccrc-xmfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vw65-ccrc-xmfw", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0746" ], "details": "A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json b/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json new file mode 100644 index 00000000000..9cab0f33f97 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w56r-g989-xqw3/GHSA-w56r-g989-xqw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w56r-g989-xqw3", + "modified": "2024-01-30T18:30:20Z", + "published": "2024-01-30T18:30:20Z", + "aliases": [ + "CVE-2024-1019" + ], + "details": "ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1019" + }, + { + "type": "WEB", + "url": "https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json b/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json index 5991a167f21..d75a1e71233 100644 --- a/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json +++ b/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x73f-6qwm-hh3x", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-30T18:30:19Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0748" ], "details": "A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z"