Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-11-08 18:31:47 +00:00
parent 1effb44466
commit bd49eefd05
42 changed files with 795 additions and 86 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq2f-69mj-r56v",
"modified": "2023-06-16T18:30:33Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-06-09T21:30:26Z",
"aliases": [
"CVE-2023-27706"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-312"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-09T19:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-279q-vh9q-c9w4",
"modified": "2023-10-31T15:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T15:30:23Z",
"aliases": [
"CVE-2023-4823"
],
"details": "The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T14:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42cp-342j-hw3x",
"modified": "2023-10-31T15:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T15:30:23Z",
"aliases": [
"CVE-2023-4390"
],
"details": "The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T14:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qwg-3cm6-6646",
"modified": "2023-10-31T12:30:24Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T12:30:24Z",
"aliases": [
"CVE-2015-2968"
],
"details": "LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,11 +32,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-924"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T10:15:08Z"
}
}
@@ -36,11 +36,12 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
"CWE-434",
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T15:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-895w-8xj4-27h7",
"modified": "2023-10-01T00:30:18Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-01T00:30:18Z",
"aliases": [
"CVE-2023-43724"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-30T22:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9m44-8f44-6rgm",
"modified": "2023-10-31T03:31:22Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T03:31:22Z",
"aliases": [
"CVE-2023-45899"
],
"details": "An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-31T02:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xm2-c28x-g93r",
"modified": "2023-10-31T12:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T12:30:23Z",
"aliases": [
"CVE-2015-0897"
],
"details": "LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,11 +32,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-924"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T10:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g55h-gq76-w8v9",
"modified": "2023-10-31T18:31:44Z",
"modified": "2023-11-08T18:30:31Z",
"published": "2023-10-31T18:31:44Z",
"aliases": [
"CVE-2023-37831"
],
"details": "An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T18:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grc3-9hxr-2h57",
"modified": "2023-10-31T21:32:35Z",
"modified": "2023-11-08T18:30:31Z",
"published": "2023-10-31T21:32:35Z",
"aliases": [
"CVE-2023-39610"
],
"details": "An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T21:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh46-rmg6-r59w",
"modified": "2023-10-31T06:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T06:30:23Z",
"aliases": [
"CVE-2023-47174"
],
"details": "Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T04:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj8j-m6ch-fccm",
"modified": "2023-10-01T00:30:18Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-01T00:30:18Z",
"aliases": [
"CVE-2023-43726"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-30T22:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpxh-9vrg-gqx5",
"modified": "2023-10-01T00:30:18Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-01T00:30:18Z",
"aliases": [
"CVE-2023-43718"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-30T22:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mrhc-jwc8-xfc6",
"modified": "2023-10-31T21:32:35Z",
"modified": "2023-11-08T18:30:31Z",
"published": "2023-10-31T21:32:35Z",
"aliases": [
"CVE-2023-43295"
],
"details": "Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T21:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p2rj-m2c8-2vm5",
"modified": "2023-10-31T15:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T15:30:23Z",
"aliases": [
"CVE-2023-4251"
],
"details": "The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T14:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6p3-mrgw-429v",
"modified": "2023-10-31T15:30:24Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T15:30:24Z",
"aliases": [
"CVE-2023-46993"
],
"details": "In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T15:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxp2-xrrh-x42h",
"modified": "2023-10-31T06:30:23Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T06:30:23Z",
"aliases": [
"CVE-2023-36263"
@@ -28,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T05:15:58Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5g2-x587-cc7c",
"modified": "2023-10-31T15:30:24Z",
"modified": "2023-11-08T18:30:30Z",
"published": "2023-10-31T15:30:24Z",
"aliases": [
"CVE-2023-46992"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T15:15:09Z"
}
}
@@ -33,6 +33,6 @@
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T21:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5x7-5rc8-h4m4",
"modified": "2023-10-31T18:31:44Z",
"modified": "2023-11-08T18:30:31Z",
"published": "2023-10-31T18:31:44Z",
"aliases": [
"CVE-2023-5739"
],
"details": "Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T16:15:10Z"
}
}

Some files were not shown because too many files have changed in this diff Show More