Publish Advisories

GHSA-4vx9-ghq5-84jw
GHSA-3c85-mx4x-435c
GHSA-62rj-gv2c-8ghr
GHSA-67c4-7f3g-r556
GHSA-8rfx-6mr3-5jh3
GHSA-f35j-mfvw-p857
GHSA-g3jm-7w7w-rf6f
GHSA-gjhc-6xm7-mc8q
GHSA-hf3r-vmrv-7w29
GHSA-q5pp-5q2h-g8rv
GHSA-wxj2-777f-vxmf
This commit is contained in:
advisory-database[bot]
2024-01-03 18:32:12 +00:00
parent 2e122d011e
commit c426b48759
11 changed files with 371 additions and 4 deletions
@@ -40,6 +40,10 @@
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5569"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176368/Chrome-BindTextSuggestionHostForFrame-Type-Confusion.html"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c85-mx4x-435c",
"modified": "2023-12-31T03:30:30Z",
"modified": "2024-01-03T18:30:50Z",
"published": "2023-12-25T00:30:17Z",
"aliases": [
"CVE-2023-7101"
@@ -30,6 +30,10 @@
"type": "WEB",
"url": "https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc"
},
{
"type": "WEB",
"url": "https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc"
},
{
"type": "WEB",
"url": "https://https://metacpan.org/dist/Spreadsheet-ParseExcel"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62rj-gv2c-8ghr",
"modified": "2023-12-22T18:30:30Z",
"modified": "2024-01-03T18:30:50Z",
"published": "2023-12-22T18:30:30Z",
"aliases": [
"CVE-2023-42465"
],
"details": "Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-22T16:15:08Z"
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-208"
],
"severity": "MODERATE",
@@ -0,0 +1,63 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rfx-6mr3-5jh3",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-21907"
],
"details": "Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21907"
},
{
"type": "WEB",
"url": "https://github.com/JamesNK/Newtonsoft.Json/issues/2457"
},
{
"type": "WEB",
"url": "https://github.com/JamesNK/Newtonsoft.Json/pull/2462"
},
{
"type": "WEB",
"url": "https://github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66"
},
{
"type": "WEB",
"url": "https://alephsecurity.com/2018/10/22/StackOverflowException/"
},
{
"type": "WEB",
"url": "https://alephsecurity.com/vulns/aleph-2018004"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-5crp-9r3c-p9vr"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr"
}
],
"database_specific": {
"cwe_ids": [
"CWE-755"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T16:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f35j-mfvw-p857",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2023-6004"
],
"details": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6004"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6004"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2251110"
},
{
"type": "WEB",
"url": "https://www.libssh.org/security/advisories/CVE-2023-6004.txt"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T17:15:11Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3jm-7w7w-rf6f",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-0217"
],
"details": "A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0217"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0217"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256624"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T17:15:12Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjhc-6xm7-mc8q",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-21908"
],
"details": "\nTinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.\n\n\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "WEB",
"url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-5h9g-x5rv-25wg"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21908"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-5h9g-x5rv-25wg"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-5h9g-x5rv-25wg"
},
{
"type": "WEB",
"url": "https://www.tiny.cloud/docs/release-notes/release-notes59/#securityfixes"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T16:15:08Z"
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf3r-vmrv-7w29",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-21909"
],
"details": "PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "WEB",
"url": "https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21909"
},
{
"type": "WEB",
"url": "https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-6r92-cgxc-r5fg"
},
{
"type": "WEB",
"url": "https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg"
}
],
"database_specific": {
"cwe_ids": [
"CWE-407"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T16:15:09Z"
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5pp-5q2h-g8rv",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-21911"
],
"details": "TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "WEB",
"url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-w7jx-j77m-wp65"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21911"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-w7jx-j77m-wp65"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-w7jx-j77m-wp65"
},
{
"type": "WEB",
"url": "https://www.npmjs.com/package/tinymce"
},
{
"type": "WEB",
"url": "https://www.tiny.cloud/docs/release-notes/release-notes56/#securityfixes"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T16:15:09Z"
}
}
@@ -0,0 +1,55 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxj2-777f-vxmf",
"modified": "2024-01-03T18:30:51Z",
"published": "2024-01-03T18:30:51Z",
"aliases": [
"CVE-2024-21910"
],
"details": "TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "WEB",
"url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21910"
},
{
"type": "WEB",
"url": "https://github.com/jazzband/django-tinymce/issues/366"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-r8hm-w5f7-wj39"
},
{
"type": "WEB",
"url": "https://github.com/jazzband/django-tinymce/releases/tag/3.4.0"
},
{
"type": "WEB",
"url": "https://pypi.org/project/django-tinymce/3.4.0/"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-03T16:15:09Z"
}
}