From c426b4875922372dbf139153913c59d4906c9980 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jan 2024 18:32:12 +0000 Subject: [PATCH] Publish Advisories GHSA-4vx9-ghq5-84jw GHSA-3c85-mx4x-435c GHSA-62rj-gv2c-8ghr GHSA-67c4-7f3g-r556 GHSA-8rfx-6mr3-5jh3 GHSA-f35j-mfvw-p857 GHSA-g3jm-7w7w-rf6f GHSA-gjhc-6xm7-mc8q GHSA-hf3r-vmrv-7w29 GHSA-q5pp-5q2h-g8rv GHSA-wxj2-777f-vxmf --- .../GHSA-4vx9-ghq5-84jw.json | 4 ++ .../GHSA-3c85-mx4x-435c.json | 6 +- .../GHSA-62rj-gv2c-8ghr.json | 9 ++- .../GHSA-67c4-7f3g-r556.json | 1 + .../GHSA-8rfx-6mr3-5jh3.json | 63 +++++++++++++++++++ .../GHSA-f35j-mfvw-p857.json | 46 ++++++++++++++ .../GHSA-g3jm-7w7w-rf6f.json | 42 +++++++++++++ .../GHSA-gjhc-6xm7-mc8q.json | 47 ++++++++++++++ .../GHSA-hf3r-vmrv-7w29.json | 51 +++++++++++++++ .../GHSA-q5pp-5q2h-g8rv.json | 51 +++++++++++++++ .../GHSA-wxj2-777f-vxmf.json | 55 ++++++++++++++++ 11 files changed, 371 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-8rfx-6mr3-5jh3/GHSA-8rfx-6mr3-5jh3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json create mode 100644 advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gjhc-6xm7-mc8q/GHSA-gjhc-6xm7-mc8q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json create mode 100644 advisories/unreviewed/2024/01/GHSA-q5pp-5q2h-g8rv/GHSA-q5pp-5q2h-g8rv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wxj2-777f-vxmf/GHSA-wxj2-777f-vxmf.json diff --git a/advisories/unreviewed/2023/11/GHSA-4vx9-ghq5-84jw/GHSA-4vx9-ghq5-84jw.json b/advisories/unreviewed/2023/11/GHSA-4vx9-ghq5-84jw/GHSA-4vx9-ghq5-84jw.json index 1a8915a3342..79dd34bae4f 100644 --- a/advisories/unreviewed/2023/11/GHSA-4vx9-ghq5-84jw/GHSA-4vx9-ghq5-84jw.json +++ b/advisories/unreviewed/2023/11/GHSA-4vx9-ghq5-84jw/GHSA-4vx9-ghq5-84jw.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5569" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176368/Chrome-BindTextSuggestionHostForFrame-Type-Confusion.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json index 2af1989f44a..21b16258c3f 100644 --- a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json +++ b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3c85-mx4x-435c", - "modified": "2023-12-31T03:30:30Z", + "modified": "2024-01-03T18:30:50Z", "published": "2023-12-25T00:30:17Z", "aliases": [ "CVE-2023-7101" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc" }, + { + "type": "WEB", + "url": "https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc" + }, { "type": "WEB", "url": "https://https://metacpan.org/dist/Spreadsheet-ParseExcel" diff --git a/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json b/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json index 6eb12a15b46..d7aaa87882e 100644 --- a/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json +++ b/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62rj-gv2c-8ghr", - "modified": "2023-12-22T18:30:30Z", + "modified": "2024-01-03T18:30:50Z", "published": "2023-12-22T18:30:30Z", "aliases": [ "CVE-2023-42465" ], "details": "Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-22T16:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-67c4-7f3g-r556/GHSA-67c4-7f3g-r556.json b/advisories/unreviewed/2023/12/GHSA-67c4-7f3g-r556/GHSA-67c4-7f3g-r556.json index 26170d8489e..8a72a0f0771 100644 --- a/advisories/unreviewed/2023/12/GHSA-67c4-7f3g-r556/GHSA-67c4-7f3g-r556.json +++ b/advisories/unreviewed/2023/12/GHSA-67c4-7f3g-r556/GHSA-67c4-7f3g-r556.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-208" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-8rfx-6mr3-5jh3/GHSA-8rfx-6mr3-5jh3.json b/advisories/unreviewed/2024/01/GHSA-8rfx-6mr3-5jh3/GHSA-8rfx-6mr3-5jh3.json new file mode 100644 index 00000000000..f9d0a0633df --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8rfx-6mr3-5jh3/GHSA-8rfx-6mr3-5jh3.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rfx-6mr3-5jh3", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-21907" + ], + "details": "Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21907" + }, + { + "type": "WEB", + "url": "https://github.com/JamesNK/Newtonsoft.Json/issues/2457" + }, + { + "type": "WEB", + "url": "https://github.com/JamesNK/Newtonsoft.Json/pull/2462" + }, + { + "type": "WEB", + "url": "https://github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66" + }, + { + "type": "WEB", + "url": "https://alephsecurity.com/2018/10/22/StackOverflowException/" + }, + { + "type": "WEB", + "url": "https://alephsecurity.com/vulns/aleph-2018004" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-5crp-9r3c-p9vr" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json b/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json new file mode 100644 index 00000000000..9492ff9e8a4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f35j-mfvw-p857/GHSA-f35j-mfvw-p857.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f35j-mfvw-p857", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2023-6004" + ], + "details": "A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6004" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6004" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2251110" + }, + { + "type": "WEB", + "url": "https://www.libssh.org/security/advisories/CVE-2023-6004.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json b/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json new file mode 100644 index 00000000000..1e739b8611e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3jm-7w7w-rf6f", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-0217" + ], + "details": "A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0217" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0217" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256624" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gjhc-6xm7-mc8q/GHSA-gjhc-6xm7-mc8q.json b/advisories/unreviewed/2024/01/GHSA-gjhc-6xm7-mc8q/GHSA-gjhc-6xm7-mc8q.json new file mode 100644 index 00000000000..142541b9047 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gjhc-6xm7-mc8q/GHSA-gjhc-6xm7-mc8q.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjhc-6xm7-mc8q", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-21908" + ], + "details": "\nTinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-5h9g-x5rv-25wg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21908" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-5h9g-x5rv-25wg" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-5h9g-x5rv-25wg" + }, + { + "type": "WEB", + "url": "https://www.tiny.cloud/docs/release-notes/release-notes59/#securityfixes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json b/advisories/unreviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json new file mode 100644 index 00000000000..a48087a3c44 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf3r-vmrv-7w29", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-21909" + ], + "details": "PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21909" + }, + { + "type": "WEB", + "url": "https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6r92-cgxc-r5fg" + }, + { + "type": "WEB", + "url": "https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q5pp-5q2h-g8rv/GHSA-q5pp-5q2h-g8rv.json b/advisories/unreviewed/2024/01/GHSA-q5pp-5q2h-g8rv/GHSA-q5pp-5q2h-g8rv.json new file mode 100644 index 00000000000..74badd0ec78 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q5pp-5q2h-g8rv/GHSA-q5pp-5q2h-g8rv.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5pp-5q2h-g8rv", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-21911" + ], + "details": "TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-w7jx-j77m-wp65" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21911" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-w7jx-j77m-wp65" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-w7jx-j77m-wp65" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/tinymce" + }, + { + "type": "WEB", + "url": "https://www.tiny.cloud/docs/release-notes/release-notes56/#securityfixes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wxj2-777f-vxmf/GHSA-wxj2-777f-vxmf.json b/advisories/unreviewed/2024/01/GHSA-wxj2-777f-vxmf/GHSA-wxj2-777f-vxmf.json new file mode 100644 index 00000000000..4560272b446 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wxj2-777f-vxmf/GHSA-wxj2-777f-vxmf.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxj2-777f-vxmf", + "modified": "2024-01-03T18:30:51Z", + "published": "2024-01-03T18:30:51Z", + "aliases": [ + "CVE-2024-21910" + ], + "details": "TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21910" + }, + { + "type": "WEB", + "url": "https://github.com/jazzband/django-tinymce/issues/366" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-r8hm-w5f7-wj39" + }, + { + "type": "WEB", + "url": "https://github.com/jazzband/django-tinymce/releases/tag/3.4.0" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/django-tinymce/3.4.0/" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T16:15:09Z" + } +} \ No newline at end of file