Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-04-10 21:31:45 +00:00
parent 8d3ab31e32
commit c4b4c1ed1a
65 changed files with 1087 additions and 107 deletions
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00012.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p58g-823f-vq5p",
"modified": "2022-02-18T00:00:55Z",
"modified": "2023-04-10T21:30:21Z",
"published": "2022-02-11T00:00:45Z",
"aliases": [
"CVE-2022-0020"
],
"details": "A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -21,6 +24,10 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2022-0020"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171782/Palo-Alto-Cortex-XSOAR-6.5.0-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfx7-787g-3rp3",
"modified": "2022-05-24T17:37:39Z",
"modified": "2023-04-10T21:30:22Z",
"published": "2022-05-24T17:37:39Z",
"aliases": [
"CVE-2020-35391"
],
"details": "Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -21,11 +24,16 @@
{
"type": "WEB",
"url": "https://medium.com/@signalhilltech/tenda-n300-authentication-bypass-via-malformed-http-request-header-5b8744ca685e"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171773/Tenda-N300-F3-12.01.01.48-Header-Processing.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
"CWE-416",
"CWE-425"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21117"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171781/Symantec-Messaging-Gateway-10.7.4-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6952319"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171772/IBM-Aspera-Faspex-4.4.1-YAML-Deserialization.html"
}
],
"database_specific": {
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29273"
},
{
"type": "WEB",
"url": "https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc"
},
{
"type": "WEB",
"url": "https://docs.netgate.com/pfsense/en/latest/releases/index.html#current-and-upcoming-supported-releases"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/patrickhener/CVE-2023-22855/blob/main/advisory/advisory.md"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/51239"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171046/Kardex-Mlog-MCC-5.7.12-0-a203c2a213-master-File-Inclusion-Remote-Code-Execution.html"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://github.com/bigzooooz/CVE-2023-26692#readme"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171787/ZCBS-ZBBS-ZPBS-4.14k-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23399"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171767/Microsoft-Excel-365-MSO-2302-Build-16.0.16130.20186-Remote-Code-Execution.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/ahmedalroky/Disclosures/blob/main/apesystems/os_command_injection.md"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171775/Altenergy-Power-Control-Software-C1.2.5-Command-Injection.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/sunktitanic/Injection-vulnerability-in-Paradox-Security-Systems-IPR512"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171783/Paradox-Security-Systems-IPR512-Denial-Of-Service.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6959969"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171770/IBM-Instana-243-0-Missing-Authentication.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://crbug.com/1417185"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171796/Chrome-base-SampleVectorBase-MoveSingleSampleToCounts-Heap-Buffer-Overflow.html"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://fortiguard.com/psirt/FG-IR-22-388"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171766/FortiRecorder-6.4.3-Denial-Of-Service.html"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23420"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171794/Windows-Kernel-Registry-Key-Issue.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://redmine.pfsense.org/issues/13574"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171791/pfsenseCE-2.6.0-Protection-Bypass.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://crbug.com/1415328"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171795/Chrome-base-debug-ActivityUserData-ActivityUserData-Heap-Buffer-Overflow.html"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2chr-h4px-85v9",
"modified": "2023-04-10T21:30:22Z",
"published": "2023-04-10T21:30:22Z",
"aliases": [
"CVE-2022-46703"
],
"details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to read sensitive location information",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46703"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213530"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213531"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213532"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T19:15:00Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p4x-63mg-m275",
"modified": "2023-04-10T21:30:20Z",
"published": "2023-04-10T21:30:20Z",
"aliases": [
"CVE-2023-27178"
],
"details": "An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40797"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27178"
},
{
"type": "WEB",
"url": "https://gist.github.com/Hadi999/4bc173bfb802c229b9bb397fa906847b"
},
{
"type": "WEB",
"url": "https://salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.conf#L5-6"
},
{
"type": "WEB",
"url": "https://www.gdidees.eu/cms-1-0.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T21:15:00Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37p5-738j-5p3x",
"modified": "2023-04-10T21:30:22Z",
"published": "2023-04-10T21:30:22Z",
"aliases": [
"CVE-2022-46717"
],
"details": "A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46717"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213530"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T19:15:00Z"
}
}

Some files were not shown because too many files have changed in this diff Show More