mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-j66v-q82h-4f8h GHSA-9rc5-4p7c-qp9h GHSA-pfh2-hfmq-phg5 GHSA-33rw-cjxq-8rgp GHSA-3pfj-g4wr-qj3j GHSA-9frx-f993-wf86 GHSA-9r9p-4477-qf64 GHSA-c543-q7r3-jw94 GHSA-c653-w7m8-34r2 GHSA-g2wq-4jp5-xm5p GHSA-q9h6-c2ff-prcp GHSA-qmfw-q6m7-ff6j GHSA-wxqg-47fv-wf96
This commit is contained in:
@@ -53,6 +53,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2023:7558"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:0089"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2023-42753"
|
||||
|
||||
@@ -21,9 +21,17 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48121"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://joerngermany.github.io/ezviz_vulnerability/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ezviz.com/data-security/security-notice/detail/911"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pfh2-hfmq-phg5",
|
||||
"modified": "2023-12-27T21:31:01Z",
|
||||
"modified": "2024-01-09T15:30:28Z",
|
||||
"published": "2023-12-27T21:31:01Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51074"
|
||||
],
|
||||
"details": "json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,9 +28,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-12-27T21:15:08Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-33rw-cjxq-8rgp",
|
||||
"modified": "2024-01-05T12:30:21Z",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-05T12:30:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51538"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3pfj-g4wr-qj3j",
|
||||
"modified": "2024-01-03T00:30:23Z",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-03T00:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2020-26625"
|
||||
],
|
||||
"details": "A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -37,9 +40,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-02T22:15:07Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9frx-f993-wf86",
|
||||
"modified": "2024-01-05T12:30:23Z",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-05T12:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51673"
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9r9p-4477-qf64",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-09T15:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0206"
|
||||
],
|
||||
"details": "\nA symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0206"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10415"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-59"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-09T14:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c653-w7m8-34r2",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-09T15:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-7221"
|
||||
],
|
||||
"details": "A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7221"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jylsec/vuldb/blob/main/TOTOLINK/T6/1/README.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.249855"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.249855"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-09T14:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g2wq-4jp5-xm5p",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-09T15:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2022-28975"
|
||||
],
|
||||
"details": "A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28975"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://piotrryciak.com/posts/xss-infoblox/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://infoblox.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-09T14:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qmfw-q6m7-ff6j",
|
||||
"modified": "2024-01-09T15:30:33Z",
|
||||
"published": "2024-01-09T15:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0213"
|
||||
],
|
||||
"details": "\nA buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly. \n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0213"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10416"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-09T14:15:46Z"
|
||||
}
|
||||
}
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
Reference in New Issue
Block a user