Publish Advisories

GHSA-j66v-q82h-4f8h
GHSA-9rc5-4p7c-qp9h
GHSA-pfh2-hfmq-phg5
GHSA-33rw-cjxq-8rgp
GHSA-3pfj-g4wr-qj3j
GHSA-9frx-f993-wf86
GHSA-9r9p-4477-qf64
GHSA-c543-q7r3-jw94
GHSA-c653-w7m8-34r2
GHSA-g2wq-4jp5-xm5p
GHSA-q9h6-c2ff-prcp
GHSA-qmfw-q6m7-ff6j
GHSA-wxqg-47fv-wf96
This commit is contained in:
advisory-database[bot]
2024-01-09 15:31:51 +00:00
parent 14a1e64282
commit caa77fb505
13 changed files with 192 additions and 13 deletions
@@ -53,6 +53,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7558"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0089"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-42753"
@@ -21,9 +21,17 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48121"
},
{
"type": "WEB",
"url": "https://joerngermany.github.io/ezviz_vulnerability/"
},
{
"type": "WEB",
"url": "https://www.ezviz.com/data-security/security-notice/detail/911"
},
{
"type": "WEB",
"url": "https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfh2-hfmq-phg5",
"modified": "2023-12-27T21:31:01Z",
"modified": "2024-01-09T15:30:28Z",
"published": "2023-12-27T21:31:01Z",
"aliases": [
"CVE-2023-51074"
],
"details": "json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-27T21:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33rw-cjxq-8rgp",
"modified": "2024-01-05T12:30:21Z",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-05T12:30:21Z",
"aliases": [
"CVE-2023-51538"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3pfj-g4wr-qj3j",
"modified": "2024-01-03T00:30:23Z",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-03T00:30:23Z",
"aliases": [
"CVE-2020-26625"
],
"details": "A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T22:15:07Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9frx-f993-wf86",
"modified": "2024-01-05T12:30:23Z",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-05T12:30:23Z",
"aliases": [
"CVE-2023-51673"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9r9p-4477-qf64",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-09T15:30:33Z",
"aliases": [
"CVE-2024-0206"
],
"details": "\nA symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0206"
},
{
"type": "WEB",
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10415"
}
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T14:15:46Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c653-w7m8-34r2",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-09T15:30:33Z",
"aliases": [
"CVE-2023-7221"
],
"details": "A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7221"
},
{
"type": "WEB",
"url": "https://github.com/jylsec/vuldb/blob/main/TOTOLINK/T6/1/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.249855"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.249855"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T14:15:46Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2wq-4jp5-xm5p",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-09T15:30:33Z",
"aliases": [
"CVE-2022-28975"
],
"details": "A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28975"
},
{
"type": "WEB",
"url": "https://piotrryciak.com/posts/xss-infoblox/"
},
{
"type": "WEB",
"url": "http://infoblox.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T14:15:45Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmfw-q6m7-ff6j",
"modified": "2024-01-09T15:30:33Z",
"published": "2024-01-09T15:30:33Z",
"aliases": [
"CVE-2024-0213"
],
"details": "\nA buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly. \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0213"
},
{
"type": "WEB",
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10416"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T14:15:46Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,