Publish Advisories

GHSA-5mwm-wccq-xqcp
GHSA-2mxf-g57h-fggq
GHSA-3mp3-p7xf-v5f6
GHSA-434x-65h3-cg6q
GHSA-46qf-g7mj-p34v
GHSA-4frm-cwqq-w26g
GHSA-5mxr-j6vv-8p4c
GHSA-5rv6-mg5f-h55g
GHSA-734f-vhpg-wrgp
GHSA-76rv-vcjw-7q23
GHSA-cgqm-2q6p-33gm
GHSA-f56m-69v4-8288
GHSA-h4w6-443w-q3c4
GHSA-h6jm-ghq6-38cg
GHSA-hm93-fhwx-7mmj
GHSA-mm96-9vx8-pfhj
GHSA-p36v-2c7w-2x8f
GHSA-p9jh-4px8-qm49
GHSA-pwqv-pfwc-3854
GHSA-qpwc-q7rm-3jjq
GHSA-rhqm-jg9x-wp83
GHSA-wmhj-jq93-j3p7
GHSA-xgf4-6mjg-7hqq
This commit is contained in:
advisory-database[bot]
2023-05-12 18:31:56 +00:00
parent c3cfe1de4c
commit cbad1aa07f
23 changed files with 326 additions and 43 deletions
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/issues/102988"
},
{
"type": "WEB",
"url": "https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html"
},
{
"type": "WEB",
"url": "http://python.com"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mxf-g57h-fggq",
"modified": "2023-05-09T03:30:40Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:40Z",
"aliases": [
"CVE-2022-47490"
],
"details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mp3-p7xf-v5f6",
"modified": "2023-05-04T21:30:29Z",
"modified": "2023-05-12T18:30:23Z",
"published": "2023-05-04T21:30:29Z",
"aliases": [
"CVE-2023-25289"
],
"details": "Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-434x-65h3-cg6q",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2023-25428"
],
"details": "A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25428"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/172259/Soft-o-Free-Password-Manager-1.1.20-DLL-Hijacking.html"
},
{
"type": "WEB",
"url": "https://www.soft-o.com/products/free-password-manager.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46qf-g7mj-p34v",
"modified": "2023-05-09T03:30:38Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:38Z",
"aliases": [
"CVE-2022-38685"
],
"details": "In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4frm-cwqq-w26g",
"modified": "2023-05-08T15:30:20Z",
"modified": "2023-05-12T18:30:24Z",
"published": "2023-05-08T15:30:20Z",
"aliases": [
"CVE-2023-30092"
],
"details": "SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mxr-j6vv-8p4c",
"modified": "2023-05-09T03:30:40Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:40Z",
"aliases": [
"CVE-2022-47493"
],
"details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rv6-mg5f-h55g",
"modified": "2023-05-06T00:30:16Z",
"modified": "2023-05-12T18:30:24Z",
"published": "2023-05-06T00:30:16Z",
"aliases": [
"CVE-2023-30065"
],
"details": "MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-734f-vhpg-wrgp",
"modified": "2023-05-08T15:30:18Z",
"modified": "2023-05-12T18:30:24Z",
"published": "2023-05-08T15:30:18Z",
"aliases": [
"CVE-2020-36065"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76rv-vcjw-7q23",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2023-2457"
],
"details": "Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2457"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-chromeos.html"
},
{
"type": "WEB",
"url": "https://crbug.com/1420790"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgqm-2q6p-33gm",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2023-25927"
],
"details": "IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25927"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/247635"
},
{
"type": "WEB",
"url": "https://https://www.ibm.com/support/pages/node/6989653"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f56m-69v4-8288",
"modified": "2023-05-09T03:30:39Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:39Z",
"aliases": [
"CVE-2022-47334"
],
"details": "In phasecheck server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4w6-443w-q3c4",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2023-31983"
],
"details": "A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31983"
},
{
"type": "WEB",
"url": "https://github.com/Erebua/CVE/blob/main/N300_BR-6428nS%20V4/2/Readme.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6jm-ghq6-38cg",
"modified": "2023-05-08T15:30:18Z",
"modified": "2023-05-12T18:30:24Z",
"published": "2023-05-08T15:30:18Z",
"aliases": [
"CVE-2021-28998"
],
"details": "File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm93-fhwx-7mmj",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2022-48020"
],
"details": "Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48020"
},
{
"type": "WEB",
"url": "https://seq.team/en/"
},
{
"type": "WEB",
"url": "https://seq.team/en/blog/reflected-cross-site-scripting-xss-in-vinteo-vcc/"
},
{
"type": "WEB",
"url": "https://www.linkedin.com/in/dmitry-kiryukhin-b5741421b/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm96-9vx8-pfhj",
"modified": "2023-05-08T15:30:18Z",
"modified": "2023-05-12T18:30:24Z",
"published": "2023-05-08T15:30:18Z",
"aliases": [
"CVE-2020-23966"
],
"details": "SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p36v-2c7w-2x8f",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-12T18:30:25Z",
"aliases": [
"CVE-2023-2458"
],
"details": "Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2458"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-chromeos.html"
},
{
"type": "WEB",
"url": "https://crbug.com/1430692"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9jh-4px8-qm49",
"modified": "2023-05-09T03:30:40Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:40Z",
"aliases": [
"CVE-2022-47492"
],
"details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-401"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpwc-q7rm-3jjq",
"modified": "2023-05-09T03:30:41Z",
"modified": "2023-05-12T18:30:25Z",
"published": "2023-05-09T03:30:41Z",
"aliases": [
"CVE-2022-48384"
],
"details": "In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More