Publish Advisories

GHSA-mxh4-p4w6-g844
GHSA-2pp8-cqff-m6w4
GHSA-5mq4-x9g5-4vc4
GHSA-8wjx-p2f8-5rjp
GHSA-c4f2-4cmw-rccv
GHSA-h42c-h7r7-cg2m
GHSA-wxvg-wr3r-wmm7
This commit is contained in:
advisory-database[bot]
2023-12-26 06:31:49 +00:00
parent 462c66db98
commit d0ca07df8b
7 changed files with 195 additions and 0 deletions
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1190975"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pp8-cqff-m6w4",
"modified": "2023-12-26T06:30:33Z",
"published": "2023-12-26T06:30:33Z",
"aliases": [
"CVE-2023-50297"
],
"details": "Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50297"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN32646742/"
},
{
"type": "WEB",
"url": "https://www.powercms.jp/news/release-powercms-202312.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T06:15:07Z"
}
}
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"
},
{
"type": "WEB",
"url": "https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wjx-p2f8-5rjp",
"modified": "2023-12-26T06:30:33Z",
"published": "2023-12-26T06:30:33Z",
"aliases": [
"CVE-2023-27150"
],
"details": "openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27150"
},
{
"type": "WEB",
"url": "https://www.esecforte.com/cve-2023-27150-cross-site-scripting-xss/"
},
{
"type": "WEB",
"url": "https://www.opencrx.org/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T04:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4f2-4cmw-rccv",
"modified": "2023-12-26T06:30:33Z",
"published": "2023-12-26T06:30:33Z",
"aliases": [
"CVE-2023-28616"
],
"details": "An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28616"
},
{
"type": "WEB",
"url": "https://advisories.stormshield.eu/2023-006"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T04:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h42c-h7r7-cg2m",
"modified": "2023-12-26T06:30:33Z",
"published": "2023-12-26T06:30:33Z",
"aliases": [
"CVE-2023-51654"
],
"details": "Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51654"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU97943829/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T06:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxvg-wr3r-wmm7",
"modified": "2023-12-26T06:30:33Z",
"published": "2023-12-26T06:30:33Z",
"aliases": [
"CVE-2023-49117"
],
"details": "PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49117"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN32646742/"
},
{
"type": "WEB",
"url": "https://www.powercms.jp/news/release-powercms-202312.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T06:15:07Z"
}
}