From d0ca07df8b8fe36065eaa085624219ad25738a9d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Dec 2023 06:31:49 +0000 Subject: [PATCH] Publish Advisories GHSA-mxh4-p4w6-g844 GHSA-2pp8-cqff-m6w4 GHSA-5mq4-x9g5-4vc4 GHSA-8wjx-p2f8-5rjp GHSA-c4f2-4cmw-rccv GHSA-h42c-h7r7-cg2m GHSA-wxvg-wr3r-wmm7 --- .../GHSA-mxh4-p4w6-g844.json | 4 ++ .../GHSA-2pp8-cqff-m6w4.json | 39 +++++++++++++++++++ .../GHSA-5mq4-x9g5-4vc4.json | 4 ++ .../GHSA-8wjx-p2f8-5rjp.json | 39 +++++++++++++++++++ .../GHSA-c4f2-4cmw-rccv.json | 35 +++++++++++++++++ .../GHSA-h42c-h7r7-cg2m.json | 35 +++++++++++++++++ .../GHSA-wxvg-wr3r-wmm7.json | 39 +++++++++++++++++++ 7 files changed, 195 insertions(+) create mode 100644 advisories/unreviewed/2023/12/GHSA-2pp8-cqff-m6w4/GHSA-2pp8-cqff-m6w4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-8wjx-p2f8-5rjp/GHSA-8wjx-p2f8-5rjp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-c4f2-4cmw-rccv/GHSA-c4f2-4cmw-rccv.json create mode 100644 advisories/unreviewed/2023/12/GHSA-h42c-h7r7-cg2m/GHSA-h42c-h7r7-cg2m.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wxvg-wr3r-wmm7/GHSA-wxvg-wr3r-wmm7.json diff --git a/advisories/unreviewed/2022/05/GHSA-mxh4-p4w6-g844/GHSA-mxh4-p4w6-g844.json b/advisories/unreviewed/2022/05/GHSA-mxh4-p4w6-g844/GHSA-mxh4-p4w6-g844.json index ed5f0e7b7a4..4b953d0a0f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxh4-p4w6-g844/GHSA-mxh4-p4w6-g844.json +++ b/advisories/unreviewed/2022/05/GHSA-mxh4-p4w6-g844/GHSA-mxh4-p4w6-g844.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://bugzilla.suse.com/show_bug.cgi?id=1190975" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/" diff --git a/advisories/unreviewed/2023/12/GHSA-2pp8-cqff-m6w4/GHSA-2pp8-cqff-m6w4.json b/advisories/unreviewed/2023/12/GHSA-2pp8-cqff-m6w4/GHSA-2pp8-cqff-m6w4.json new file mode 100644 index 00000000000..73a3dc08a14 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2pp8-cqff-m6w4/GHSA-2pp8-cqff-m6w4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pp8-cqff-m6w4", + "modified": "2023-12-26T06:30:33Z", + "published": "2023-12-26T06:30:33Z", + "aliases": [ + "CVE-2023-50297" + ], + "details": "Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50297" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN32646742/" + }, + { + "type": "WEB", + "url": "https://www.powercms.jp/news/release-powercms-202312.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-26T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json index df5716553ee..c90ac933d23 100644 --- a/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json +++ b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html" + }, { "type": "WEB", "url": "https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html" diff --git a/advisories/unreviewed/2023/12/GHSA-8wjx-p2f8-5rjp/GHSA-8wjx-p2f8-5rjp.json b/advisories/unreviewed/2023/12/GHSA-8wjx-p2f8-5rjp/GHSA-8wjx-p2f8-5rjp.json new file mode 100644 index 00000000000..f48aeb5e9c9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8wjx-p2f8-5rjp/GHSA-8wjx-p2f8-5rjp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wjx-p2f8-5rjp", + "modified": "2023-12-26T06:30:33Z", + "published": "2023-12-26T06:30:33Z", + "aliases": [ + "CVE-2023-27150" + ], + "details": "openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27150" + }, + { + "type": "WEB", + "url": "https://www.esecforte.com/cve-2023-27150-cross-site-scripting-xss/" + }, + { + "type": "WEB", + "url": "https://www.opencrx.org/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-26T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c4f2-4cmw-rccv/GHSA-c4f2-4cmw-rccv.json b/advisories/unreviewed/2023/12/GHSA-c4f2-4cmw-rccv/GHSA-c4f2-4cmw-rccv.json new file mode 100644 index 00000000000..8404e0bb024 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c4f2-4cmw-rccv/GHSA-c4f2-4cmw-rccv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4f2-4cmw-rccv", + "modified": "2023-12-26T06:30:33Z", + "published": "2023-12-26T06:30:33Z", + "aliases": [ + "CVE-2023-28616" + ], + "details": "An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28616" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu/2023-006" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-26T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-h42c-h7r7-cg2m/GHSA-h42c-h7r7-cg2m.json b/advisories/unreviewed/2023/12/GHSA-h42c-h7r7-cg2m/GHSA-h42c-h7r7-cg2m.json new file mode 100644 index 00000000000..1d6de49feb3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-h42c-h7r7-cg2m/GHSA-h42c-h7r7-cg2m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h42c-h7r7-cg2m", + "modified": "2023-12-26T06:30:33Z", + "published": "2023-12-26T06:30:33Z", + "aliases": [ + "CVE-2023-51654" + ], + "details": "Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51654" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU97943829/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-26T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wxvg-wr3r-wmm7/GHSA-wxvg-wr3r-wmm7.json b/advisories/unreviewed/2023/12/GHSA-wxvg-wr3r-wmm7/GHSA-wxvg-wr3r-wmm7.json new file mode 100644 index 00000000000..799b746426f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wxvg-wr3r-wmm7/GHSA-wxvg-wr3r-wmm7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxvg-wr3r-wmm7", + "modified": "2023-12-26T06:30:33Z", + "published": "2023-12-26T06:30:33Z", + "aliases": [ + "CVE-2023-49117" + ], + "details": "PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49117" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN32646742/" + }, + { + "type": "WEB", + "url": "https://www.powercms.jp/news/release-powercms-202312.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-26T06:15:07Z" + } +} \ No newline at end of file