Publish Advisories

GHSA-5rpw-fg4q-7wj5
GHSA-9q57-wj63-96j5
GHSA-c59h-r6p8-q9wc
GHSA-vm4p-cgrm-3hvm
This commit is contained in:
advisory-database[bot]
2023-10-22 03:31:34 +00:00
parent 6ecc000614
commit d2c992a510
4 changed files with 169 additions and 0 deletions
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rpw-fg4q-7wj5",
"modified": "2023-10-22T03:30:22Z",
"published": "2023-10-22T03:30:22Z",
"aliases": [
"CVE-2023-38275"
],
"details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38275"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260735"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7031207"
}
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q57-wj63-96j5",
"modified": "2023-10-22T03:30:23Z",
"published": "2023-10-22T03:30:23Z",
"aliases": [
"CVE-2023-38735"
],
"details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38735"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/262482"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7031207"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c59h-r6p8-q9wc",
"modified": "2023-10-22T03:30:23Z",
"published": "2023-10-22T03:30:23Z",
"aliases": [
"CVE-2023-46298"
],
"details": "Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46298"
},
{
"type": "WEB",
"url": "https://github.com/vercel/next.js/issues/45301"
},
{
"type": "WEB",
"url": "https://github.com/vercel/next.js/pull/54732"
},
{
"type": "WEB",
"url": "https://github.com/vercel/next.js/compare/v13.4.20-canary.12...v13.4.20-canary.13"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vm4p-cgrm-3hvm",
"modified": "2023-10-22T03:30:23Z",
"published": "2023-10-22T03:30:23Z",
"aliases": [
"CVE-2023-38276"
],
"details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38276"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260736"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7031207"
}
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}