From d2c992a510bf498664e0befe2847bc0389bef09f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 22 Oct 2023 03:31:34 +0000 Subject: [PATCH] Publish Advisories GHSA-5rpw-fg4q-7wj5 GHSA-9q57-wj63-96j5 GHSA-c59h-r6p8-q9wc GHSA-vm4p-cgrm-3hvm --- .../GHSA-5rpw-fg4q-7wj5.json | 42 ++++++++++++++++++ .../GHSA-9q57-wj63-96j5.json | 42 ++++++++++++++++++ .../GHSA-c59h-r6p8-q9wc.json | 43 +++++++++++++++++++ .../GHSA-vm4p-cgrm-3hvm.json | 42 ++++++++++++++++++ 4 files changed, 169 insertions(+) create mode 100644 advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json create mode 100644 advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json create mode 100644 advisories/unreviewed/2023/10/GHSA-c59h-r6p8-q9wc/GHSA-c59h-r6p8-q9wc.json create mode 100644 advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json diff --git a/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json b/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json new file mode 100644 index 00000000000..9ac677bb0f6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5rpw-fg4q-7wj5/GHSA-5rpw-fg4q-7wj5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rpw-fg4q-7wj5", + "modified": "2023-10-22T03:30:22Z", + "published": "2023-10-22T03:30:22Z", + "aliases": [ + "CVE-2023-38275" + ], + "details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38275" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260735" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7031207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json b/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json new file mode 100644 index 00000000000..607e0f94120 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9q57-wj63-96j5/GHSA-9q57-wj63-96j5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q57-wj63-96j5", + "modified": "2023-10-22T03:30:23Z", + "published": "2023-10-22T03:30:23Z", + "aliases": [ + "CVE-2023-38735" + ], + "details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38735" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/262482" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7031207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-c59h-r6p8-q9wc/GHSA-c59h-r6p8-q9wc.json b/advisories/unreviewed/2023/10/GHSA-c59h-r6p8-q9wc/GHSA-c59h-r6p8-q9wc.json new file mode 100644 index 00000000000..d426aebfd90 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-c59h-r6p8-q9wc/GHSA-c59h-r6p8-q9wc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c59h-r6p8-q9wc", + "modified": "2023-10-22T03:30:23Z", + "published": "2023-10-22T03:30:23Z", + "aliases": [ + "CVE-2023-46298" + ], + "details": "Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46298" + }, + { + "type": "WEB", + "url": "https://github.com/vercel/next.js/issues/45301" + }, + { + "type": "WEB", + "url": "https://github.com/vercel/next.js/pull/54732" + }, + { + "type": "WEB", + "url": "https://github.com/vercel/next.js/compare/v13.4.20-canary.12...v13.4.20-canary.13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json b/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json new file mode 100644 index 00000000000..504b0cb2e6b --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-vm4p-cgrm-3hvm/GHSA-vm4p-cgrm-3hvm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm4p-cgrm-3hvm", + "modified": "2023-10-22T03:30:23Z", + "published": "2023-10-22T03:30:23Z", + "aliases": [ + "CVE-2023-38276" + ], + "details": "IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38276" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260736" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7031207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file