Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-24 18:32:21 +00:00
parent 72a9717618
commit d43480984f
46 changed files with 1032 additions and 53 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf6v-gw88-w63q",
"modified": "2023-08-01T18:30:27Z",
"modified": "2024-01-24T18:30:59Z",
"published": "2023-07-22T18:30:23Z",
"aliases": [
"CVE-2023-38633"
@@ -33,6 +33,14 @@
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/librsvg/-/releases/2.56.3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5BCXT5GW6RCL45ZUHUZR4CJG2BAFDVC/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/"
@@ -74,7 +82,7 @@
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-22T17:15:09Z"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Using%20Shell%20Metacharacter%20Injection%20via%20API.md"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176708/GL.iNet-Unauthenticated-Remote-Command-Execution.html"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23p4-xxgc-xqvf",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2021-42143"
],
"details": "An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42143"
},
{
"type": "WEB",
"url": "https://seclists.org/fulldisclosure/2024/Jan/16"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-279h-8hwx-39m5",
"modified": "2024-01-16T18:31:09Z",
"modified": "2024-01-24T18:31:00Z",
"published": "2024-01-16T18:31:09Z",
"aliases": [
"CVE-2022-3899"
],
"details": "The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T16:15:10Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-913"
],
"severity": "MODERATE",
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c9m-w3h6-q5pr",
"modified": "2024-01-24T18:31:00Z",
"published": "2024-01-24T18:31:00Z",
"aliases": [
"CVE-2023-44281"
],
"details": "\nDell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44281"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000219185/dsa-2023-141"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T16:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36xj-gcr2-cgrf",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51888"
],
"details": "Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51888"
},
{
"type": "WEB",
"url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
}
}
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Authentication-bypass.md"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176708/GL.iNet-Unauthenticated-Remote-Command-Execution.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4fwh-vhv3-7xx7",
"modified": "2024-01-13T03:30:17Z",
"modified": "2024-01-24T18:30:59Z",
"published": "2024-01-13T03:30:17Z",
"aliases": [
"CVE-2023-51804"
],
"details": "An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-13T02:15:07Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jcp-mmrj-mv7r",
"modified": "2024-01-17T18:31:38Z",
"modified": "2024-01-24T18:31:00Z",
"published": "2024-01-17T18:31:38Z",
"aliases": [
"CVE-2022-41786"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53ph-2r2x-vqw8",
"modified": "2024-01-24T18:31:02Z",
"published": "2024-01-24T18:31:02Z",
"aliases": [
"CVE-2024-23898"
],
"details": "Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23898"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3315"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/24/6"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-567x-h4g5-2gwq",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51890"
],
"details": "An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51890"
},
{
"type": "WEB",
"url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57w7-wm2r-3f6f",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51889"
],
"details": "Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51889"
},
{
"type": "WEB",
"url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g8x-4pjj-p6fm",
"modified": "2024-01-16T18:31:09Z",
"modified": "2024-01-24T18:31:00Z",
"published": "2024-01-16T18:31:09Z",
"aliases": [
"CVE-2022-3194"
],
"details": "The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T16:15:09Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q2h-m2hm-4r3w",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51886"
],
"details": "Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \\convertpath.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51886"
},
{
"type": "WEB",
"url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63fr-hqmm-7x7r",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2024-22229"
],
"details": "\nDell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22229"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-117"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-663j-9vv5-mmf4",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51887"
],
"details": "Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51887"
},
{
"type": "WEB",
"url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f9g-cxwr-q5jr",
"modified": "2024-01-24T18:31:02Z",
"published": "2024-01-24T18:31:02Z",
"aliases": [
"CVE-2024-23897"
],
"details": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23897"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/24/6"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78p2-p949-pjvr",
"modified": "2024-01-24T18:31:01Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-52038"
],
"details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52038"
},
{
"type": "WEB",
"url": "https://github.com/Beckaf/vunl/blob/main/TOTOLINK/X6000R/1/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79pc-32f9-phcw",
"modified": "2024-01-17T00:30:21Z",
"modified": "2024-01-24T18:31:00Z",
"published": "2024-01-17T00:30:21Z",
"aliases": [
"CVE-2024-22916"
],
"details": "In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T22:15:46Z"

Some files were not shown because too many files have changed in this diff Show More