From d43480984ff64e2b55e90371d5fade0e151d4545 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 24 Jan 2024 18:32:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jf6v-gw88-w63q.json | 12 +++++- .../GHSA-r64h-95wm-rrfq.json | 4 ++ .../GHSA-23p4-xxgc-xqvf.json | 35 +++++++++++++++++ .../GHSA-279h-8hwx-39m5.json | 11 ++++-- .../GHSA-28qj-gvxv-p5g9.json | 1 + .../GHSA-2c9m-w3h6-q5pr.json | 38 ++++++++++++++++++ .../GHSA-36xj-gcr2-cgrf.json | 35 +++++++++++++++++ .../GHSA-3vmx-5x6r-25cw.json | 4 ++ .../GHSA-4fwh-vhv3-7xx7.json | 11 ++++-- .../GHSA-4jcp-mmrj-mv7r.json | 2 +- .../GHSA-53ph-2r2x-vqw8.json | 39 +++++++++++++++++++ .../GHSA-567x-h4g5-2gwq.json | 35 +++++++++++++++++ .../GHSA-57w7-wm2r-3f6f.json | 35 +++++++++++++++++ .../GHSA-5g8x-4pjj-p6fm.json | 11 ++++-- .../GHSA-5q2h-m2hm-4r3w.json | 35 +++++++++++++++++ .../GHSA-63fr-hqmm-7x7r.json | 38 ++++++++++++++++++ .../GHSA-663j-9vv5-mmf4.json | 35 +++++++++++++++++ .../GHSA-6f9g-cxwr-q5jr.json | 39 +++++++++++++++++++ .../GHSA-78p2-p949-pjvr.json | 35 +++++++++++++++++ .../GHSA-79pc-32f9-phcw.json | 11 ++++-- .../GHSA-7j77-3p87-xr63.json | 35 +++++++++++++++++ .../GHSA-7r27-33fg-9cpx.json | 35 +++++++++++++++++ .../GHSA-8h9j-pxfp-9p97.json | 35 +++++++++++++++++ .../GHSA-8r93-59cf-358f.json | 39 +++++++++++++++++++ .../GHSA-983x-5446-qc2q.json | 9 +++-- .../GHSA-9r3v-3w88-2hh3.json | 11 ++++-- .../GHSA-cjgm-9vc9-56mx.json | 39 +++++++++++++++++++ .../GHSA-f67f-2j6r-m4c9.json | 39 +++++++++++++++++++ .../GHSA-f8xf-39w2-mrc6.json | 4 ++ .../GHSA-fpx6-qj6w-4m83.json | 11 ++++-- .../GHSA-fv65-3wh4-c445.json | 11 ++++-- .../GHSA-fw9h-cxx9-gfq3.json | 39 +++++++++++++++++++ .../GHSA-j2p7-j8v8-q5g2.json | 39 +++++++++++++++++++ .../GHSA-j8f3-4cqg-mhw4.json | 1 + .../GHSA-p5gj-h5v3-rqph.json | 11 ++++-- .../GHSA-qcfg-49mv-9hvw.json | 11 ++++-- .../GHSA-qfm4-9qqj-3w82.json | 35 +++++++++++++++++ .../GHSA-qjpf-2jhx-3758.json | 39 +++++++++++++++++++ .../GHSA-r278-g84p-6h4c.json | 11 ++++-- .../GHSA-rp98-9vmx-835h.json | 11 ++++-- .../GHSA-rpqp-hf76-rjpp.json | 2 +- .../GHSA-vh9j-8vw4-5hp6.json | 35 +++++++++++++++++ .../GHSA-vph5-2q33-7r9h.json | 39 +++++++++++++++++++ .../GHSA-x22x-5pp9-8v7f.json | 39 +++++++++++++++++++ .../GHSA-xc7v-9m4q-8q68.json | 35 +++++++++++++++++ .../GHSA-xhpq-8p2q-qgm6.json | 4 +- 46 files changed, 1032 insertions(+), 53 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-2c9m-w3h6-q5pr/GHSA-2c9m-w3h6-q5pr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-53ph-2r2x-vqw8/GHSA-53ph-2r2x-vqw8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json create mode 100644 advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-63fr-hqmm-7x7r/GHSA-63fr-hqmm-7x7r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6f9g-cxwr-q5jr/GHSA-6f9g-cxwr-q5jr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8r93-59cf-358f/GHSA-8r93-59cf-358f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-cjgm-9vc9-56mx/GHSA-cjgm-9vc9-56mx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f67f-2j6r-m4c9/GHSA-f67f-2j6r-m4c9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fw9h-cxx9-gfq3/GHSA-fw9h-cxx9-gfq3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qjpf-2jhx-3758/GHSA-qjpf-2jhx-3758.json create mode 100644 advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-vph5-2q33-7r9h/GHSA-vph5-2q33-7r9h.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x22x-5pp9-8v7f/GHSA-x22x-5pp9-8v7f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json diff --git a/advisories/unreviewed/2023/07/GHSA-jf6v-gw88-w63q/GHSA-jf6v-gw88-w63q.json b/advisories/unreviewed/2023/07/GHSA-jf6v-gw88-w63q/GHSA-jf6v-gw88-w63q.json index b4e7d9d9748..f350c6eb218 100644 --- a/advisories/unreviewed/2023/07/GHSA-jf6v-gw88-w63q/GHSA-jf6v-gw88-w63q.json +++ b/advisories/unreviewed/2023/07/GHSA-jf6v-gw88-w63q/GHSA-jf6v-gw88-w63q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jf6v-gw88-w63q", - "modified": "2023-08-01T18:30:27Z", + "modified": "2024-01-24T18:30:59Z", "published": "2023-07-22T18:30:23Z", "aliases": [ "CVE-2023-38633" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://gitlab.gnome.org/GNOME/librsvg/-/releases/2.56.3" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5BCXT5GW6RCL45ZUHUZR4CJG2BAFDVC/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/" @@ -74,7 +82,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-22T17:15:09Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json b/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json index b95cfef7614..5405531e69e 100644 --- a/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json +++ b/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Using%20Shell%20Metacharacter%20Injection%20via%20API.md" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176708/GL.iNet-Unauthenticated-Remote-Command-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json b/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json new file mode 100644 index 00000000000..a230dbe92e4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23p4-xxgc-xqvf", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2021-42143" + ], + "details": "An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42143" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2024/Jan/16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json b/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json index fec4d4487e3..3228ebae329 100644 --- a/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json +++ b/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-279h-8hwx-39m5", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3899" ], "details": "The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-28qj-gvxv-p5g9/GHSA-28qj-gvxv-p5g9.json b/advisories/unreviewed/2024/01/GHSA-28qj-gvxv-p5g9/GHSA-28qj-gvxv-p5g9.json index c2819d00393..e2885c1d9c3 100644 --- a/advisories/unreviewed/2024/01/GHSA-28qj-gvxv-p5g9/GHSA-28qj-gvxv-p5g9.json +++ b/advisories/unreviewed/2024/01/GHSA-28qj-gvxv-p5g9/GHSA-28qj-gvxv-p5g9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-913" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-2c9m-w3h6-q5pr/GHSA-2c9m-w3h6-q5pr.json b/advisories/unreviewed/2024/01/GHSA-2c9m-w3h6-q5pr/GHSA-2c9m-w3h6-q5pr.json new file mode 100644 index 00000000000..c84c68ed9fb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2c9m-w3h6-q5pr/GHSA-2c9m-w3h6-q5pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c9m-w3h6-q5pr", + "modified": "2024-01-24T18:31:00Z", + "published": "2024-01-24T18:31:00Z", + "aliases": [ + "CVE-2023-44281" + ], + "details": "\nDell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44281" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000219185/dsa-2023-141" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json new file mode 100644 index 00000000000..aae1d9b755e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xj-gcr2-cgrf", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51888" + ], + "details": "Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51888" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json b/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json index 72d5726c55f..6f7e35a1241 100644 --- a/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json +++ b/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Authentication-bypass.md" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176708/GL.iNet-Unauthenticated-Remote-Command-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-4fwh-vhv3-7xx7/GHSA-4fwh-vhv3-7xx7.json b/advisories/unreviewed/2024/01/GHSA-4fwh-vhv3-7xx7/GHSA-4fwh-vhv3-7xx7.json index c37c71a5797..351b438d144 100644 --- a/advisories/unreviewed/2024/01/GHSA-4fwh-vhv3-7xx7/GHSA-4fwh-vhv3-7xx7.json +++ b/advisories/unreviewed/2024/01/GHSA-4fwh-vhv3-7xx7/GHSA-4fwh-vhv3-7xx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fwh-vhv3-7xx7", - "modified": "2024-01-13T03:30:17Z", + "modified": "2024-01-24T18:30:59Z", "published": "2024-01-13T03:30:17Z", "aliases": [ "CVE-2023-51804" ], "details": "An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-13T02:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4jcp-mmrj-mv7r/GHSA-4jcp-mmrj-mv7r.json b/advisories/unreviewed/2024/01/GHSA-4jcp-mmrj-mv7r/GHSA-4jcp-mmrj-mv7r.json index bc921a11b4f..785854ed057 100644 --- a/advisories/unreviewed/2024/01/GHSA-4jcp-mmrj-mv7r/GHSA-4jcp-mmrj-mv7r.json +++ b/advisories/unreviewed/2024/01/GHSA-4jcp-mmrj-mv7r/GHSA-4jcp-mmrj-mv7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jcp-mmrj-mv7r", - "modified": "2024-01-17T18:31:38Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T18:31:38Z", "aliases": [ "CVE-2022-41786" diff --git a/advisories/unreviewed/2024/01/GHSA-53ph-2r2x-vqw8/GHSA-53ph-2r2x-vqw8.json b/advisories/unreviewed/2024/01/GHSA-53ph-2r2x-vqw8/GHSA-53ph-2r2x-vqw8.json new file mode 100644 index 00000000000..3b3ab175ba8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-53ph-2r2x-vqw8/GHSA-53ph-2r2x-vqw8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53ph-2r2x-vqw8", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23898" + ], + "details": "Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23898" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3315" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json b/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json new file mode 100644 index 00000000000..97a2c40b4a8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-567x-h4g5-2gwq", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51890" + ], + "details": "An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51890" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json b/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json new file mode 100644 index 00000000000..4d26ae3a0a0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57w7-wm2r-3f6f", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51889" + ], + "details": "Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51889" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json b/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json index 8c13728de44..7546e168c10 100644 --- a/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json +++ b/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5g8x-4pjj-p6fm", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3194" ], "details": "The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json b/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json new file mode 100644 index 00000000000..350bbcb0548 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q2h-m2hm-4r3w", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51886" + ], + "details": "Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \\convertpath.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51886" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-63fr-hqmm-7x7r/GHSA-63fr-hqmm-7x7r.json b/advisories/unreviewed/2024/01/GHSA-63fr-hqmm-7x7r/GHSA-63fr-hqmm-7x7r.json new file mode 100644 index 00000000000..ac2ee5379a3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-63fr-hqmm-7x7r/GHSA-63fr-hqmm-7x7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63fr-hqmm-7x7r", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2024-22229" + ], + "details": "\nDell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22229" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json b/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json new file mode 100644 index 00000000000..fa94cc2576f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-663j-9vv5-mmf4", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51887" + ], + "details": "Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51887" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6f9g-cxwr-q5jr/GHSA-6f9g-cxwr-q5jr.json b/advisories/unreviewed/2024/01/GHSA-6f9g-cxwr-q5jr/GHSA-6f9g-cxwr-q5jr.json new file mode 100644 index 00000000000..406014e46dd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6f9g-cxwr-q5jr/GHSA-6f9g-cxwr-q5jr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f9g-cxwr-q5jr", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23897" + ], + "details": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23897" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json b/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json new file mode 100644 index 00000000000..dc228a6ceb7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78p2-p949-pjvr", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-52038" + ], + "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52038" + }, + { + "type": "WEB", + "url": "https://github.com/Beckaf/vunl/blob/main/TOTOLINK/X6000R/1/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-79pc-32f9-phcw/GHSA-79pc-32f9-phcw.json b/advisories/unreviewed/2024/01/GHSA-79pc-32f9-phcw/GHSA-79pc-32f9-phcw.json index 82516220a7a..8a70b60a7df 100644 --- a/advisories/unreviewed/2024/01/GHSA-79pc-32f9-phcw/GHSA-79pc-32f9-phcw.json +++ b/advisories/unreviewed/2024/01/GHSA-79pc-32f9-phcw/GHSA-79pc-32f9-phcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79pc-32f9-phcw", - "modified": "2024-01-17T00:30:21Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T00:30:21Z", "aliases": [ "CVE-2024-22916" ], "details": "In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T22:15:46Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json b/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json new file mode 100644 index 00000000000..ed818b64aff --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j77-3p87-xr63", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-52039" + ], + "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52039" + }, + { + "type": "WEB", + "url": "https://github.com/Beckaf/vunl/blob/main/TOTOLINK/X6000R/2/2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json b/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json new file mode 100644 index 00000000000..628d8230711 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r27-33fg-9cpx", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2021-42144" + ], + "details": "Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42144" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2024/Jan/17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json b/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json new file mode 100644 index 00000000000..8d93964d7f8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h9j-pxfp-9p97", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-51885" + ], + "details": "Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51885" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-mathtex/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8r93-59cf-358f/GHSA-8r93-59cf-358f.json b/advisories/unreviewed/2024/01/GHSA-8r93-59cf-358f/GHSA-8r93-59cf-358f.json new file mode 100644 index 00000000000..d67edb6ef37 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8r93-59cf-358f/GHSA-8r93-59cf-358f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r93-59cf-358f", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23902" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23902" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3251" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json b/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json index 7fe6fbf0f37..0ea9fb1bd95 100644 --- a/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json +++ b/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-983x-5446-qc2q", - "modified": "2024-01-17T03:30:55Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T03:30:55Z", "aliases": [ "CVE-2023-49515" ], "details": "Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-17T02:15:06Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json b/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json index 8a1c64e1ab1..4dd317f946d 100644 --- a/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json +++ b/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9r3v-3w88-2hh3", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-2413" ], "details": "The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cjgm-9vc9-56mx/GHSA-cjgm-9vc9-56mx.json b/advisories/unreviewed/2024/01/GHSA-cjgm-9vc9-56mx/GHSA-cjgm-9vc9-56mx.json new file mode 100644 index 00000000000..3b99dacf978 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cjgm-9vc9-56mx/GHSA-cjgm-9vc9-56mx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjgm-9vc9-56mx", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23900" + ], + "details": "Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23900" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3289" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f67f-2j6r-m4c9/GHSA-f67f-2j6r-m4c9.json b/advisories/unreviewed/2024/01/GHSA-f67f-2j6r-m4c9/GHSA-f67f-2j6r-m4c9.json new file mode 100644 index 00000000000..98cd8a79179 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f67f-2j6r-m4c9/GHSA-f67f-2j6r-m4c9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f67f-2j6r-m4c9", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23903" + ], + "details": "Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23903" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-2871" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f8xf-39w2-mrc6/GHSA-f8xf-39w2-mrc6.json b/advisories/unreviewed/2024/01/GHSA-f8xf-39w2-mrc6/GHSA-f8xf-39w2-mrc6.json index 1c88ebe191a..a556d45e77e 100644 --- a/advisories/unreviewed/2024/01/GHSA-f8xf-39w2-mrc6/GHSA-f8xf-39w2-mrc6.json +++ b/advisories/unreviewed/2024/01/GHSA-f8xf-39w2-mrc6/GHSA-f8xf-39w2-mrc6.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.fortra.com/security/advisory/fi-2024-001" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json b/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json index 2c8dc6227cf..73456f64e2c 100644 --- a/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json +++ b/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpx6-qj6w-4m83", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3604" ], "details": "The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-fv65-3wh4-c445/GHSA-fv65-3wh4-c445.json b/advisories/unreviewed/2024/01/GHSA-fv65-3wh4-c445/GHSA-fv65-3wh4-c445.json index 775d5452409..318046acb90 100644 --- a/advisories/unreviewed/2024/01/GHSA-fv65-3wh4-c445/GHSA-fv65-3wh4-c445.json +++ b/advisories/unreviewed/2024/01/GHSA-fv65-3wh4-c445/GHSA-fv65-3wh4-c445.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv65-3wh4-c445", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3739" ], "details": "The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-fw9h-cxx9-gfq3/GHSA-fw9h-cxx9-gfq3.json b/advisories/unreviewed/2024/01/GHSA-fw9h-cxx9-gfq3/GHSA-fw9h-cxx9-gfq3.json new file mode 100644 index 00000000000..208e4954a1b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fw9h-cxx9-gfq3/GHSA-fw9h-cxx9-gfq3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw9h-cxx9-gfq3", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23901" + ], + "details": "Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23901" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3040" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json b/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json new file mode 100644 index 00000000000..2630d364f1d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2p7-j8v8-q5g2", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2024-22725" + ], + "details": "Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22725" + }, + { + "type": "WEB", + "url": "https://orthanc.uclouvain.be/hg/orthanc/file/Orthanc-1.12.2/NEWS" + }, + { + "type": "WEB", + "url": "https://orthanc.uclouvain.be/hg/orthanc/rev/505416b269a0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j8f3-4cqg-mhw4/GHSA-j8f3-4cqg-mhw4.json b/advisories/unreviewed/2024/01/GHSA-j8f3-4cqg-mhw4/GHSA-j8f3-4cqg-mhw4.json index e748978a3e2..0522ccef1a0 100644 --- a/advisories/unreviewed/2024/01/GHSA-j8f3-4cqg-mhw4/GHSA-j8f3-4cqg-mhw4.json +++ b/advisories/unreviewed/2024/01/GHSA-j8f3-4cqg-mhw4/GHSA-j8f3-4cqg-mhw4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-p5gj-h5v3-rqph/GHSA-p5gj-h5v3-rqph.json b/advisories/unreviewed/2024/01/GHSA-p5gj-h5v3-rqph/GHSA-p5gj-h5v3-rqph.json index 03f71816a3b..f5b23ed9cb3 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5gj-h5v3-rqph/GHSA-p5gj-h5v3-rqph.json +++ b/advisories/unreviewed/2024/01/GHSA-p5gj-h5v3-rqph/GHSA-p5gj-h5v3-rqph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5gj-h5v3-rqph", - "modified": "2024-01-17T15:30:27Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T15:30:27Z", "aliases": [ "CVE-2023-5006" ], "details": "The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-17T15:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json b/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json index 81efb5341af..ed0caaf5280 100644 --- a/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json +++ b/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcfg-49mv-9hvw", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3836" ], "details": "The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json new file mode 100644 index 00000000000..665fb3f569d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfm4-9qqj-3w82", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2024-22651" + ], + "details": "There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22651" + }, + { + "type": "WEB", + "url": "https://github.com/goldds96/Report/blob/main/DLink/DIR-815/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qjpf-2jhx-3758/GHSA-qjpf-2jhx-3758.json b/advisories/unreviewed/2024/01/GHSA-qjpf-2jhx-3758/GHSA-qjpf-2jhx-3758.json new file mode 100644 index 00000000000..7f4f298b746 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qjpf-2jhx-3758/GHSA-qjpf-2jhx-3758.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjpf-2jhx-3758", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23904" + ], + "details": "Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23904" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3334" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r278-g84p-6h4c/GHSA-r278-g84p-6h4c.json b/advisories/unreviewed/2024/01/GHSA-r278-g84p-6h4c/GHSA-r278-g84p-6h4c.json index 70272fe80c9..6b65dd5c6f0 100644 --- a/advisories/unreviewed/2024/01/GHSA-r278-g84p-6h4c/GHSA-r278-g84p-6h4c.json +++ b/advisories/unreviewed/2024/01/GHSA-r278-g84p-6h4c/GHSA-r278-g84p-6h4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r278-g84p-6h4c", - "modified": "2024-01-17T09:30:22Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T09:30:22Z", "aliases": [ "CVE-2023-52285" ], "details": "ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-17T08:15:39Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json b/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json index f370865049a..495452b25a5 100644 --- a/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json +++ b/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rp98-9vmx-835h", - "modified": "2024-01-17T03:30:55Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T03:30:55Z", "aliases": [ "CVE-2023-36235" ], "details": "An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-17T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rpqp-hf76-rjpp/GHSA-rpqp-hf76-rjpp.json b/advisories/unreviewed/2024/01/GHSA-rpqp-hf76-rjpp/GHSA-rpqp-hf76-rjpp.json index cc098ecc5a8..6f307beb9e2 100644 --- a/advisories/unreviewed/2024/01/GHSA-rpqp-hf76-rjpp/GHSA-rpqp-hf76-rjpp.json +++ b/advisories/unreviewed/2024/01/GHSA-rpqp-hf76-rjpp/GHSA-rpqp-hf76-rjpp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json b/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json new file mode 100644 index 00000000000..2a2fca2b247 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh9j-8vw4-5hp6", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2023-52040" + ], + "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52040" + }, + { + "type": "WEB", + "url": "https://github.com/Beckaf/vunl/blob/main/TOTOLINK/X6000R/3/3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vph5-2q33-7r9h/GHSA-vph5-2q33-7r9h.json b/advisories/unreviewed/2024/01/GHSA-vph5-2q33-7r9h/GHSA-vph5-2q33-7r9h.json new file mode 100644 index 00000000000..806945a12c8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vph5-2q33-7r9h/GHSA-vph5-2q33-7r9h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vph5-2q33-7r9h", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23899" + ], + "details": "Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23899" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3319" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x22x-5pp9-8v7f/GHSA-x22x-5pp9-8v7f.json b/advisories/unreviewed/2024/01/GHSA-x22x-5pp9-8v7f/GHSA-x22x-5pp9-8v7f.json new file mode 100644 index 00000000000..c17a3799c97 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x22x-5pp9-8v7f/GHSA-x22x-5pp9-8v7f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x22x-5pp9-8v7f", + "modified": "2024-01-24T18:31:02Z", + "published": "2024-01-24T18:31:02Z", + "aliases": [ + "CVE-2024-23905" + ], + "details": "Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23905" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3322" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json b/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json new file mode 100644 index 00000000000..a805aac9c30 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc7v-9m4q-8q68", + "modified": "2024-01-24T18:31:01Z", + "published": "2024-01-24T18:31:01Z", + "aliases": [ + "CVE-2024-22720" + ], + "details": "Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22720" + }, + { + "type": "WEB", + "url": "https://cupc4k3.medium.com/html-injection-vulnerability-in-kanboard-group-management-d9fe5154bb1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-24T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xhpq-8p2q-qgm6/GHSA-xhpq-8p2q-qgm6.json b/advisories/unreviewed/2024/01/GHSA-xhpq-8p2q-qgm6/GHSA-xhpq-8p2q-qgm6.json index e3231ba1ff0..b1e4888540f 100644 --- a/advisories/unreviewed/2024/01/GHSA-xhpq-8p2q-qgm6/GHSA-xhpq-8p2q-qgm6.json +++ b/advisories/unreviewed/2024/01/GHSA-xhpq-8p2q-qgm6/GHSA-xhpq-8p2q-qgm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhpq-8p2q-qgm6", - "modified": "2024-01-17T06:30:25Z", + "modified": "2024-01-24T18:31:00Z", "published": "2024-01-17T06:30:25Z", "aliases": [ "CVE-2024-0405" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false,