Publish Advisories

GHSA-9225-wwj6-c3w3
GHSA-jx37-m37q-v7c2
GHSA-j6rf-pfmw-h88q
GHSA-jgg8-69rp-g5j5
GHSA-jvqw-9mq6-23h9
GHSA-m2x2-7xv3-gc3m
GHSA-wp8f-hfpr-h9w9
GHSA-x44h-jr6p-888x
GHSA-xv78-4qjf-hjxf
This commit is contained in:
advisory-database[bot]
2023-07-10 15:32:39 +00:00
parent 14db7336da
commit d4ae07f98b
9 changed files with 48 additions and 24 deletions
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx37-m37q-v7c2",
"modified": "2023-06-30T21:30:26Z",
"modified": "2023-07-10T15:31:15Z",
"published": "2023-06-30T21:30:26Z",
"aliases": [
"CVE-2023-29147"
],
"details": "In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6rf-pfmw-h88q",
"modified": "2023-07-06T15:30:33Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-06T15:30:33Z",
"aliases": [
"CVE-2023-36968"
],
"details": "A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgg8-69rp-g5j5",
"modified": "2023-07-01T00:30:45Z",
"modified": "2023-07-10T15:31:15Z",
"published": "2023-07-01T00:30:45Z",
"aliases": [
"CVE-2023-36144"
],
"details": "An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvqw-9mq6-23h9",
"modified": "2023-07-01T00:30:45Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-01T00:30:45Z",
"aliases": [
"CVE-2023-30586"
],
"details": "A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model when called with a compatible OpenSSL engine. The OpenSSL engine can, for example, disable the permission model in the host process by manipulating the process's stack memory to locate the permission model Permission::enabled_ in the host process's heap memory. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2x2-7xv3-gc3m",
"modified": "2023-07-03T21:30:57Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-03T21:30:57Z",
"aliases": [
"CVE-2023-36183"
],
"details": "Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp8f-hfpr-h9w9",
"modified": "2023-07-03T21:30:57Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-03T21:30:57Z",
"aliases": [
"CVE-2023-36291"
],
"details": "Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x44h-jr6p-888x",
"modified": "2023-07-05T21:30:17Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-05T21:30:17Z",
"aliases": [
"CVE-2023-34654"
],
"details": "taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv78-4qjf-hjxf",
"modified": "2023-07-05T18:30:44Z",
"modified": "2023-07-10T15:31:16Z",
"published": "2023-07-05T18:30:44Z",
"aliases": [
"CVE-2023-36934"
],
"details": "In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,