From d4ae07f98b5d3ec98535b2df1622efed6dbe2439 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Jul 2023 15:32:39 +0000 Subject: [PATCH] Publish Advisories GHSA-9225-wwj6-c3w3 GHSA-jx37-m37q-v7c2 GHSA-j6rf-pfmw-h88q GHSA-jgg8-69rp-g5j5 GHSA-jvqw-9mq6-23h9 GHSA-m2x2-7xv3-gc3m GHSA-wp8f-hfpr-h9w9 GHSA-x44h-jr6p-888x GHSA-xv78-4qjf-hjxf --- .../2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json | 2 +- .../2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json | 7 +++++-- .../2023/07/GHSA-j6rf-pfmw-h88q/GHSA-j6rf-pfmw-h88q.json | 9 ++++++--- .../2023/07/GHSA-jgg8-69rp-g5j5/GHSA-jgg8-69rp-g5j5.json | 9 ++++++--- .../2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json | 9 ++++++--- .../2023/07/GHSA-m2x2-7xv3-gc3m/GHSA-m2x2-7xv3-gc3m.json | 9 ++++++--- .../2023/07/GHSA-wp8f-hfpr-h9w9/GHSA-wp8f-hfpr-h9w9.json | 9 ++++++--- .../2023/07/GHSA-x44h-jr6p-888x/GHSA-x44h-jr6p-888x.json | 9 ++++++--- .../2023/07/GHSA-xv78-4qjf-hjxf/GHSA-xv78-4qjf-hjxf.json | 9 ++++++--- 9 files changed, 48 insertions(+), 24 deletions(-) diff --git a/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json b/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json index c6968b30dc3..e4bd00ba752 100644 --- a/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json +++ b/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json b/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json index 37bae0ca108..cb9e98e09c1 100644 --- a/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json +++ b/advisories/unreviewed/2023/06/GHSA-jx37-m37q-v7c2/GHSA-jx37-m37q-v7c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx37-m37q-v7c2", - "modified": "2023-06-30T21:30:26Z", + "modified": "2023-07-10T15:31:15Z", "published": "2023-06-30T21:30:26Z", "aliases": [ "CVE-2023-29147" ], "details": "In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-j6rf-pfmw-h88q/GHSA-j6rf-pfmw-h88q.json b/advisories/unreviewed/2023/07/GHSA-j6rf-pfmw-h88q/GHSA-j6rf-pfmw-h88q.json index 75276e7d17e..4c7a609c50e 100644 --- a/advisories/unreviewed/2023/07/GHSA-j6rf-pfmw-h88q/GHSA-j6rf-pfmw-h88q.json +++ b/advisories/unreviewed/2023/07/GHSA-j6rf-pfmw-h88q/GHSA-j6rf-pfmw-h88q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6rf-pfmw-h88q", - "modified": "2023-07-06T15:30:33Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-06T15:30:33Z", "aliases": [ "CVE-2023-36968" ], "details": "A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jgg8-69rp-g5j5/GHSA-jgg8-69rp-g5j5.json b/advisories/unreviewed/2023/07/GHSA-jgg8-69rp-g5j5/GHSA-jgg8-69rp-g5j5.json index fb2c9ffa264..757bab3878e 100644 --- a/advisories/unreviewed/2023/07/GHSA-jgg8-69rp-g5j5/GHSA-jgg8-69rp-g5j5.json +++ b/advisories/unreviewed/2023/07/GHSA-jgg8-69rp-g5j5/GHSA-jgg8-69rp-g5j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jgg8-69rp-g5j5", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T15:31:15Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-36144" ], "details": "An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json b/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json index 03e64268b1e..34e0b12c6ab 100644 --- a/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json +++ b/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvqw-9mq6-23h9", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-30586" ], "details": "A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model when called with a compatible OpenSSL engine. The OpenSSL engine can, for example, disable the permission model in the host process by manipulating the process's stack memory to locate the permission model Permission::enabled_ in the host process's heap memory. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-m2x2-7xv3-gc3m/GHSA-m2x2-7xv3-gc3m.json b/advisories/unreviewed/2023/07/GHSA-m2x2-7xv3-gc3m/GHSA-m2x2-7xv3-gc3m.json index a9e420b4595..d920e18ffef 100644 --- a/advisories/unreviewed/2023/07/GHSA-m2x2-7xv3-gc3m/GHSA-m2x2-7xv3-gc3m.json +++ b/advisories/unreviewed/2023/07/GHSA-m2x2-7xv3-gc3m/GHSA-m2x2-7xv3-gc3m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2x2-7xv3-gc3m", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36183" ], "details": "Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-wp8f-hfpr-h9w9/GHSA-wp8f-hfpr-h9w9.json b/advisories/unreviewed/2023/07/GHSA-wp8f-hfpr-h9w9/GHSA-wp8f-hfpr-h9w9.json index 962771f8fa3..20a39e375cd 100644 --- a/advisories/unreviewed/2023/07/GHSA-wp8f-hfpr-h9w9/GHSA-wp8f-hfpr-h9w9.json +++ b/advisories/unreviewed/2023/07/GHSA-wp8f-hfpr-h9w9/GHSA-wp8f-hfpr-h9w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp8f-hfpr-h9w9", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36291" ], "details": "Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-x44h-jr6p-888x/GHSA-x44h-jr6p-888x.json b/advisories/unreviewed/2023/07/GHSA-x44h-jr6p-888x/GHSA-x44h-jr6p-888x.json index dd59dbb145b..e006e07ea4f 100644 --- a/advisories/unreviewed/2023/07/GHSA-x44h-jr6p-888x/GHSA-x44h-jr6p-888x.json +++ b/advisories/unreviewed/2023/07/GHSA-x44h-jr6p-888x/GHSA-x44h-jr6p-888x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x44h-jr6p-888x", - "modified": "2023-07-05T21:30:17Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-05T21:30:17Z", "aliases": [ "CVE-2023-34654" ], "details": "taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-xv78-4qjf-hjxf/GHSA-xv78-4qjf-hjxf.json b/advisories/unreviewed/2023/07/GHSA-xv78-4qjf-hjxf/GHSA-xv78-4qjf-hjxf.json index c465f61e206..a87a6b39af4 100644 --- a/advisories/unreviewed/2023/07/GHSA-xv78-4qjf-hjxf/GHSA-xv78-4qjf-hjxf.json +++ b/advisories/unreviewed/2023/07/GHSA-xv78-4qjf-hjxf/GHSA-xv78-4qjf-hjxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv78-4qjf-hjxf", - "modified": "2023-07-05T18:30:44Z", + "modified": "2023-07-10T15:31:16Z", "published": "2023-07-05T18:30:44Z", "aliases": [ "CVE-2023-36934" ], "details": "In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false,