From d577f53487b94c5444d5e5d2b9877cc9e7860dd0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 25 Dec 2023 06:31:31 +0000 Subject: [PATCH] Publish Advisories GHSA-3gjc-mp82-fj4q GHSA-3m3v-xv6x-mhqh GHSA-3rcv-jmj4-w65f GHSA-4m6r-4mpf-3p4q GHSA-4prj-w93p-4j89 GHSA-88cv-mw5r-6xcj GHSA-9rj5-9jpj-cqqh GHSA-ccq5-7ghx-j6xg GHSA-f8jx-jrmh-qpr6 GHSA-fwrj-5c8f-f8h2 GHSA-gv74-v3v2-h2x9 GHSA-h8h3-f8x2-6ggh GHSA-rxj5-x7r4-38wm GHSA-v6x9-c2q6-xc4w GHSA-vcc2-j3rm-53wf GHSA-vjxw-62pr-vrfg GHSA-wfg4-v93p-7mj4 GHSA-xp6x-8hgv-x5w5 --- .../GHSA-3gjc-mp82-fj4q.json | 35 +++++++++++++++++ .../GHSA-3m3v-xv6x-mhqh.json | 35 +++++++++++++++++ .../GHSA-3rcv-jmj4-w65f.json | 35 +++++++++++++++++ .../GHSA-4m6r-4mpf-3p4q.json | 35 +++++++++++++++++ .../GHSA-4prj-w93p-4j89.json | 35 +++++++++++++++++ .../GHSA-88cv-mw5r-6xcj.json | 35 +++++++++++++++++ .../GHSA-9rj5-9jpj-cqqh.json | 39 +++++++++++++++++++ .../GHSA-ccq5-7ghx-j6xg.json | 35 +++++++++++++++++ .../GHSA-f8jx-jrmh-qpr6.json | 35 +++++++++++++++++ .../GHSA-fwrj-5c8f-f8h2.json | 4 ++ .../GHSA-gv74-v3v2-h2x9.json | 35 +++++++++++++++++ .../GHSA-h8h3-f8x2-6ggh.json | 35 +++++++++++++++++ .../GHSA-rxj5-x7r4-38wm.json | 35 +++++++++++++++++ .../GHSA-v6x9-c2q6-xc4w.json | 35 +++++++++++++++++ .../GHSA-vcc2-j3rm-53wf.json | 35 +++++++++++++++++ .../GHSA-vjxw-62pr-vrfg.json | 39 +++++++++++++++++++ .../GHSA-wfg4-v93p-7mj4.json | 39 +++++++++++++++++++ .../GHSA-xp6x-8hgv-x5w5.json | 4 ++ 18 files changed, 580 insertions(+) create mode 100644 advisories/unreviewed/2023/12/GHSA-3gjc-mp82-fj4q/GHSA-3gjc-mp82-fj4q.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3m3v-xv6x-mhqh/GHSA-3m3v-xv6x-mhqh.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4m6r-4mpf-3p4q/GHSA-4m6r-4mpf-3p4q.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json create mode 100644 advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json create mode 100644 advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json create mode 100644 advisories/unreviewed/2023/12/GHSA-f8jx-jrmh-qpr6/GHSA-f8jx-jrmh-qpr6.json create mode 100644 advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json create mode 100644 advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json create mode 100644 advisories/unreviewed/2023/12/GHSA-rxj5-x7r4-38wm/GHSA-rxj5-x7r4-38wm.json create mode 100644 advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json create mode 100644 advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json create mode 100644 advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json diff --git a/advisories/unreviewed/2023/12/GHSA-3gjc-mp82-fj4q/GHSA-3gjc-mp82-fj4q.json b/advisories/unreviewed/2023/12/GHSA-3gjc-mp82-fj4q/GHSA-3gjc-mp82-fj4q.json new file mode 100644 index 00000000000..ae07f61c91e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3gjc-mp82-fj4q/GHSA-3gjc-mp82-fj4q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gjc-mp82-fj4q", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2023-30451" + ], + "details": "In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30451" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176274/TYPO3-11.5.24-Path-Traversal.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3m3v-xv6x-mhqh/GHSA-3m3v-xv6x-mhqh.json b/advisories/unreviewed/2023/12/GHSA-3m3v-xv6x-mhqh/GHSA-3m3v-xv6x-mhqh.json new file mode 100644 index 00000000000..ea8d1730cc0 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3m3v-xv6x-mhqh/GHSA-3m3v-xv6x-mhqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m3v-xv6x-mhqh", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-40236" + ], + "details": "In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40236" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json b/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json new file mode 100644 index 00000000000..f74da5ca816 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3rcv-jmj4-w65f/GHSA-3rcv-jmj4-w65f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rcv-jmj4-w65f", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2022-39822" + ], + "details": "In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39822" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4m6r-4mpf-3p4q/GHSA-4m6r-4mpf-3p4q.json b/advisories/unreviewed/2023/12/GHSA-4m6r-4mpf-3p4q/GHSA-4m6r-4mpf-3p4q.json new file mode 100644 index 00000000000..47aa987bbc3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4m6r-4mpf-3p4q/GHSA-4m6r-4mpf-3p4q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m6r-4mpf-3p4q", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-31289" + ], + "details": "Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31289" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json b/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json new file mode 100644 index 00000000000..7668e020601 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4prj-w93p-4j89/GHSA-4prj-w93p-4j89.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4prj-w93p-4j89", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2022-39818" + ], + "details": "In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39818" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json b/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json new file mode 100644 index 00000000000..c7da53de119 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-88cv-mw5r-6xcj/GHSA-88cv-mw5r-6xcj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88cv-mw5r-6xcj", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-49328" + ], + "details": "On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49328" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json b/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json new file mode 100644 index 00000000000..234a4580485 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9rj5-9jpj-cqqh/GHSA-9rj5-9jpj-cqqh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rj5-9jpj-cqqh", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2023-51771" + ], + "details": "In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51771" + }, + { + "type": "WEB", + "url": "https://github.com/starnight/MicroHttpServer/issues/8" + }, + { + "type": "WEB", + "url": "https://github.com/starnight/MicroHttpServer/tree/a8ab029c9a26a4c9f26b9d8a2757b8299aaff120" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json b/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json new file mode 100644 index 00000000000..d16ce4a2c1a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-ccq5-7ghx-j6xg/GHSA-ccq5-7ghx-j6xg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccq5-7ghx-j6xg", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2022-41762" + ], + "details": "An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41762" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-f8jx-jrmh-qpr6/GHSA-f8jx-jrmh-qpr6.json b/advisories/unreviewed/2023/12/GHSA-f8jx-jrmh-qpr6/GHSA-f8jx-jrmh-qpr6.json new file mode 100644 index 00000000000..70f99c1f2a8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-f8jx-jrmh-qpr6/GHSA-f8jx-jrmh-qpr6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8jx-jrmh-qpr6", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-37225" + ], + "details": "Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37225" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json index 12d4cee6f9f..093cbcc47bf 100644 --- a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json +++ b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/" diff --git a/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json b/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json new file mode 100644 index 00000000000..d2121fdf955 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gv74-v3v2-h2x9/GHSA-gv74-v3v2-h2x9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv74-v3v2-h2x9", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2022-41761" + ], + "details": "An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41761" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json b/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json new file mode 100644 index 00000000000..948293a4cb5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-h8h3-f8x2-6ggh/GHSA-h8h3-f8x2-6ggh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8h3-f8x2-6ggh", + "modified": "2023-12-25T06:30:20Z", + "published": "2023-12-25T06:30:20Z", + "aliases": [ + "CVE-2022-39820" + ], + "details": "In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39820" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rxj5-x7r4-38wm/GHSA-rxj5-x7r4-38wm.json b/advisories/unreviewed/2023/12/GHSA-rxj5-x7r4-38wm/GHSA-rxj5-x7r4-38wm.json new file mode 100644 index 00000000000..528ad8ef66e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rxj5-x7r4-38wm/GHSA-rxj5-x7r4-38wm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxj5-x7r4-38wm", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-31455" + ], + "details": "Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31455" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json b/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json new file mode 100644 index 00000000000..816a834c0d6 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v6x9-c2q6-xc4w/GHSA-v6x9-c2q6-xc4w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6x9-c2q6-xc4w", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2022-41760" + ], + "details": "An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41760" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json b/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json new file mode 100644 index 00000000000..0d636699c68 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vcc2-j3rm-53wf/GHSA-vcc2-j3rm-53wf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcc2-j3rm-53wf", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2022-43675" + ], + "details": "An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43675" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/redteam" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json new file mode 100644 index 00000000000..26f6a169968 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vjxw-62pr-vrfg/GHSA-vjxw-62pr-vrfg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjxw-62pr-vrfg", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-51772" + ], + "details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click on the Help icon, observe that there is a browser window for the One Identity website, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51772" + }, + { + "type": "WEB", + "url": "https://sec-consult.com/vulnerability-lab/advisory/kiosk-escape-privilege-escalation-one-identity-password-manager-secure-password-extension/" + }, + { + "type": "WEB", + "url": "https://www.oneidentity.com/products/password-manager/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json b/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json new file mode 100644 index 00000000000..1f9ccbf308e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wfg4-v93p-7mj4/GHSA-wfg4-v93p-7mj4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfg4-v93p-7mj4", + "modified": "2023-12-25T06:30:21Z", + "published": "2023-12-25T06:30:21Z", + "aliases": [ + "CVE-2023-48654" + ], + "details": "One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\\SYSTEM.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48654" + }, + { + "type": "WEB", + "url": "https://sec-consult.com/vulnerability-lab/advisory/kiosk-escape-privilege-escalation-one-identity-password-manager-secure-password-extension/" + }, + { + "type": "WEB", + "url": "https://www.oneidentity.com/products/password-manager/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json index 5bcedee24d6..21ca60df64d 100644 --- a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json +++ b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00013.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/"