Publish Advisories

GHSA-mp92-3jfm-3575
GHSA-294c-hpxh-5qrx
GHSA-g44j-f8wm-6622
GHSA-hv45-r2f5-fmhj
GHSA-q38f-wwqq-rr3v
GHSA-qp68-5v39-r869
GHSA-4jch-8qq5-hqg6
This commit is contained in:
advisory-database[bot]
2023-11-10 03:31:45 +00:00
parent b3cbce5141
commit d5fa2e1585
7 changed files with 80 additions and 6 deletions
@@ -55,6 +55,14 @@
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-230.yaml"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVS/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEY/"
}
],
"database_specific": {
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g44j-f8wm-6622",
"modified": "2023-10-17T09:30:23Z",
"modified": "2023-11-10T03:30:25Z",
"published": "2023-10-17T09:30:23Z",
"aliases": [
"CVE-2023-42629"
@@ -24,13 +24,17 @@
{
"type": "WEB",
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42629"
},
{
"type": "WEB",
"url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T09:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv45-r2f5-fmhj",
"modified": "2023-10-17T12:30:26Z",
"modified": "2023-11-10T03:30:25Z",
"published": "2023-10-17T12:30:26Z",
"aliases": [
"CVE-2023-42628"
@@ -24,13 +24,17 @@
{
"type": "WEB",
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42628"
},
{
"type": "WEB",
"url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T12:15:10Z"
@@ -45,6 +45,14 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4YBK3I6SETHETBHDETFWM3VSZUQICIDV/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L2RMNR4235YXZZQ2X7Q4MTOZDMZ7BBQU/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEDJN4VFN57K5POOC7BNVD6L6WUUCSG6/"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp68-5v39-r869",
"modified": "2023-10-17T15:30:27Z",
"modified": "2023-11-10T03:30:25Z",
"published": "2023-10-17T15:30:27Z",
"aliases": [
"CVE-2023-42627"
@@ -24,13 +24,17 @@
{
"type": "WEB",
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42627"
},
{
"type": "WEB",
"url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T13:15:11Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jch-8qq5-hqg6",
"modified": "2023-11-10T03:30:25Z",
"published": "2023-11-10T03:30:25Z",
"aliases": [
"CVE-2023-6069"
],
"details": "Improper Input Validation in GitHub repository froxlor/froxlor prior to 2.1.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6069"
},
{
"type": "WEB",
"url": "https://github.com/froxlor/froxlor/commit/9e8f32f1e86016733b603b50c31b97f472e8dabc"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/aac0627e-e59d-476e-9385-edb7ff53758c"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-10T01:15:07Z"
}
}