diff --git a/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json b/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json index ee4ec0554cf..e2f47b732c7 100644 --- a/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json +++ b/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json @@ -55,6 +55,14 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-230.yaml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVS/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEY/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json index 79d5b036c2b..7b04e4388f3 100644 --- a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json +++ b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/" diff --git a/advisories/unreviewed/2023/10/GHSA-g44j-f8wm-6622/GHSA-g44j-f8wm-6622.json b/advisories/unreviewed/2023/10/GHSA-g44j-f8wm-6622/GHSA-g44j-f8wm-6622.json index c14abc00f30..a47b5241f58 100644 --- a/advisories/unreviewed/2023/10/GHSA-g44j-f8wm-6622/GHSA-g44j-f8wm-6622.json +++ b/advisories/unreviewed/2023/10/GHSA-g44j-f8wm-6622/GHSA-g44j-f8wm-6622.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g44j-f8wm-6622", - "modified": "2023-10-17T09:30:23Z", + "modified": "2023-11-10T03:30:25Z", "published": "2023-10-17T09:30:23Z", "aliases": [ "CVE-2023-42629" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42629" + }, + { + "type": "WEB", + "url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T09:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-hv45-r2f5-fmhj/GHSA-hv45-r2f5-fmhj.json b/advisories/unreviewed/2023/10/GHSA-hv45-r2f5-fmhj/GHSA-hv45-r2f5-fmhj.json index fccf9f40a8f..7757ea8dc93 100644 --- a/advisories/unreviewed/2023/10/GHSA-hv45-r2f5-fmhj/GHSA-hv45-r2f5-fmhj.json +++ b/advisories/unreviewed/2023/10/GHSA-hv45-r2f5-fmhj/GHSA-hv45-r2f5-fmhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hv45-r2f5-fmhj", - "modified": "2023-10-17T12:30:26Z", + "modified": "2023-11-10T03:30:25Z", "published": "2023-10-17T12:30:26Z", "aliases": [ "CVE-2023-42628" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42628" + }, + { + "type": "WEB", + "url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T12:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 6734f8a9aaf..0bf35c81aed 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4YBK3I6SETHETBHDETFWM3VSZUQICIDV/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L2RMNR4235YXZZQ2X7Q4MTOZDMZ7BBQU/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEDJN4VFN57K5POOC7BNVD6L6WUUCSG6/" diff --git a/advisories/unreviewed/2023/10/GHSA-qp68-5v39-r869/GHSA-qp68-5v39-r869.json b/advisories/unreviewed/2023/10/GHSA-qp68-5v39-r869/GHSA-qp68-5v39-r869.json index c2aafe0d3a7..6f315915959 100644 --- a/advisories/unreviewed/2023/10/GHSA-qp68-5v39-r869/GHSA-qp68-5v39-r869.json +++ b/advisories/unreviewed/2023/10/GHSA-qp68-5v39-r869/GHSA-qp68-5v39-r869.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp68-5v39-r869", - "modified": "2023-10-17T15:30:27Z", + "modified": "2023-11-10T03:30:25Z", "published": "2023-10-17T15:30:27Z", "aliases": [ "CVE-2023-42627" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42627" + }, + { + "type": "WEB", + "url": "https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T13:15:11Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4jch-8qq5-hqg6/GHSA-4jch-8qq5-hqg6.json b/advisories/unreviewed/2023/11/GHSA-4jch-8qq5-hqg6/GHSA-4jch-8qq5-hqg6.json new file mode 100644 index 00000000000..5a97263d548 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4jch-8qq5-hqg6/GHSA-4jch-8qq5-hqg6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jch-8qq5-hqg6", + "modified": "2023-11-10T03:30:25Z", + "published": "2023-11-10T03:30:25Z", + "aliases": [ + "CVE-2023-6069" + ], + "details": "Improper Input Validation in GitHub repository froxlor/froxlor prior to 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6069" + }, + { + "type": "WEB", + "url": "https://github.com/froxlor/froxlor/commit/9e8f32f1e86016733b603b50c31b97f472e8dabc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/aac0627e-e59d-476e-9385-edb7ff53758c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-10T01:15:07Z" + } +} \ No newline at end of file