Publish Advisories

GHSA-22mh-fcv5-gcmq
GHSA-2m28-wgxj-v265
GHSA-37j9-g226-hg3x
GHSA-6847-pprf-rmvh
GHSA-89h6-2239-3vw2
GHSA-9vmw-8f7f-qhch
GHSA-gh3f-7cgq-5c59
GHSA-hxv8-f44w-4g6h
GHSA-jqw7-j588-4wrq
GHSA-jwhj-r8gf-xm67
GHSA-mhqh-6m58-844q
GHSA-mqq2-gjcf-j3cq
GHSA-pgrj-wm9q-gw8p
GHSA-pvxc-v7pp-fmx4
GHSA-wf9j-m8jq-36qr
GHSA-wg8w-8qrr-6452
GHSA-xwhf-r489-w73v
GHSA-5q43-fxm7-9fhw
GHSA-j5pp-6f4w-r5r6
GHSA-p73q-78q5-cwpp
This commit is contained in:
advisory-database[bot]
2023-05-04 15:31:32 +00:00
parent ccfd32f01f
commit e0e8288139
20 changed files with 205 additions and 41 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22mh-fcv5-gcmq",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-28086"
],
"details": "An HPE OneView appliance dump may expose proxy credential settings",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m28-wgxj-v265",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-28088"
],
"details": "An HPE OneView appliance dump may expose SAN switch administrative credentials",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37j9-g226-hg3x",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-2282"
],
"details": "Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6847-pprf-rmvh",
"modified": "2023-04-25T00:30:41Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T00:30:41Z",
"aliases": [
"CVE-2023-30414"
],
"details": "Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-89h6-2239-3vw2",
"modified": "2023-04-25T00:30:41Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T00:30:41Z",
"aliases": [
"CVE-2023-30408"
],
"details": "Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vmw-8f7f-qhch",
"modified": "2023-04-24T21:30:30Z",
"modified": "2023-05-04T15:30:20Z",
"published": "2023-04-24T21:30:30Z",
"aliases": [
"CVE-2023-2019"
],
"details": "A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxv8-f44w-4g6h",
"modified": "2023-04-24T21:30:30Z",
"modified": "2023-05-04T15:30:20Z",
"published": "2023-04-24T21:30:30Z",
"aliases": [
"CVE-2023-2250"
],
"details": "A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all secrets for all kubernetes namespaces, leading into a cluster-level privilege escalation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqw7-j588-4wrq",
"modified": "2023-04-25T00:30:41Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T00:30:41Z",
"aliases": [
"CVE-2023-30410"
],
"details": "Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwhj-r8gf-xm67",
"modified": "2023-04-25T00:30:40Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T00:30:40Z",
"aliases": [
"CVE-2023-30406"
],
"details": "Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhqh-6m58-844q",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-28089"
],
"details": "An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqq2-gjcf-j3cq",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-28090"
],
"details": "An HPE OneView appliance dump may expose SNMPv3 read credentials",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": null,
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvxc-v7pp-fmx4",
"modified": "2023-04-24T21:30:30Z",
"modified": "2023-05-04T15:30:20Z",
"published": "2023-04-24T21:30:30Z",
"aliases": [
"CVE-2023-2006"
],
"details": "A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf9j-m8jq-36qr",
"modified": "2023-04-13T21:30:27Z",
"modified": "2023-05-04T15:30:19Z",
"published": "2023-04-13T21:30:27Z",
"aliases": [
"CVE-2023-22948"
],
"details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-311"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wg8w-8qrr-6452",
"modified": "2023-04-25T21:30:28Z",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-04-25T21:30:28Z",
"aliases": [
"CVE-2023-28087"
],
"details": "An HPE OneView appliance dump may expose OneView user accounts",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwhf-r489-w73v",
"modified": "2023-04-13T18:30:29Z",
"modified": "2023-05-04T15:30:19Z",
"published": "2023-04-13T18:30:29Z",
"aliases": [
"CVE-2023-22950"
],
"details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-669"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q43-fxm7-9fhw",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-05-04T15:30:21Z",
"aliases": [
"CVE-2023-23470"
],
"details": "IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23470"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/244510"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6987767"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5pp-6f4w-r5r6",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-05-04T15:30:21Z",
"aliases": [
"CVE-2023-29827"
],
"details": "ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29827"
},
{
"type": "WEB",
"url": "https://github.com/mde/ejs/issues/720"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p73q-78q5-cwpp",
"modified": "2023-05-04T15:30:21Z",
"published": "2023-05-04T15:30:21Z",
"aliases": [
"CVE-2023-24958"
],
"details": "A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24958"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/246320"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6980845"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}