diff --git a/advisories/unreviewed/2023/04/GHSA-22mh-fcv5-gcmq/GHSA-22mh-fcv5-gcmq.json b/advisories/unreviewed/2023/04/GHSA-22mh-fcv5-gcmq/GHSA-22mh-fcv5-gcmq.json index 5beda039d90..0f15de2afa9 100644 --- a/advisories/unreviewed/2023/04/GHSA-22mh-fcv5-gcmq/GHSA-22mh-fcv5-gcmq.json +++ b/advisories/unreviewed/2023/04/GHSA-22mh-fcv5-gcmq/GHSA-22mh-fcv5-gcmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22mh-fcv5-gcmq", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-28086" ], "details": "An HPE OneView appliance dump may expose proxy credential settings", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-2m28-wgxj-v265/GHSA-2m28-wgxj-v265.json b/advisories/unreviewed/2023/04/GHSA-2m28-wgxj-v265/GHSA-2m28-wgxj-v265.json index 1e5729ddd4e..c602b2b0929 100644 --- a/advisories/unreviewed/2023/04/GHSA-2m28-wgxj-v265/GHSA-2m28-wgxj-v265.json +++ b/advisories/unreviewed/2023/04/GHSA-2m28-wgxj-v265/GHSA-2m28-wgxj-v265.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m28-wgxj-v265", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-28088" ], "details": "An HPE OneView appliance dump may expose SAN switch administrative credentials", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-37j9-g226-hg3x/GHSA-37j9-g226-hg3x.json b/advisories/unreviewed/2023/04/GHSA-37j9-g226-hg3x/GHSA-37j9-g226-hg3x.json index 134b9d04150..7b67ead9d72 100644 --- a/advisories/unreviewed/2023/04/GHSA-37j9-g226-hg3x/GHSA-37j9-g226-hg3x.json +++ b/advisories/unreviewed/2023/04/GHSA-37j9-g226-hg3x/GHSA-37j9-g226-hg3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37j9-g226-hg3x", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-2282" ], "details": "Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-6847-pprf-rmvh/GHSA-6847-pprf-rmvh.json b/advisories/unreviewed/2023/04/GHSA-6847-pprf-rmvh/GHSA-6847-pprf-rmvh.json index 67e8597e009..cd91454fb3d 100644 --- a/advisories/unreviewed/2023/04/GHSA-6847-pprf-rmvh/GHSA-6847-pprf-rmvh.json +++ b/advisories/unreviewed/2023/04/GHSA-6847-pprf-rmvh/GHSA-6847-pprf-rmvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6847-pprf-rmvh", - "modified": "2023-04-25T00:30:41Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T00:30:41Z", "aliases": [ "CVE-2023-30414" ], "details": "Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json b/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json index 204104876fe..6cf7eb12250 100644 --- a/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json +++ b/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89h6-2239-3vw2", - "modified": "2023-04-25T00:30:41Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T00:30:41Z", "aliases": [ "CVE-2023-30408" ], "details": "Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-9vmw-8f7f-qhch/GHSA-9vmw-8f7f-qhch.json b/advisories/unreviewed/2023/04/GHSA-9vmw-8f7f-qhch/GHSA-9vmw-8f7f-qhch.json index 2b0ee3dcc87..cb7b2791b1a 100644 --- a/advisories/unreviewed/2023/04/GHSA-9vmw-8f7f-qhch/GHSA-9vmw-8f7f-qhch.json +++ b/advisories/unreviewed/2023/04/GHSA-9vmw-8f7f-qhch/GHSA-9vmw-8f7f-qhch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vmw-8f7f-qhch", - "modified": "2023-04-24T21:30:30Z", + "modified": "2023-05-04T15:30:20Z", "published": "2023-04-24T21:30:30Z", "aliases": [ "CVE-2023-2019" ], "details": "A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json b/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json index a601026328a..c051fbdea87 100644 --- a/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json +++ b/advisories/unreviewed/2023/04/GHSA-gh3f-7cgq-5c59/GHSA-gh3f-7cgq-5c59.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-hxv8-f44w-4g6h/GHSA-hxv8-f44w-4g6h.json b/advisories/unreviewed/2023/04/GHSA-hxv8-f44w-4g6h/GHSA-hxv8-f44w-4g6h.json index 0c75acecebe..421e29378b6 100644 --- a/advisories/unreviewed/2023/04/GHSA-hxv8-f44w-4g6h/GHSA-hxv8-f44w-4g6h.json +++ b/advisories/unreviewed/2023/04/GHSA-hxv8-f44w-4g6h/GHSA-hxv8-f44w-4g6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxv8-f44w-4g6h", - "modified": "2023-04-24T21:30:30Z", + "modified": "2023-05-04T15:30:20Z", "published": "2023-04-24T21:30:30Z", "aliases": [ "CVE-2023-2250" ], "details": "A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all secrets for all kubernetes namespaces, leading into a cluster-level privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-jqw7-j588-4wrq/GHSA-jqw7-j588-4wrq.json b/advisories/unreviewed/2023/04/GHSA-jqw7-j588-4wrq/GHSA-jqw7-j588-4wrq.json index 7f45ea43dca..22b1e0136e3 100644 --- a/advisories/unreviewed/2023/04/GHSA-jqw7-j588-4wrq/GHSA-jqw7-j588-4wrq.json +++ b/advisories/unreviewed/2023/04/GHSA-jqw7-j588-4wrq/GHSA-jqw7-j588-4wrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqw7-j588-4wrq", - "modified": "2023-04-25T00:30:41Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T00:30:41Z", "aliases": [ "CVE-2023-30410" ], "details": "Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json b/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json index 5c0f85480b7..336ce91f995 100644 --- a/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json +++ b/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwhj-r8gf-xm67", - "modified": "2023-04-25T00:30:40Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T00:30:40Z", "aliases": [ "CVE-2023-30406" ], "details": "Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-mhqh-6m58-844q/GHSA-mhqh-6m58-844q.json b/advisories/unreviewed/2023/04/GHSA-mhqh-6m58-844q/GHSA-mhqh-6m58-844q.json index eb2faf0286e..809acdb62df 100644 --- a/advisories/unreviewed/2023/04/GHSA-mhqh-6m58-844q/GHSA-mhqh-6m58-844q.json +++ b/advisories/unreviewed/2023/04/GHSA-mhqh-6m58-844q/GHSA-mhqh-6m58-844q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhqh-6m58-844q", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-28089" ], "details": "An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-mqq2-gjcf-j3cq/GHSA-mqq2-gjcf-j3cq.json b/advisories/unreviewed/2023/04/GHSA-mqq2-gjcf-j3cq/GHSA-mqq2-gjcf-j3cq.json index afb474dc1c9..d1c66e8a727 100644 --- a/advisories/unreviewed/2023/04/GHSA-mqq2-gjcf-j3cq/GHSA-mqq2-gjcf-j3cq.json +++ b/advisories/unreviewed/2023/04/GHSA-mqq2-gjcf-j3cq/GHSA-mqq2-gjcf-j3cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqq2-gjcf-j3cq", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-28090" ], "details": "An HPE OneView appliance dump may expose SNMPv3 read credentials", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json b/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json index edca109ae8c..2a88a292319 100644 --- a/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json +++ b/advisories/unreviewed/2023/04/GHSA-pgrj-wm9q-gw8p/GHSA-pgrj-wm9q-gw8p.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-pvxc-v7pp-fmx4/GHSA-pvxc-v7pp-fmx4.json b/advisories/unreviewed/2023/04/GHSA-pvxc-v7pp-fmx4/GHSA-pvxc-v7pp-fmx4.json index fb43204207e..9226863002d 100644 --- a/advisories/unreviewed/2023/04/GHSA-pvxc-v7pp-fmx4/GHSA-pvxc-v7pp-fmx4.json +++ b/advisories/unreviewed/2023/04/GHSA-pvxc-v7pp-fmx4/GHSA-pvxc-v7pp-fmx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvxc-v7pp-fmx4", - "modified": "2023-04-24T21:30:30Z", + "modified": "2023-05-04T15:30:20Z", "published": "2023-04-24T21:30:30Z", "aliases": [ "CVE-2023-2006" ], "details": "A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-wf9j-m8jq-36qr/GHSA-wf9j-m8jq-36qr.json b/advisories/unreviewed/2023/04/GHSA-wf9j-m8jq-36qr/GHSA-wf9j-m8jq-36qr.json index 938355d51ab..a5db6a645ed 100644 --- a/advisories/unreviewed/2023/04/GHSA-wf9j-m8jq-36qr/GHSA-wf9j-m8jq-36qr.json +++ b/advisories/unreviewed/2023/04/GHSA-wf9j-m8jq-36qr/GHSA-wf9j-m8jq-36qr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wf9j-m8jq-36qr", - "modified": "2023-04-13T21:30:27Z", + "modified": "2023-05-04T15:30:19Z", "published": "2023-04-13T21:30:27Z", "aliases": [ "CVE-2023-22948" ], "details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-311" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wg8w-8qrr-6452/GHSA-wg8w-8qrr-6452.json b/advisories/unreviewed/2023/04/GHSA-wg8w-8qrr-6452/GHSA-wg8w-8qrr-6452.json index d93c8d61bf0..dc65eb2137b 100644 --- a/advisories/unreviewed/2023/04/GHSA-wg8w-8qrr-6452/GHSA-wg8w-8qrr-6452.json +++ b/advisories/unreviewed/2023/04/GHSA-wg8w-8qrr-6452/GHSA-wg8w-8qrr-6452.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg8w-8qrr-6452", - "modified": "2023-04-25T21:30:28Z", + "modified": "2023-05-04T15:30:21Z", "published": "2023-04-25T21:30:28Z", "aliases": [ "CVE-2023-28087" ], "details": "An HPE OneView appliance dump may expose OneView user accounts", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-xwhf-r489-w73v/GHSA-xwhf-r489-w73v.json b/advisories/unreviewed/2023/04/GHSA-xwhf-r489-w73v/GHSA-xwhf-r489-w73v.json index f2107e74a8d..45f736d1c5a 100644 --- a/advisories/unreviewed/2023/04/GHSA-xwhf-r489-w73v/GHSA-xwhf-r489-w73v.json +++ b/advisories/unreviewed/2023/04/GHSA-xwhf-r489-w73v/GHSA-xwhf-r489-w73v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwhf-r489-w73v", - "modified": "2023-04-13T18:30:29Z", + "modified": "2023-05-04T15:30:19Z", "published": "2023-04-13T18:30:29Z", "aliases": [ "CVE-2023-22950" ], "details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-669" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json b/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json new file mode 100644 index 00000000000..fd8314becc0 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q43-fxm7-9fhw", + "modified": "2023-05-04T15:30:21Z", + "published": "2023-05-04T15:30:21Z", + "aliases": [ + "CVE-2023-23470" + ], + "details": "IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23470" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/244510" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6987767" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json b/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json new file mode 100644 index 00000000000..4a874143144 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-j5pp-6f4w-r5r6/GHSA-j5pp-6f4w-r5r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5pp-6f4w-r5r6", + "modified": "2023-05-04T15:30:21Z", + "published": "2023-05-04T15:30:21Z", + "aliases": [ + "CVE-2023-29827" + ], + "details": "ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29827" + }, + { + "type": "WEB", + "url": "https://github.com/mde/ejs/issues/720" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json b/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json new file mode 100644 index 00000000000..8937242bf5a --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p73q-78q5-cwpp", + "modified": "2023-05-04T15:30:21Z", + "published": "2023-05-04T15:30:21Z", + "aliases": [ + "CVE-2023-24958" + ], + "details": "A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24958" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/246320" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6980845" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file