Publish Advisories

GHSA-72xf-g2v4-qvf3
GHSA-x9w5-v3q2-3rhw
GHSA-8c82-xj9x-mxgj
GHSA-hm4h-jq5c-c933
GHSA-28p7-rxh6-3h6x
GHSA-63f3-2rgp-79qx
GHSA-67p4-4qm6-h6gq
GHSA-6pc7-4x73-wwc6
GHSA-7pp5-c4g8-xxc4
GHSA-cr7m-mx45-3638
GHSA-fm2x-2crw-hf7h
GHSA-fq97-hv4f-crm6
GHSA-j66f-jc3v-93vp
GHSA-j737-8h5g-42g9
GHSA-jg84-v5xw-8m52
GHSA-rjjw-vjj8-q96x
GHSA-xf63-228h-qhch
GHSA-xjjp-35cq-88wh
This commit is contained in:
advisory-database[bot]
2024-02-28 03:31:53 +00:00
parent 5886347b69
commit e226dd7f6c
18 changed files with 299 additions and 13 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72xf-g2v4-qvf3",
"modified": "2023-07-07T21:39:57Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2023-07-01T06:30:16Z",
"aliases": [
"CVE-2023-26136"
@@ -65,6 +65,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00010.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9w5-v3q2-3rhw",
"modified": "2023-10-26T20:53:21Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2023-10-26T20:53:21Z",
"aliases": [
"CVE-2023-46234"
@@ -59,6 +59,22 @@
{
"type": "PACKAGE",
"url": "https://github.com/browserify/browserify-sign"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00040.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5539"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c82-xj9x-mxgj",
"modified": "2024-01-30T00:30:29Z",
"modified": "2024-02-28T03:30:29Z",
"published": "2024-01-23T09:30:22Z",
"aliases": [
"CVE-2024-23850"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23850"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/6a80cb4b32af89787dadee728310e5e2ca85343f.1705741883.git.wqu%40suse.com"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm4h-jq5c-c933",
"modified": "2024-01-30T00:30:29Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-01-23T09:30:22Z",
"aliases": [
"CVE-2024-23851"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23851"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://www.spinics.net/lists/dm-devel/msg56574.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28p7-rxh6-3h6x",
"modified": "2024-02-27T06:30:31Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-27T06:30:31Z",
"aliases": [
"CVE-2023-7033"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU96145466/index.html"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-058-01"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-023_en.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63f3-2rgp-79qx",
"modified": "2024-02-23T09:30:38Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-21T15:30:45Z",
"aliases": [
"CVE-2024-26585"
@@ -29,6 +29,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67p4-4qm6-h6gq",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-28T03:30:30Z",
"aliases": [
"CVE-2023-50303"
],
"details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273333.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50303"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/273333"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7116120"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pc7-4x73-wwc6",
"modified": "2024-02-26T18:30:31Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26606"
@@ -49,6 +49,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/dd64bb8329ce0ea27bc557e4160c2688835402ac"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pp5-c4g8-xxc4",
"modified": "2024-02-23T12:30:31Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-23T12:30:31Z",
"aliases": [
"CVE-2024-26593"
@@ -45,6 +45,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d074d5ff5ae77b18300e5079c6bda6342a4d44b7"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr7m-mx45-3638",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-28T03:30:30Z",
"aliases": [
"CVE-2023-50734"
],
"details": "A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50734"
},
{
"type": "WEB",
"url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T02:15:23Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fm2x-2crw-hf7h",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-28T03:30:30Z",
"aliases": [
"CVE-2023-50736"
],
"details": "A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50736"
},
{
"type": "WEB",
"url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-131"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T03:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq97-hv4f-crm6",
"modified": "2024-02-26T18:30:31Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26603"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d877550eaf2dc9090d782864c96939397a3c6835"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j66f-jc3v-93vp",
"modified": "2024-02-23T09:30:38Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-21T15:30:45Z",
"aliases": [
"CVE-2024-26582"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d684763534b969cca1022e2a28645c7cc91f7fa5"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j737-8h5g-42g9",
"modified": "2024-02-23T09:30:38Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-21T15:30:45Z",
"aliases": [
"CVE-2024-26583"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg84-v5xw-8m52",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-28T03:30:30Z",
"aliases": [
"CVE-2023-50737"
],
"details": "The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50737"
},
{
"type": "WEB",
"url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T03:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjjw-vjj8-q96x",
"modified": "2024-02-23T09:30:38Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-21T15:30:45Z",
"aliases": [
"CVE-2024-26584"
@@ -29,6 +29,14 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ab6397f072e5097f267abf5cb08a8004e6b17694"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf63-228h-qhch",
"modified": "2024-02-26T18:30:31Z",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26604"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b746d52ce7bcac325a2fa264216ead85b7fbbfaa"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjjp-35cq-88wh",
"modified": "2024-02-28T03:30:30Z",
"published": "2024-02-28T03:30:30Z",
"aliases": [
"CVE-2023-50735"
],
"details": "A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50735"
},
{
"type": "WEB",
"url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T03:15:07Z"
}
}