From e55c5318ec600d819ba5f28f9e5081d337c594ce Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 Feb 2024 21:31:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6v23-8229-rc5j.json | 2 +- .../GHSA-c7vv-qr7x-g477.json | 2 +- .../GHSA-hrxr-54xq-7fmj.json | 6 +-- .../GHSA-494r-cmj8-94j9.json | 6 ++- .../GHSA-7crr-gq7j-5wcr.json | 6 ++- .../GHSA-j7rp-w7cg-34p9.json | 6 ++- .../GHSA-p326-98p9-wprv.json | 6 ++- .../GHSA-65xx-vwx2-w8qf.json | 15 ++++-- .../GHSA-gqvv-8rrx-g836.json | 15 ++++-- .../GHSA-jv36-3qpq-7g23.json | 8 ++- .../GHSA-f7p2-4f5g-hfv9.json | 8 ++- .../GHSA-g3h3-xh77-5fcf.json | 8 ++- .../GHSA-hpg6-hp9w-vxqp.json | 8 ++- .../GHSA-34xr-h92c-2m86.json | 6 ++- .../GHSA-5pq2-w3x5-q9f2.json | 6 ++- .../GHSA-6gv5-48rm-6999.json | 6 ++- .../GHSA-7r55-mp9r-c8pj.json | 6 ++- .../GHSA-8wpw-g939-rjw4.json | 6 ++- .../GHSA-9fmg-2fcx-q3vf.json | 6 ++- .../GHSA-cjh4-hrfc-4xj7.json | 6 ++- .../GHSA-r7xg-3gm7-8q8p.json | 6 ++- .../GHSA-vgxm-8jf8-3h3v.json | 6 ++- .../GHSA-w776-w5x6-c2xf.json | 6 ++- .../GHSA-wrmf-3x8w-vcx2.json | 6 ++- .../GHSA-263h-mwf7-v6rq.json | 35 +++++++++++++ .../GHSA-37j2-h4x2-rp3v.json | 2 +- .../GHSA-37r9-v4pm-3344.json | 4 +- .../GHSA-3c4g-j683-8mx6.json | 4 +- .../GHSA-3jmf-c2v9-xc39.json | 35 +++++++++++++ .../GHSA-4rgm-786j-w9cc.json | 4 +- .../GHSA-54qf-h346-xgmg.json | 50 +++++++++++++++++++ .../GHSA-5fqp-6xx2-943w.json | 35 +++++++++++++ .../GHSA-5j36-2f99-3384.json | 11 ++-- .../GHSA-694p-hcfm-p8q8.json | 6 +-- .../GHSA-6j8w-8cxv-823q.json | 42 ++++++++++++++++ .../GHSA-6r4c-h9mj-c94g.json | 50 +++++++++++++++++++ .../GHSA-6xj8-7c6f-w9rq.json | 11 ++-- .../GHSA-7cgq-w654-fmv8.json | 4 +- .../GHSA-82mh-pj8x-3fw7.json | 2 +- .../GHSA-8jw8-7cq8-7qcf.json | 6 +-- .../GHSA-8xpr-jq7w-573j.json | 6 +-- .../GHSA-9779-f4qr-x2w9.json | 50 +++++++++++++++++++ .../GHSA-99jr-pjjw-hqmq.json | 6 +-- .../GHSA-c5fg-c732-px5h.json | 3 +- .../GHSA-c6rw-7vmm-m3h7.json | 3 +- .../GHSA-c6w6-rrgw-p384.json | 35 +++++++++++++ .../GHSA-cf78-r42v-cqjp.json | 6 +-- .../GHSA-cm2j-xhch-gm5q.json | 2 +- .../GHSA-fwm6-ghvh-8mr4.json | 6 +-- .../GHSA-gfj2-m63m-4q89.json | 6 +-- .../GHSA-ggv6-7vfj-r2fw.json | 35 +++++++++++++ .../GHSA-h8pv-m5jr-4f99.json | 2 +- .../GHSA-hwq5-wx3r-8r5g.json | 50 +++++++++++++++++++ .../GHSA-j3jq-jm2x-gvwx.json | 50 +++++++++++++++++++ .../GHSA-j9rf-q3p6-99gv.json | 11 ++-- .../GHSA-mfph-26j7-jm24.json | 6 +-- .../GHSA-mgqx-9848-6j3q.json | 2 +- .../GHSA-mmfm-2hr6-jvqr.json | 6 +-- .../GHSA-mx4m-rmpq-fcw6.json | 50 +++++++++++++++++++ .../GHSA-mxm6-6659-cv7p.json | 50 +++++++++++++++++++ .../GHSA-p23j-w6jc-gg7v.json | 6 +-- .../GHSA-p9mc-3cgc-v8h2.json | 3 +- .../GHSA-pg8c-mxmr-vcqr.json | 2 +- .../GHSA-pqfp-6wmf-23ch.json | 50 +++++++++++++++++++ .../GHSA-qgx2-jx39-h26j.json | 8 +-- .../GHSA-qrmv-p28h-q98v.json | 6 +-- .../GHSA-qw52-qmwq-9mjq.json | 6 +-- .../GHSA-r823-2q58-c7vx.json | 50 +++++++++++++++++++ .../GHSA-rf3h-hj2j-v6cr.json | 6 +-- .../GHSA-rpjv-hwjc-55jj.json | 6 +-- .../GHSA-rpw7-c5cp-v8vp.json | 3 +- .../GHSA-rv54-p5vw-c6p6.json | 6 +-- .../GHSA-rvmr-97cf-9f3m.json | 35 +++++++++++++ .../GHSA-v42h-5rm7-cppg.json | 6 +-- .../GHSA-vhh3-wrc8-frc4.json | 6 +-- .../GHSA-vv93-j256-hpwh.json | 6 +-- 76 files changed, 929 insertions(+), 124 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-263h-mwf7-v6rq/GHSA-263h-mwf7-v6rq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json create mode 100644 advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5fqp-6xx2-943w/GHSA-5fqp-6xx2-943w.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9779-f4qr-x2w9/GHSA-9779-f4qr-x2w9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c6w6-rrgw-p384/GHSA-c6w6-rrgw-p384.json create mode 100644 advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j3jq-jm2x-gvwx/GHSA-j3jq-jm2x-gvwx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mx4m-rmpq-fcw6/GHSA-mx4m-rmpq-fcw6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mxm6-6659-cv7p/GHSA-mxm6-6659-cv7p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pqfp-6wmf-23ch/GHSA-pqfp-6wmf-23ch.json create mode 100644 advisories/unreviewed/2024/02/GHSA-r823-2q58-c7vx/GHSA-r823-2q58-c7vx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json diff --git a/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json b/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json index 46c5f602b41..2c92f89cfbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json +++ b/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json @@ -53,7 +53,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json b/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json index 29843642be3..0d91a1a025e 100644 --- a/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json +++ b/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json b/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json index 19ecec8d047..3df8ac75a1f 100644 --- a/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json +++ b/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrxr-54xq-7fmj", - "modified": "2022-04-29T03:00:54Z", + "modified": "2024-02-13T21:30:19Z", "published": "2022-04-29T03:00:53Z", "aliases": [ "CVE-2004-2150" @@ -24,7 +24,7 @@ }, { "type": "WEB", - "url": "http://secunia.com/advisories/12661/" + "url": "http://secunia.com/advisories/12661" }, { "type": "WEB", @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json b/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json index 7cc219289f9..5bdf9164a46 100644 --- a/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json +++ b/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-494r-cmj8-94j9", - "modified": "2022-11-23T15:30:22Z", + "modified": "2024-02-13T21:30:20Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2021-26392" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json b/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json index 9b828b62c3b..da22fe66acd 100644 --- a/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json +++ b/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7crr-gq7j-5wcr", - "modified": "2022-11-23T15:30:23Z", + "modified": "2024-02-13T21:30:20Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2020-12930" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json b/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json index eb594f03d88..860a3dfc1a0 100644 --- a/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json +++ b/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7rp-w7cg-34p9", - "modified": "2022-11-23T15:30:22Z", + "modified": "2024-02-13T21:30:20Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2020-12931" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json b/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json index 3a0a3f9f424..0095c58a8de 100644 --- a/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json +++ b/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p326-98p9-wprv", - "modified": "2022-11-23T15:30:22Z", + "modified": "2024-02-13T21:30:21Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2021-26393" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-65xx-vwx2-w8qf/GHSA-65xx-vwx2-w8qf.json b/advisories/unreviewed/2023/05/GHSA-65xx-vwx2-w8qf/GHSA-65xx-vwx2-w8qf.json index f23609ddc9a..4b591feaa50 100644 --- a/advisories/unreviewed/2023/05/GHSA-65xx-vwx2-w8qf/GHSA-65xx-vwx2-w8qf.json +++ b/advisories/unreviewed/2023/05/GHSA-65xx-vwx2-w8qf/GHSA-65xx-vwx2-w8qf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65xx-vwx2-w8qf", - "modified": "2023-05-09T21:30:23Z", + "modified": "2024-02-13T21:30:21Z", "published": "2023-05-09T21:30:23Z", "aliases": [ "CVE-2021-46762" ], "details": "Insufficient input validation in the SMU may\nallow an attacker to corrupt SMU SRAM potentially leading to a loss of\nintegrity or denial of service.\n\n\n\n\n\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3001" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-09T19:15:11Z" diff --git a/advisories/unreviewed/2023/05/GHSA-gqvv-8rrx-g836/GHSA-gqvv-8rrx-g836.json b/advisories/unreviewed/2023/05/GHSA-gqvv-8rrx-g836/GHSA-gqvv-8rrx-g836.json index 1fb57175fd8..b210cd19f88 100644 --- a/advisories/unreviewed/2023/05/GHSA-gqvv-8rrx-g836/GHSA-gqvv-8rrx-g836.json +++ b/advisories/unreviewed/2023/05/GHSA-gqvv-8rrx-g836/GHSA-gqvv-8rrx-g836.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqvv-8rrx-g836", - "modified": "2023-05-09T21:30:23Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-05-09T21:30:23Z", "aliases": [ "CVE-2021-46754" ], "details": "Insufficient input validation in the ASP (AMD\nSecure Processor) bootloader may allow an attacker with a compromised Uapp or\nABL to coerce the bootloader into exposing sensitive information to the SMU\n(System Management Unit) resulting in a potential loss of confidentiality and\nintegrity.\n\n\n\n\n\n\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-09T20:15:12Z" diff --git a/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json b/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json index fba75872d9a..16ff4c8d1ef 100644 --- a/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json +++ b/advisories/unreviewed/2023/05/GHSA-jv36-3qpq-7g23/GHSA-jv36-3qpq-7g23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv36-3qpq-7g23", - "modified": "2023-06-01T21:30:25Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-05-26T00:30:20Z", "aliases": [ "CVE-2023-2804" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2208447" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html" } ], "database_specific": { @@ -47,7 +51,7 @@ "CWE-122", "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-25T22:15:09Z" diff --git a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json index 645b66bc22d..a28c560d68a 100644 --- a/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json +++ b/advisories/unreviewed/2023/07/GHSA-f7p2-4f5g-hfv9/GHSA-f7p2-4f5g-hfv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7p2-4f5g-hfv9", - "modified": "2023-08-07T21:30:59Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43701" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://developer.arm.com/documentation/ka005596/latest" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00930.html" } ], "database_specific": { "cwe_ids": [ "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-27T22:15:10Z" diff --git a/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json b/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json index c10a4567669..6777036acb5 100644 --- a/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json +++ b/advisories/unreviewed/2023/07/GHSA-g3h3-xh77-5fcf/GHSA-g3h3-xh77-5fcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3h3-xh77-5fcf", - "modified": "2023-08-07T21:30:59Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43702" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://developer.arm.com/documentation/ka005596/latest" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00930.html" } ], "database_specific": { @@ -31,7 +35,7 @@ "CWE-276", "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-27T22:15:12Z" diff --git a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json index 1f8ddfbd06a..243e414a05e 100644 --- a/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json +++ b/advisories/unreviewed/2023/07/GHSA-hpg6-hp9w-vxqp/GHSA-hpg6-hp9w-vxqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpg6-hp9w-vxqp", - "modified": "2023-08-08T15:33:39Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-07-28T00:30:22Z", "aliases": [ "CVE-2022-43703" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://developer.arm.com/documentation/ka005596/latest" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00930.html" } ], "database_specific": { "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-27T22:15:12Z" diff --git a/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json b/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json index 25c8ee9e4b0..e3bef9fda5c 100644 --- a/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json +++ b/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34xr-h92c-2m86", - "modified": "2023-11-27T21:30:53Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2021-46766" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json b/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json index 168b71770de..7d8f597f35a 100644 --- a/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json +++ b/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pq2-w3x5-q9f2", - "modified": "2023-11-27T21:30:54Z", + "modified": "2024-02-13T21:30:26Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20533" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json b/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json index 4410e76c24d..90bb026c767 100644 --- a/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json +++ b/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gv5-48rm-6999", - "modified": "2023-11-27T21:30:54Z", + "modified": "2024-02-13T21:30:25Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20526" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json b/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json index 4de9227be2f..76335b6bca4 100644 --- a/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json +++ b/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r55-mp9r-c8pj", - "modified": "2023-11-27T21:30:54Z", + "modified": "2024-02-13T21:30:25Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20521" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json b/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json index 0619f22e0f8..4eea6b83346 100644 --- a/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json +++ b/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wpw-g939-rjw4", - "modified": "2023-11-27T21:30:53Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2021-46774" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json b/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json index f8454ee01f1..a2c80c7d525 100644 --- a/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json +++ b/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fmg-2fcx-q3vf", - "modified": "2023-12-01T18:30:24Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2022-23820" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json b/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json index 9103f77a87a..9f7e4c52a0e 100644 --- a/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json +++ b/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjh4-hrfc-4xj7", - "modified": "2023-11-28T18:30:22Z", + "modified": "2024-02-13T21:30:26Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20563" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json b/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json index 2ce85a65831..d724c9fe87a 100644 --- a/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json +++ b/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7xg-3gm7-8q8p", - "modified": "2023-11-22T00:30:19Z", + "modified": "2024-02-13T21:30:24Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2022-23830" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json b/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json index 8660fe44995..b28efb6f57b 100644 --- a/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json +++ b/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgxm-8jf8-3h3v", - "modified": "2023-11-18T03:30:20Z", + "modified": "2024-02-13T21:30:23Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2021-26345" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json b/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json index 9bdc1bcf7e4..509b9be3f96 100644 --- a/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json +++ b/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w776-w5x6-c2xf", - "modified": "2023-11-28T18:30:23Z", + "modified": "2024-02-13T21:30:27Z", "published": "2023-11-14T21:31:00Z", "aliases": [ "CVE-2023-20565" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json b/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json index 6632be1901d..f65c77591c4 100644 --- a/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json +++ b/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrmf-3x8w-vcx2", - "modified": "2023-12-01T18:30:25Z", + "modified": "2024-02-13T21:30:24Z", "published": "2023-11-14T21:30:59Z", "aliases": [ "CVE-2022-23821" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-263h-mwf7-v6rq/GHSA-263h-mwf7-v6rq.json b/advisories/unreviewed/2024/02/GHSA-263h-mwf7-v6rq/GHSA-263h-mwf7-v6rq.json new file mode 100644 index 00000000000..6254da45f81 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-263h-mwf7-v6rq/GHSA-263h-mwf7-v6rq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-263h-mwf7-v6rq", + "modified": "2024-02-13T21:30:30Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2023-20579" + ], + "details": "Improper\nAccess Control in the AMD SPI protection feature may allow a user with Ring0\n(kernel mode) privileged access to bypass protections potentially resulting in\nloss of integrity and availability.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20579" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7009" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T20:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json b/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json index 85a3fc44b81..42033d77ca1 100644 --- a/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json +++ b/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37j2-h4x2-rp3v", - "modified": "2024-02-06T18:30:21Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T18:30:21Z", "aliases": [ "CVE-2023-40545" diff --git a/advisories/unreviewed/2024/02/GHSA-37r9-v4pm-3344/GHSA-37r9-v4pm-3344.json b/advisories/unreviewed/2024/02/GHSA-37r9-v4pm-3344/GHSA-37r9-v4pm-3344.json index eaacfceba91..52542bea90e 100644 --- a/advisories/unreviewed/2024/02/GHSA-37r9-v4pm-3344/GHSA-37r9-v4pm-3344.json +++ b/advisories/unreviewed/2024/02/GHSA-37r9-v4pm-3344/GHSA-37r9-v4pm-3344.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37r9-v4pm-3344", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0954" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3c4g-j683-8mx6/GHSA-3c4g-j683-8mx6.json b/advisories/unreviewed/2024/02/GHSA-3c4g-j683-8mx6/GHSA-3c4g-j683-8mx6.json index 7f49e787b2f..de3079d2e81 100644 --- a/advisories/unreviewed/2024/02/GHSA-3c4g-j683-8mx6/GHSA-3c4g-j683-8mx6.json +++ b/advisories/unreviewed/2024/02/GHSA-3c4g-j683-8mx6/GHSA-3c4g-j683-8mx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3c4g-j683-8mx6", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-1072" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json b/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json new file mode 100644 index 00000000000..4afdfd87d0c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jmf-c2v9-xc39", + "modified": "2024-02-13T21:30:30Z", + "published": "2024-02-13T21:30:30Z", + "aliases": [ + "CVE-2023-20587" + ], + "details": "Improper\nAccess Control in System Management Mode (SMM) may allow an attacker access to\nthe SPI flash potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20587" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7009" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T20:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4rgm-786j-w9cc/GHSA-4rgm-786j-w9cc.json b/advisories/unreviewed/2024/02/GHSA-4rgm-786j-w9cc/GHSA-4rgm-786j-w9cc.json index 9fc85624953..d2356535999 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rgm-786j-w9cc/GHSA-4rgm-786j-w9cc.json +++ b/advisories/unreviewed/2024/02/GHSA-4rgm-786j-w9cc/GHSA-4rgm-786j-w9cc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rgm-786j-w9cc", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-1046" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json b/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json new file mode 100644 index 00000000000..07201cc035b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qf-h346-xgmg", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1082" + ], + "details": "A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.15, 3.9.10, 3.10.7, 3.11.5. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1082" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5fqp-6xx2-943w/GHSA-5fqp-6xx2-943w.json b/advisories/unreviewed/2024/02/GHSA-5fqp-6xx2-943w/GHSA-5fqp-6xx2-943w.json new file mode 100644 index 00000000000..175e1427ab6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5fqp-6xx2-943w/GHSA-5fqp-6xx2-943w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fqp-6xx2-943w", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2021-46757" + ], + "details": "Insufficient checking of memory buffer in ASP\nSecure OS may allow an attacker with a malicious TA to read/write to the ASP\nSecure OS kernel virtual address space potentially leading to privilege\nescalation.\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46757" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T20:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json b/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json index 45dca959ef7..183bb7ea252 100644 --- a/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json +++ b/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j36-2f99-3384", - "modified": "2024-02-02T09:30:22Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-02T09:30:22Z", "aliases": [ "CVE-2023-48645" ], "details": "An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in the Maintenance module of the app. This allows performing queries on the local database.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-02T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json b/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json index e8eb2743fc8..1071af83f26 100644 --- a/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json +++ b/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-694p-hcfm-p8q8", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6230" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json b/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json new file mode 100644 index 00000000000..fc172e4d679 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6j8w-8cxv-823q/GHSA-6j8w-8cxv-823q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j8w-8cxv-823q", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1216" + ], + "details": "Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112044, 0x8011204B, 0x8011204F, 0x80112057, 0x8011205B, 0x8011205F, 0x80112063, 0x8011206F, 0x80112073, 0x80112077, 0x80112078, 0x8011207C and 0x80112080 IOCTL codes of the fildds.sys driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1216" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/gershwin" + }, + { + "type": "WEB", + "url": "http://www.filseclab.com/en-us/products/twister.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json b/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json new file mode 100644 index 00000000000..697090c973d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r4c-h9mj-c94g", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1355" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1355" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json b/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json index cb089665b84..05129b51993 100644 --- a/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json +++ b/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xj8-7c6f-w9rq", - "modified": "2024-02-06T18:30:21Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T18:30:21Z", "aliases": [ "CVE-2024-24000" ], "details": "jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T16:15:52Z" diff --git a/advisories/unreviewed/2024/02/GHSA-7cgq-w654-fmv8/GHSA-7cgq-w654-fmv8.json b/advisories/unreviewed/2024/02/GHSA-7cgq-w654-fmv8/GHSA-7cgq-w654-fmv8.json index f609d66f763..de27a18524b 100644 --- a/advisories/unreviewed/2024/02/GHSA-7cgq-w654-fmv8/GHSA-7cgq-w654-fmv8.json +++ b/advisories/unreviewed/2024/02/GHSA-7cgq-w654-fmv8/GHSA-7cgq-w654-fmv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cgq-w654-fmv8", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0869" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://wordpress.org/plugins/instant-images/" + "url": "https://wordpress.org/plugins/instant-images" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-82mh-pj8x-3fw7/GHSA-82mh-pj8x-3fw7.json b/advisories/unreviewed/2024/02/GHSA-82mh-pj8x-3fw7/GHSA-82mh-pj8x-3fw7.json index 85dd5fb9e4e..1843fdd653d 100644 --- a/advisories/unreviewed/2024/02/GHSA-82mh-pj8x-3fw7/GHSA-82mh-pj8x-3fw7.json +++ b/advisories/unreviewed/2024/02/GHSA-82mh-pj8x-3fw7/GHSA-82mh-pj8x-3fw7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8jw8-7cq8-7qcf/GHSA-8jw8-7cq8-7qcf.json b/advisories/unreviewed/2024/02/GHSA-8jw8-7cq8-7qcf/GHSA-8jw8-7cq8-7qcf.json index 6ab7e8eff72..160eac56431 100644 --- a/advisories/unreviewed/2024/02/GHSA-8jw8-7cq8-7qcf/GHSA-8jw8-7cq8-7qcf.json +++ b/advisories/unreviewed/2024/02/GHSA-8jw8-7cq8-7qcf/GHSA-8jw8-7cq8-7qcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jw8-7cq8-7qcf", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0834" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3031349%40addon-elements-for-elementor-page-builder&new=3031349%40addon-elements-for-elementor-page-builder&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3031349@addon-elements-for-elementor-page-builder&new=3031349@addon-elements-for-elementor-page-builder&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json b/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json index d1d140ee9d0..5ab9be2ede3 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json +++ b/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xpr-jq7w-573j", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6234" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-9779-f4qr-x2w9/GHSA-9779-f4qr-x2w9.json b/advisories/unreviewed/2024/02/GHSA-9779-f4qr-x2w9/GHSA-9779-f4qr-x2w9.json new file mode 100644 index 00000000000..6c25265c659 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9779-f4qr-x2w9/GHSA-9779-f4qr-x2w9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9779-f4qr-x2w9", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1374" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com .\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1374" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json b/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json index a57f4cd8dff..d62a39f6a1c 100644 --- a/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json +++ b/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99jr-pjjw-hqmq", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6233" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json b/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json index eab9aff1bc9..4c0fda92c32 100644 --- a/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json +++ b/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json b/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json index 2f29999d691..f2dc848c0ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json +++ b/advisories/unreviewed/2024/02/GHSA-c6rw-7vmm-m3h7/GHSA-c6rw-7vmm-m3h7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-c6w6-rrgw-p384/GHSA-c6w6-rrgw-p384.json b/advisories/unreviewed/2024/02/GHSA-c6w6-rrgw-p384/GHSA-c6w6-rrgw-p384.json new file mode 100644 index 00000000000..379dffb4b72 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c6w6-rrgw-p384/GHSA-c6w6-rrgw-p384.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6w6-rrgw-p384", + "modified": "2024-02-13T21:30:30Z", + "published": "2024-02-13T21:30:30Z", + "aliases": [ + "CVE-2024-24142" + ], + "details": "Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24142" + }, + { + "type": "WEB", + "url": "https://github.com/BurakSevben/School-Task-Manager-SQL-Injection-2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cf78-r42v-cqjp/GHSA-cf78-r42v-cqjp.json b/advisories/unreviewed/2024/02/GHSA-cf78-r42v-cqjp/GHSA-cf78-r42v-cqjp.json index 77a6c0759a8..3efb828fb21 100644 --- a/advisories/unreviewed/2024/02/GHSA-cf78-r42v-cqjp/GHSA-cf78-r42v-cqjp.json +++ b/advisories/unreviewed/2024/02/GHSA-cf78-r42v-cqjp/GHSA-cf78-r42v-cqjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf78-r42v-cqjp", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-1121" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3031007%40advanced-forms&new=3031007%40advanced-forms&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3031007@advanced-forms&new=3031007@advanced-forms&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-cm2j-xhch-gm5q/GHSA-cm2j-xhch-gm5q.json b/advisories/unreviewed/2024/02/GHSA-cm2j-xhch-gm5q/GHSA-cm2j-xhch-gm5q.json index 2a6a54eb081..d177cd28c82 100644 --- a/advisories/unreviewed/2024/02/GHSA-cm2j-xhch-gm5q/GHSA-cm2j-xhch-gm5q.json +++ b/advisories/unreviewed/2024/02/GHSA-cm2j-xhch-gm5q/GHSA-cm2j-xhch-gm5q.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-fwm6-ghvh-8mr4/GHSA-fwm6-ghvh-8mr4.json b/advisories/unreviewed/2024/02/GHSA-fwm6-ghvh-8mr4/GHSA-fwm6-ghvh-8mr4.json index 037a375e402..2a9f8e4e897 100644 --- a/advisories/unreviewed/2024/02/GHSA-fwm6-ghvh-8mr4/GHSA-fwm6-ghvh-8mr4.json +++ b/advisories/unreviewed/2024/02/GHSA-fwm6-ghvh-8mr4/GHSA-fwm6-ghvh-8mr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwm6-ghvh-8mr4", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0859" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3028484/affiliates-manager/trunk?contextall=1&old=3015278&old_path=%2Faffiliates-manager%2Ftrunk" + "url": "https://plugins.trac.wordpress.org/changeset/3028484/affiliates-manager/trunk?contextall=1&old=3015278&old_path=/affiliates-manager/trunk" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gfj2-m63m-4q89/GHSA-gfj2-m63m-4q89.json b/advisories/unreviewed/2024/02/GHSA-gfj2-m63m-4q89/GHSA-gfj2-m63m-4q89.json index 77032fb9fd1..f95ae009667 100644 --- a/advisories/unreviewed/2024/02/GHSA-gfj2-m63m-4q89/GHSA-gfj2-m63m-4q89.json +++ b/advisories/unreviewed/2024/02/GHSA-gfj2-m63m-4q89/GHSA-gfj2-m63m-4q89.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfj2-m63m-4q89", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-1092" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3030538%40feedzy-rss-feeds%2Ftrunk&old=3028200%40feedzy-rss-feeds%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3030538@feedzy-rss-feeds/trunk&old=3028200@feedzy-rss-feeds/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json b/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json new file mode 100644 index 00000000000..329ce5ecbc8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggv6-7vfj-r2fw", + "modified": "2024-02-13T21:30:30Z", + "published": "2024-02-13T21:30:30Z", + "aliases": [ + "CVE-2023-31347" + ], + "details": "Due to a code bug in\nSecure_TSC, SEV firmware may allow an attacker with high privileges to cause a\nguest to observe an incorrect TSC when Secure TSC is enabled potentially\nresulting in a loss of guest integrity.  \n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31347" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T20:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h8pv-m5jr-4f99/GHSA-h8pv-m5jr-4f99.json b/advisories/unreviewed/2024/02/GHSA-h8pv-m5jr-4f99/GHSA-h8pv-m5jr-4f99.json index 0df0bc0d9e8..0e6e908d1c9 100644 --- a/advisories/unreviewed/2024/02/GHSA-h8pv-m5jr-4f99/GHSA-h8pv-m5jr-4f99.json +++ b/advisories/unreviewed/2024/02/GHSA-h8pv-m5jr-4f99/GHSA-h8pv-m5jr-4f99.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json b/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json new file mode 100644 index 00000000000..343768bda57 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwq5-wx3r-8r5g", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1084" + ], + "details": "Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12  and was fixed in all versions of 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1084" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j3jq-jm2x-gvwx/GHSA-j3jq-jm2x-gvwx.json b/advisories/unreviewed/2024/02/GHSA-j3jq-jm2x-gvwx/GHSA-j3jq-jm2x-gvwx.json new file mode 100644 index 00000000000..987ce2c3706 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j3jq-jm2x-gvwx/GHSA-j3jq-jm2x-gvwx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jq-jm2x-gvwx", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1359" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com .\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1359" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json b/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json index 5c67944748b..1288b9e3bfa 100644 --- a/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json +++ b/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9rf-q3p6-99gv", - "modified": "2024-02-06T18:30:21Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T18:30:21Z", "aliases": [ "CVE-2024-24291" ], "details": "An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T16:15:52Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json b/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json index 66be65c1d5f..0bf95fef4ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json +++ b/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfph-26j7-jm24", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2024-0244" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-mgqx-9848-6j3q/GHSA-mgqx-9848-6j3q.json b/advisories/unreviewed/2024/02/GHSA-mgqx-9848-6j3q/GHSA-mgqx-9848-6j3q.json index a6be019d47f..91acfc780a0 100644 --- a/advisories/unreviewed/2024/02/GHSA-mgqx-9848-6j3q/GHSA-mgqx-9848-6j3q.json +++ b/advisories/unreviewed/2024/02/GHSA-mgqx-9848-6j3q/GHSA-mgqx-9848-6j3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgqx-9848-6j3q", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-1075" diff --git a/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json b/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json index 3a087d39dd7..b81843c3726 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json +++ b/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmfm-2hr6-jvqr", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6229" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-mx4m-rmpq-fcw6/GHSA-mx4m-rmpq-fcw6.json b/advisories/unreviewed/2024/02/GHSA-mx4m-rmpq-fcw6/GHSA-mx4m-rmpq-fcw6.json new file mode 100644 index 00000000000..17b8eae25f1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mx4m-rmpq-fcw6/GHSA-mx4m-rmpq-fcw6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx4m-rmpq-fcw6", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1369" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com .\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1369" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mxm6-6659-cv7p/GHSA-mxm6-6659-cv7p.json b/advisories/unreviewed/2024/02/GHSA-mxm6-6659-cv7p/GHSA-mxm6-6659-cv7p.json new file mode 100644 index 00000000000..8eac32fc386 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mxm6-6659-cv7p/GHSA-mxm6-6659-cv7p.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxm6-6659-cv7p", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1378" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com .\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1378" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p23j-w6jc-gg7v/GHSA-p23j-w6jc-gg7v.json b/advisories/unreviewed/2024/02/GHSA-p23j-w6jc-gg7v/GHSA-p23j-w6jc-gg7v.json index 965956e10f3..cd6935de579 100644 --- a/advisories/unreviewed/2024/02/GHSA-p23j-w6jc-gg7v/GHSA-p23j-w6jc-gg7v.json +++ b/advisories/unreviewed/2024/02/GHSA-p23j-w6jc-gg7v/GHSA-p23j-w6jc-gg7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p23j-w6jc-gg7v", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0791" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028699%40bulk-editor%2Ftrunk&old=3012874%40bulk-editor%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028699@bulk-editor/trunk&old=3012874@bulk-editor/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json b/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json index b121fa0c671..08182625e30 100644 --- a/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json +++ b/advisories/unreviewed/2024/02/GHSA-p9mc-3cgc-v8h2/GHSA-p9mc-3cgc-v8h2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json b/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json index 74364daf57c..c84b196e3c9 100644 --- a/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json +++ b/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pqfp-6wmf-23ch/GHSA-pqfp-6wmf-23ch.json b/advisories/unreviewed/2024/02/GHSA-pqfp-6wmf-23ch/GHSA-pqfp-6wmf-23ch.json new file mode 100644 index 00000000000..3ec2f0ffcb7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pqfp-6wmf-23ch/GHSA-pqfp-6wmf-23ch.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqfp-6wmf-23ch", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1372" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program https://bounty.github.com .\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1372" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qgx2-jx39-h26j/GHSA-qgx2-jx39-h26j.json b/advisories/unreviewed/2024/02/GHSA-qgx2-jx39-h26j/GHSA-qgx2-jx39-h26j.json index 8d15cabc9dc..b7565dc749d 100644 --- a/advisories/unreviewed/2024/02/GHSA-qgx2-jx39-h26j/GHSA-qgx2-jx39-h26j.json +++ b/advisories/unreviewed/2024/02/GHSA-qgx2-jx39-h26j/GHSA-qgx2-jx39-h26j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgx2-jx39-h26j", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0835" @@ -23,11 +23,11 @@ }, { "type": "WEB", - "url": "https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=216524%40royal-elementor-kit&new=216524%40royal-elementor-kit&sfp_email=&sfph_mail=" + "url": "https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=216524@royal-elementor-kit&new=216524@royal-elementor-kit&sfp_email=&sfph_mail=" }, { "type": "WEB", - "url": "https://wordpress.org/themes/royal-elementor-kit/" + "url": "https://wordpress.org/themes/royal-elementor-kit" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-qrmv-p28h-q98v/GHSA-qrmv-p28h-q98v.json b/advisories/unreviewed/2024/02/GHSA-qrmv-p28h-q98v/GHSA-qrmv-p28h-q98v.json index e860048aca7..732f0c4d499 100644 --- a/advisories/unreviewed/2024/02/GHSA-qrmv-p28h-q98v/GHSA-qrmv-p28h-q98v.json +++ b/advisories/unreviewed/2024/02/GHSA-qrmv-p28h-q98v/GHSA-qrmv-p28h-q98v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrmv-p28h-q98v", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0961" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3027675%40so-widgets-bundle%2Ftrunk&old=3027506%40so-widgets-bundle%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3027675@so-widgets-bundle/trunk&old=3027506@so-widgets-bundle/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json b/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json index e4c42a2999a..1e1d9481f4e 100644 --- a/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json +++ b/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw52-qmwq-9mjq", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0797" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk" + "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=/profit-products-tables-for-woocommerce/trunk" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-r823-2q58-c7vx/GHSA-r823-2q58-c7vx.json b/advisories/unreviewed/2024/02/GHSA-r823-2q58-c7vx/GHSA-r823-2q58-c7vx.json new file mode 100644 index 00000000000..e7e942e68b9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r823-2q58-c7vx/GHSA-r823-2q58-c7vx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r823-2q58-c7vx", + "modified": "2024-02-13T21:30:29Z", + "published": "2024-02-13T21:30:29Z", + "aliases": [ + "CVE-2024-1354" + ], + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1354" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rf3h-hj2j-v6cr/GHSA-rf3h-hj2j-v6cr.json b/advisories/unreviewed/2024/02/GHSA-rf3h-hj2j-v6cr/GHSA-rf3h-hj2j-v6cr.json index f062b35ecb9..7a28bdb83c9 100644 --- a/advisories/unreviewed/2024/02/GHSA-rf3h-hj2j-v6cr/GHSA-rf3h-hj2j-v6cr.json +++ b/advisories/unreviewed/2024/02/GHSA-rf3h-hj2j-v6cr/GHSA-rf3h-hj2j-v6cr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf3h-hj2j-v6cr", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0790" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028699%40bulk-editor%2Ftrunk&old=3012874%40bulk-editor%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028699@bulk-editor/trunk&old=3012874@bulk-editor/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rpjv-hwjc-55jj/GHSA-rpjv-hwjc-55jj.json b/advisories/unreviewed/2024/02/GHSA-rpjv-hwjc-55jj/GHSA-rpjv-hwjc-55jj.json index 67aacc43005..ff69281d464 100644 --- a/advisories/unreviewed/2024/02/GHSA-rpjv-hwjc-55jj/GHSA-rpjv-hwjc-55jj.json +++ b/advisories/unreviewed/2024/02/GHSA-rpjv-hwjc-55jj/GHSA-rpjv-hwjc-55jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpjv-hwjc-55jj", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2024-0221" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3022981%40photo-gallery%2Ftrunk&old=3013021%40photo-gallery%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3022981@photo-gallery/trunk&old=3013021@photo-gallery/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json b/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json index ef4938006da..f7e9bc6aee1 100644 --- a/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json +++ b/advisories/unreviewed/2024/02/GHSA-rpw7-c5cp-v8vp/GHSA-rpw7-c5cp-v8vp.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json b/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json index f054b2e1807..0224b25f8ac 100644 --- a/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json +++ b/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv54-p5vw-c6p6", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2024-0324" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3022354/" + "url": "https://plugins.trac.wordpress.org/changeset/3022354" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json b/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json new file mode 100644 index 00000000000..112efb26298 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvmr-97cf-9f3m", + "modified": "2024-02-13T21:30:30Z", + "published": "2024-02-13T21:30:30Z", + "aliases": [ + "CVE-2023-31346" + ], + "details": "Failure to initialize\nmemory in SEV Firmware may allow a privileged attacker to access stale data\nfrom other guests.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31346" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T20:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json b/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json index 015397e1fbb..241dde7c347 100644 --- a/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json +++ b/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v42h-5rm7-cppg", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6231" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-vhh3-wrc8-frc4/GHSA-vhh3-wrc8-frc4.json b/advisories/unreviewed/2024/02/GHSA-vhh3-wrc8-frc4/GHSA-vhh3-wrc8-frc4.json index c17254b3e2c..256cc59d02a 100644 --- a/advisories/unreviewed/2024/02/GHSA-vhh3-wrc8-frc4/GHSA-vhh3-wrc8-frc4.json +++ b/advisories/unreviewed/2024/02/GHSA-vhh3-wrc8-frc4/GHSA-vhh3-wrc8-frc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhh3-wrc8-frc4", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T21:30:28Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0796" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk" + "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=/profit-products-tables-for-woocommerce/trunk" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json b/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json index efd983fd94f..9a13b876c0a 100644 --- a/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json +++ b/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv93-j256-hpwh", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T21:30:29Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2023-6232" @@ -27,11 +27,11 @@ }, { "type": "WEB", - "url": "https://psirt.canon/advisory-information/cp2024-001/" + "url": "https://psirt.canon/advisory-information/cp2024-001" }, { "type": "WEB", - "url": "https://www.canon-europe.com/support/product-security-latest-news/" + "url": "https://www.canon-europe.com/support/product-security-latest-news" }, { "type": "WEB",