Publish Advisories

GHSA-wmv8-5f2q-h9xg
GHSA-2xc6-pfrf-w5p4
GHSA-2w86-wv37-w7h5
GHSA-5c29-2r8j-8727
GHSA-792w-295c-v45g
GHSA-94xx-ww3x-xh3v
GHSA-9cw8-p5p2-35pf
GHSA-ccxm-r356-vpjv
GHSA-jr5v-4546-4997
GHSA-mh49-rqvq-cjxg
GHSA-mr7g-4crw-jcpj
GHSA-p29w-9j4h-g34x
GHSA-rqh4-x2v7-j34g
This commit is contained in:
advisory-database[bot]
2024-01-12 00:31:11 +00:00
parent 28f5a23265
commit e6f9bd3e44
13 changed files with 234 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmv8-5f2q-h9xg",
"modified": "2023-07-11T18:31:27Z",
"modified": "2024-01-12T00:30:16Z",
"published": "2023-07-11T18:31:27Z",
"aliases": [
"CVE-2023-35356"
@@ -32,13 +32,17 @@
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/174118/Microsoft-Windows-Kernel-Security-Descriptor-Use-After-Free.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176451/Microsoft-Windows-Registry-Predefined-Keys-Privilege-Escalation.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-11T18:15:19Z"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35633"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176451/Microsoft-Windows-Registry-Predefined-Keys-Privilege-Escalation.html"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w86-wv37-w7h5",
"modified": "2024-01-12T00:30:17Z",
"published": "2024-01-12T00:30:17Z",
"aliases": [
"CVE-2023-51350"
],
"details": "A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51350"
},
{
"type": "WEB",
"url": "https://github.com/ujcms/ujcms/issues/7"
},
{
"type": "WEB",
"url": "https://github.com/ujcms/ujcms"
},
{
"type": "WEB",
"url": "https://www.ujcms.com/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-11T23:15:08Z"
}
}
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94xx-ww3x-xh3v",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-12T00:30:16Z",
"aliases": [
"CVE-2024-21337"
],
"details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21337"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21337"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-11T22:15:46Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9cw8-p5p2-35pf",
"modified": "2024-01-11T09:30:36Z",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-11T09:30:36Z",
"aliases": [
"CVE-2023-6875"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e675d64c-cbb8-4f24-9b6f-2597a97b49af?source=cve"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176525/WordPress-POST-SMTP-Mailer-2.8.7-Authorization-Bypass-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccxm-r356-vpjv",
"modified": "2024-01-09T03:30:22Z",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-09T03:30:22Z",
"aliases": [
"CVE-2024-21738"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr5v-4546-4997",
"modified": "2024-01-09T03:30:22Z",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-09T03:30:22Z",
"aliases": [
"CVE-2023-27000"
],
"details": "Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T02:15:44Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh49-rqvq-cjxg",
"modified": "2024-01-09T21:30:34Z",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-03T06:30:27Z",
"aliases": [
"CVE-2023-7027"
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e8911a3-ce0f-420c-bf2a-1c2929d01cef?source=cve"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176525/WordPress-POST-SMTP-Mailer-2.8.7-Authorization-Bypass-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mr7g-4crw-jcpj",
"modified": "2024-01-12T00:30:17Z",
"published": "2024-01-12T00:30:17Z",
"aliases": [
"CVE-2024-21982"
],
"details": "ONTAP versions 9.4 and higher are susceptible to a vulnerability \nwhich when successfully exploited could lead to disclosure of sensitive \ninformation to unprivileged attackers when the object-store profiler \ncommand is being run by an administrative user.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21982"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240111-0001/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T00:15:45Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p29w-9j4h-g34x",
"modified": "2024-01-12T00:30:16Z",
"published": "2024-01-12T00:30:16Z",
"aliases": [
"CVE-2023-46474"
],
"details": "File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46474"
},
{
"type": "WEB",
"url": "https://github.com/Xn2/CVE-2023-46474"
},
{
"type": "WEB",
"url": "http://pmb.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-11T22:15:45Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqh4-x2v7-j34g",
"modified": "2024-01-12T00:30:17Z",
"published": "2024-01-12T00:30:17Z",
"aliases": [
"CVE-2024-0443"
],
"details": "A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0443"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0443"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257968"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/linux-block/20221215033132.230023-3-longman@redhat.com/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-402"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T00:15:45Z"
}
}