From e73f40b6174592d0e34bb631f1ce611d1ccb5751 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 12 Jan 2024 09:31:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-25mr-w95m-82v7.json | 8 +++- .../GHSA-5xxc-86g5-876q.json | 8 +++- .../GHSA-9628-xx9p-xjqj.json | 8 +++- .../GHSA-f8cc-v72f-5rm2.json | 8 +++- .../GHSA-fqgf-87c4-qvqm.json | 8 +++- .../GHSA-q84v-pwf5-wm4x.json | 8 +++- .../GHSA-qg93-cpf3-386g.json | 8 +++- .../GHSA-qv8q-wwpq-485r.json | 8 +++- .../GHSA-rfrx-wp2r-q456.json | 8 +++- .../GHSA-6vx9-wpjf-5pf7.json | 16 +++++++- .../GHSA-9ppx-xr68-cm59.json | 8 +++- .../GHSA-9rfr-rprq-pv78.json | 8 +++- .../GHSA-c2rq-xcq6-frfg.json | 8 +++- .../GHSA-ccm5-74vf-c7hj.json | 8 +++- .../GHSA-cp3q-q6mx-w79j.json | 17 +++++++- .../GHSA-h33q-26v7-q343.json | 8 +++- .../GHSA-h5f9-372r-9xwq.json | 16 +++++++- .../GHSA-hpjf-rjwg-v743.json | 8 +++- .../GHSA-prhg-xpp4-c8mx.json | 16 +++++++- .../GHSA-qfq4-f9vc-vv2j.json | 16 +++++++- .../GHSA-rq8q-w9hr-c2fr.json | 8 +++- .../GHSA-vvf9-x2f5-h29c.json | 8 +++- .../GHSA-xq7r-2vx2-8jgj.json | 8 +++- .../GHSA-4xwv-7982-j5wj.json | 4 ++ .../GHSA-6f4g-5r7v-g37f.json | 4 ++ .../GHSA-9wv2-mrrp-v8g7.json | 4 ++ .../GHSA-c568-gcr5-3gmw.json | 4 ++ .../GHSA-f746-g4q7-wxcp.json | 4 ++ .../GHSA-h37j-vw7r-prg3.json | 4 ++ .../GHSA-jcjp-p87g-594h.json | 4 ++ .../GHSA-jxxq-5fp9-76wc.json | 4 ++ .../GHSA-w4gp-rmfp-f2gh.json | 4 ++ .../GHSA-xmj4-pwxq-wq63.json | 4 ++ .../GHSA-2jxj-pf6p-qrpf.json | 35 +++++++++++++++++ .../GHSA-2w87-fjj9-j39h.json | 4 ++ .../GHSA-3vmx-5x6r-25cw.json | 35 +++++++++++++++++ .../GHSA-4mhf-c48q-rghx.json | 39 +++++++++++++++++++ .../GHSA-4p4p-22cr-2gqw.json | 4 ++ .../GHSA-5cw3-5rmf-j5f2.json | 35 +++++++++++++++++ .../GHSA-8w7f-m7fg-fhfc.json | 35 +++++++++++++++++ .../GHSA-9rm8-w7j5-j66w.json | 4 ++ .../GHSA-fmr7-cqjx-qmxg.json | 39 +++++++++++++++++++ .../GHSA-hgr6-fxr2-jx3f.json | 38 ++++++++++++++++++ .../GHSA-hvvx-qx2r-4h8q.json | 39 +++++++++++++++++++ .../GHSA-hwrv-r72x-jcwr.json | 4 ++ .../GHSA-j8hh-2v2c-wqmv.json | 38 ++++++++++++++++++ .../GHSA-m89q-5h24-2xm5.json | 38 ++++++++++++++++++ .../GHSA-p7pv-w5qm-8pxv.json | 39 +++++++++++++++++++ .../GHSA-pgpx-675x-4jcv.json | 4 ++ .../GHSA-pxmv-x94g-j48f.json | 35 +++++++++++++++++ .../GHSA-xr84-qwr9-vj33.json | 4 ++ .../GHSA-xr94-cv8c-7r6v.json | 38 ++++++++++++++++++ 52 files changed, 726 insertions(+), 46 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-2jxj-pf6p-qrpf/GHSA-2jxj-pf6p-qrpf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4mhf-c48q-rghx/GHSA-4mhf-c48q-rghx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5cw3-5rmf-j5f2/GHSA-5cw3-5rmf-j5f2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fmr7-cqjx-qmxg/GHSA-fmr7-cqjx-qmxg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hgr6-fxr2-jx3f/GHSA-hgr6-fxr2-jx3f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hvvx-qx2r-4h8q/GHSA-hvvx-qx2r-4h8q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-j8hh-2v2c-wqmv/GHSA-j8hh-2v2c-wqmv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-m89q-5h24-2xm5/GHSA-m89q-5h24-2xm5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pxmv-x94g-j48f/GHSA-pxmv-x94g-j48f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json diff --git a/advisories/unreviewed/2023/06/GHSA-25mr-w95m-82v7/GHSA-25mr-w95m-82v7.json b/advisories/unreviewed/2023/06/GHSA-25mr-w95m-82v7/GHSA-25mr-w95m-82v7.json index b28b6ceafc1..0c6b5b6080f 100644 --- a/advisories/unreviewed/2023/06/GHSA-25mr-w95m-82v7/GHSA-25mr-w95m-82v7.json +++ b/advisories/unreviewed/2023/06/GHSA-25mr-w95m-82v7/GHSA-25mr-w95m-82v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25mr-w95m-82v7", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26434" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26434" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json b/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json index 5127bc65564..2f6566fe8a4 100644 --- a/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json +++ b/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xxc-86g5-876q", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26436" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26436" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -43,7 +47,7 @@ "CWE-502", "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-9628-xx9p-xjqj/GHSA-9628-xx9p-xjqj.json b/advisories/unreviewed/2023/06/GHSA-9628-xx9p-xjqj/GHSA-9628-xx9p-xjqj.json index a46c7e8f3ac..c4924201d0c 100644 --- a/advisories/unreviewed/2023/06/GHSA-9628-xx9p-xjqj/GHSA-9628-xx9p-xjqj.json +++ b/advisories/unreviewed/2023/06/GHSA-9628-xx9p-xjqj/GHSA-9628-xx9p-xjqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9628-xx9p-xjqj", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:26Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26432" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26432" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-f8cc-v72f-5rm2/GHSA-f8cc-v72f-5rm2.json b/advisories/unreviewed/2023/06/GHSA-f8cc-v72f-5rm2/GHSA-f8cc-v72f-5rm2.json index 718e8fa6c22..efcef7c3e98 100644 --- a/advisories/unreviewed/2023/06/GHSA-f8cc-v72f-5rm2/GHSA-f8cc-v72f-5rm2.json +++ b/advisories/unreviewed/2023/06/GHSA-f8cc-v72f-5rm2/GHSA-f8cc-v72f-5rm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8cc-v72f-5rm2", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:26Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26433" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26433" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-fqgf-87c4-qvqm/GHSA-fqgf-87c4-qvqm.json b/advisories/unreviewed/2023/06/GHSA-fqgf-87c4-qvqm/GHSA-fqgf-87c4-qvqm.json index fc39c627f96..fd0e2ad52b2 100644 --- a/advisories/unreviewed/2023/06/GHSA-fqgf-87c4-qvqm/GHSA-fqgf-87c4-qvqm.json +++ b/advisories/unreviewed/2023/06/GHSA-fqgf-87c4-qvqm/GHSA-fqgf-87c4-qvqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqgf-87c4-qvqm", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:25Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26431" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26431" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-q84v-pwf5-wm4x/GHSA-q84v-pwf5-wm4x.json b/advisories/unreviewed/2023/06/GHSA-q84v-pwf5-wm4x/GHSA-q84v-pwf5-wm4x.json index a75c194ee89..9c8fc8fedda 100644 --- a/advisories/unreviewed/2023/06/GHSA-q84v-pwf5-wm4x/GHSA-q84v-pwf5-wm4x.json +++ b/advisories/unreviewed/2023/06/GHSA-q84v-pwf5-wm4x/GHSA-q84v-pwf5-wm4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q84v-pwf5-wm4x", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:25Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26429" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26429" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-qg93-cpf3-386g/GHSA-qg93-cpf3-386g.json b/advisories/unreviewed/2023/06/GHSA-qg93-cpf3-386g/GHSA-qg93-cpf3-386g.json index 2b5cb9d29f9..0a2ff271a20 100644 --- a/advisories/unreviewed/2023/06/GHSA-qg93-cpf3-386g/GHSA-qg93-cpf3-386g.json +++ b/advisories/unreviewed/2023/06/GHSA-qg93-cpf3-386g/GHSA-qg93-cpf3-386g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg93-cpf3-386g", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26435" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26435" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-qv8q-wwpq-485r/GHSA-qv8q-wwpq-485r.json b/advisories/unreviewed/2023/06/GHSA-qv8q-wwpq-485r/GHSA-qv8q-wwpq-485r.json index 3cc1781009d..d2f7b8a6c59 100644 --- a/advisories/unreviewed/2023/06/GHSA-qv8q-wwpq-485r/GHSA-qv8q-wwpq-485r.json +++ b/advisories/unreviewed/2023/06/GHSA-qv8q-wwpq-485r/GHSA-qv8q-wwpq-485r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv8q-wwpq-485r", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:25Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26428" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26428" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-rfrx-wp2r-q456/GHSA-rfrx-wp2r-q456.json b/advisories/unreviewed/2023/06/GHSA-rfrx-wp2r-q456/GHSA-rfrx-wp2r-q456.json index a9d60797b25..33cb86b4e9a 100644 --- a/advisories/unreviewed/2023/06/GHSA-rfrx-wp2r-q456/GHSA-rfrx-wp2r-q456.json +++ b/advisories/unreviewed/2023/06/GHSA-rfrx-wp2r-q456/GHSA-rfrx-wp2r-q456.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfrx-wp2r-q456", - "modified": "2023-06-20T09:30:23Z", + "modified": "2024-01-12T09:30:25Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-26427" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26427" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json" @@ -43,7 +47,7 @@ "CWE-732", "CWE-922" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-20T08:15:09Z" diff --git a/advisories/unreviewed/2023/08/GHSA-6vx9-wpjf-5pf7/GHSA-6vx9-wpjf-5pf7.json b/advisories/unreviewed/2023/08/GHSA-6vx9-wpjf-5pf7/GHSA-6vx9-wpjf-5pf7.json index e42f379ddc0..ebf7260622e 100644 --- a/advisories/unreviewed/2023/08/GHSA-6vx9-wpjf-5pf7/GHSA-6vx9-wpjf-5pf7.json +++ b/advisories/unreviewed/2023/08/GHSA-6vx9-wpjf-5pf7/GHSA-6vx9-wpjf-5pf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vx9-wpjf-5pf7", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26446" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26446" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -28,13 +32,21 @@ { "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Aug/8" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-9ppx-xr68-cm59/GHSA-9ppx-xr68-cm59.json b/advisories/unreviewed/2023/08/GHSA-9ppx-xr68-cm59/GHSA-9ppx-xr68-cm59.json index 55ca2b38c80..553c25b1abf 100644 --- a/advisories/unreviewed/2023/08/GHSA-9ppx-xr68-cm59/GHSA-9ppx-xr68-cm59.json +++ b/advisories/unreviewed/2023/08/GHSA-9ppx-xr68-cm59/GHSA-9ppx-xr68-cm59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ppx-xr68-cm59", - "modified": "2023-08-02T15:30:54Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:54Z", "aliases": [ "CVE-2023-26450" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26450" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:11Z" diff --git a/advisories/unreviewed/2023/08/GHSA-9rfr-rprq-pv78/GHSA-9rfr-rprq-pv78.json b/advisories/unreviewed/2023/08/GHSA-9rfr-rprq-pv78/GHSA-9rfr-rprq-pv78.json index 3d0ce5eeac7..cf81f6486c5 100644 --- a/advisories/unreviewed/2023/08/GHSA-9rfr-rprq-pv78/GHSA-9rfr-rprq-pv78.json +++ b/advisories/unreviewed/2023/08/GHSA-9rfr-rprq-pv78/GHSA-9rfr-rprq-pv78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rfr-rprq-pv78", - "modified": "2023-08-02T15:30:52Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-08-02T15:30:52Z", "aliases": [ "CVE-2023-26430" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26430" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-c2rq-xcq6-frfg/GHSA-c2rq-xcq6-frfg.json b/advisories/unreviewed/2023/08/GHSA-c2rq-xcq6-frfg/GHSA-c2rq-xcq6-frfg.json index 9bf0b475fe8..0b6300f93a7 100644 --- a/advisories/unreviewed/2023/08/GHSA-c2rq-xcq6-frfg/GHSA-c2rq-xcq6-frfg.json +++ b/advisories/unreviewed/2023/08/GHSA-c2rq-xcq6-frfg/GHSA-c2rq-xcq6-frfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2rq-xcq6-frfg", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26443" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26443" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-ccm5-74vf-c7hj/GHSA-ccm5-74vf-c7hj.json b/advisories/unreviewed/2023/08/GHSA-ccm5-74vf-c7hj/GHSA-ccm5-74vf-c7hj.json index bce60cc6266..6ee3b895a2f 100644 --- a/advisories/unreviewed/2023/08/GHSA-ccm5-74vf-c7hj/GHSA-ccm5-74vf-c7hj.json +++ b/advisories/unreviewed/2023/08/GHSA-ccm5-74vf-c7hj/GHSA-ccm5-74vf-c7hj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccm5-74vf-c7hj", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26445" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26445" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-cp3q-q6mx-w79j/GHSA-cp3q-q6mx-w79j.json b/advisories/unreviewed/2023/08/GHSA-cp3q-q6mx-w79j/GHSA-cp3q-q6mx-w79j.json index cc652a6a9cd..bcd8b08a5a2 100644 --- a/advisories/unreviewed/2023/08/GHSA-cp3q-q6mx-w79j/GHSA-cp3q-q6mx-w79j.json +++ b/advisories/unreviewed/2023/08/GHSA-cp3q-q6mx-w79j/GHSA-cp3q-q6mx-w79j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cp3q-q6mx-w79j", - "modified": "2023-08-02T15:30:52Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-08-02T15:30:52Z", "aliases": [ "CVE-2023-26438" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26438" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -28,13 +32,22 @@ { "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Aug/8" } ], "database_specific": { "cwe_ids": [ + "CWE-367", "CWE-918" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-h33q-26v7-q343/GHSA-h33q-26v7-q343.json b/advisories/unreviewed/2023/08/GHSA-h33q-26v7-q343/GHSA-h33q-26v7-q343.json index 1febcc3dc6d..aa6f179a452 100644 --- a/advisories/unreviewed/2023/08/GHSA-h33q-26v7-q343/GHSA-h33q-26v7-q343.json +++ b/advisories/unreviewed/2023/08/GHSA-h33q-26v7-q343/GHSA-h33q-26v7-q343.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h33q-26v7-q343", - "modified": "2023-08-02T15:30:52Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-08-02T15:30:52Z", "aliases": [ "CVE-2023-26439" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26439" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-h5f9-372r-9xwq/GHSA-h5f9-372r-9xwq.json b/advisories/unreviewed/2023/08/GHSA-h5f9-372r-9xwq/GHSA-h5f9-372r-9xwq.json index b6566499285..fd23dbb63b5 100644 --- a/advisories/unreviewed/2023/08/GHSA-h5f9-372r-9xwq/GHSA-h5f9-372r-9xwq.json +++ b/advisories/unreviewed/2023/08/GHSA-h5f9-372r-9xwq/GHSA-h5f9-372r-9xwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5f9-372r-9xwq", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26442" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26442" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -28,13 +32,21 @@ { "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Aug/8" } ], "database_specific": { "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-hpjf-rjwg-v743/GHSA-hpjf-rjwg-v743.json b/advisories/unreviewed/2023/08/GHSA-hpjf-rjwg-v743/GHSA-hpjf-rjwg-v743.json index 920ce265d17..ec7f2387ee5 100644 --- a/advisories/unreviewed/2023/08/GHSA-hpjf-rjwg-v743/GHSA-hpjf-rjwg-v743.json +++ b/advisories/unreviewed/2023/08/GHSA-hpjf-rjwg-v743/GHSA-hpjf-rjwg-v743.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpjf-rjwg-v743", - "modified": "2023-08-02T15:30:54Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:54Z", "aliases": [ "CVE-2023-26449" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26449" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:11Z" diff --git a/advisories/unreviewed/2023/08/GHSA-prhg-xpp4-c8mx/GHSA-prhg-xpp4-c8mx.json b/advisories/unreviewed/2023/08/GHSA-prhg-xpp4-c8mx/GHSA-prhg-xpp4-c8mx.json index 0e587da34e1..b4ab8848931 100644 --- a/advisories/unreviewed/2023/08/GHSA-prhg-xpp4-c8mx/GHSA-prhg-xpp4-c8mx.json +++ b/advisories/unreviewed/2023/08/GHSA-prhg-xpp4-c8mx/GHSA-prhg-xpp4-c8mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prhg-xpp4-c8mx", - "modified": "2023-08-02T15:30:54Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:54Z", "aliases": [ "CVE-2023-26448" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26448" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -28,13 +32,21 @@ { "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Aug/8" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:11Z" diff --git a/advisories/unreviewed/2023/08/GHSA-qfq4-f9vc-vv2j/GHSA-qfq4-f9vc-vv2j.json b/advisories/unreviewed/2023/08/GHSA-qfq4-f9vc-vv2j/GHSA-qfq4-f9vc-vv2j.json index 5c2899ca01c..5655a6acae0 100644 --- a/advisories/unreviewed/2023/08/GHSA-qfq4-f9vc-vv2j/GHSA-qfq4-f9vc-vv2j.json +++ b/advisories/unreviewed/2023/08/GHSA-qfq4-f9vc-vv2j/GHSA-qfq4-f9vc-vv2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qfq4-f9vc-vv2j", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26447" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26447" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -28,13 +32,21 @@ { "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Aug/8" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-rq8q-w9hr-c2fr/GHSA-rq8q-w9hr-c2fr.json b/advisories/unreviewed/2023/08/GHSA-rq8q-w9hr-c2fr/GHSA-rq8q-w9hr-c2fr.json index e5f294bbac5..f015ab123eb 100644 --- a/advisories/unreviewed/2023/08/GHSA-rq8q-w9hr-c2fr/GHSA-rq8q-w9hr-c2fr.json +++ b/advisories/unreviewed/2023/08/GHSA-rq8q-w9hr-c2fr/GHSA-rq8q-w9hr-c2fr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rq8q-w9hr-c2fr", - "modified": "2023-08-02T15:30:54Z", + "modified": "2024-01-12T09:30:28Z", "published": "2023-08-02T15:30:54Z", "aliases": [ "CVE-2023-26451" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26451" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-330" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:11Z" diff --git a/advisories/unreviewed/2023/08/GHSA-vvf9-x2f5-h29c/GHSA-vvf9-x2f5-h29c.json b/advisories/unreviewed/2023/08/GHSA-vvf9-x2f5-h29c/GHSA-vvf9-x2f5-h29c.json index 53e09d95726..e21fe6fdb42 100644 --- a/advisories/unreviewed/2023/08/GHSA-vvf9-x2f5-h29c/GHSA-vvf9-x2f5-h29c.json +++ b/advisories/unreviewed/2023/08/GHSA-vvf9-x2f5-h29c/GHSA-vvf9-x2f5-h29c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vvf9-x2f5-h29c", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26440" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26440" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json b/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json index a675c5e325a..653547d86ab 100644 --- a/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json +++ b/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq7r-2vx2-8jgj", - "modified": "2023-08-02T15:30:53Z", + "modified": "2024-01-12T09:30:27Z", "published": "2023-08-02T15:30:53Z", "aliases": [ "CVE-2023-26441" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26441" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0003.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json" @@ -43,7 +47,7 @@ "CWE-200", "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-02T13:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4xwv-7982-j5wj/GHSA-4xwv-7982-j5wj.json b/advisories/unreviewed/2023/11/GHSA-4xwv-7982-j5wj/GHSA-4xwv-7982-j5wj.json index 91f8d806de1..92db2714714 100644 --- a/advisories/unreviewed/2023/11/GHSA-4xwv-7982-j5wj/GHSA-4xwv-7982-j5wj.json +++ b/advisories/unreviewed/2023/11/GHSA-4xwv-7982-j5wj/GHSA-4xwv-7982-j5wj.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26452" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-6f4g-5r7v-g37f/GHSA-6f4g-5r7v-g37f.json b/advisories/unreviewed/2023/11/GHSA-6f4g-5r7v-g37f/GHSA-6f4g-5r7v-g37f.json index f2cd0f99cfa..e845a68d6af 100644 --- a/advisories/unreviewed/2023/11/GHSA-6f4g-5r7v-g37f/GHSA-6f4g-5r7v-g37f.json +++ b/advisories/unreviewed/2023/11/GHSA-6f4g-5r7v-g37f/GHSA-6f4g-5r7v-g37f.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29045" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-9wv2-mrrp-v8g7/GHSA-9wv2-mrrp-v8g7.json b/advisories/unreviewed/2023/11/GHSA-9wv2-mrrp-v8g7/GHSA-9wv2-mrrp-v8g7.json index c9686624817..b4b12c968d9 100644 --- a/advisories/unreviewed/2023/11/GHSA-9wv2-mrrp-v8g7/GHSA-9wv2-mrrp-v8g7.json +++ b/advisories/unreviewed/2023/11/GHSA-9wv2-mrrp-v8g7/GHSA-9wv2-mrrp-v8g7.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26455" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-c568-gcr5-3gmw/GHSA-c568-gcr5-3gmw.json b/advisories/unreviewed/2023/11/GHSA-c568-gcr5-3gmw/GHSA-c568-gcr5-3gmw.json index 7b08a539588..7c25a99aef5 100644 --- a/advisories/unreviewed/2023/11/GHSA-c568-gcr5-3gmw/GHSA-c568-gcr5-3gmw.json +++ b/advisories/unreviewed/2023/11/GHSA-c568-gcr5-3gmw/GHSA-c568-gcr5-3gmw.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29047" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-f746-g4q7-wxcp/GHSA-f746-g4q7-wxcp.json b/advisories/unreviewed/2023/11/GHSA-f746-g4q7-wxcp/GHSA-f746-g4q7-wxcp.json index 17ba45353b5..928755b8ef3 100644 --- a/advisories/unreviewed/2023/11/GHSA-f746-g4q7-wxcp/GHSA-f746-g4q7-wxcp.json +++ b/advisories/unreviewed/2023/11/GHSA-f746-g4q7-wxcp/GHSA-f746-g4q7-wxcp.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26454" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-h37j-vw7r-prg3/GHSA-h37j-vw7r-prg3.json b/advisories/unreviewed/2023/11/GHSA-h37j-vw7r-prg3/GHSA-h37j-vw7r-prg3.json index bb9affa8982..93dc3297584 100644 --- a/advisories/unreviewed/2023/11/GHSA-h37j-vw7r-prg3/GHSA-h37j-vw7r-prg3.json +++ b/advisories/unreviewed/2023/11/GHSA-h37j-vw7r-prg3/GHSA-h37j-vw7r-prg3.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29043" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-jcjp-p87g-594h/GHSA-jcjp-p87g-594h.json b/advisories/unreviewed/2023/11/GHSA-jcjp-p87g-594h/GHSA-jcjp-p87g-594h.json index 5cd58587ee2..a0deb18b857 100644 --- a/advisories/unreviewed/2023/11/GHSA-jcjp-p87g-594h/GHSA-jcjp-p87g-594h.json +++ b/advisories/unreviewed/2023/11/GHSA-jcjp-p87g-594h/GHSA-jcjp-p87g-594h.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29046" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-jxxq-5fp9-76wc/GHSA-jxxq-5fp9-76wc.json b/advisories/unreviewed/2023/11/GHSA-jxxq-5fp9-76wc/GHSA-jxxq-5fp9-76wc.json index 763634ed2e0..690a0037539 100644 --- a/advisories/unreviewed/2023/11/GHSA-jxxq-5fp9-76wc/GHSA-jxxq-5fp9-76wc.json +++ b/advisories/unreviewed/2023/11/GHSA-jxxq-5fp9-76wc/GHSA-jxxq-5fp9-76wc.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26453" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-w4gp-rmfp-f2gh/GHSA-w4gp-rmfp-f2gh.json b/advisories/unreviewed/2023/11/GHSA-w4gp-rmfp-f2gh/GHSA-w4gp-rmfp-f2gh.json index 6f848db6df9..9b2418d52d4 100644 --- a/advisories/unreviewed/2023/11/GHSA-w4gp-rmfp-f2gh/GHSA-w4gp-rmfp-f2gh.json +++ b/advisories/unreviewed/2023/11/GHSA-w4gp-rmfp-f2gh/GHSA-w4gp-rmfp-f2gh.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29044" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2023/11/GHSA-xmj4-pwxq-wq63/GHSA-xmj4-pwxq-wq63.json b/advisories/unreviewed/2023/11/GHSA-xmj4-pwxq-wq63/GHSA-xmj4-pwxq-wq63.json index 431bda8f6ed..78e5139b0da 100644 --- a/advisories/unreviewed/2023/11/GHSA-xmj4-pwxq-wq63/GHSA-xmj4-pwxq-wq63.json +++ b/advisories/unreviewed/2023/11/GHSA-xmj4-pwxq-wq63/GHSA-xmj4-pwxq-wq63.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26456" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0004.json" diff --git a/advisories/unreviewed/2024/01/GHSA-2jxj-pf6p-qrpf/GHSA-2jxj-pf6p-qrpf.json b/advisories/unreviewed/2024/01/GHSA-2jxj-pf6p-qrpf/GHSA-2jxj-pf6p-qrpf.json new file mode 100644 index 00000000000..134d628aeb9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2jxj-pf6p-qrpf/GHSA-2jxj-pf6p-qrpf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jxj-pf6p-qrpf", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-30015" + ], + "details": "SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30015" + }, + { + "type": "WEB", + "url": "https://github.com/Pings1031/cve_report/blob/main/judging-management-system/SQLi-3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T09:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json index 3d001774583..3d929ebf7d3 100644 --- a/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json +++ b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29048" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" diff --git a/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json b/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json new file mode 100644 index 00000000000..e366594879c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3vmx-5x6r-25cw/GHSA-3vmx-5x6r-25cw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vmx-5x6r-25cw", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-50919" + ], + "details": "An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50919" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Authentication-bypass.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4mhf-c48q-rghx/GHSA-4mhf-c48q-rghx.json b/advisories/unreviewed/2024/01/GHSA-4mhf-c48q-rghx/GHSA-4mhf-c48q-rghx.json new file mode 100644 index 00000000000..c26bab0b43a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4mhf-c48q-rghx/GHSA-4mhf-c48q-rghx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mhf-c48q-rghx", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-40362" + ], + "details": "An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40362" + }, + { + "type": "WEB", + "url": "https://github.com/ally-petitt/CVE-2023-40362" + }, + { + "type": "WEB", + "url": "https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breach" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json index e5ae62ae855..819b234ffd0 100644 --- a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json +++ b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29050" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" diff --git a/advisories/unreviewed/2024/01/GHSA-5cw3-5rmf-j5f2/GHSA-5cw3-5rmf-j5f2.json b/advisories/unreviewed/2024/01/GHSA-5cw3-5rmf-j5f2/GHSA-5cw3-5rmf-j5f2.json new file mode 100644 index 00000000000..5c7992e643b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5cw3-5rmf-j5f2/GHSA-5cw3-5rmf-j5f2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cw3-5rmf-j5f2", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-30014" + ], + "details": "SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30014" + }, + { + "type": "WEB", + "url": "https://github.com/Pings1031/cve_report/blob/main/judging-management-system/SQLi-1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T09:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json b/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json new file mode 100644 index 00000000000..44f62ac9f12 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w7f-m7fg-fhfc", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-30016" + ], + "details": "SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30016" + }, + { + "type": "WEB", + "url": "https://github.com/Pings1031/cve_report/blob/main/judging-management-system/SQLi-2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T09:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json index 1c5b04151bd..d96a51c5a0f 100644 --- a/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json +++ b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41710" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" diff --git a/advisories/unreviewed/2024/01/GHSA-fmr7-cqjx-qmxg/GHSA-fmr7-cqjx-qmxg.json b/advisories/unreviewed/2024/01/GHSA-fmr7-cqjx-qmxg/GHSA-fmr7-cqjx-qmxg.json new file mode 100644 index 00000000000..6f5eb469cff --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fmr7-cqjx-qmxg/GHSA-fmr7-cqjx-qmxg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmr7-cqjx-qmxg", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-48909" + ], + "details": "An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48909" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Dollhouse-18/288b4774bc296722c9e3c60bafa392bf" + }, + { + "type": "WEB", + "url": "https://github.com/Dollhouse-18/jave-core-Command-execution-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T09:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hgr6-fxr2-jx3f/GHSA-hgr6-fxr2-jx3f.json b/advisories/unreviewed/2024/01/GHSA-hgr6-fxr2-jx3f/GHSA-hgr6-fxr2-jx3f.json new file mode 100644 index 00000000000..90322f9e69f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hgr6-fxr2-jx3f/GHSA-hgr6-fxr2-jx3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgr6-fxr2-jx3f", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-6735" + ], + "details": "Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows local user to escalate privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6735" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16273" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hvvx-qx2r-4h8q/GHSA-hvvx-qx2r-4h8q.json b/advisories/unreviewed/2024/01/GHSA-hvvx-qx2r-4h8q/GHSA-hvvx-qx2r-4h8q.json new file mode 100644 index 00000000000..ac967366076 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hvvx-qx2r-4h8q/GHSA-hvvx-qx2r-4h8q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvvx-qx2r-4h8q", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-37117" + ], + "details": "A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37117" + }, + { + "type": "WEB", + "url": "http://lists.live555.com/pipermail/live-devel/2023-June/022331.html" + }, + { + "type": "WEB", + "url": "http://www.live555.com/liveMedia/public/changelog.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json index 4989edeadff..942cf0e57b9 100644 --- a/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json +++ b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29051" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" diff --git a/advisories/unreviewed/2024/01/GHSA-j8hh-2v2c-wqmv/GHSA-j8hh-2v2c-wqmv.json b/advisories/unreviewed/2024/01/GHSA-j8hh-2v2c-wqmv/GHSA-j8hh-2v2c-wqmv.json new file mode 100644 index 00000000000..0ee7b3919c9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j8hh-2v2c-wqmv/GHSA-j8hh-2v2c-wqmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8hh-2v2c-wqmv", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-31211" + ], + "details": "Insufficient authentication flow in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows attacker to use locked credentials", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31211" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-691" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m89q-5h24-2xm5/GHSA-m89q-5h24-2xm5.json b/advisories/unreviewed/2024/01/GHSA-m89q-5h24-2xm5/GHSA-m89q-5h24-2xm5.json new file mode 100644 index 00000000000..c61465aee87 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m89q-5h24-2xm5/GHSA-m89q-5h24-2xm5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m89q-5h24-2xm5", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-6740" + ], + "details": "Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows local user to escalate privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6740" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/16163" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json b/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json new file mode 100644 index 00000000000..03ee6de9ec4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7pv-w5qm-8pxv", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2024-22027" + ], + "details": "Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22027" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN37326856/" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/quiz-maker/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json index d8f36826bab..5cd3544eb8a 100644 --- a/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json +++ b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29049" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" diff --git a/advisories/unreviewed/2024/01/GHSA-pxmv-x94g-j48f/GHSA-pxmv-x94g-j48f.json b/advisories/unreviewed/2024/01/GHSA-pxmv-x94g-j48f/GHSA-pxmv-x94g-j48f.json new file mode 100644 index 00000000000..bc5e1dc6856 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pxmv-x94g-j48f/GHSA-pxmv-x94g-j48f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxmv-x94g-j48f", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-50920" + ], + "details": "An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate legitimate users or perform unauthorized actions. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50920" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Authentication-bypass-seesion-ID.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json index 12f2dd258fd..5737b14943d 100644 --- a/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json +++ b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29052" }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0006.json" + }, { "type": "WEB", "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" diff --git a/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json b/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json new file mode 100644 index 00000000000..a38f4df6d46 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr94-cv8c-7r6v", + "modified": "2024-01-12T09:30:29Z", + "published": "2024-01-12T09:30:29Z", + "aliases": [ + "CVE-2023-34061" + ], + "details": "Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34061" + }, + { + "type": "WEB", + "url": "https://www.cloudfoundry.org/blog/cve-2023-34061-gorouter-route-pruning/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T07:15:11Z" + } +} \ No newline at end of file