Publish Advisories

GHSA-w6ww-869j-cgm6
GHSA-fqfx-v8f6-cc7c
GHSA-pjh6-2v65-x4fj
GHSA-vfhc-4q79-wvf9
This commit is contained in:
advisory-database[bot]
2024-01-01 18:31:44 +00:00
parent 7a35f93dd2
commit eb3d84f397
4 changed files with 136 additions and 0 deletions
@@ -42,6 +42,10 @@
"type": "WEB",
"url": "https://git.exim.org/exim.git/commit/cf1376206284f2a4f11e32d931d4aade34c206c5"
},
{
"type": "WEB",
"url": "https://github.com/Exim/exim/blob/master/doc/doc-txt/cve-2023-51766"
},
{
"type": "WEB",
"url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
@@ -61,6 +65,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/29/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/01/1"
}
],
"database_specific": {
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqfx-v8f6-cc7c",
"modified": "2024-01-01T18:30:25Z",
"published": "2024-01-01T18:30:25Z",
"aliases": [
"CVE-2024-0181"
],
"details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin_user.php of the component Admin Panel. The manipulation of the argument Firstname/Lastname/Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249433 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0181"
},
{
"type": "WEB",
"url": "https://mega.nz/file/3Yc2iRzY#Uv7ECzLwUvff__JXEcyPG9oxJ0A1fsBIFGVaS35pvtA"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.249433"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.249433"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-01T17:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjh6-2v65-x4fj",
"modified": "2024-01-01T18:30:25Z",
"published": "2024-01-01T18:30:25Z",
"aliases": [
"CVE-2023-50096"
],
"details": "STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50096"
},
{
"type": "WEB",
"url": "https://github.com/elttam/publications/blob/master/writeups/CVE-2023-50096.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-01T18:15:09Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfhc-4q79-wvf9",
"modified": "2024-01-01T18:30:25Z",
"published": "2024-01-01T18:30:25Z",
"aliases": [
"CVE-2023-50094"
],
"details": "reNgine through 2.0.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50094"
},
{
"type": "WEB",
"url": "https://github.com/yogeshojha/rengine/blob/5e120bd5f9dfbd1da82a193e8c9702e483d38d22/web/api/views.py#L195"
},
{
"type": "WEB",
"url": "https://github.com/yogeshojha/rengine/releases"
},
{
"type": "WEB",
"url": "https://github.com/yogeshojha/rengine/security"
},
{
"type": "WEB",
"url": "https://www.mattz.io/posts/cve-2023-50094/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-01T18:15:09Z"
}
}