Publish Advisories

GHSA-2ccj-67xq-j58p
GHSA-2q9c-qj72-94fh
GHSA-3grg-4gwx-fp3c
GHSA-47gq-m9v9-v35g
GHSA-5ggr-2fgq-wj6h
GHSA-6hfq-xhjq-23gj
GHSA-6xfq-86q7-v85v
GHSA-7cm5-9qc6-j36q
GHSA-7crh-9v7x-2x2r
GHSA-866c-q5rf-f4vh
GHSA-8vwj-f33x-4pw9
GHSA-c56w-7hv5-9xpf
GHSA-ccx6-6vgf-c5rw
GHSA-fvf4-jv3j-73mq
GHSA-fvwx-63p4-jv5q
GHSA-gm2v-qrgq-3fhf
GHSA-gpv4-3vx7-hr4h
GHSA-j42j-4v6g-8gm8
GHSA-m96m-mfqc-86mf
GHSA-q755-7vhv-rpcf
GHSA-v9c8-gcwh-7xvh
GHSA-vwrx-67m6-2266
GHSA-w2x2-xp9p-jxxc
GHSA-x8q4-jwf8-q3ff
This commit is contained in:
advisory-database[bot]
2023-05-12 21:31:25 +00:00
parent 9d52165a6c
commit eec5ee3ac1
24 changed files with 566 additions and 24 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2ccj-67xq-j58p",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27943"
],
"details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. Files downloaded from the internet may not have the quarantine flag applied",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q9c-qj72-94fh",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27954"
],
"details": "The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. A website may be able to track sensitive user information",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3grg-4gwx-fp3c",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-20880"
],
"details": "VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20880"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47gq-m9v9-v35g",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-30247"
],
"details": "File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30247"
},
{
"type": "WEB",
"url": "https://github.com/qingning988/cve_report/blob/main/storage-unit-rental-management-system/RCE-1.md"
},
{
"type": "WEB",
"url": "https://www.github.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5ggr-2fgq-wj6h",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27968"
],
"details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hfq-xhjq-23gj",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-25007"
],
"details": "A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25007"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xfq-86q7-v85v",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-20878"
],
"details": "VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20878"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cm5-9qc6-j36q",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27953"
],
"details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7crh-9v7x-2x2r",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27955"
],
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4. An app may be able to read arbitrary files",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-866c-q5rf-f4vh",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-1096"
],
"details": "SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1096"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230511-0011/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vwj-f33x-4pw9",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-27863"
],
"details": "IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27863"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249325"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6965812"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c56w-7hv5-9xpf",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-25008"
],
"details": "A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25008"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccx6-6vgf-c5rw",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-20877"
],
"details": "VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20877"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvf4-jv3j-73mq",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-2088"
],
"details": "A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2088"
},
{
"type": "WEB",
"url": "https://bugs.launchpad.net/bugs/2004555"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvwx-63p4-jv5q",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-25005"
],
"details": "A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25005"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0006"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gm2v-qrgq-3fhf",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-25009"
],
"details": "A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25009"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpv4-3vx7-hr4h",
"modified": "2023-05-08T21:31:06Z",
"modified": "2023-05-12T21:30:14Z",
"published": "2023-05-08T21:31:06Z",
"aliases": [
"CVE-2023-27929"
],
"details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted image may result in disclosure of process memory",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -37,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j42j-4v6g-8gm8",
"modified": "2023-05-08T21:31:07Z",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-08T21:31:07Z",
"aliases": [
"CVE-2023-27957"
],
"details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m96m-mfqc-86mf",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-2181"
],
"details": "An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2181"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/1938185"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2181.json"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/407859"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q755-7vhv-rpcf",
"modified": "2023-05-12T21:30:15Z",
"published": "2023-05-12T21:30:15Z",
"aliases": [
"CVE-2023-25006"
],
"details": "A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25006"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}

Some files were not shown because too many files have changed in this diff Show More