From eec5ee3ac1d0806d1ccb4acc8fe19cc153d20833 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 12 May 2023 21:31:25 +0000 Subject: [PATCH] Publish Advisories GHSA-2ccj-67xq-j58p GHSA-2q9c-qj72-94fh GHSA-3grg-4gwx-fp3c GHSA-47gq-m9v9-v35g GHSA-5ggr-2fgq-wj6h GHSA-6hfq-xhjq-23gj GHSA-6xfq-86q7-v85v GHSA-7cm5-9qc6-j36q GHSA-7crh-9v7x-2x2r GHSA-866c-q5rf-f4vh GHSA-8vwj-f33x-4pw9 GHSA-c56w-7hv5-9xpf GHSA-ccx6-6vgf-c5rw GHSA-fvf4-jv3j-73mq GHSA-fvwx-63p4-jv5q GHSA-gm2v-qrgq-3fhf GHSA-gpv4-3vx7-hr4h GHSA-j42j-4v6g-8gm8 GHSA-m96m-mfqc-86mf GHSA-q755-7vhv-rpcf GHSA-v9c8-gcwh-7xvh GHSA-vwrx-67m6-2266 GHSA-w2x2-xp9p-jxxc GHSA-x8q4-jwf8-q3ff --- .../GHSA-2ccj-67xq-j58p.json | 7 ++- .../GHSA-2q9c-qj72-94fh.json | 7 ++- .../GHSA-3grg-4gwx-fp3c.json | 35 ++++++++++++++ .../GHSA-47gq-m9v9-v35g.json | 39 ++++++++++++++++ .../GHSA-5ggr-2fgq-wj6h.json | 9 ++-- .../GHSA-6hfq-xhjq-23gj.json | 35 ++++++++++++++ .../GHSA-6xfq-86q7-v85v.json | 35 ++++++++++++++ .../GHSA-7cm5-9qc6-j36q.json | 9 ++-- .../GHSA-7crh-9v7x-2x2r.json | 7 ++- .../GHSA-866c-q5rf-f4vh.json | 35 ++++++++++++++ .../GHSA-8vwj-f33x-4pw9.json | 42 +++++++++++++++++ .../GHSA-c56w-7hv5-9xpf.json | 35 ++++++++++++++ .../GHSA-ccx6-6vgf-c5rw.json | 35 ++++++++++++++ .../GHSA-fvf4-jv3j-73mq.json | 35 ++++++++++++++ .../GHSA-fvwx-63p4-jv5q.json | 35 ++++++++++++++ .../GHSA-gm2v-qrgq-3fhf.json | 35 ++++++++++++++ .../GHSA-gpv4-3vx7-hr4h.json | 9 ++-- .../GHSA-j42j-4v6g-8gm8.json | 9 ++-- .../GHSA-m96m-mfqc-86mf.json | 46 +++++++++++++++++++ .../GHSA-q755-7vhv-rpcf.json | 35 ++++++++++++++ .../GHSA-v9c8-gcwh-7xvh.json | 7 ++- .../GHSA-vwrx-67m6-2266.json | 35 ++++++++++++++ .../GHSA-w2x2-xp9p-jxxc.json | 7 ++- .../GHSA-x8q4-jwf8-q3ff.json | 7 ++- 24 files changed, 566 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2023/05/GHSA-3grg-4gwx-fp3c/GHSA-3grg-4gwx-fp3c.json create mode 100644 advisories/unreviewed/2023/05/GHSA-47gq-m9v9-v35g/GHSA-47gq-m9v9-v35g.json create mode 100644 advisories/unreviewed/2023/05/GHSA-6hfq-xhjq-23gj/GHSA-6hfq-xhjq-23gj.json create mode 100644 advisories/unreviewed/2023/05/GHSA-6xfq-86q7-v85v/GHSA-6xfq-86q7-v85v.json create mode 100644 advisories/unreviewed/2023/05/GHSA-866c-q5rf-f4vh/GHSA-866c-q5rf-f4vh.json create mode 100644 advisories/unreviewed/2023/05/GHSA-8vwj-f33x-4pw9/GHSA-8vwj-f33x-4pw9.json create mode 100644 advisories/unreviewed/2023/05/GHSA-c56w-7hv5-9xpf/GHSA-c56w-7hv5-9xpf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-ccx6-6vgf-c5rw/GHSA-ccx6-6vgf-c5rw.json create mode 100644 advisories/unreviewed/2023/05/GHSA-fvf4-jv3j-73mq/GHSA-fvf4-jv3j-73mq.json create mode 100644 advisories/unreviewed/2023/05/GHSA-fvwx-63p4-jv5q/GHSA-fvwx-63p4-jv5q.json create mode 100644 advisories/unreviewed/2023/05/GHSA-gm2v-qrgq-3fhf/GHSA-gm2v-qrgq-3fhf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-m96m-mfqc-86mf/GHSA-m96m-mfqc-86mf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-q755-7vhv-rpcf/GHSA-q755-7vhv-rpcf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-vwrx-67m6-2266/GHSA-vwrx-67m6-2266.json diff --git a/advisories/unreviewed/2023/05/GHSA-2ccj-67xq-j58p/GHSA-2ccj-67xq-j58p.json b/advisories/unreviewed/2023/05/GHSA-2ccj-67xq-j58p/GHSA-2ccj-67xq-j58p.json index e402c5e5547..c093791d990 100644 --- a/advisories/unreviewed/2023/05/GHSA-2ccj-67xq-j58p/GHSA-2ccj-67xq-j58p.json +++ b/advisories/unreviewed/2023/05/GHSA-2ccj-67xq-j58p/GHSA-2ccj-67xq-j58p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2ccj-67xq-j58p", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27943" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. Files downloaded from the internet may not have the quarantine flag applied", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-2q9c-qj72-94fh/GHSA-2q9c-qj72-94fh.json b/advisories/unreviewed/2023/05/GHSA-2q9c-qj72-94fh/GHSA-2q9c-qj72-94fh.json index bf6b076914c..ab610d528fa 100644 --- a/advisories/unreviewed/2023/05/GHSA-2q9c-qj72-94fh/GHSA-2q9c-qj72-94fh.json +++ b/advisories/unreviewed/2023/05/GHSA-2q9c-qj72-94fh/GHSA-2q9c-qj72-94fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2q9c-qj72-94fh", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27954" ], "details": "The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. A website may be able to track sensitive user information", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-3grg-4gwx-fp3c/GHSA-3grg-4gwx-fp3c.json b/advisories/unreviewed/2023/05/GHSA-3grg-4gwx-fp3c/GHSA-3grg-4gwx-fp3c.json new file mode 100644 index 00000000000..6cf196334e7 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-3grg-4gwx-fp3c/GHSA-3grg-4gwx-fp3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3grg-4gwx-fp3c", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-20880" + ], + "details": "VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20880" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-47gq-m9v9-v35g/GHSA-47gq-m9v9-v35g.json b/advisories/unreviewed/2023/05/GHSA-47gq-m9v9-v35g/GHSA-47gq-m9v9-v35g.json new file mode 100644 index 00000000000..b0a1503f29a --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-47gq-m9v9-v35g/GHSA-47gq-m9v9-v35g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47gq-m9v9-v35g", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-30247" + ], + "details": "File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30247" + }, + { + "type": "WEB", + "url": "https://github.com/qingning988/cve_report/blob/main/storage-unit-rental-management-system/RCE-1.md" + }, + { + "type": "WEB", + "url": "https://www.github.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-5ggr-2fgq-wj6h/GHSA-5ggr-2fgq-wj6h.json b/advisories/unreviewed/2023/05/GHSA-5ggr-2fgq-wj6h/GHSA-5ggr-2fgq-wj6h.json index 3d3a40ff9e1..317f8e23bd0 100644 --- a/advisories/unreviewed/2023/05/GHSA-5ggr-2fgq-wj6h/GHSA-5ggr-2fgq-wj6h.json +++ b/advisories/unreviewed/2023/05/GHSA-5ggr-2fgq-wj6h/GHSA-5ggr-2fgq-wj6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5ggr-2fgq-wj6h", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27968" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-6hfq-xhjq-23gj/GHSA-6hfq-xhjq-23gj.json b/advisories/unreviewed/2023/05/GHSA-6hfq-xhjq-23gj/GHSA-6hfq-xhjq-23gj.json new file mode 100644 index 00000000000..83b9af16f55 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-6hfq-xhjq-23gj/GHSA-6hfq-xhjq-23gj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hfq-xhjq-23gj", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-25007" + ], + "details": "A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25007" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-6xfq-86q7-v85v/GHSA-6xfq-86q7-v85v.json b/advisories/unreviewed/2023/05/GHSA-6xfq-86q7-v85v/GHSA-6xfq-86q7-v85v.json new file mode 100644 index 00000000000..7cdeae15297 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-6xfq-86q7-v85v/GHSA-6xfq-86q7-v85v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xfq-86q7-v85v", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-20878" + ], + "details": "VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20878" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-7cm5-9qc6-j36q/GHSA-7cm5-9qc6-j36q.json b/advisories/unreviewed/2023/05/GHSA-7cm5-9qc6-j36q/GHSA-7cm5-9qc6-j36q.json index 14af7a72928..9f38b6d36a0 100644 --- a/advisories/unreviewed/2023/05/GHSA-7cm5-9qc6-j36q/GHSA-7cm5-9qc6-j36q.json +++ b/advisories/unreviewed/2023/05/GHSA-7cm5-9qc6-j36q/GHSA-7cm5-9qc6-j36q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7cm5-9qc6-j36q", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27953" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-7crh-9v7x-2x2r/GHSA-7crh-9v7x-2x2r.json b/advisories/unreviewed/2023/05/GHSA-7crh-9v7x-2x2r/GHSA-7crh-9v7x-2x2r.json index 15f83c81075..c6abcbcd31a 100644 --- a/advisories/unreviewed/2023/05/GHSA-7crh-9v7x-2x2r/GHSA-7crh-9v7x-2x2r.json +++ b/advisories/unreviewed/2023/05/GHSA-7crh-9v7x-2x2r/GHSA-7crh-9v7x-2x2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7crh-9v7x-2x2r", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27955" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4. An app may be able to read arbitrary files", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-866c-q5rf-f4vh/GHSA-866c-q5rf-f4vh.json b/advisories/unreviewed/2023/05/GHSA-866c-q5rf-f4vh/GHSA-866c-q5rf-f4vh.json new file mode 100644 index 00000000000..da0e5ad230e --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-866c-q5rf-f4vh/GHSA-866c-q5rf-f4vh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-866c-q5rf-f4vh", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-1096" + ], + "details": "SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1096" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230511-0011/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-8vwj-f33x-4pw9/GHSA-8vwj-f33x-4pw9.json b/advisories/unreviewed/2023/05/GHSA-8vwj-f33x-4pw9/GHSA-8vwj-f33x-4pw9.json new file mode 100644 index 00000000000..3eaaf648281 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-8vwj-f33x-4pw9/GHSA-8vwj-f33x-4pw9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vwj-f33x-4pw9", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-27863" + ], + "details": "IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27863" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249325" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6965812" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-c56w-7hv5-9xpf/GHSA-c56w-7hv5-9xpf.json b/advisories/unreviewed/2023/05/GHSA-c56w-7hv5-9xpf/GHSA-c56w-7hv5-9xpf.json new file mode 100644 index 00000000000..2bc71efa0f5 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-c56w-7hv5-9xpf/GHSA-c56w-7hv5-9xpf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c56w-7hv5-9xpf", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-25008" + ], + "details": "A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25008" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-ccx6-6vgf-c5rw/GHSA-ccx6-6vgf-c5rw.json b/advisories/unreviewed/2023/05/GHSA-ccx6-6vgf-c5rw/GHSA-ccx6-6vgf-c5rw.json new file mode 100644 index 00000000000..73362cff8e4 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-ccx6-6vgf-c5rw/GHSA-ccx6-6vgf-c5rw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccx6-6vgf-c5rw", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-20877" + ], + "details": "VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20877" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-fvf4-jv3j-73mq/GHSA-fvf4-jv3j-73mq.json b/advisories/unreviewed/2023/05/GHSA-fvf4-jv3j-73mq/GHSA-fvf4-jv3j-73mq.json new file mode 100644 index 00000000000..95b1890bb95 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-fvf4-jv3j-73mq/GHSA-fvf4-jv3j-73mq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvf4-jv3j-73mq", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-2088" + ], + "details": "A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2088" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/bugs/2004555" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-fvwx-63p4-jv5q/GHSA-fvwx-63p4-jv5q.json b/advisories/unreviewed/2023/05/GHSA-fvwx-63p4-jv5q/GHSA-fvwx-63p4-jv5q.json new file mode 100644 index 00000000000..06f03f56469 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-fvwx-63p4-jv5q/GHSA-fvwx-63p4-jv5q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvwx-63p4-jv5q", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-25005" + ], + "details": "A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25005" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0006" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-gm2v-qrgq-3fhf/GHSA-gm2v-qrgq-3fhf.json b/advisories/unreviewed/2023/05/GHSA-gm2v-qrgq-3fhf/GHSA-gm2v-qrgq-3fhf.json new file mode 100644 index 00000000000..2b3ec7e990d --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-gm2v-qrgq-3fhf/GHSA-gm2v-qrgq-3fhf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm2v-qrgq-3fhf", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-25009" + ], + "details": "A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25009" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-gpv4-3vx7-hr4h/GHSA-gpv4-3vx7-hr4h.json b/advisories/unreviewed/2023/05/GHSA-gpv4-3vx7-hr4h/GHSA-gpv4-3vx7-hr4h.json index 9d13347ee2e..2f7e7211b58 100644 --- a/advisories/unreviewed/2023/05/GHSA-gpv4-3vx7-hr4h/GHSA-gpv4-3vx7-hr4h.json +++ b/advisories/unreviewed/2023/05/GHSA-gpv4-3vx7-hr4h/GHSA-gpv4-3vx7-hr4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpv4-3vx7-hr4h", - "modified": "2023-05-08T21:31:06Z", + "modified": "2023-05-12T21:30:14Z", "published": "2023-05-08T21:31:06Z", "aliases": [ "CVE-2023-27929" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted image may result in disclosure of process memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-j42j-4v6g-8gm8/GHSA-j42j-4v6g-8gm8.json b/advisories/unreviewed/2023/05/GHSA-j42j-4v6g-8gm8/GHSA-j42j-4v6g-8gm8.json index 72718f87631..92d9b19e6d6 100644 --- a/advisories/unreviewed/2023/05/GHSA-j42j-4v6g-8gm8/GHSA-j42j-4v6g-8gm8.json +++ b/advisories/unreviewed/2023/05/GHSA-j42j-4v6g-8gm8/GHSA-j42j-4v6g-8gm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j42j-4v6g-8gm8", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27957" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-m96m-mfqc-86mf/GHSA-m96m-mfqc-86mf.json b/advisories/unreviewed/2023/05/GHSA-m96m-mfqc-86mf/GHSA-m96m-mfqc-86mf.json new file mode 100644 index 00000000000..788a0ecc3ee --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-m96m-mfqc-86mf/GHSA-m96m-mfqc-86mf.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m96m-mfqc-86mf", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-2181" + ], + "details": "An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2181" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1938185" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2181.json" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/407859" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-q755-7vhv-rpcf/GHSA-q755-7vhv-rpcf.json b/advisories/unreviewed/2023/05/GHSA-q755-7vhv-rpcf/GHSA-q755-7vhv-rpcf.json new file mode 100644 index 00000000000..1a1c19c04b8 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-q755-7vhv-rpcf/GHSA-q755-7vhv-rpcf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q755-7vhv-rpcf", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-25006" + ], + "details": "A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25006" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0008" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json b/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json index a152a89e34b..c7097a68065 100644 --- a/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json +++ b/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9c8-gcwh-7xvh", - "modified": "2023-05-08T21:31:06Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:06Z", "aliases": [ "CVE-2023-27931" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to access user-sensitive data", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-vwrx-67m6-2266/GHSA-vwrx-67m6-2266.json b/advisories/unreviewed/2023/05/GHSA-vwrx-67m6-2266/GHSA-vwrx-67m6-2266.json new file mode 100644 index 00000000000..4c0f47eccf3 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-vwrx-67m6-2266/GHSA-vwrx-67m6-2266.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwrx-67m6-2266", + "modified": "2023-05-12T21:30:15Z", + "published": "2023-05-12T21:30:15Z", + "aliases": [ + "CVE-2023-20879" + ], + "details": "VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20879" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2023-0009.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-w2x2-xp9p-jxxc/GHSA-w2x2-xp9p-jxxc.json b/advisories/unreviewed/2023/05/GHSA-w2x2-xp9p-jxxc/GHSA-w2x2-xp9p-jxxc.json index 59cfc52f47a..077d554771e 100644 --- a/advisories/unreviewed/2023/05/GHSA-w2x2-xp9p-jxxc/GHSA-w2x2-xp9p-jxxc.json +++ b/advisories/unreviewed/2023/05/GHSA-w2x2-xp9p-jxxc/GHSA-w2x2-xp9p-jxxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2x2-xp9p-jxxc", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27967" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json b/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json index d5902f02b8f..548399ef223 100644 --- a/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json +++ b/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8q4-jwf8-q3ff", - "modified": "2023-05-08T21:31:07Z", + "modified": "2023-05-12T21:30:15Z", "published": "2023-05-08T21:31:07Z", "aliases": [ "CVE-2023-27959" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [