From f12cdc14c3efb40c7f95d68b1276c6a67f459440 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 12 Apr 2024 18:34:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-32rf-9mpv-rfcv.json | 1 + .../GHSA-4fmh-mf22-vcrx.json | 3 +- .../GHSA-hwh2-grqv-74jx.json | 1 + .../GHSA-jmmv-6pvw-x59r.json | 1 + .../GHSA-vw4p-3wx5-4j4r.json | 1 + .../GHSA-27pg-f79j-mx3w.json | 3 +- .../GHSA-2fjf-h46q-8mfr.json | 3 +- .../GHSA-367p-mrph-mgh2.json | 3 +- .../GHSA-4vg5-hr2c-c4fq.json | 1 + .../GHSA-567r-j9fc-2696.json | 2 +- .../GHSA-5796-pg6j-m9rr.json | 3 +- .../GHSA-7xgm-mmjm-x822.json | 1 + .../GHSA-9pxw-85r8-pc8f.json | 2 +- .../GHSA-9rjc-p324-p26x.json | 3 +- .../GHSA-cmgw-jmjc-q6wf.json | 1 + .../GHSA-cxvm-4f6m-6mjv.json | 1 + .../GHSA-hrfm-pmc4-p9mw.json | 1 + .../GHSA-j6qx-q96r-gvw3.json | 3 +- .../GHSA-mq83-6jqr-c293.json | 1 + .../GHSA-p54g-g6xw-2jm9.json | 3 +- .../GHSA-pw8j-xxwv-qpr8.json | 2 +- .../GHSA-qxqc-qj6p-cwjv.json | 1 + .../GHSA-rf7x-m444-39m4.json | 1 + .../GHSA-w7wm-wchq-gc2x.json | 1 + .../GHSA-wjq7-rmcv-8f9w.json | 1 + .../GHSA-x92g-cprm-m7v4.json | 1 + .../GHSA-xxr7-cchg-fr5v.json | 1 + .../GHSA-426p-74fr-m2wx.json | 1 + .../GHSA-4vv2-435c-33ch.json | 1 + .../GHSA-h89f-5h94-vmj5.json | 1 + .../GHSA-hxqc-xv34-842x.json | 3 +- .../GHSA-jjvv-vqpp-vvhm.json | 1 + .../GHSA-m57v-fhqq-h74x.json | 2 +- .../GHSA-mgcq-32pv-mr2j.json | 2 +- .../GHSA-p5pp-ppfp-mrrh.json | 1 + .../GHSA-pqg5-9528-cm52.json | 1 + .../GHSA-q2gh-hfh3-q82q.json | 3 +- .../GHSA-r633-28cw-p576.json | 3 +- .../GHSA-rc6f-wq75-jcqx.json | 2 +- .../GHSA-x536-qrvc-92xm.json | 2 +- .../GHSA-xj6f-mr2f-7c6m.json | 2 +- .../GHSA-3vm5-5963-pw52.json | 1 + .../GHSA-3xpq-vc4j-pfj2.json | 3 +- .../GHSA-6cjv-9fv8-4hx9.json | 1 + .../GHSA-6mg8-hg8j-x5mp.json | 1 + .../GHSA-75gw-fw7p-53r3.json | 2 +- .../GHSA-7p43-mhw4-pxh2.json | 2 +- .../GHSA-8882-q5f7-v9h8.json | 1 + .../GHSA-9p33-fhfv-86gg.json | 1 + .../GHSA-9pj9-m7vp-27hp.json | 3 +- .../GHSA-9qfg-vjxj-gjf3.json | 1 + .../GHSA-cxvw-76f5-px84.json | 1 + .../GHSA-gc7p-mvx7-rv54.json | 2 +- .../GHSA-hj4c-9fp7-4vrh.json | 2 +- .../GHSA-p46c-qgr8-xvh2.json | 2 +- .../GHSA-pgw3-2gjq-fhgr.json | 3 +- .../GHSA-q2vq-xj2q-g729.json | 2 +- .../GHSA-q34h-jjh9-ggfh.json | 2 +- .../GHSA-qq7m-q225-9v82.json | 1 + .../GHSA-x4vh-ch66-jvcq.json | 1 + .../GHSA-x89p-6rqm-64cc.json | 2 +- .../GHSA-xq75-p9cv-wvw7.json | 3 +- .../GHSA-xvfh-vpm8-j2fh.json | 1 + .../GHSA-2q8v-r2xr-c9xc.json | 1 + .../GHSA-3299-66vv-h629.json | 1 + .../GHSA-48vm-fq56-767f.json | 3 +- .../GHSA-68vj-vr49-ppvw.json | 1 + .../GHSA-6pgv-mjmc-g3jw.json | 3 +- .../GHSA-7fw8-gr6f-mrc3.json | 1 + .../GHSA-fhmx-cqxp-j8f6.json | 1 + .../GHSA-fpw4-7h2w-2x94.json | 3 +- .../GHSA-h36p-v4x7-w44w.json | 3 +- .../GHSA-jvvx-6w65-rj24.json | 1 + .../GHSA-mp7j-cmhv-jxm4.json | 3 +- .../GHSA-pj8h-cmgw-7xpg.json | 3 +- .../GHSA-r2r8-fq65-h82j.json | 1 + .../GHSA-rh2q-252v-ccqc.json | 3 +- .../GHSA-rw95-68xg-rf7m.json | 3 +- .../GHSA-x563-8qf7-q64m.json | 3 +- .../GHSA-x56w-m67j-6hmr.json | 3 +- .../GHSA-25rm-72cp-x5mm.json | 1 + .../GHSA-4q33-wj3r-p79q.json | 3 +- .../GHSA-9fw6-m2v2-f3rp.json | 1 + .../GHSA-c44g-2jv9-3436.json | 2 +- .../GHSA-cv8x-5cww-p4pf.json | 3 +- .../GHSA-cxcm-vgv2-mq4g.json | 2 +- .../GHSA-q9h6-c2ff-prcp.json | 1 + .../GHSA-rh7v-fmqc-c7rj.json | 1 + .../GHSA-vgh7-9mhq-v768.json | 2 +- .../GHSA-vw9c-c8qf-hw7g.json | 3 +- .../GHSA-wxqg-47fv-wf96.json | 3 +- .../GHSA-292c-8vv7-pg3v.json | 3 +- .../GHSA-3wh9-2fg7-9h5g.json | 3 +- .../GHSA-3xhr-vwcx-8p3c.json | 3 +- .../GHSA-52vv-5jc5-5gmv.json | 3 +- .../GHSA-997r-3g6v-ph4j.json | 1 + .../GHSA-9w2r-p3qj-g3gm.json | 3 +- .../GHSA-cffx-cf3x-mr9h.json | 2 +- .../GHSA-fv23-fj7r-w7w4.json | 1 + .../GHSA-g9xq-vwmw-hprm.json | 3 +- .../GHSA-h234-9whq-hx7f.json | 3 +- .../GHSA-hqm8-gpp6-j34p.json | 3 +- .../GHSA-pg26-49x3-7h59.json | 3 +- .../GHSA-pp44-pghv-3r5p.json | 3 +- .../GHSA-wfj3-hjp7-62gf.json | 3 +- .../GHSA-3cpf-72w5-65j4.json | 42 ++++++++++++++++ .../GHSA-46mj-7xpv-pprw.json | 42 ++++++++++++++++ .../GHSA-52fw-vg2v-rc9p.json | 38 ++++++++++++++ .../GHSA-6w72-x59c-h2c9.json | 42 ++++++++++++++++ .../GHSA-75rx-c73c-98q9.json | 42 ++++++++++++++++ .../GHSA-76fc-hwwm-wmhg.json | 42 ++++++++++++++++ .../GHSA-83pq-frch-8xf2.json | 42 ++++++++++++++++ .../GHSA-85x4-mgg9-rmg6.json | 50 +++++++++++++++++++ .../GHSA-8vc5-fgcg-4vh9.json | 42 ++++++++++++++++ .../GHSA-fwcw-wmg8-r4vq.json | 42 ++++++++++++++++ .../GHSA-gfmf-6ghh-gjwr.json | 42 ++++++++++++++++ .../GHSA-h843-jc82-h6jf.json | 42 ++++++++++++++++ .../GHSA-hcvj-cm7m-2774.json | 50 +++++++++++++++++++ .../GHSA-hvcg-7mfp-56mm.json | 50 +++++++++++++++++++ .../GHSA-hxmw-j74g-j23w.json | 42 ++++++++++++++++ .../GHSA-jjxw-r7pq-27g5.json | 50 +++++++++++++++++++ .../GHSA-jqhc-3v3m-gjx4.json | 42 ++++++++++++++++ .../GHSA-pqmg-f829-g3ww.json | 42 ++++++++++++++++ .../GHSA-qgwf-2fx2-cv5v.json | 50 +++++++++++++++++++ .../GHSA-qmmh-x7m4-pr56.json | 42 ++++++++++++++++ .../GHSA-r4g7-rp4j-9cv7.json | 42 ++++++++++++++++ .../GHSA-vpfm-675m-rfm8.json | 42 ++++++++++++++++ .../GHSA-vqqg-v6v5-gm7x.json | 38 ++++++++++++++ .../GHSA-w8g8-33g5-c7m6.json | 38 ++++++++++++++ .../GHSA-x2p9-2jc3-8gpp.json | 38 ++++++++++++++ .../GHSA-x368-w88j-3c3r.json | 42 ++++++++++++++++ .../GHSA-x3m5-7cpw-xq9j.json | 42 ++++++++++++++++ 132 files changed, 1303 insertions(+), 60 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-3cpf-72w5-65j4/GHSA-3cpf-72w5-65j4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-46mj-7xpv-pprw/GHSA-46mj-7xpv-pprw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-52fw-vg2v-rc9p/GHSA-52fw-vg2v-rc9p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6w72-x59c-h2c9/GHSA-6w72-x59c-h2c9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-75rx-c73c-98q9/GHSA-75rx-c73c-98q9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-76fc-hwwm-wmhg/GHSA-76fc-hwwm-wmhg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-83pq-frch-8xf2/GHSA-83pq-frch-8xf2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-85x4-mgg9-rmg6/GHSA-85x4-mgg9-rmg6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8vc5-fgcg-4vh9/GHSA-8vc5-fgcg-4vh9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fwcw-wmg8-r4vq/GHSA-fwcw-wmg8-r4vq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gfmf-6ghh-gjwr/GHSA-gfmf-6ghh-gjwr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h843-jc82-h6jf/GHSA-h843-jc82-h6jf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hcvj-cm7m-2774/GHSA-hcvj-cm7m-2774.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hvcg-7mfp-56mm/GHSA-hvcg-7mfp-56mm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hxmw-j74g-j23w/GHSA-hxmw-j74g-j23w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jjxw-r7pq-27g5/GHSA-jjxw-r7pq-27g5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jqhc-3v3m-gjx4/GHSA-jqhc-3v3m-gjx4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pqmg-f829-g3ww/GHSA-pqmg-f829-g3ww.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qgwf-2fx2-cv5v/GHSA-qgwf-2fx2-cv5v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qmmh-x7m4-pr56/GHSA-qmmh-x7m4-pr56.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r4g7-rp4j-9cv7/GHSA-r4g7-rp4j-9cv7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vqqg-v6v5-gm7x/GHSA-vqqg-v6v5-gm7x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w8g8-33g5-c7m6/GHSA-w8g8-33g5-c7m6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x368-w88j-3c3r/GHSA-x368-w88j-3c3r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x3m5-7cpw-xq9j/GHSA-x3m5-7cpw-xq9j.json diff --git a/advisories/unreviewed/2023/08/GHSA-32rf-9mpv-rfcv/GHSA-32rf-9mpv-rfcv.json b/advisories/unreviewed/2023/08/GHSA-32rf-9mpv-rfcv/GHSA-32rf-9mpv-rfcv.json index 2aad6e97813..a9675b661c3 100644 --- a/advisories/unreviewed/2023/08/GHSA-32rf-9mpv-rfcv/GHSA-32rf-9mpv-rfcv.json +++ b/advisories/unreviewed/2023/08/GHSA-32rf-9mpv-rfcv/GHSA-32rf-9mpv-rfcv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-823", "CWE-843" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-4fmh-mf22-vcrx/GHSA-4fmh-mf22-vcrx.json b/advisories/unreviewed/2023/08/GHSA-4fmh-mf22-vcrx/GHSA-4fmh-mf22-vcrx.json index e15e62cba5e..6e1cda2ecb5 100644 --- a/advisories/unreviewed/2023/08/GHSA-4fmh-mf22-vcrx/GHSA-4fmh-mf22-vcrx.json +++ b/advisories/unreviewed/2023/08/GHSA-4fmh-mf22-vcrx/GHSA-4fmh-mf22-vcrx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-hwh2-grqv-74jx/GHSA-hwh2-grqv-74jx.json b/advisories/unreviewed/2023/08/GHSA-hwh2-grqv-74jx/GHSA-hwh2-grqv-74jx.json index 2c7c849cbbe..fff62406b0e 100644 --- a/advisories/unreviewed/2023/08/GHSA-hwh2-grqv-74jx/GHSA-hwh2-grqv-74jx.json +++ b/advisories/unreviewed/2023/08/GHSA-hwh2-grqv-74jx/GHSA-hwh2-grqv-74jx.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-jmmv-6pvw-x59r/GHSA-jmmv-6pvw-x59r.json b/advisories/unreviewed/2023/08/GHSA-jmmv-6pvw-x59r/GHSA-jmmv-6pvw-x59r.json index f956c5a72e6..6e992ccad8f 100644 --- a/advisories/unreviewed/2023/08/GHSA-jmmv-6pvw-x59r/GHSA-jmmv-6pvw-x59r.json +++ b/advisories/unreviewed/2023/08/GHSA-jmmv-6pvw-x59r/GHSA-jmmv-6pvw-x59r.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-vw4p-3wx5-4j4r/GHSA-vw4p-3wx5-4j4r.json b/advisories/unreviewed/2023/08/GHSA-vw4p-3wx5-4j4r/GHSA-vw4p-3wx5-4j4r.json index 6c50c050b75..09535d78a33 100644 --- a/advisories/unreviewed/2023/08/GHSA-vw4p-3wx5-4j4r/GHSA-vw4p-3wx5-4j4r.json +++ b/advisories/unreviewed/2023/08/GHSA-vw4p-3wx5-4j4r/GHSA-vw4p-3wx5-4j4r.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-27pg-f79j-mx3w/GHSA-27pg-f79j-mx3w.json b/advisories/unreviewed/2023/09/GHSA-27pg-f79j-mx3w/GHSA-27pg-f79j-mx3w.json index ac6d9b8e4ea..50cf1ab28d4 100644 --- a/advisories/unreviewed/2023/09/GHSA-27pg-f79j-mx3w/GHSA-27pg-f79j-mx3w.json +++ b/advisories/unreviewed/2023/09/GHSA-27pg-f79j-mx3w/GHSA-27pg-f79j-mx3w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-2fjf-h46q-8mfr/GHSA-2fjf-h46q-8mfr.json b/advisories/unreviewed/2023/09/GHSA-2fjf-h46q-8mfr/GHSA-2fjf-h46q-8mfr.json index 58ed20cd2aa..341f174b9d0 100644 --- a/advisories/unreviewed/2023/09/GHSA-2fjf-h46q-8mfr/GHSA-2fjf-h46q-8mfr.json +++ b/advisories/unreviewed/2023/09/GHSA-2fjf-h46q-8mfr/GHSA-2fjf-h46q-8mfr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-367p-mrph-mgh2/GHSA-367p-mrph-mgh2.json b/advisories/unreviewed/2023/09/GHSA-367p-mrph-mgh2/GHSA-367p-mrph-mgh2.json index 38b3aac82c7..d17a391762a 100644 --- a/advisories/unreviewed/2023/09/GHSA-367p-mrph-mgh2/GHSA-367p-mrph-mgh2.json +++ b/advisories/unreviewed/2023/09/GHSA-367p-mrph-mgh2/GHSA-367p-mrph-mgh2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-4vg5-hr2c-c4fq/GHSA-4vg5-hr2c-c4fq.json b/advisories/unreviewed/2023/09/GHSA-4vg5-hr2c-c4fq/GHSA-4vg5-hr2c-c4fq.json index 70145775d2d..bfb47f457b2 100644 --- a/advisories/unreviewed/2023/09/GHSA-4vg5-hr2c-c4fq/GHSA-4vg5-hr2c-c4fq.json +++ b/advisories/unreviewed/2023/09/GHSA-4vg5-hr2c-c4fq/GHSA-4vg5-hr2c-c4fq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-129", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-567r-j9fc-2696/GHSA-567r-j9fc-2696.json b/advisories/unreviewed/2023/09/GHSA-567r-j9fc-2696/GHSA-567r-j9fc-2696.json index 7dc18632fb8..88247e89032 100644 --- a/advisories/unreviewed/2023/09/GHSA-567r-j9fc-2696/GHSA-567r-j9fc-2696.json +++ b/advisories/unreviewed/2023/09/GHSA-567r-j9fc-2696/GHSA-567r-j9fc-2696.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-5796-pg6j-m9rr/GHSA-5796-pg6j-m9rr.json b/advisories/unreviewed/2023/09/GHSA-5796-pg6j-m9rr/GHSA-5796-pg6j-m9rr.json index c71743b64b7..aa344bd2a46 100644 --- a/advisories/unreviewed/2023/09/GHSA-5796-pg6j-m9rr/GHSA-5796-pg6j-m9rr.json +++ b/advisories/unreviewed/2023/09/GHSA-5796-pg6j-m9rr/GHSA-5796-pg6j-m9rr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-7xgm-mmjm-x822/GHSA-7xgm-mmjm-x822.json b/advisories/unreviewed/2023/09/GHSA-7xgm-mmjm-x822/GHSA-7xgm-mmjm-x822.json index 39c672e3c35..5af93170b93 100644 --- a/advisories/unreviewed/2023/09/GHSA-7xgm-mmjm-x822/GHSA-7xgm-mmjm-x822.json +++ b/advisories/unreviewed/2023/09/GHSA-7xgm-mmjm-x822/GHSA-7xgm-mmjm-x822.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-9pxw-85r8-pc8f/GHSA-9pxw-85r8-pc8f.json b/advisories/unreviewed/2023/09/GHSA-9pxw-85r8-pc8f/GHSA-9pxw-85r8-pc8f.json index e05a097de28..ce50e1647d9 100644 --- a/advisories/unreviewed/2023/09/GHSA-9pxw-85r8-pc8f/GHSA-9pxw-85r8-pc8f.json +++ b/advisories/unreviewed/2023/09/GHSA-9pxw-85r8-pc8f/GHSA-9pxw-85r8-pc8f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-9rjc-p324-p26x/GHSA-9rjc-p324-p26x.json b/advisories/unreviewed/2023/09/GHSA-9rjc-p324-p26x/GHSA-9rjc-p324-p26x.json index 2113b4a93e0..405255ddb97 100644 --- a/advisories/unreviewed/2023/09/GHSA-9rjc-p324-p26x/GHSA-9rjc-p324-p26x.json +++ b/advisories/unreviewed/2023/09/GHSA-9rjc-p324-p26x/GHSA-9rjc-p324-p26x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-cmgw-jmjc-q6wf/GHSA-cmgw-jmjc-q6wf.json b/advisories/unreviewed/2023/09/GHSA-cmgw-jmjc-q6wf/GHSA-cmgw-jmjc-q6wf.json index a570d097019..bc19c7ee11c 100644 --- a/advisories/unreviewed/2023/09/GHSA-cmgw-jmjc-q6wf/GHSA-cmgw-jmjc-q6wf.json +++ b/advisories/unreviewed/2023/09/GHSA-cmgw-jmjc-q6wf/GHSA-cmgw-jmjc-q6wf.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-cxvm-4f6m-6mjv/GHSA-cxvm-4f6m-6mjv.json b/advisories/unreviewed/2023/09/GHSA-cxvm-4f6m-6mjv/GHSA-cxvm-4f6m-6mjv.json index a6c028c4292..f2e816dd907 100644 --- a/advisories/unreviewed/2023/09/GHSA-cxvm-4f6m-6mjv/GHSA-cxvm-4f6m-6mjv.json +++ b/advisories/unreviewed/2023/09/GHSA-cxvm-4f6m-6mjv/GHSA-cxvm-4f6m-6mjv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-hrfm-pmc4-p9mw/GHSA-hrfm-pmc4-p9mw.json b/advisories/unreviewed/2023/09/GHSA-hrfm-pmc4-p9mw/GHSA-hrfm-pmc4-p9mw.json index 44225a66fee..6ea4183d7cb 100644 --- a/advisories/unreviewed/2023/09/GHSA-hrfm-pmc4-p9mw/GHSA-hrfm-pmc4-p9mw.json +++ b/advisories/unreviewed/2023/09/GHSA-hrfm-pmc4-p9mw/GHSA-hrfm-pmc4-p9mw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-129", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-j6qx-q96r-gvw3/GHSA-j6qx-q96r-gvw3.json b/advisories/unreviewed/2023/09/GHSA-j6qx-q96r-gvw3/GHSA-j6qx-q96r-gvw3.json index fc74b06844a..60ba07730aa 100644 --- a/advisories/unreviewed/2023/09/GHSA-j6qx-q96r-gvw3/GHSA-j6qx-q96r-gvw3.json +++ b/advisories/unreviewed/2023/09/GHSA-j6qx-q96r-gvw3/GHSA-j6qx-q96r-gvw3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-680" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-mq83-6jqr-c293/GHSA-mq83-6jqr-c293.json b/advisories/unreviewed/2023/09/GHSA-mq83-6jqr-c293/GHSA-mq83-6jqr-c293.json index c29c853dbac..51d54ba8aee 100644 --- a/advisories/unreviewed/2023/09/GHSA-mq83-6jqr-c293/GHSA-mq83-6jqr-c293.json +++ b/advisories/unreviewed/2023/09/GHSA-mq83-6jqr-c293/GHSA-mq83-6jqr-c293.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-p54g-g6xw-2jm9/GHSA-p54g-g6xw-2jm9.json b/advisories/unreviewed/2023/09/GHSA-p54g-g6xw-2jm9/GHSA-p54g-g6xw-2jm9.json index 5297d7c07e8..81bbc50d042 100644 --- a/advisories/unreviewed/2023/09/GHSA-p54g-g6xw-2jm9/GHSA-p54g-g6xw-2jm9.json +++ b/advisories/unreviewed/2023/09/GHSA-p54g-g6xw-2jm9/GHSA-p54g-g6xw-2jm9.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-pw8j-xxwv-qpr8/GHSA-pw8j-xxwv-qpr8.json b/advisories/unreviewed/2023/09/GHSA-pw8j-xxwv-qpr8/GHSA-pw8j-xxwv-qpr8.json index 51aacf7cd06..2414d94dae5 100644 --- a/advisories/unreviewed/2023/09/GHSA-pw8j-xxwv-qpr8/GHSA-pw8j-xxwv-qpr8.json +++ b/advisories/unreviewed/2023/09/GHSA-pw8j-xxwv-qpr8/GHSA-pw8j-xxwv-qpr8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-qxqc-qj6p-cwjv/GHSA-qxqc-qj6p-cwjv.json b/advisories/unreviewed/2023/09/GHSA-qxqc-qj6p-cwjv/GHSA-qxqc-qj6p-cwjv.json index 6e112d53a50..7b220595b2e 100644 --- a/advisories/unreviewed/2023/09/GHSA-qxqc-qj6p-cwjv/GHSA-qxqc-qj6p-cwjv.json +++ b/advisories/unreviewed/2023/09/GHSA-qxqc-qj6p-cwjv/GHSA-qxqc-qj6p-cwjv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-129", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-rf7x-m444-39m4/GHSA-rf7x-m444-39m4.json b/advisories/unreviewed/2023/09/GHSA-rf7x-m444-39m4/GHSA-rf7x-m444-39m4.json index 9c7e41c1a60..f6e055a8cae 100644 --- a/advisories/unreviewed/2023/09/GHSA-rf7x-m444-39m4/GHSA-rf7x-m444-39m4.json +++ b/advisories/unreviewed/2023/09/GHSA-rf7x-m444-39m4/GHSA-rf7x-m444-39m4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-w7wm-wchq-gc2x/GHSA-w7wm-wchq-gc2x.json b/advisories/unreviewed/2023/09/GHSA-w7wm-wchq-gc2x/GHSA-w7wm-wchq-gc2x.json index df6624c690b..c47b5fb5e91 100644 --- a/advisories/unreviewed/2023/09/GHSA-w7wm-wchq-gc2x/GHSA-w7wm-wchq-gc2x.json +++ b/advisories/unreviewed/2023/09/GHSA-w7wm-wchq-gc2x/GHSA-w7wm-wchq-gc2x.json @@ -29,6 +29,7 @@ "database_specific": { "cwe_ids": [ "CWE-119", + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-wjq7-rmcv-8f9w/GHSA-wjq7-rmcv-8f9w.json b/advisories/unreviewed/2023/09/GHSA-wjq7-rmcv-8f9w/GHSA-wjq7-rmcv-8f9w.json index e03b930af19..8305a6900ac 100644 --- a/advisories/unreviewed/2023/09/GHSA-wjq7-rmcv-8f9w/GHSA-wjq7-rmcv-8f9w.json +++ b/advisories/unreviewed/2023/09/GHSA-wjq7-rmcv-8f9w/GHSA-wjq7-rmcv-8f9w.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-x92g-cprm-m7v4/GHSA-x92g-cprm-m7v4.json b/advisories/unreviewed/2023/09/GHSA-x92g-cprm-m7v4/GHSA-x92g-cprm-m7v4.json index 1ca4e927c59..9ef60bd9e88 100644 --- a/advisories/unreviewed/2023/09/GHSA-x92g-cprm-m7v4/GHSA-x92g-cprm-m7v4.json +++ b/advisories/unreviewed/2023/09/GHSA-x92g-cprm-m7v4/GHSA-x92g-cprm-m7v4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-129", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-xxr7-cchg-fr5v/GHSA-xxr7-cchg-fr5v.json b/advisories/unreviewed/2023/09/GHSA-xxr7-cchg-fr5v/GHSA-xxr7-cchg-fr5v.json index 5586542ab1c..635cef27293 100644 --- a/advisories/unreviewed/2023/09/GHSA-xxr7-cchg-fr5v/GHSA-xxr7-cchg-fr5v.json +++ b/advisories/unreviewed/2023/09/GHSA-xxr7-cchg-fr5v/GHSA-xxr7-cchg-fr5v.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/10/GHSA-426p-74fr-m2wx/GHSA-426p-74fr-m2wx.json b/advisories/unreviewed/2023/10/GHSA-426p-74fr-m2wx/GHSA-426p-74fr-m2wx.json index 89cc7e95698..0fd22e88548 100644 --- a/advisories/unreviewed/2023/10/GHSA-426p-74fr-m2wx/GHSA-426p-74fr-m2wx.json +++ b/advisories/unreviewed/2023/10/GHSA-426p-74fr-m2wx/GHSA-426p-74fr-m2wx.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/10/GHSA-4vv2-435c-33ch/GHSA-4vv2-435c-33ch.json b/advisories/unreviewed/2023/10/GHSA-4vv2-435c-33ch/GHSA-4vv2-435c-33ch.json index 65a6e02030d..50dba5e81a4 100644 --- a/advisories/unreviewed/2023/10/GHSA-4vv2-435c-33ch/GHSA-4vv2-435c-33ch.json +++ b/advisories/unreviewed/2023/10/GHSA-4vv2-435c-33ch/GHSA-4vv2-435c-33ch.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-126", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/10/GHSA-h89f-5h94-vmj5/GHSA-h89f-5h94-vmj5.json b/advisories/unreviewed/2023/10/GHSA-h89f-5h94-vmj5/GHSA-h89f-5h94-vmj5.json index 0ec28f33794..67166384414 100644 --- a/advisories/unreviewed/2023/10/GHSA-h89f-5h94-vmj5/GHSA-h89f-5h94-vmj5.json +++ b/advisories/unreviewed/2023/10/GHSA-h89f-5h94-vmj5/GHSA-h89f-5h94-vmj5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-126", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-hxqc-xv34-842x/GHSA-hxqc-xv34-842x.json b/advisories/unreviewed/2023/10/GHSA-hxqc-xv34-842x/GHSA-hxqc-xv34-842x.json index c907a551ad0..b72b975adc7 100644 --- a/advisories/unreviewed/2023/10/GHSA-hxqc-xv34-842x/GHSA-hxqc-xv34-842x.json +++ b/advisories/unreviewed/2023/10/GHSA-hxqc-xv34-842x/GHSA-hxqc-xv34-842x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-jjvv-vqpp-vvhm/GHSA-jjvv-vqpp-vvhm.json b/advisories/unreviewed/2023/10/GHSA-jjvv-vqpp-vvhm/GHSA-jjvv-vqpp-vvhm.json index f9a0aa0dcc4..6cec49dcd65 100644 --- a/advisories/unreviewed/2023/10/GHSA-jjvv-vqpp-vvhm/GHSA-jjvv-vqpp-vvhm.json +++ b/advisories/unreviewed/2023/10/GHSA-jjvv-vqpp-vvhm/GHSA-jjvv-vqpp-vvhm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-m57v-fhqq-h74x/GHSA-m57v-fhqq-h74x.json b/advisories/unreviewed/2023/10/GHSA-m57v-fhqq-h74x/GHSA-m57v-fhqq-h74x.json index 41a8684fd51..237d4e33351 100644 --- a/advisories/unreviewed/2023/10/GHSA-m57v-fhqq-h74x/GHSA-m57v-fhqq-h74x.json +++ b/advisories/unreviewed/2023/10/GHSA-m57v-fhqq-h74x/GHSA-m57v-fhqq-h74x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-mgcq-32pv-mr2j/GHSA-mgcq-32pv-mr2j.json b/advisories/unreviewed/2023/10/GHSA-mgcq-32pv-mr2j/GHSA-mgcq-32pv-mr2j.json index ff64fd4ad1c..49e1f7751fc 100644 --- a/advisories/unreviewed/2023/10/GHSA-mgcq-32pv-mr2j/GHSA-mgcq-32pv-mr2j.json +++ b/advisories/unreviewed/2023/10/GHSA-mgcq-32pv-mr2j/GHSA-mgcq-32pv-mr2j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-p5pp-ppfp-mrrh/GHSA-p5pp-ppfp-mrrh.json b/advisories/unreviewed/2023/10/GHSA-p5pp-ppfp-mrrh/GHSA-p5pp-ppfp-mrrh.json index 3a8ab56c577..50370b0d7bd 100644 --- a/advisories/unreviewed/2023/10/GHSA-p5pp-ppfp-mrrh/GHSA-p5pp-ppfp-mrrh.json +++ b/advisories/unreviewed/2023/10/GHSA-p5pp-ppfp-mrrh/GHSA-p5pp-ppfp-mrrh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-195", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-pqg5-9528-cm52/GHSA-pqg5-9528-cm52.json b/advisories/unreviewed/2023/10/GHSA-pqg5-9528-cm52/GHSA-pqg5-9528-cm52.json index 00c0d3a588e..421361fd4ec 100644 --- a/advisories/unreviewed/2023/10/GHSA-pqg5-9528-cm52/GHSA-pqg5-9528-cm52.json +++ b/advisories/unreviewed/2023/10/GHSA-pqg5-9528-cm52/GHSA-pqg5-9528-cm52.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-q2gh-hfh3-q82q/GHSA-q2gh-hfh3-q82q.json b/advisories/unreviewed/2023/10/GHSA-q2gh-hfh3-q82q/GHSA-q2gh-hfh3-q82q.json index 2dd6e78b97a..1bf42a6c768 100644 --- a/advisories/unreviewed/2023/10/GHSA-q2gh-hfh3-q82q/GHSA-q2gh-hfh3-q82q.json +++ b/advisories/unreviewed/2023/10/GHSA-q2gh-hfh3-q82q/GHSA-q2gh-hfh3-q82q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-r633-28cw-p576/GHSA-r633-28cw-p576.json b/advisories/unreviewed/2023/10/GHSA-r633-28cw-p576/GHSA-r633-28cw-p576.json index 8bd3c45f6fc..185e75d8550 100644 --- a/advisories/unreviewed/2023/10/GHSA-r633-28cw-p576/GHSA-r633-28cw-p576.json +++ b/advisories/unreviewed/2023/10/GHSA-r633-28cw-p576/GHSA-r633-28cw-p576.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-rc6f-wq75-jcqx/GHSA-rc6f-wq75-jcqx.json b/advisories/unreviewed/2023/10/GHSA-rc6f-wq75-jcqx/GHSA-rc6f-wq75-jcqx.json index 3802f574d4e..62c5ec1925b 100644 --- a/advisories/unreviewed/2023/10/GHSA-rc6f-wq75-jcqx/GHSA-rc6f-wq75-jcqx.json +++ b/advisories/unreviewed/2023/10/GHSA-rc6f-wq75-jcqx/GHSA-rc6f-wq75-jcqx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-x536-qrvc-92xm/GHSA-x536-qrvc-92xm.json b/advisories/unreviewed/2023/10/GHSA-x536-qrvc-92xm/GHSA-x536-qrvc-92xm.json index b4cf7f7aa38..1b245834bb8 100644 --- a/advisories/unreviewed/2023/10/GHSA-x536-qrvc-92xm/GHSA-x536-qrvc-92xm.json +++ b/advisories/unreviewed/2023/10/GHSA-x536-qrvc-92xm/GHSA-x536-qrvc-92xm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-xj6f-mr2f-7c6m/GHSA-xj6f-mr2f-7c6m.json b/advisories/unreviewed/2023/10/GHSA-xj6f-mr2f-7c6m/GHSA-xj6f-mr2f-7c6m.json index 69a4ca8108f..995c35e242f 100644 --- a/advisories/unreviewed/2023/10/GHSA-xj6f-mr2f-7c6m/GHSA-xj6f-mr2f-7c6m.json +++ b/advisories/unreviewed/2023/10/GHSA-xj6f-mr2f-7c6m/GHSA-xj6f-mr2f-7c6m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json b/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json index db2f462ba78..f92b11c5374 100644 --- a/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json +++ b/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json b/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json index 435b8b26405..f9f44c38629 100644 --- a/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json +++ b/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-6cjv-9fv8-4hx9/GHSA-6cjv-9fv8-4hx9.json b/advisories/unreviewed/2023/11/GHSA-6cjv-9fv8-4hx9/GHSA-6cjv-9fv8-4hx9.json index 30da2ffe2b4..ac577e4cdbc 100644 --- a/advisories/unreviewed/2023/11/GHSA-6cjv-9fv8-4hx9/GHSA-6cjv-9fv8-4hx9.json +++ b/advisories/unreviewed/2023/11/GHSA-6cjv-9fv8-4hx9/GHSA-6cjv-9fv8-4hx9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-6mg8-hg8j-x5mp/GHSA-6mg8-hg8j-x5mp.json b/advisories/unreviewed/2023/11/GHSA-6mg8-hg8j-x5mp/GHSA-6mg8-hg8j-x5mp.json index 9c0cc28c428..b1615234b04 100644 --- a/advisories/unreviewed/2023/11/GHSA-6mg8-hg8j-x5mp/GHSA-6mg8-hg8j-x5mp.json +++ b/advisories/unreviewed/2023/11/GHSA-6mg8-hg8j-x5mp/GHSA-6mg8-hg8j-x5mp.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-75gw-fw7p-53r3/GHSA-75gw-fw7p-53r3.json b/advisories/unreviewed/2023/11/GHSA-75gw-fw7p-53r3/GHSA-75gw-fw7p-53r3.json index efb3ffa4c36..beb725b0f1f 100644 --- a/advisories/unreviewed/2023/11/GHSA-75gw-fw7p-53r3/GHSA-75gw-fw7p-53r3.json +++ b/advisories/unreviewed/2023/11/GHSA-75gw-fw7p-53r3/GHSA-75gw-fw7p-53r3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-7p43-mhw4-pxh2/GHSA-7p43-mhw4-pxh2.json b/advisories/unreviewed/2023/11/GHSA-7p43-mhw4-pxh2/GHSA-7p43-mhw4-pxh2.json index e4699974564..307a0dece9f 100644 --- a/advisories/unreviewed/2023/11/GHSA-7p43-mhw4-pxh2/GHSA-7p43-mhw4-pxh2.json +++ b/advisories/unreviewed/2023/11/GHSA-7p43-mhw4-pxh2/GHSA-7p43-mhw4-pxh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json b/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json index e2943ee5d8c..faf75f9be02 100644 --- a/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json +++ b/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json b/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json index 4c4832d8a76..27e694c13ff 100644 --- a/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json +++ b/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json b/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json index 19efcfed8e8..fa57a3e724c 100644 --- a/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json +++ b/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json b/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json index 5a95dc73f65..1b08de31f4c 100644 --- a/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json +++ b/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-191", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json b/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json index 58f3c551676..5f40a28c7a8 100644 --- a/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json +++ b/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-gc7p-mvx7-rv54/GHSA-gc7p-mvx7-rv54.json b/advisories/unreviewed/2023/11/GHSA-gc7p-mvx7-rv54/GHSA-gc7p-mvx7-rv54.json index e2e4e1f906e..4750ff3aabb 100644 --- a/advisories/unreviewed/2023/11/GHSA-gc7p-mvx7-rv54/GHSA-gc7p-mvx7-rv54.json +++ b/advisories/unreviewed/2023/11/GHSA-gc7p-mvx7-rv54/GHSA-gc7p-mvx7-rv54.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-hj4c-9fp7-4vrh/GHSA-hj4c-9fp7-4vrh.json b/advisories/unreviewed/2023/11/GHSA-hj4c-9fp7-4vrh/GHSA-hj4c-9fp7-4vrh.json index e1906746da1..8e369c773f1 100644 --- a/advisories/unreviewed/2023/11/GHSA-hj4c-9fp7-4vrh/GHSA-hj4c-9fp7-4vrh.json +++ b/advisories/unreviewed/2023/11/GHSA-hj4c-9fp7-4vrh/GHSA-hj4c-9fp7-4vrh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-p46c-qgr8-xvh2/GHSA-p46c-qgr8-xvh2.json b/advisories/unreviewed/2023/11/GHSA-p46c-qgr8-xvh2/GHSA-p46c-qgr8-xvh2.json index fb7e3f46243..5d0ebab731e 100644 --- a/advisories/unreviewed/2023/11/GHSA-p46c-qgr8-xvh2/GHSA-p46c-qgr8-xvh2.json +++ b/advisories/unreviewed/2023/11/GHSA-p46c-qgr8-xvh2/GHSA-p46c-qgr8-xvh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-pgw3-2gjq-fhgr/GHSA-pgw3-2gjq-fhgr.json b/advisories/unreviewed/2023/11/GHSA-pgw3-2gjq-fhgr/GHSA-pgw3-2gjq-fhgr.json index 5baf34eac78..8fc3c5b6b95 100644 --- a/advisories/unreviewed/2023/11/GHSA-pgw3-2gjq-fhgr/GHSA-pgw3-2gjq-fhgr.json +++ b/advisories/unreviewed/2023/11/GHSA-pgw3-2gjq-fhgr/GHSA-pgw3-2gjq-fhgr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json b/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json index b97d65c85d8..a844b5d34b2 100644 --- a/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json +++ b/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-q34h-jjh9-ggfh/GHSA-q34h-jjh9-ggfh.json b/advisories/unreviewed/2023/11/GHSA-q34h-jjh9-ggfh/GHSA-q34h-jjh9-ggfh.json index b8e6b159a57..e8aae4d525c 100644 --- a/advisories/unreviewed/2023/11/GHSA-q34h-jjh9-ggfh/GHSA-q34h-jjh9-ggfh.json +++ b/advisories/unreviewed/2023/11/GHSA-q34h-jjh9-ggfh/GHSA-q34h-jjh9-ggfh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json b/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json index 26f2256186e..487bc5c1696 100644 --- a/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json +++ b/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-126", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json b/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json index 19d6ae68b1e..9c0cf534238 100644 --- a/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json +++ b/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-x89p-6rqm-64cc/GHSA-x89p-6rqm-64cc.json b/advisories/unreviewed/2023/11/GHSA-x89p-6rqm-64cc/GHSA-x89p-6rqm-64cc.json index c4eb5384a5c..2264da09d78 100644 --- a/advisories/unreviewed/2023/11/GHSA-x89p-6rqm-64cc/GHSA-x89p-6rqm-64cc.json +++ b/advisories/unreviewed/2023/11/GHSA-x89p-6rqm-64cc/GHSA-x89p-6rqm-64cc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json b/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json index c98e6136482..ba527928b6f 100644 --- a/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json +++ b/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json b/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json index 96d32deb93d..cc0aec92932 100644 --- a/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json +++ b/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-2q8v-r2xr-c9xc/GHSA-2q8v-r2xr-c9xc.json b/advisories/unreviewed/2023/12/GHSA-2q8v-r2xr-c9xc/GHSA-2q8v-r2xr-c9xc.json index ccd69c65a2f..03e050e1042 100644 --- a/advisories/unreviewed/2023/12/GHSA-2q8v-r2xr-c9xc/GHSA-2q8v-r2xr-c9xc.json +++ b/advisories/unreviewed/2023/12/GHSA-2q8v-r2xr-c9xc/GHSA-2q8v-r2xr-c9xc.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-3299-66vv-h629/GHSA-3299-66vv-h629.json b/advisories/unreviewed/2023/12/GHSA-3299-66vv-h629/GHSA-3299-66vv-h629.json index ba313d0f6b3..cf5966d72f0 100644 --- a/advisories/unreviewed/2023/12/GHSA-3299-66vv-h629/GHSA-3299-66vv-h629.json +++ b/advisories/unreviewed/2023/12/GHSA-3299-66vv-h629/GHSA-3299-66vv-h629.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-48vm-fq56-767f/GHSA-48vm-fq56-767f.json b/advisories/unreviewed/2023/12/GHSA-48vm-fq56-767f/GHSA-48vm-fq56-767f.json index b6191621ad5..1b806a10c76 100644 --- a/advisories/unreviewed/2023/12/GHSA-48vm-fq56-767f/GHSA-48vm-fq56-767f.json +++ b/advisories/unreviewed/2023/12/GHSA-48vm-fq56-767f/GHSA-48vm-fq56-767f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-680" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-68vj-vr49-ppvw/GHSA-68vj-vr49-ppvw.json b/advisories/unreviewed/2023/12/GHSA-68vj-vr49-ppvw/GHSA-68vj-vr49-ppvw.json index 1dae1b73cbc..6b2533e05f8 100644 --- a/advisories/unreviewed/2023/12/GHSA-68vj-vr49-ppvw/GHSA-68vj-vr49-ppvw.json +++ b/advisories/unreviewed/2023/12/GHSA-68vj-vr49-ppvw/GHSA-68vj-vr49-ppvw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-6pgv-mjmc-g3jw/GHSA-6pgv-mjmc-g3jw.json b/advisories/unreviewed/2023/12/GHSA-6pgv-mjmc-g3jw/GHSA-6pgv-mjmc-g3jw.json index 8e20f1648b9..7455c526dc7 100644 --- a/advisories/unreviewed/2023/12/GHSA-6pgv-mjmc-g3jw/GHSA-6pgv-mjmc-g3jw.json +++ b/advisories/unreviewed/2023/12/GHSA-6pgv-mjmc-g3jw/GHSA-6pgv-mjmc-g3jw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-7fw8-gr6f-mrc3/GHSA-7fw8-gr6f-mrc3.json b/advisories/unreviewed/2023/12/GHSA-7fw8-gr6f-mrc3/GHSA-7fw8-gr6f-mrc3.json index 257da1819ea..8968267d130 100644 --- a/advisories/unreviewed/2023/12/GHSA-7fw8-gr6f-mrc3/GHSA-7fw8-gr6f-mrc3.json +++ b/advisories/unreviewed/2023/12/GHSA-7fw8-gr6f-mrc3/GHSA-7fw8-gr6f-mrc3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-fhmx-cqxp-j8f6/GHSA-fhmx-cqxp-j8f6.json b/advisories/unreviewed/2023/12/GHSA-fhmx-cqxp-j8f6/GHSA-fhmx-cqxp-j8f6.json index 8cbe30ffdce..2a8b5c96bda 100644 --- a/advisories/unreviewed/2023/12/GHSA-fhmx-cqxp-j8f6/GHSA-fhmx-cqxp-j8f6.json +++ b/advisories/unreviewed/2023/12/GHSA-fhmx-cqxp-j8f6/GHSA-fhmx-cqxp-j8f6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-fpw4-7h2w-2x94/GHSA-fpw4-7h2w-2x94.json b/advisories/unreviewed/2023/12/GHSA-fpw4-7h2w-2x94/GHSA-fpw4-7h2w-2x94.json index e57efc7e8e0..32a9d12880e 100644 --- a/advisories/unreviewed/2023/12/GHSA-fpw4-7h2w-2x94/GHSA-fpw4-7h2w-2x94.json +++ b/advisories/unreviewed/2023/12/GHSA-fpw4-7h2w-2x94/GHSA-fpw4-7h2w-2x94.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-h36p-v4x7-w44w/GHSA-h36p-v4x7-w44w.json b/advisories/unreviewed/2023/12/GHSA-h36p-v4x7-w44w/GHSA-h36p-v4x7-w44w.json index 655e645fe52..e0994d5665a 100644 --- a/advisories/unreviewed/2023/12/GHSA-h36p-v4x7-w44w/GHSA-h36p-v4x7-w44w.json +++ b/advisories/unreviewed/2023/12/GHSA-h36p-v4x7-w44w/GHSA-h36p-v4x7-w44w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-jvvx-6w65-rj24/GHSA-jvvx-6w65-rj24.json b/advisories/unreviewed/2023/12/GHSA-jvvx-6w65-rj24/GHSA-jvvx-6w65-rj24.json index 82234b45a20..ef04d0cda74 100644 --- a/advisories/unreviewed/2023/12/GHSA-jvvx-6w65-rj24/GHSA-jvvx-6w65-rj24.json +++ b/advisories/unreviewed/2023/12/GHSA-jvvx-6w65-rj24/GHSA-jvvx-6w65-rj24.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-mp7j-cmhv-jxm4/GHSA-mp7j-cmhv-jxm4.json b/advisories/unreviewed/2023/12/GHSA-mp7j-cmhv-jxm4/GHSA-mp7j-cmhv-jxm4.json index ce5c509136b..625894fe9df 100644 --- a/advisories/unreviewed/2023/12/GHSA-mp7j-cmhv-jxm4/GHSA-mp7j-cmhv-jxm4.json +++ b/advisories/unreviewed/2023/12/GHSA-mp7j-cmhv-jxm4/GHSA-mp7j-cmhv-jxm4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-pj8h-cmgw-7xpg/GHSA-pj8h-cmgw-7xpg.json b/advisories/unreviewed/2023/12/GHSA-pj8h-cmgw-7xpg/GHSA-pj8h-cmgw-7xpg.json index 68a38ce6dd9..a905fb022c5 100644 --- a/advisories/unreviewed/2023/12/GHSA-pj8h-cmgw-7xpg/GHSA-pj8h-cmgw-7xpg.json +++ b/advisories/unreviewed/2023/12/GHSA-pj8h-cmgw-7xpg/GHSA-pj8h-cmgw-7xpg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-r2r8-fq65-h82j/GHSA-r2r8-fq65-h82j.json b/advisories/unreviewed/2023/12/GHSA-r2r8-fq65-h82j/GHSA-r2r8-fq65-h82j.json index eed509d8541..33bf7807f19 100644 --- a/advisories/unreviewed/2023/12/GHSA-r2r8-fq65-h82j/GHSA-r2r8-fq65-h82j.json +++ b/advisories/unreviewed/2023/12/GHSA-r2r8-fq65-h82j/GHSA-r2r8-fq65-h82j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-rh2q-252v-ccqc/GHSA-rh2q-252v-ccqc.json b/advisories/unreviewed/2023/12/GHSA-rh2q-252v-ccqc/GHSA-rh2q-252v-ccqc.json index 35e1eb2cd81..84fa6994757 100644 --- a/advisories/unreviewed/2023/12/GHSA-rh2q-252v-ccqc/GHSA-rh2q-252v-ccqc.json +++ b/advisories/unreviewed/2023/12/GHSA-rh2q-252v-ccqc/GHSA-rh2q-252v-ccqc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rw95-68xg-rf7m/GHSA-rw95-68xg-rf7m.json b/advisories/unreviewed/2023/12/GHSA-rw95-68xg-rf7m/GHSA-rw95-68xg-rf7m.json index 62161dbaea9..2fb3782634e 100644 --- a/advisories/unreviewed/2023/12/GHSA-rw95-68xg-rf7m/GHSA-rw95-68xg-rf7m.json +++ b/advisories/unreviewed/2023/12/GHSA-rw95-68xg-rf7m/GHSA-rw95-68xg-rf7m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-680" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-x563-8qf7-q64m/GHSA-x563-8qf7-q64m.json b/advisories/unreviewed/2023/12/GHSA-x563-8qf7-q64m/GHSA-x563-8qf7-q64m.json index d097d8f03ca..f30f99f22dd 100644 --- a/advisories/unreviewed/2023/12/GHSA-x563-8qf7-q64m/GHSA-x563-8qf7-q64m.json +++ b/advisories/unreviewed/2023/12/GHSA-x563-8qf7-q64m/GHSA-x563-8qf7-q64m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-x56w-m67j-6hmr/GHSA-x56w-m67j-6hmr.json b/advisories/unreviewed/2023/12/GHSA-x56w-m67j-6hmr/GHSA-x56w-m67j-6hmr.json index b1cce5d61a8..95e6fa942c5 100644 --- a/advisories/unreviewed/2023/12/GHSA-x56w-m67j-6hmr/GHSA-x56w-m67j-6hmr.json +++ b/advisories/unreviewed/2023/12/GHSA-x56w-m67j-6hmr/GHSA-x56w-m67j-6hmr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-680" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json b/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json index d78aa020556..a3a05ea51e3 100644 --- a/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json +++ b/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json index 98d53cd9a2b..a18e73d0bd5 100644 --- a/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json +++ b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json b/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json index de289b0932b..fdaf4e22374 100644 --- a/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json +++ b/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json b/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json index 8667be67de2..ed1408ede81 100644 --- a/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json +++ b/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json index d5eb5caf3df..5e4dc72f618 100644 --- a/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json +++ b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json b/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json index 8bb8de3b20f..e6915b5f7b2 100644 --- a/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json +++ b/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json index 65e9ec9d725..b85e2dc1885 100644 --- a/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json +++ b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json b/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json index f03b5648cb2..723f19c8074 100644 --- a/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json +++ b/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json b/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json index aa716ac35bb..6400838be2d 100644 --- a/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json +++ b/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json b/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json index 3d6dd3579e2..585eb35b52d 100644 --- a/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json +++ b/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-362" + "CWE-362", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json index 042d9cfa8dc..c9565c69a13 100644 --- a/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json +++ b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-292c-8vv7-pg3v/GHSA-292c-8vv7-pg3v.json b/advisories/unreviewed/2024/02/GHSA-292c-8vv7-pg3v/GHSA-292c-8vv7-pg3v.json index c5dc709fc95..a6f87e93158 100644 --- a/advisories/unreviewed/2024/02/GHSA-292c-8vv7-pg3v/GHSA-292c-8vv7-pg3v.json +++ b/advisories/unreviewed/2024/02/GHSA-292c-8vv7-pg3v/GHSA-292c-8vv7-pg3v.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3wh9-2fg7-9h5g/GHSA-3wh9-2fg7-9h5g.json b/advisories/unreviewed/2024/02/GHSA-3wh9-2fg7-9h5g/GHSA-3wh9-2fg7-9h5g.json index 101c77e5259..927bc042ba1 100644 --- a/advisories/unreviewed/2024/02/GHSA-3wh9-2fg7-9h5g/GHSA-3wh9-2fg7-9h5g.json +++ b/advisories/unreviewed/2024/02/GHSA-3wh9-2fg7-9h5g/GHSA-3wh9-2fg7-9h5g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3xhr-vwcx-8p3c/GHSA-3xhr-vwcx-8p3c.json b/advisories/unreviewed/2024/02/GHSA-3xhr-vwcx-8p3c/GHSA-3xhr-vwcx-8p3c.json index bfecc0512ea..c1b5a9620a9 100644 --- a/advisories/unreviewed/2024/02/GHSA-3xhr-vwcx-8p3c/GHSA-3xhr-vwcx-8p3c.json +++ b/advisories/unreviewed/2024/02/GHSA-3xhr-vwcx-8p3c/GHSA-3xhr-vwcx-8p3c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-52vv-5jc5-5gmv/GHSA-52vv-5jc5-5gmv.json b/advisories/unreviewed/2024/02/GHSA-52vv-5jc5-5gmv/GHSA-52vv-5jc5-5gmv.json index 9d18b69506a..2e9e1932fb1 100644 --- a/advisories/unreviewed/2024/02/GHSA-52vv-5jc5-5gmv/GHSA-52vv-5jc5-5gmv.json +++ b/advisories/unreviewed/2024/02/GHSA-52vv-5jc5-5gmv/GHSA-52vv-5jc5-5gmv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-997r-3g6v-ph4j/GHSA-997r-3g6v-ph4j.json b/advisories/unreviewed/2024/02/GHSA-997r-3g6v-ph4j/GHSA-997r-3g6v-ph4j.json index 9ecd8d9dc01..7ce84ac77cd 100644 --- a/advisories/unreviewed/2024/02/GHSA-997r-3g6v-ph4j/GHSA-997r-3g6v-ph4j.json +++ b/advisories/unreviewed/2024/02/GHSA-997r-3g6v-ph4j/GHSA-997r-3g6v-ph4j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-9w2r-p3qj-g3gm/GHSA-9w2r-p3qj-g3gm.json b/advisories/unreviewed/2024/02/GHSA-9w2r-p3qj-g3gm/GHSA-9w2r-p3qj-g3gm.json index 586f17d17de..e595877c3e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-9w2r-p3qj-g3gm/GHSA-9w2r-p3qj-g3gm.json +++ b/advisories/unreviewed/2024/02/GHSA-9w2r-p3qj-g3gm/GHSA-9w2r-p3qj-g3gm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-763" + "CWE-763", + "CWE-822" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-cffx-cf3x-mr9h/GHSA-cffx-cf3x-mr9h.json b/advisories/unreviewed/2024/02/GHSA-cffx-cf3x-mr9h/GHSA-cffx-cf3x-mr9h.json index be294396cbc..9d318735f3e 100644 --- a/advisories/unreviewed/2024/02/GHSA-cffx-cf3x-mr9h/GHSA-cffx-cf3x-mr9h.json +++ b/advisories/unreviewed/2024/02/GHSA-cffx-cf3x-mr9h/GHSA-cffx-cf3x-mr9h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-fv23-fj7r-w7w4/GHSA-fv23-fj7r-w7w4.json b/advisories/unreviewed/2024/02/GHSA-fv23-fj7r-w7w4/GHSA-fv23-fj7r-w7w4.json index 8d009000533..f0d97c491c3 100644 --- a/advisories/unreviewed/2024/02/GHSA-fv23-fj7r-w7w4/GHSA-fv23-fj7r-w7w4.json +++ b/advisories/unreviewed/2024/02/GHSA-fv23-fj7r-w7w4/GHSA-fv23-fj7r-w7w4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-g9xq-vwmw-hprm/GHSA-g9xq-vwmw-hprm.json b/advisories/unreviewed/2024/02/GHSA-g9xq-vwmw-hprm/GHSA-g9xq-vwmw-hprm.json index cff3c711df6..26f2689bef0 100644 --- a/advisories/unreviewed/2024/02/GHSA-g9xq-vwmw-hprm/GHSA-g9xq-vwmw-hprm.json +++ b/advisories/unreviewed/2024/02/GHSA-g9xq-vwmw-hprm/GHSA-g9xq-vwmw-hprm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-h234-9whq-hx7f/GHSA-h234-9whq-hx7f.json b/advisories/unreviewed/2024/02/GHSA-h234-9whq-hx7f/GHSA-h234-9whq-hx7f.json index 78dcf59cd30..d7e0b40569c 100644 --- a/advisories/unreviewed/2024/02/GHSA-h234-9whq-hx7f/GHSA-h234-9whq-hx7f.json +++ b/advisories/unreviewed/2024/02/GHSA-h234-9whq-hx7f/GHSA-h234-9whq-hx7f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-hqm8-gpp6-j34p/GHSA-hqm8-gpp6-j34p.json b/advisories/unreviewed/2024/02/GHSA-hqm8-gpp6-j34p/GHSA-hqm8-gpp6-j34p.json index 27897aa28e4..c5781089b01 100644 --- a/advisories/unreviewed/2024/02/GHSA-hqm8-gpp6-j34p/GHSA-hqm8-gpp6-j34p.json +++ b/advisories/unreviewed/2024/02/GHSA-hqm8-gpp6-j34p/GHSA-hqm8-gpp6-j34p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pg26-49x3-7h59/GHSA-pg26-49x3-7h59.json b/advisories/unreviewed/2024/02/GHSA-pg26-49x3-7h59/GHSA-pg26-49x3-7h59.json index 8a884e69184..4ffdbf4155f 100644 --- a/advisories/unreviewed/2024/02/GHSA-pg26-49x3-7h59/GHSA-pg26-49x3-7h59.json +++ b/advisories/unreviewed/2024/02/GHSA-pg26-49x3-7h59/GHSA-pg26-49x3-7h59.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-823" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pp44-pghv-3r5p/GHSA-pp44-pghv-3r5p.json b/advisories/unreviewed/2024/02/GHSA-pp44-pghv-3r5p/GHSA-pp44-pghv-3r5p.json index 5a75d458578..8878636488b 100644 --- a/advisories/unreviewed/2024/02/GHSA-pp44-pghv-3r5p/GHSA-pp44-pghv-3r5p.json +++ b/advisories/unreviewed/2024/02/GHSA-pp44-pghv-3r5p/GHSA-pp44-pghv-3r5p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-822" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-wfj3-hjp7-62gf/GHSA-wfj3-hjp7-62gf.json b/advisories/unreviewed/2024/02/GHSA-wfj3-hjp7-62gf/GHSA-wfj3-hjp7-62gf.json index 30229f66a1b..06060332d2c 100644 --- a/advisories/unreviewed/2024/02/GHSA-wfj3-hjp7-62gf/GHSA-wfj3-hjp7-62gf.json +++ b/advisories/unreviewed/2024/02/GHSA-wfj3-hjp7-62gf/GHSA-wfj3-hjp7-62gf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-3cpf-72w5-65j4/GHSA-3cpf-72w5-65j4.json b/advisories/unreviewed/2024/04/GHSA-3cpf-72w5-65j4/GHSA-3cpf-72w5-65j4.json new file mode 100644 index 00000000000..92e6014236a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3cpf-72w5-65j4/GHSA-3cpf-72w5-65j4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cpf-72w5-65j4", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-22359" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22359" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/280897" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-46mj-7xpv-pprw/GHSA-46mj-7xpv-pprw.json b/advisories/unreviewed/2024/04/GHSA-46mj-7xpv-pprw/GHSA-46mj-7xpv-pprw.json new file mode 100644 index 00000000000..c75536ccc64 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-46mj-7xpv-pprw/GHSA-46mj-7xpv-pprw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46mj-7xpv-pprw", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-22358" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 280896.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22358" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/280896" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-52fw-vg2v-rc9p/GHSA-52fw-vg2v-rc9p.json b/advisories/unreviewed/2024/04/GHSA-52fw-vg2v-rc9p/GHSA-52fw-vg2v-rc9p.json new file mode 100644 index 00000000000..b8cf609daf4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-52fw-vg2v-rc9p/GHSA-52fw-vg2v-rc9p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52fw-vg2v-rc9p", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30210" + ], + "details": "IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30210" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-093-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6w72-x59c-h2c9/GHSA-6w72-x59c-h2c9.json b/advisories/unreviewed/2024/04/GHSA-6w72-x59c-h2c9/GHSA-6w72-x59c-h2c9.json new file mode 100644 index 00000000000..475620999c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6w72-x59c-h2c9/GHSA-6w72-x59c-h2c9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w72-x59c-h2c9", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30390" + ], + "details": "An Improper Restriction of Excessive Authentication Attempts vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited Denial of Service (DoS) to the management plane.\n\nWhen an incoming connection was blocked because it exceeded the connections-per-second rate-limit, the system doesn't consider existing connections anymore for subsequent connection attempts so that the connection limit can be exceeded.\nThis issue affects Junos OS Evolved:\n\nAll versions before 21.4R3-S4-EVO,\n\n22.1-EVO versions before 22.1R3-S3-EVO,\n\n22.2-EVO versions before 22.2R3-S2-EVO, \n\n22.3-EVO versions before 22.3R2-S1-EVO, 22.3R3-EVO.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30390" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-75rx-c73c-98q9/GHSA-75rx-c73c-98q9.json b/advisories/unreviewed/2024/04/GHSA-75rx-c73c-98q9/GHSA-75rx-c73c-98q9.json new file mode 100644 index 00000000000..8243d071d12 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-75rx-c73c-98q9/GHSA-75rx-c73c-98q9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75rx-c73c-98q9", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-22339" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM X-Force ID: 279979.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22339" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279979" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-76fc-hwwm-wmhg/GHSA-76fc-hwwm-wmhg.json b/advisories/unreviewed/2024/04/GHSA-76fc-hwwm-wmhg/GHSA-76fc-hwwm-wmhg.json new file mode 100644 index 00000000000..8a0ffd247f8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-76fc-hwwm-wmhg/GHSA-76fc-hwwm-wmhg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76fc-hwwm-wmhg", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30384" + ], + "details": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows a locally authenticated attacker with low privileges to cause a Denial-of-Service (Dos).\n\nIf a specific CLI command is issued, a PFE crash will occur. This will cause traffic forwarding to be interrupted until the system self-recovers. \n\nThis issue affects Junos OS: \n\nAll versions before 20.4R3-S10,\n\n21.2 versions before 21.2R3-S7,\n\n21.4 versions before 21.4R3-S6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30384" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-83pq-frch-8xf2/GHSA-83pq-frch-8xf2.json b/advisories/unreviewed/2024/04/GHSA-83pq-frch-8xf2/GHSA-83pq-frch-8xf2.json new file mode 100644 index 00000000000..ee6e41bcc4f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-83pq-frch-8xf2/GHSA-83pq-frch-8xf2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83pq-frch-8xf2", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30382" + ], + "details": "An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS).\n\nThis issue can only be triggered when the system is configured for CoS-based forwarding (CBF) with a policy map containing a cos-next-hop-map action (see below).\nThis issue affects:\nJunos OS: \n\n\n * all versions before 20.4R3-S10, \n * from 21.2 before 21.2R3-S8,\n * from 21.3 before 21.3R3, \n * from 21.4 before 21.4R3, \n * from 22.1 before 22.1R2;\n\n\n\n\nJunos OS Evolved: \n\n\n * all versions before 21.2R3-S8-EVO,\n * from 21.3 before 21.3R3-EVO, \n * from 21.4 before 21.4R3-EVO, \n * from 22.1 before 22.1R2-EVO.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30382" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79174" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-85x4-mgg9-rmg6/GHSA-85x4-mgg9-rmg6.json b/advisories/unreviewed/2024/04/GHSA-85x4-mgg9-rmg6/GHSA-85x4-mgg9-rmg6.json new file mode 100644 index 00000000000..3296fd32c2d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-85x4-mgg9-rmg6/GHSA-85x4-mgg9-rmg6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85x4-mgg9-rmg6", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-3698" + ], + "details": "A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_payment.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260485 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3698" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260485" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260485" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.314204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8vc5-fgcg-4vh9/GHSA-8vc5-fgcg-4vh9.json b/advisories/unreviewed/2024/04/GHSA-8vc5-fgcg-4vh9/GHSA-8vc5-fgcg-4vh9.json new file mode 100644 index 00000000000..dae02e5cef4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8vc5-fgcg-4vh9/GHSA-8vc5-fgcg-4vh9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vc5-fgcg-4vh9", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30402" + ], + "details": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\nWhen telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. Repeated occurrences of these events causes a sustained DoS condition.\n\n\nThis issue affects:\nJunos OS:\nAll versions earlier than 20.4R3-S10;\n21.2 versions earlier than 21.2R3-S7;\n21.4 versions earlier than 21.4R3-S5;\n22.1 versions earlier than 22.1R3-S4;\n22.2 versions earlier than 22.2R3-S3;\n22.3 versions earlier than 22.3R3-S1;\n22.4 versions earlier than 22.4R3;\n23.2 versions earlier than 23.2R1-S2, 23.2R2.\n\nJunos OS Evolved:\n\nAll versions earlier than 21.4R3-S5-EVO;\n22.1-EVO versions earlier than 22.1R3-S4-EVO;\n22.2-EVO versions earlier than 22.2R3-S3-EVO;\n22.3-EVO versions earlier than 22.3R3-S1-EVO;\n22.4-EVO versions earlier than 22.4R3-EVO;\n23.2-EVO versions earlier than 23.2R2-EVO.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30402" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79180" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fwcw-wmg8-r4vq/GHSA-fwcw-wmg8-r4vq.json b/advisories/unreviewed/2024/04/GHSA-fwcw-wmg8-r4vq/GHSA-fwcw-wmg8-r4vq.json new file mode 100644 index 00000000000..dcf05fd0175 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fwcw-wmg8-r4vq/GHSA-fwcw-wmg8-r4vq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwcw-wmg8-r4vq", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30388" + ], + "details": "An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\nIf a specific malformed LACP packet is received by a QFX5000 Series, or an EX4400, EX4100 or EX4650 Series device, an LACP flap will occur resulting in traffic loss.\nThis issue affects Junos OS on QFX5000 Series, and on EX4400, EX4100 or EX4650 Series:\n\n\n\n * 20.4 versions from \n\n20.4R3-S4\n\nbefore 20.4R3-S8,\n * 21.2 versions from \n\n21.2R3-S2\n\nbefore 21.2R3-S6,\n * 21.4 versions from \n\n21.4R2\n\nbefore 21.4R3-S4,\n\n * 22.1 versions from\n\n22.1R2\n\n before 22.1R3-S3,\n * 22.2 versions before 22.2R3-S1,\n * 22.3 versions before 22.3R2-S2, 22.3R3,\n * 22.4 versions before 22.4R2-S1, 22.4R3.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30388" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gfmf-6ghh-gjwr/GHSA-gfmf-6ghh-gjwr.json b/advisories/unreviewed/2024/04/GHSA-gfmf-6ghh-gjwr/GHSA-gfmf-6ghh-gjwr.json new file mode 100644 index 00000000000..66d31b3b522 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gfmf-6ghh-gjwr/GHSA-gfmf-6ghh-gjwr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfmf-6ghh-gjwr", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30397" + ], + "details": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS).\n\nThe pkid is responsible for the certificate verification. Upon a failed verification, the pkid uses all CPU resources and becomes unresponsive to future verification attempts. This means that all subsequent VPN negotiations depending on certificate verification will fail.\n\nThis CPU utilization of pkid can be checked using this command: \n  root@srx> show system processes extensive | match pkid\n  xxxxx  root  103  0  846M  136M  CPU1  1 569:00 100.00% pkid\n\nThis issue affects:\nJuniper Networks Junos OS\nAll versions prior to 20.4R3-S10;\n21.2 versions prior to 21.2R3-S7;\n21.4 versions prior to 21.4R3-S5;\n22.1 versions prior to 22.1R3-S4;\n22.2 versions prior to 22.2R3-S3;\n22.3 versions prior to 22.3R3-S1;\n22.4 versions prior to 22.4R3;\n23.2 versions prior to 23.2R1-S2, 23.2R2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30397" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79179" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h843-jc82-h6jf/GHSA-h843-jc82-h6jf.json b/advisories/unreviewed/2024/04/GHSA-h843-jc82-h6jf/GHSA-h843-jc82-h6jf.json new file mode 100644 index 00000000000..58d202c62f3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h843-jc82-h6jf/GHSA-h843-jc82-h6jf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h843-jc82-h6jf", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30387" + ], + "details": "A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).\n\nIf an interface flaps while the system gathers statistics on that interface, two processes simultaneously access a shared resource which leads to a PFE crash and restart.\n\nThis issue affects Junos OS:\n\nAll versions before 20.4R3-S9,\n\n21.2 versions before 21.2R3-S5, \n\n21.3 versions before 21.3R3-S5, \n\n21.4 versions before 21.4R3-S4,\n\n22.1 versions before 22.1R3-S2,\n\n22.2 versions before 22.2R3-S2,\n\n22.3 versions before 22.3R2-S2, 22.3R3,\n\n22.4 versions before 22.4R2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30387" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-820" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hcvj-cm7m-2774/GHSA-hcvj-cm7m-2774.json b/advisories/unreviewed/2024/04/GHSA-hcvj-cm7m-2774/GHSA-hcvj-cm7m-2774.json new file mode 100644 index 00000000000..cf22269083c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hcvj-cm7m-2774/GHSA-hcvj-cm7m-2774.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcvj-cm7m-2774", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-3695" + ], + "details": "A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-260482 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3695" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Computer%20Laboratory%20Management%20System%20using%20PHP%20and%20MySQL%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260482" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260482" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.314071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hvcg-7mfp-56mm/GHSA-hvcg-7mfp-56mm.json b/advisories/unreviewed/2024/04/GHSA-hvcg-7mfp-56mm/GHSA-hvcg-7mfp-56mm.json new file mode 100644 index 00000000000..f5d5f166a3a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hvcg-7mfp-56mm/GHSA-hvcg-7mfp-56mm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvcg-7mfp-56mm", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-3691" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260480.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3691" + }, + { + "type": "WEB", + "url": "https://github.com/nikhil-aniill/Small-CRM-CVE" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312975" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hxmw-j74g-j23w/GHSA-hxmw-j74g-j23w.json b/advisories/unreviewed/2024/04/GHSA-hxmw-j74g-j23w/GHSA-hxmw-j74g-j23w.json new file mode 100644 index 00000000000..7a5da037ca6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hxmw-j74g-j23w/GHSA-hxmw-j74g-j23w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxmw-j74g-j23w", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30403" + ], + "details": "A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\nWhen Layer 2 traffic is sent through a logical interface, MAC learning happens. If during this process, the interface flaps, an Advanced Forwarding Toolkit manager (evo-aftmand-bt) core is observed. This leads to a PFE restart. The crash reoccurs if the same sequence of events happens, which will lead to a sustained DoS condition.\n\nThis issue affects Juniper Networks Junos OS Evolved:\n23.2-EVO versions earlier than 23.2R1-S1-EVO, 23.2R2-EVO. \n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30403" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79181" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jjxw-r7pq-27g5/GHSA-jjxw-r7pq-27g5.json b/advisories/unreviewed/2024/04/GHSA-jjxw-r7pq-27g5/GHSA-jjxw-r7pq-27g5.json new file mode 100644 index 00000000000..2cf16773153 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jjxw-r7pq-27g5/GHSA-jjxw-r7pq-27g5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjxw-r7pq-27g5", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-3697" + ], + "details": "A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260484.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3697" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260484" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260484" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.314203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jqhc-3v3m-gjx4/GHSA-jqhc-3v3m-gjx4.json b/advisories/unreviewed/2024/04/GHSA-jqhc-3v3m-gjx4/GHSA-jqhc-3v3m-gjx4.json new file mode 100644 index 00000000000..b441eb9be74 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jqhc-3v3m-gjx4/GHSA-jqhc-3v3m-gjx4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqhc-3v3m-gjx4", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30392" + ], + "details": "A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).\n\nOn all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC, when URL filtering is enabled and a specific URL request is received and processed, flowd will crash and restart. Continuous reception of the specific URL request will lead to a sustained Denial of Service (DoS) condition.\n\nThis issue affects:\nJunos OS:\n\n\n\n * all versions before 21.2R3-S6,\n\n * from 21.3 before 21.3R3-S5,\n\n * from 21.4 before 21.4R3-S5,\n\n * from 22.1 before 22.1R3-S3,\n\n * from 22.2 before 22.2R3-S1,\n\n * from 22.3 before 22.3R2-S2, 22.3R3,\n\n * from 22.4 before 22.4R2-S1, 22.4R3.\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30392" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79092" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pqmg-f829-g3ww/GHSA-pqmg-f829-g3ww.json b/advisories/unreviewed/2024/04/GHSA-pqmg-f829-g3ww/GHSA-pqmg-f829-g3ww.json new file mode 100644 index 00000000000..470ddffa081 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pqmg-f829-g3ww/GHSA-pqmg-f829-g3ww.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqmg-f829-g3ww", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30401" + ], + "details": "An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C, may allow an attacker to exploit a stack-based buffer overflow, leading to a reboot of the FPC.\n\nThrough code review, it was determined that the interface definition code for aftman could read beyond a buffer boundary, leading to a stack-based buffer overflow.\nThis issue affects Junos OS on MX Series and EX9200-15C:\n\n\n * from 21.2 before 21.2R3-S1, \n * from 21.4 before 21.4R3, \n * from 22.1 before 22.1R2, \n * from 22.2 before 22.2R2; \n\n\n\n\nThis issue does not affect:\n\n\n\n * versions of Junos OS prior to 20.3R1;\n * any version of Junos OS 20.4.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30401" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79110" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qgwf-2fx2-cv5v/GHSA-qgwf-2fx2-cv5v.json b/advisories/unreviewed/2024/04/GHSA-qgwf-2fx2-cv5v/GHSA-qgwf-2fx2-cv5v.json new file mode 100644 index 00000000000..ae27ccb6f7a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qgwf-2fx2-cv5v/GHSA-qgwf-2fx2-cv5v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgwf-2fx2-cv5v", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-3696" + ], + "details": "A vulnerability was found in Campcodes House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260483.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3696" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260483" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260483" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.314199" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qmmh-x7m4-pr56/GHSA-qmmh-x7m4-pr56.json b/advisories/unreviewed/2024/04/GHSA-qmmh-x7m4-pr56/GHSA-qmmh-x7m4-pr56.json new file mode 100644 index 00000000000..5f553a65f93 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qmmh-x7m4-pr56/GHSA-qmmh-x7m4-pr56.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmmh-x7m4-pr56", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-22334" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated permissions of objects using that type may not be fully revoked. This could lead to incorrect reporting of permission configuration and unexpected privileges being retained. IBM X-Force ID: 279974.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22334" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279974" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r4g7-rp4j-9cv7/GHSA-r4g7-rp4j-9cv7.json b/advisories/unreviewed/2024/04/GHSA-r4g7-rp4j-9cv7/GHSA-r4g7-rp4j-9cv7.json new file mode 100644 index 00000000000..11f7010aea8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r4g7-rp4j-9cv7/GHSA-r4g7-rp4j-9cv7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4g7-rp4j-9cv7", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30386" + ], + "details": "A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald)\n\n of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause l2ald to crash leading to a Denial-of-Service (DoS).\n\nIn an EVPN-VXLAN scenario, when \n\nstate updates are received and processed by the affected system, the correct order of some processing steps is not ensured, which can lead to an l2ald crash and restart. Whether the crash occurs depends on system internal timing which is outside the attackers control.\nThis issue affects:\n\nJunos OS: \n\n\n\n * All versions before 20.4R3-S8,\n * 21.2 versions before 21.2R3-S6,\n * 21.3 versions before 21.3R3-S5,\n * 21.4 versions before 21.4R3-S4,\n * 22.1 versions before 22.1R3-S3,\n * 22.2 versions before 22.2R3-S1,\n * 22.3 versions before 22.3R3,,\n * 22.4 versions before 22.4R2;\n\n\n\n\nJunos OS Evolved: \n\n\n\n * All versions before 20.4R3-S8-EVO,\n * 21.2-EVO versions before 21.2R3-S6-EVO, \n * 21.3-EVO\n\n versions before 21.3R3-S5-EVO,\n * 21.4-EVO\n\n versions before 21.4R3-S4-EVO,\n * 22.1-EVO\n\n versions before 22.1R3-S3-EVO,\n * 22.2-EVO\n\n versions before 22.2R3-S1-EVO,\n * 22.3-EVO\n\n versions before 22.3R3-EVO,\n * 22.4-EVO\n\n versions before 22.4R2-EVO.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30386" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json b/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json new file mode 100644 index 00000000000..2f8869bb57f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpfm-675m-rfm8", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30391" + ], + "details": "A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device.\n\nIf a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. So if the peer is an unaffected device transit traffic is going to fail in both directions. If the peer is an also affected device transit traffic works, but without authentication, and configuration and CLI operational commands indicate authentication is performed.\nThis issue affects Junos OS:\n\nAll versions before 20.4R3-S7,\n\n21.1 versions before 21.1R3, \n\n21.2 versions before 21.2R2-S1, 21.2R3, \n\n21.3 versions before 21.3R1-S2, 21.3R2.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30391" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vqqg-v6v5-gm7x/GHSA-vqqg-v6v5-gm7x.json b/advisories/unreviewed/2024/04/GHSA-vqqg-v6v5-gm7x/GHSA-vqqg-v6v5-gm7x.json new file mode 100644 index 00000000000..116e9637999 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vqqg-v6v5-gm7x/GHSA-vqqg-v6v5-gm7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqqg-v6v5-gm7x", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-28878" + ], + "details": "\nIO-1020 Micro ELD downloads source code or an executable from an \nadjacent location and executes the code without sufficiently verifying \nthe origin or integrity of the code.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28878" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-093-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-494" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w8g8-33g5-c7m6/GHSA-w8g8-33g5-c7m6.json b/advisories/unreviewed/2024/04/GHSA-w8g8-33g5-c7m6/GHSA-w8g8-33g5-c7m6.json new file mode 100644 index 00000000000..e5183b1159a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w8g8-33g5-c7m6/GHSA-w8g8-33g5-c7m6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8g8-33g5-c7m6", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-31069" + ], + "details": "IO-1020 Micro ELD web server uses a default password for authentication.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31069" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-093-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json b/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json new file mode 100644 index 00000000000..f671ef29bef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2p9-2jc3-8gpp", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-0157" + ], + "details": "Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0157" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-nz/000224070/dsa-2024-143-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T17:17:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x368-w88j-3c3r/GHSA-x368-w88j-3c3r.json b/advisories/unreviewed/2024/04/GHSA-x368-w88j-3c3r/GHSA-x368-w88j-3c3r.json new file mode 100644 index 00000000000..7bc61ed5083 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x368-w88j-3c3r/GHSA-x368-w88j-3c3r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x368-w88j-3c3r", + "modified": "2024-04-12T18:33:26Z", + "published": "2024-04-12T18:33:26Z", + "aliases": [ + "CVE-2024-30389" + ], + "details": "An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device.\n\nWhen an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic.\nThis issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6.\nThis issue does not affect Junos OS releases earlier than 21.4R1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30389" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N" + }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA79185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-696" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x3m5-7cpw-xq9j/GHSA-x3m5-7cpw-xq9j.json b/advisories/unreviewed/2024/04/GHSA-x3m5-7cpw-xq9j/GHSA-x3m5-7cpw-xq9j.json new file mode 100644 index 00000000000..8b2e9965a2f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x3m5-7cpw-xq9j/GHSA-x3m5-7cpw-xq9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3m5-7cpw-xq9j", + "modified": "2024-04-12T18:33:27Z", + "published": "2024-04-12T18:33:27Z", + "aliases": [ + "CVE-2024-30398" + ], + "details": "An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\n\nWhen a high amount of specific traffic is received on a SRX4600 device, due to an error in internal packet handling, a consistent rise in CPU memory utilization occurs. This results in packet drops in the traffic and eventually the PFE crashes. A manual reboot of the PFE will be required to restore the device to original state.\n\nThis issue affects Junos OS:  \n21.2 before 21.2R3-S7,\n21.4 before 21.4R3-S6, \n22.1 before 22.1R3-S5, \n22.2 before 22.2R3-S3,\n22.3 before 22.3R3-S2,\n22.4 before 22.4R3,\n23.2 before 23.2R1-S2, 23.2R2.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30398" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA79176" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-12T16:15:39Z" + } +} \ No newline at end of file