mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-wc6r-9c75-44gq GHSA-fpmh-3mrp-3732 GHSA-f54v-wcj4-v4cc GHSA-f652-mrvw-479m GHSA-f6vq-2724-9c29 GHSA-r25h-4q4w-q5q3 GHSA-29p2-7jvf-2jvf GHSA-3cp9-5473-gp87 GHSA-69m4-r76x-j23h GHSA-c3gq-8ffr-r9gp GHSA-f5wq-j5xc-xjc7 GHSA-jh6c-99xj-2gpm GHSA-jxww-33mj-j76w GHSA-mh5h-4v4h-vcvq GHSA-pcm9-gv4v-rfw2 GHSA-pxgf-7mqc-v7vx GHSA-qp7j-9526-r655 GHSA-xf7x-v424-j8mq GHSA-3phf-jwf8-gj9x GHSA-3rwq-pxmh-pw55 GHSA-52x7-wcqq-wfjp GHSA-pc3v-rhjc-2wvq GHSA-x62c-jmjr-qf58
This commit is contained in:
@@ -28,6 +28,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.gentoo.org/glsa/202309-01"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fpmh-3mrp-3732",
|
||||
"modified": "2023-07-12T06:30:33Z",
|
||||
"modified": "2024-01-02T18:30:18Z",
|
||||
"published": "2023-07-12T06:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3080"
|
||||
@@ -34,7 +34,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-07-12T05:15:09Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f54v-wcj4-v4cc",
|
||||
"modified": "2023-11-01T00:30:48Z",
|
||||
"modified": "2024-01-02T18:30:19Z",
|
||||
"published": "2023-11-01T00:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5306"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f652-mrvw-479m",
|
||||
"modified": "2023-11-01T00:30:48Z",
|
||||
"modified": "2024-01-02T18:30:18Z",
|
||||
"published": "2023-11-01T00:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44486"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f6vq-2724-9c29",
|
||||
"modified": "2023-11-01T00:30:48Z",
|
||||
"modified": "2024-01-02T18:30:18Z",
|
||||
"published": "2023-11-01T00:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44485"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r25h-4q4w-q5q3",
|
||||
"modified": "2023-11-01T00:30:48Z",
|
||||
"modified": "2024-01-02T18:30:18Z",
|
||||
"published": "2023-11-01T00:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44484"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-29p2-7jvf-2jvf",
|
||||
"modified": "2023-12-21T21:30:32Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48719"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3cp9-5473-gp87",
|
||||
"modified": "2023-12-21T00:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T00:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49032"
|
||||
],
|
||||
"details": "An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -31,7 +34,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-12-21T00:15:26Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-69m4-r76x-j23h",
|
||||
"modified": "2023-12-19T00:30:21Z",
|
||||
"modified": "2024-01-02T18:30:19Z",
|
||||
"published": "2023-12-19T00:30:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49819"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c3gq-8ffr-r9gp",
|
||||
"modified": "2023-12-22T00:30:31Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-22T00:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48723"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f5wq-j5xc-xjc7",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T18:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45123"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jh6c-99xj-2gpm",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T18:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45122"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jxww-33mj-j76w",
|
||||
"modified": "2023-12-21T21:30:32Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48717"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mh5h-4v4h-vcvq",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45124"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pcm9-gv4v-rfw2",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45125"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pxgf-7mqc-v7vx",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45127"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qp7j-9526-r655",
|
||||
"modified": "2024-01-02T15:30:24Z",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2023-12-21T21:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45126"
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3phf-jwf8-gj9x",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2024-01-02T18:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0189"
|
||||
],
|
||||
"details": "A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0189"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mega.nz/file/WNNSmRbR#ANdE-2h3pyJ8rEktaD2XlSyuksUiCPWBMGMJlJnhb9Q"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.249502"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.249502"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-02T18:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3rwq-pxmh-pw55",
|
||||
"modified": "2024-01-02T18:30:20Z",
|
||||
"published": "2024-01-02T18:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4280"
|
||||
],
|
||||
"details": "An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4280"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://community.silabs.com/069Vm0000004NinIAE"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SiliconLabs/gecko_sdk"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-02T17:15:09Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user