Publish Advisories

GHSA-wc6r-9c75-44gq
GHSA-fpmh-3mrp-3732
GHSA-f54v-wcj4-v4cc
GHSA-f652-mrvw-479m
GHSA-f6vq-2724-9c29
GHSA-r25h-4q4w-q5q3
GHSA-29p2-7jvf-2jvf
GHSA-3cp9-5473-gp87
GHSA-69m4-r76x-j23h
GHSA-c3gq-8ffr-r9gp
GHSA-f5wq-j5xc-xjc7
GHSA-jh6c-99xj-2gpm
GHSA-jxww-33mj-j76w
GHSA-mh5h-4v4h-vcvq
GHSA-pcm9-gv4v-rfw2
GHSA-pxgf-7mqc-v7vx
GHSA-qp7j-9526-r655
GHSA-xf7x-v424-j8mq
GHSA-3phf-jwf8-gj9x
GHSA-3rwq-pxmh-pw55
GHSA-52x7-wcqq-wfjp
GHSA-pc3v-rhjc-2wvq
GHSA-x62c-jmjr-qf58
This commit is contained in:
advisory-database[bot]
2024-01-02 18:31:33 +00:00
parent e0a6611a3e
commit f1dd938673
23 changed files with 242 additions and 20 deletions
@@ -28,6 +28,14 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202309-01"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpmh-3mrp-3732",
"modified": "2023-07-12T06:30:33Z",
"modified": "2024-01-02T18:30:18Z",
"published": "2023-07-12T06:30:33Z",
"aliases": [
"CVE-2023-3080"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-12T05:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f54v-wcj4-v4cc",
"modified": "2023-11-01T00:30:48Z",
"modified": "2024-01-02T18:30:19Z",
"published": "2023-11-01T00:30:48Z",
"aliases": [
"CVE-2023-5306"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f652-mrvw-479m",
"modified": "2023-11-01T00:30:48Z",
"modified": "2024-01-02T18:30:18Z",
"published": "2023-11-01T00:30:48Z",
"aliases": [
"CVE-2023-44486"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6vq-2724-9c29",
"modified": "2023-11-01T00:30:48Z",
"modified": "2024-01-02T18:30:18Z",
"published": "2023-11-01T00:30:48Z",
"aliases": [
"CVE-2023-44485"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r25h-4q4w-q5q3",
"modified": "2023-11-01T00:30:48Z",
"modified": "2024-01-02T18:30:18Z",
"published": "2023-11-01T00:30:48Z",
"aliases": [
"CVE-2023-44484"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29p2-7jvf-2jvf",
"modified": "2023-12-21T21:30:32Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:32Z",
"aliases": [
"CVE-2023-48719"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cp9-5473-gp87",
"modified": "2023-12-21T00:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T00:30:24Z",
"aliases": [
"CVE-2023-49032"
],
"details": "An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T00:15:26Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-69m4-r76x-j23h",
"modified": "2023-12-19T00:30:21Z",
"modified": "2024-01-02T18:30:19Z",
"published": "2023-12-19T00:30:21Z",
"aliases": [
"CVE-2023-49819"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c3gq-8ffr-r9gp",
"modified": "2023-12-22T00:30:31Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-22T00:30:31Z",
"aliases": [
"CVE-2023-48723"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5wq-j5xc-xjc7",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T18:30:23Z",
"aliases": [
"CVE-2023-45123"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh6c-99xj-2gpm",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T18:30:23Z",
"aliases": [
"CVE-2023-45122"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxww-33mj-j76w",
"modified": "2023-12-21T21:30:32Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:32Z",
"aliases": [
"CVE-2023-48717"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh5h-4v4h-vcvq",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:30Z",
"aliases": [
"CVE-2023-45124"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcm9-gv4v-rfw2",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:30Z",
"aliases": [
"CVE-2023-45125"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxgf-7mqc-v7vx",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:30Z",
"aliases": [
"CVE-2023-45127"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp7j-9526-r655",
"modified": "2024-01-02T15:30:24Z",
"modified": "2024-01-02T18:30:20Z",
"published": "2023-12-21T21:30:30Z",
"aliases": [
"CVE-2023-45126"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3phf-jwf8-gj9x",
"modified": "2024-01-02T18:30:20Z",
"published": "2024-01-02T18:30:20Z",
"aliases": [
"CVE-2024-0189"
],
"details": "A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0189"
},
{
"type": "WEB",
"url": "https://mega.nz/file/WNNSmRbR#ANdE-2h3pyJ8rEktaD2XlSyuksUiCPWBMGMJlJnhb9Q"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.249502"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.249502"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T18:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rwq-pxmh-pw55",
"modified": "2024-01-02T18:30:20Z",
"published": "2024-01-02T18:30:20Z",
"aliases": [
"CVE-2023-4280"
],
"details": "An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4280"
},
{
"type": "WEB",
"url": "https://community.silabs.com/069Vm0000004NinIAE"
},
{
"type": "WEB",
"url": "https://github.com/SiliconLabs/gecko_sdk"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-02T17:15:09Z"
}
}

Some files were not shown because too many files have changed in this diff Show More