From f1dd9386733751841fc4e4afa9d47c295b905604 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 2 Jan 2024 18:31:33 +0000 Subject: [PATCH] Publish Advisories GHSA-wc6r-9c75-44gq GHSA-fpmh-3mrp-3732 GHSA-f54v-wcj4-v4cc GHSA-f652-mrvw-479m GHSA-f6vq-2724-9c29 GHSA-r25h-4q4w-q5q3 GHSA-29p2-7jvf-2jvf GHSA-3cp9-5473-gp87 GHSA-69m4-r76x-j23h GHSA-c3gq-8ffr-r9gp GHSA-f5wq-j5xc-xjc7 GHSA-jh6c-99xj-2gpm GHSA-jxww-33mj-j76w GHSA-mh5h-4v4h-vcvq GHSA-pcm9-gv4v-rfw2 GHSA-pxgf-7mqc-v7vx GHSA-qp7j-9526-r655 GHSA-xf7x-v424-j8mq GHSA-3phf-jwf8-gj9x GHSA-3rwq-pxmh-pw55 GHSA-52x7-wcqq-wfjp GHSA-pc3v-rhjc-2wvq GHSA-x62c-jmjr-qf58 --- .../GHSA-wc6r-9c75-44gq.json | 8 +++ .../GHSA-fpmh-3mrp-3732.json | 4 +- .../GHSA-f54v-wcj4-v4cc.json | 2 +- .../GHSA-f652-mrvw-479m.json | 2 +- .../GHSA-f6vq-2724-9c29.json | 2 +- .../GHSA-r25h-4q4w-q5q3.json | 2 +- .../GHSA-29p2-7jvf-2jvf.json | 2 +- .../GHSA-3cp9-5473-gp87.json | 9 ++-- .../GHSA-69m4-r76x-j23h.json | 2 +- .../GHSA-c3gq-8ffr-r9gp.json | 2 +- .../GHSA-f5wq-j5xc-xjc7.json | 2 +- .../GHSA-jh6c-99xj-2gpm.json | 2 +- .../GHSA-jxww-33mj-j76w.json | 2 +- .../GHSA-mh5h-4v4h-vcvq.json | 2 +- .../GHSA-pcm9-gv4v-rfw2.json | 2 +- .../GHSA-pxgf-7mqc-v7vx.json | 2 +- .../GHSA-qp7j-9526-r655.json | 2 +- .../GHSA-xf7x-v424-j8mq.json | 2 +- .../GHSA-3phf-jwf8-gj9x.json | 46 +++++++++++++++++ .../GHSA-3rwq-pxmh-pw55.json | 42 ++++++++++++++++ .../GHSA-52x7-wcqq-wfjp.json | 42 ++++++++++++++++ .../GHSA-pc3v-rhjc-2wvq.json | 50 +++++++++++++++++++ .../GHSA-x62c-jmjr-qf58.json | 31 ++++++++++++ 23 files changed, 242 insertions(+), 20 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-3phf-jwf8-gj9x/GHSA-3phf-jwf8-gj9x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3rwq-pxmh-pw55/GHSA-3rwq-pxmh-pw55.json create mode 100644 advisories/unreviewed/2024/01/GHSA-52x7-wcqq-wfjp/GHSA-52x7-wcqq-wfjp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pc3v-rhjc-2wvq/GHSA-pc3v-rhjc-2wvq.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x62c-jmjr-qf58/GHSA-x62c-jmjr-qf58.json diff --git a/advisories/unreviewed/2023/03/GHSA-wc6r-9c75-44gq/GHSA-wc6r-9c75-44gq.json b/advisories/unreviewed/2023/03/GHSA-wc6r-9c75-44gq/GHSA-wc6r-9c75-44gq.json index aaa78f499e4..0423fd8bf83 100644 --- a/advisories/unreviewed/2023/03/GHSA-wc6r-9c75-44gq/GHSA-wc6r-9c75-44gq.json +++ b/advisories/unreviewed/2023/03/GHSA-wc6r-9c75-44gq/GHSA-wc6r-9c75-44gq.json @@ -28,6 +28,14 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202309-01" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-fpmh-3mrp-3732/GHSA-fpmh-3mrp-3732.json b/advisories/unreviewed/2023/07/GHSA-fpmh-3mrp-3732/GHSA-fpmh-3mrp-3732.json index 0683ace5d9f..2c17e8d56e3 100644 --- a/advisories/unreviewed/2023/07/GHSA-fpmh-3mrp-3732/GHSA-fpmh-3mrp-3732.json +++ b/advisories/unreviewed/2023/07/GHSA-fpmh-3mrp-3732/GHSA-fpmh-3mrp-3732.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpmh-3mrp-3732", - "modified": "2023-07-12T06:30:33Z", + "modified": "2024-01-02T18:30:18Z", "published": "2023-07-12T06:30:33Z", "aliases": [ "CVE-2023-3080" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-12T05:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-f54v-wcj4-v4cc/GHSA-f54v-wcj4-v4cc.json b/advisories/unreviewed/2023/11/GHSA-f54v-wcj4-v4cc/GHSA-f54v-wcj4-v4cc.json index 682743f305b..61c2189e3c6 100644 --- a/advisories/unreviewed/2023/11/GHSA-f54v-wcj4-v4cc/GHSA-f54v-wcj4-v4cc.json +++ b/advisories/unreviewed/2023/11/GHSA-f54v-wcj4-v4cc/GHSA-f54v-wcj4-v4cc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f54v-wcj4-v4cc", - "modified": "2023-11-01T00:30:48Z", + "modified": "2024-01-02T18:30:19Z", "published": "2023-11-01T00:30:48Z", "aliases": [ "CVE-2023-5306" diff --git a/advisories/unreviewed/2023/11/GHSA-f652-mrvw-479m/GHSA-f652-mrvw-479m.json b/advisories/unreviewed/2023/11/GHSA-f652-mrvw-479m/GHSA-f652-mrvw-479m.json index dc643c0c9db..d495611a266 100644 --- a/advisories/unreviewed/2023/11/GHSA-f652-mrvw-479m/GHSA-f652-mrvw-479m.json +++ b/advisories/unreviewed/2023/11/GHSA-f652-mrvw-479m/GHSA-f652-mrvw-479m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f652-mrvw-479m", - "modified": "2023-11-01T00:30:48Z", + "modified": "2024-01-02T18:30:18Z", "published": "2023-11-01T00:30:48Z", "aliases": [ "CVE-2023-44486" diff --git a/advisories/unreviewed/2023/11/GHSA-f6vq-2724-9c29/GHSA-f6vq-2724-9c29.json b/advisories/unreviewed/2023/11/GHSA-f6vq-2724-9c29/GHSA-f6vq-2724-9c29.json index 449ba989b67..94d9a1e468e 100644 --- a/advisories/unreviewed/2023/11/GHSA-f6vq-2724-9c29/GHSA-f6vq-2724-9c29.json +++ b/advisories/unreviewed/2023/11/GHSA-f6vq-2724-9c29/GHSA-f6vq-2724-9c29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6vq-2724-9c29", - "modified": "2023-11-01T00:30:48Z", + "modified": "2024-01-02T18:30:18Z", "published": "2023-11-01T00:30:48Z", "aliases": [ "CVE-2023-44485" diff --git a/advisories/unreviewed/2023/11/GHSA-r25h-4q4w-q5q3/GHSA-r25h-4q4w-q5q3.json b/advisories/unreviewed/2023/11/GHSA-r25h-4q4w-q5q3/GHSA-r25h-4q4w-q5q3.json index cc63e2e8b76..6cbbd814b03 100644 --- a/advisories/unreviewed/2023/11/GHSA-r25h-4q4w-q5q3/GHSA-r25h-4q4w-q5q3.json +++ b/advisories/unreviewed/2023/11/GHSA-r25h-4q4w-q5q3/GHSA-r25h-4q4w-q5q3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r25h-4q4w-q5q3", - "modified": "2023-11-01T00:30:48Z", + "modified": "2024-01-02T18:30:18Z", "published": "2023-11-01T00:30:48Z", "aliases": [ "CVE-2023-44484" diff --git a/advisories/unreviewed/2023/12/GHSA-29p2-7jvf-2jvf/GHSA-29p2-7jvf-2jvf.json b/advisories/unreviewed/2023/12/GHSA-29p2-7jvf-2jvf/GHSA-29p2-7jvf-2jvf.json index 1310102d51e..1415eb3a6d5 100644 --- a/advisories/unreviewed/2023/12/GHSA-29p2-7jvf-2jvf/GHSA-29p2-7jvf-2jvf.json +++ b/advisories/unreviewed/2023/12/GHSA-29p2-7jvf-2jvf/GHSA-29p2-7jvf-2jvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29p2-7jvf-2jvf", - "modified": "2023-12-21T21:30:32Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:32Z", "aliases": [ "CVE-2023-48719" diff --git a/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json b/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json index 5ff275b2569..f90870c5b5f 100644 --- a/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json +++ b/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cp9-5473-gp87", - "modified": "2023-12-21T00:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-49032" ], "details": "An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-21T00:15:26Z" diff --git a/advisories/unreviewed/2023/12/GHSA-69m4-r76x-j23h/GHSA-69m4-r76x-j23h.json b/advisories/unreviewed/2023/12/GHSA-69m4-r76x-j23h/GHSA-69m4-r76x-j23h.json index 272504d4486..ec6aa6d5e12 100644 --- a/advisories/unreviewed/2023/12/GHSA-69m4-r76x-j23h/GHSA-69m4-r76x-j23h.json +++ b/advisories/unreviewed/2023/12/GHSA-69m4-r76x-j23h/GHSA-69m4-r76x-j23h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69m4-r76x-j23h", - "modified": "2023-12-19T00:30:21Z", + "modified": "2024-01-02T18:30:19Z", "published": "2023-12-19T00:30:21Z", "aliases": [ "CVE-2023-49819" diff --git a/advisories/unreviewed/2023/12/GHSA-c3gq-8ffr-r9gp/GHSA-c3gq-8ffr-r9gp.json b/advisories/unreviewed/2023/12/GHSA-c3gq-8ffr-r9gp/GHSA-c3gq-8ffr-r9gp.json index 1eb809d2cc2..ec191828061 100644 --- a/advisories/unreviewed/2023/12/GHSA-c3gq-8ffr-r9gp/GHSA-c3gq-8ffr-r9gp.json +++ b/advisories/unreviewed/2023/12/GHSA-c3gq-8ffr-r9gp/GHSA-c3gq-8ffr-r9gp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3gq-8ffr-r9gp", - "modified": "2023-12-22T00:30:31Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-48723" diff --git a/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json b/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json index de26cab82dc..60c30845e4a 100644 --- a/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json +++ b/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5wq-j5xc-xjc7", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45123" diff --git a/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json b/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json index db545eee69a..401c12aacc3 100644 --- a/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json +++ b/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh6c-99xj-2gpm", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45122" diff --git a/advisories/unreviewed/2023/12/GHSA-jxww-33mj-j76w/GHSA-jxww-33mj-j76w.json b/advisories/unreviewed/2023/12/GHSA-jxww-33mj-j76w/GHSA-jxww-33mj-j76w.json index b6f8a6475d7..fe9e10fb744 100644 --- a/advisories/unreviewed/2023/12/GHSA-jxww-33mj-j76w/GHSA-jxww-33mj-j76w.json +++ b/advisories/unreviewed/2023/12/GHSA-jxww-33mj-j76w/GHSA-jxww-33mj-j76w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxww-33mj-j76w", - "modified": "2023-12-21T21:30:32Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:32Z", "aliases": [ "CVE-2023-48717" diff --git a/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json b/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json index d6cb57016ad..6c1f2ab1673 100644 --- a/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json +++ b/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh5h-4v4h-vcvq", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45124" diff --git a/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json b/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json index 6a795cd6ca5..b5f2a5b5e59 100644 --- a/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json +++ b/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcm9-gv4v-rfw2", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45125" diff --git a/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json b/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json index c24183c6cf3..ee92c26c261 100644 --- a/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json +++ b/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxgf-7mqc-v7vx", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45127" diff --git a/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json b/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json index bfe7628bca9..8a1c5d3495d 100644 --- a/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json +++ b/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp7j-9526-r655", - "modified": "2024-01-02T15:30:24Z", + "modified": "2024-01-02T18:30:20Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45126" diff --git a/advisories/unreviewed/2023/12/GHSA-xf7x-v424-j8mq/GHSA-xf7x-v424-j8mq.json b/advisories/unreviewed/2023/12/GHSA-xf7x-v424-j8mq/GHSA-xf7x-v424-j8mq.json index 4699c8bcdc7..4d6efff04d5 100644 --- a/advisories/unreviewed/2023/12/GHSA-xf7x-v424-j8mq/GHSA-xf7x-v424-j8mq.json +++ b/advisories/unreviewed/2023/12/GHSA-xf7x-v424-j8mq/GHSA-xf7x-v424-j8mq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3phf-jwf8-gj9x/GHSA-3phf-jwf8-gj9x.json b/advisories/unreviewed/2024/01/GHSA-3phf-jwf8-gj9x/GHSA-3phf-jwf8-gj9x.json new file mode 100644 index 00000000000..a9f35ea4cf6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3phf-jwf8-gj9x/GHSA-3phf-jwf8-gj9x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3phf-jwf8-gj9x", + "modified": "2024-01-02T18:30:20Z", + "published": "2024-01-02T18:30:20Z", + "aliases": [ + "CVE-2024-0189" + ], + "details": "A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0189" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/WNNSmRbR#ANdE-2h3pyJ8rEktaD2XlSyuksUiCPWBMGMJlJnhb9Q" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249502" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249502" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3rwq-pxmh-pw55/GHSA-3rwq-pxmh-pw55.json b/advisories/unreviewed/2024/01/GHSA-3rwq-pxmh-pw55/GHSA-3rwq-pxmh-pw55.json new file mode 100644 index 00000000000..93871863451 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3rwq-pxmh-pw55/GHSA-3rwq-pxmh-pw55.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rwq-pxmh-pw55", + "modified": "2024-01-02T18:30:20Z", + "published": "2024-01-02T18:30:20Z", + "aliases": [ + "CVE-2023-4280" + ], + "details": "An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4280" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm0000004NinIAE" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/gecko_sdk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-52x7-wcqq-wfjp/GHSA-52x7-wcqq-wfjp.json b/advisories/unreviewed/2024/01/GHSA-52x7-wcqq-wfjp/GHSA-52x7-wcqq-wfjp.json new file mode 100644 index 00000000000..901c7d3569b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-52x7-wcqq-wfjp/GHSA-52x7-wcqq-wfjp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52x7-wcqq-wfjp", + "modified": "2024-01-02T18:30:20Z", + "published": "2024-01-02T18:30:20Z", + "aliases": [ + "CVE-2024-0193" + ], + "details": "A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user to escalate their privileges on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0193" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0193" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255653" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pc3v-rhjc-2wvq/GHSA-pc3v-rhjc-2wvq.json b/advisories/unreviewed/2024/01/GHSA-pc3v-rhjc-2wvq/GHSA-pc3v-rhjc-2wvq.json new file mode 100644 index 00000000000..35ec210d0f8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pc3v-rhjc-2wvq/GHSA-pc3v-rhjc-2wvq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc3v-rhjc-2wvq", + "modified": "2024-01-02T18:30:20Z", + "published": "2024-01-02T18:30:20Z", + "aliases": [ + "CVE-2018-25097" + ], + "details": "A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The name of the patch is 0df8a5e8722188744973168648e4c74c69ce67fd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249420.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25097" + }, + { + "type": "WEB", + "url": "https://github.com/acumos/design-studio/commit/0df8a5e8722188744973168648e4c74c69ce67fd" + }, + { + "type": "WEB", + "url": "https://github.com/acumos/design-studio/releases/tag/2.0.8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249420" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249420" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x62c-jmjr-qf58/GHSA-x62c-jmjr-qf58.json b/advisories/unreviewed/2024/01/GHSA-x62c-jmjr-qf58/GHSA-x62c-jmjr-qf58.json new file mode 100644 index 00000000000..90cd90a5a58 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x62c-jmjr-qf58/GHSA-x62c-jmjr-qf58.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x62c-jmjr-qf58", + "modified": "2024-01-02T18:30:20Z", + "published": "2024-01-02T18:30:20Z", + "aliases": [ + "CVE-2023-48721" + ], + "details": "Rejected reason: Not used", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48721" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T16:15:12Z" + } +} \ No newline at end of file