Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-12-22 21:31:58 +00:00
parent b1af6ed4f8
commit f20494de9c
57 changed files with 1013 additions and 76 deletions
@@ -68,6 +68,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ME34ROZWMDK5KLMZKTSA422XVJZ7IMTE/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231222-0001/"
},
{
"type": "WEB",
"url": "https://www.terrapin-attack.com"
@@ -68,6 +68,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ME34ROZWMDK5KLMZKTSA422XVJZ7IMTE/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231222-0001/"
},
{
"type": "WEB",
"url": "https://www.terrapin-attack.com"
@@ -0,0 +1,65 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfq3-wpjh-ppvg",
"modified": "2023-12-22T21:31:02Z",
"published": "2023-12-22T18:30:30Z",
"aliases": [
"CVE-2023-6911"
],
"summary": "WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability",
"details": "WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.wso2.carbon.registry:carbon-registry"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.7.37"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6911"
},
{
"type": "WEB",
"url": "https://github.com/wso2/carbon-registry/commit/878fc7e53c90acc85e303d2af73440014a68b246"
},
{
"type": "PACKAGE",
"url": "https://github.com/wso2/carbon-registry/"
},
{
"type": "WEB",
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-12-22T21:31:02Z",
"nvd_published_at": "2023-12-18T09:15:05Z"
}
}
@@ -157,7 +157,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -53,7 +53,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -73,7 +73,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-193"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-972p-jcp3-q2cv",
"modified": "2023-04-21T06:30:17Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-04-13T15:30:35Z",
"aliases": [
"CVE-2023-27812"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-13T14:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6h4-4gxw-xxg8",
"modified": "2023-04-21T18:30:24Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-04-13T15:30:35Z",
"aliases": [
"CVE-2023-29597"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-13T14:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cvv-cxch-6c5q",
"modified": "2023-10-18T00:31:41Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22032"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22032"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5v2h-8g8q-mwmw",
"modified": "2023-10-18T00:31:40Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-18T00:31:40Z",
"aliases": [
"CVE-2023-22015"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22015"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgr2-322v-vgjm",
"modified": "2023-10-18T00:31:40Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-18T00:31:40Z",
"aliases": [
"CVE-2023-22028"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22028"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phr8-8r83-j89w",
"modified": "2023-10-19T06:30:23Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-19T06:30:23Z",
"aliases": [
"CVE-2023-5212"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T06:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppg6-248w-w8px",
"modified": "2023-10-18T00:31:40Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-18T00:31:40Z",
"aliases": [
"CVE-2023-22026"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22026"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v28w-vh2w-263g",
"modified": "2023-10-19T06:30:23Z",
"modified": "2023-12-22T21:30:21Z",
"published": "2023-10-19T06:30:23Z",
"aliases": [
"CVE-2023-5241"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T06:15:11Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w499-gpr6-v77v",
"modified": "2023-10-18T00:31:41Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-18T00:31:41Z",
"aliases": [
"CVE-2023-22059"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22059"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2023.html"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-17T22:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjgr-47gv-2g9p",
"modified": "2023-10-19T06:30:23Z",
"modified": "2023-12-22T21:30:20Z",
"published": "2023-10-19T06:30:23Z",
"aliases": [
"CVE-2023-5204"
@@ -42,7 +42,7 @@
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-19T06:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25x6-5f6g-h9pv",
"modified": "2023-12-19T21:32:20Z",
"modified": "2023-12-22T21:30:21Z",
"published": "2023-12-19T21:32:20Z",
"aliases": [
"CVE-2023-45105"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p37-96m9-9qq9",
"modified": "2023-12-22T21:30:23Z",
"published": "2023-12-22T21:30:23Z",
"aliases": [
"CVE-2023-51015"
],
"details": "TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the enable parameter of the setDmzCfg interface of the cstecgi .cgi",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51015"
},
{
"type": "WEB",
"url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setDmzCfg/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-22T19:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q65-8x4g-wppr",
"modified": "2023-12-21T00:30:24Z",
"modified": "2023-12-22T21:30:22Z",
"published": "2023-12-21T00:30:24Z",
"aliases": [
"CVE-2023-50990"
],
"details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-20T22:15:35Z"

Some files were not shown because too many files have changed in this diff Show More