From f20494de9cd36b8acef63fc80b08a9f8efb208af Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 22 Dec 2023 21:31:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-c35q-ffpf-5qpm.json | 4 ++ .../GHSA-cfc2-wr2v-gxm5.json | 4 ++ .../GHSA-rfq3-wpjh-ppvg.json | 65 +++++++++++++++++++ .../GHSA-636h-f5g9-p45x.json | 2 +- .../GHSA-fc5w-vwp8-7vm2.json | 2 +- .../GHSA-vg34-58mc-jr2w.json | 2 +- .../GHSA-f396-7w6f-w8qq.json | 3 +- .../GHSA-972p-jcp3-q2cv.json | 4 +- .../GHSA-w6h4-4gxw-xxg8.json | 4 +- .../GHSA-5cvv-cxch-6c5q.json | 8 ++- .../GHSA-5v2h-8g8q-mwmw.json | 8 ++- .../GHSA-cgr2-322v-vgjm.json | 8 ++- .../GHSA-phr8-8r83-j89w.json | 4 +- .../GHSA-ppg6-248w-w8px.json | 8 ++- .../GHSA-v28w-vh2w-263g.json | 4 +- .../GHSA-w499-gpr6-v77v.json | 8 ++- .../GHSA-xjgr-47gv-2g9p.json | 4 +- .../GHSA-25x6-5f6g-h9pv.json | 2 +- .../GHSA-2p37-96m9-9qq9.json | 35 ++++++++++ .../GHSA-2q65-8x4g-wppr.json | 11 ++-- .../GHSA-3cv7-mfff-4c27.json | 35 ++++++++++ .../GHSA-457r-86mp-h5w4.json | 35 ++++++++++ .../GHSA-4c5v-86xf-p6j6.json | 2 +- .../GHSA-5m24-g5mr-69cj.json | 35 ++++++++++ .../GHSA-8cvf-jqfj-79q8.json | 35 ++++++++++ .../GHSA-9f6c-6m59-979h.json | 35 ++++++++++ .../GHSA-9f9x-vfjh-3j83.json | 2 +- .../GHSA-9qq8-mmh8-945v.json | 35 ++++++++++ .../GHSA-c372-hwmc-mqg5.json | 54 +++++++++++++++ .../GHSA-c722-cx97-rp6v.json | 11 ++-- .../GHSA-cfr4-r47j-2q46.json | 38 +++++++++++ .../GHSA-gf9m-89mh-m8rh.json | 11 ++-- .../GHSA-h9m8-8h93-r67x.json | 43 ++++++++++++ .../GHSA-hj54-qg34-2jrm.json | 38 +++++++++++ .../GHSA-hj6m-wxm8-r5hg.json | 11 ++-- .../GHSA-hp25-42wp-6hqm.json | 35 ++++++++++ .../GHSA-hqhw-r7ww-86xw.json | 11 ++-- .../GHSA-hwfx-2cgg-ppq9.json | 38 +++++++++++ .../GHSA-j9r3-qr9f-mqgg.json | 35 ++++++++++ .../GHSA-jmmr-8jx7-f9wr.json | 35 ++++++++++ .../GHSA-m6gh-58ph-rm3q.json | 11 ++-- .../GHSA-mcx3-vm34-5q9w.json | 35 ++++++++++ .../GHSA-mhh9-22f6-qjjm.json | 4 +- .../GHSA-mv2c-c44v-x327.json | 35 ++++++++++ .../GHSA-pj43-x92m-gprh.json | 39 +++++++++++ .../GHSA-q7xw-xqp3-xj7j.json | 11 ++-- .../GHSA-qpx2-mjvq-cv4m.json | 11 ++-- .../GHSA-qq4c-662q-v7qj.json | 11 ++-- .../GHSA-r8ch-vw3q-8h8q.json | 11 ++-- .../GHSA-v5cv-j9qw-9f6c.json | 11 ++-- .../GHSA-vrcg-9jfv-rmqj.json | 2 +- .../GHSA-vww6-8734-frv4.json | 35 ++++++++++ .../GHSA-w33g-h324-x5g8.json | 35 ++++++++++ .../GHSA-wc2j-86rx-j339.json | 35 ++++++++++ .../GHSA-wcp8-4v73-rcc2.json | 2 +- .../GHSA-wmh6-wh26-4mj9.json | 2 +- .../GHSA-xx2v-j2rm-5c42.json | 35 ++++++++++ 57 files changed, 1013 insertions(+), 76 deletions(-) create mode 100644 advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json create mode 100644 advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json create mode 100644 advisories/unreviewed/2023/12/GHSA-3cv7-mfff-4c27/GHSA-3cv7-mfff-4c27.json create mode 100644 advisories/unreviewed/2023/12/GHSA-457r-86mp-h5w4/GHSA-457r-86mp-h5w4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json create mode 100644 advisories/unreviewed/2023/12/GHSA-8cvf-jqfj-79q8/GHSA-8cvf-jqfj-79q8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9f6c-6m59-979h/GHSA-9f6c-6m59-979h.json create mode 100644 advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json create mode 100644 advisories/unreviewed/2023/12/GHSA-c372-hwmc-mqg5/GHSA-c372-hwmc-mqg5.json create mode 100644 advisories/unreviewed/2023/12/GHSA-cfr4-r47j-2q46/GHSA-cfr4-r47j-2q46.json create mode 100644 advisories/unreviewed/2023/12/GHSA-h9m8-8h93-r67x/GHSA-h9m8-8h93-r67x.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hj54-qg34-2jrm/GHSA-hj54-qg34-2jrm.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hp25-42wp-6hqm/GHSA-hp25-42wp-6hqm.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hwfx-2cgg-ppq9/GHSA-hwfx-2cgg-ppq9.json create mode 100644 advisories/unreviewed/2023/12/GHSA-j9r3-qr9f-mqgg/GHSA-j9r3-qr9f-mqgg.json create mode 100644 advisories/unreviewed/2023/12/GHSA-jmmr-8jx7-f9wr/GHSA-jmmr-8jx7-f9wr.json create mode 100644 advisories/unreviewed/2023/12/GHSA-mcx3-vm34-5q9w/GHSA-mcx3-vm34-5q9w.json create mode 100644 advisories/unreviewed/2023/12/GHSA-mv2c-c44v-x327/GHSA-mv2c-c44v-x327.json create mode 100644 advisories/unreviewed/2023/12/GHSA-pj43-x92m-gprh/GHSA-pj43-x92m-gprh.json create mode 100644 advisories/unreviewed/2023/12/GHSA-vww6-8734-frv4/GHSA-vww6-8734-frv4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-w33g-h324-x5g8/GHSA-w33g-h324-x5g8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wc2j-86rx-j339/GHSA-wc2j-86rx-j339.json create mode 100644 advisories/unreviewed/2023/12/GHSA-xx2v-j2rm-5c42/GHSA-xx2v-j2rm-5c42.json diff --git a/advisories/github-reviewed/2023/11/GHSA-c35q-ffpf-5qpm/GHSA-c35q-ffpf-5qpm.json b/advisories/github-reviewed/2023/11/GHSA-c35q-ffpf-5qpm/GHSA-c35q-ffpf-5qpm.json index abde5077f20..89a81594a9c 100644 --- a/advisories/github-reviewed/2023/11/GHSA-c35q-ffpf-5qpm/GHSA-c35q-ffpf-5qpm.json +++ b/advisories/github-reviewed/2023/11/GHSA-c35q-ffpf-5qpm/GHSA-c35q-ffpf-5qpm.json @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ME34ROZWMDK5KLMZKTSA422XVJZ7IMTE/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231222-0001/" + }, { "type": "WEB", "url": "https://www.terrapin-attack.com" diff --git a/advisories/github-reviewed/2023/11/GHSA-cfc2-wr2v-gxm5/GHSA-cfc2-wr2v-gxm5.json b/advisories/github-reviewed/2023/11/GHSA-cfc2-wr2v-gxm5/GHSA-cfc2-wr2v-gxm5.json index 60240844d10..43fdbdcb1a1 100644 --- a/advisories/github-reviewed/2023/11/GHSA-cfc2-wr2v-gxm5/GHSA-cfc2-wr2v-gxm5.json +++ b/advisories/github-reviewed/2023/11/GHSA-cfc2-wr2v-gxm5/GHSA-cfc2-wr2v-gxm5.json @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ME34ROZWMDK5KLMZKTSA422XVJZ7IMTE/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231222-0001/" + }, { "type": "WEB", "url": "https://www.terrapin-attack.com" diff --git a/advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json b/advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json new file mode 100644 index 00000000000..cc2d1c736f3 --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfq3-wpjh-ppvg", + "modified": "2023-12-22T21:31:02Z", + "published": "2023-12-22T18:30:30Z", + "aliases": [ + "CVE-2023-6911" + ], + "summary": "WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability", + "details": "WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.wso2.carbon.registry:carbon-registry" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.7.37" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6911" + }, + { + "type": "WEB", + "url": "https://github.com/wso2/carbon-registry/commit/878fc7e53c90acc85e303d2af73440014a68b246" + }, + { + "type": "PACKAGE", + "url": "https://github.com/wso2/carbon-registry/" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-12-22T21:31:02Z", + "nvd_published_at": "2023-12-18T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-636h-f5g9-p45x/GHSA-636h-f5g9-p45x.json b/advisories/unreviewed/2022/05/GHSA-636h-f5g9-p45x/GHSA-636h-f5g9-p45x.json index 73196c4365c..4a4cf1eecca 100644 --- a/advisories/unreviewed/2022/05/GHSA-636h-f5g9-p45x/GHSA-636h-f5g9-p45x.json +++ b/advisories/unreviewed/2022/05/GHSA-636h-f5g9-p45x/GHSA-636h-f5g9-p45x.json @@ -157,7 +157,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-fc5w-vwp8-7vm2/GHSA-fc5w-vwp8-7vm2.json b/advisories/unreviewed/2022/05/GHSA-fc5w-vwp8-7vm2/GHSA-fc5w-vwp8-7vm2.json index 23ccbbefff5..880ae2eaca1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc5w-vwp8-7vm2/GHSA-fc5w-vwp8-7vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-fc5w-vwp8-7vm2/GHSA-fc5w-vwp8-7vm2.json @@ -53,7 +53,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vg34-58mc-jr2w/GHSA-vg34-58mc-jr2w.json b/advisories/unreviewed/2022/05/GHSA-vg34-58mc-jr2w/GHSA-vg34-58mc-jr2w.json index 1662a42b77b..9b9a80d68f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg34-58mc-jr2w/GHSA-vg34-58mc-jr2w.json +++ b/advisories/unreviewed/2022/05/GHSA-vg34-58mc-jr2w/GHSA-vg34-58mc-jr2w.json @@ -73,7 +73,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-193" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-f396-7w6f-w8qq/GHSA-f396-7w6f-w8qq.json b/advisories/unreviewed/2022/10/GHSA-f396-7w6f-w8qq/GHSA-f396-7w6f-w8qq.json index 2989a3f4b0c..4a8374135a6 100644 --- a/advisories/unreviewed/2022/10/GHSA-f396-7w6f-w8qq/GHSA-f396-7w6f-w8qq.json +++ b/advisories/unreviewed/2022/10/GHSA-f396-7w6f-w8qq/GHSA-f396-7w6f-w8qq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-972p-jcp3-q2cv/GHSA-972p-jcp3-q2cv.json b/advisories/unreviewed/2023/04/GHSA-972p-jcp3-q2cv/GHSA-972p-jcp3-q2cv.json index c468ff5d780..7e186d53da7 100644 --- a/advisories/unreviewed/2023/04/GHSA-972p-jcp3-q2cv/GHSA-972p-jcp3-q2cv.json +++ b/advisories/unreviewed/2023/04/GHSA-972p-jcp3-q2cv/GHSA-972p-jcp3-q2cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-972p-jcp3-q2cv", - "modified": "2023-04-21T06:30:17Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-04-13T15:30:35Z", "aliases": [ "CVE-2023-27812" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-13T14:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-w6h4-4gxw-xxg8/GHSA-w6h4-4gxw-xxg8.json b/advisories/unreviewed/2023/04/GHSA-w6h4-4gxw-xxg8/GHSA-w6h4-4gxw-xxg8.json index 8ad0d6ce8d5..f9b9aa24916 100644 --- a/advisories/unreviewed/2023/04/GHSA-w6h4-4gxw-xxg8/GHSA-w6h4-4gxw-xxg8.json +++ b/advisories/unreviewed/2023/04/GHSA-w6h4-4gxw-xxg8/GHSA-w6h4-4gxw-xxg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6h4-4gxw-xxg8", - "modified": "2023-04-21T18:30:24Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-04-13T15:30:35Z", "aliases": [ "CVE-2023-29597" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-13T14:15:00Z" diff --git a/advisories/unreviewed/2023/10/GHSA-5cvv-cxch-6c5q/GHSA-5cvv-cxch-6c5q.json b/advisories/unreviewed/2023/10/GHSA-5cvv-cxch-6c5q/GHSA-5cvv-cxch-6c5q.json index 62c8aca3e05..2e3064283b6 100644 --- a/advisories/unreviewed/2023/10/GHSA-5cvv-cxch-6c5q/GHSA-5cvv-cxch-6c5q.json +++ b/advisories/unreviewed/2023/10/GHSA-5cvv-cxch-6c5q/GHSA-5cvv-cxch-6c5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cvv-cxch-6c5q", - "modified": "2023-10-18T00:31:41Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-18T00:31:41Z", "aliases": [ "CVE-2023-22032" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22032" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0009/" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T22:15:12Z" diff --git a/advisories/unreviewed/2023/10/GHSA-5v2h-8g8q-mwmw/GHSA-5v2h-8g8q-mwmw.json b/advisories/unreviewed/2023/10/GHSA-5v2h-8g8q-mwmw/GHSA-5v2h-8g8q-mwmw.json index 9dac443c84b..a89d6fa2633 100644 --- a/advisories/unreviewed/2023/10/GHSA-5v2h-8g8q-mwmw/GHSA-5v2h-8g8q-mwmw.json +++ b/advisories/unreviewed/2023/10/GHSA-5v2h-8g8q-mwmw/GHSA-5v2h-8g8q-mwmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v2h-8g8q-mwmw", - "modified": "2023-10-18T00:31:40Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-18T00:31:40Z", "aliases": [ "CVE-2023-22015" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22015" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0009/" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T22:15:11Z" diff --git a/advisories/unreviewed/2023/10/GHSA-cgr2-322v-vgjm/GHSA-cgr2-322v-vgjm.json b/advisories/unreviewed/2023/10/GHSA-cgr2-322v-vgjm/GHSA-cgr2-322v-vgjm.json index 57bfb337d51..e75d67bef40 100644 --- a/advisories/unreviewed/2023/10/GHSA-cgr2-322v-vgjm/GHSA-cgr2-322v-vgjm.json +++ b/advisories/unreviewed/2023/10/GHSA-cgr2-322v-vgjm/GHSA-cgr2-322v-vgjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgr2-322v-vgjm", - "modified": "2023-10-18T00:31:40Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-18T00:31:40Z", "aliases": [ "CVE-2023-22028" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22028" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0009/" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T22:15:12Z" diff --git a/advisories/unreviewed/2023/10/GHSA-phr8-8r83-j89w/GHSA-phr8-8r83-j89w.json b/advisories/unreviewed/2023/10/GHSA-phr8-8r83-j89w/GHSA-phr8-8r83-j89w.json index d72ef01b65c..67ac6950d47 100644 --- a/advisories/unreviewed/2023/10/GHSA-phr8-8r83-j89w/GHSA-phr8-8r83-j89w.json +++ b/advisories/unreviewed/2023/10/GHSA-phr8-8r83-j89w/GHSA-phr8-8r83-j89w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phr8-8r83-j89w", - "modified": "2023-10-19T06:30:23Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-19T06:30:23Z", "aliases": [ "CVE-2023-5212" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-19T06:15:11Z" diff --git a/advisories/unreviewed/2023/10/GHSA-ppg6-248w-w8px/GHSA-ppg6-248w-w8px.json b/advisories/unreviewed/2023/10/GHSA-ppg6-248w-w8px/GHSA-ppg6-248w-w8px.json index 9f31e73d285..2dbb391537e 100644 --- a/advisories/unreviewed/2023/10/GHSA-ppg6-248w-w8px/GHSA-ppg6-248w-w8px.json +++ b/advisories/unreviewed/2023/10/GHSA-ppg6-248w-w8px/GHSA-ppg6-248w-w8px.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppg6-248w-w8px", - "modified": "2023-10-18T00:31:40Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-18T00:31:40Z", "aliases": [ "CVE-2023-22026" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22026" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0009/" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T22:15:11Z" diff --git a/advisories/unreviewed/2023/10/GHSA-v28w-vh2w-263g/GHSA-v28w-vh2w-263g.json b/advisories/unreviewed/2023/10/GHSA-v28w-vh2w-263g/GHSA-v28w-vh2w-263g.json index b9dded381e1..f889075fdfd 100644 --- a/advisories/unreviewed/2023/10/GHSA-v28w-vh2w-263g/GHSA-v28w-vh2w-263g.json +++ b/advisories/unreviewed/2023/10/GHSA-v28w-vh2w-263g/GHSA-v28w-vh2w-263g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v28w-vh2w-263g", - "modified": "2023-10-19T06:30:23Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-10-19T06:30:23Z", "aliases": [ "CVE-2023-5241" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-19T06:15:11Z" diff --git a/advisories/unreviewed/2023/10/GHSA-w499-gpr6-v77v/GHSA-w499-gpr6-v77v.json b/advisories/unreviewed/2023/10/GHSA-w499-gpr6-v77v/GHSA-w499-gpr6-v77v.json index dece4c8875b..ca6ee3f95c6 100644 --- a/advisories/unreviewed/2023/10/GHSA-w499-gpr6-v77v/GHSA-w499-gpr6-v77v.json +++ b/advisories/unreviewed/2023/10/GHSA-w499-gpr6-v77v/GHSA-w499-gpr6-v77v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w499-gpr6-v77v", - "modified": "2023-10-18T00:31:41Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-18T00:31:41Z", "aliases": [ "CVE-2023-22059" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22059" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0009/" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-17T22:15:12Z" diff --git a/advisories/unreviewed/2023/10/GHSA-xjgr-47gv-2g9p/GHSA-xjgr-47gv-2g9p.json b/advisories/unreviewed/2023/10/GHSA-xjgr-47gv-2g9p/GHSA-xjgr-47gv-2g9p.json index 6ea7ac9b81a..f5c5d0317c4 100644 --- a/advisories/unreviewed/2023/10/GHSA-xjgr-47gv-2g9p/GHSA-xjgr-47gv-2g9p.json +++ b/advisories/unreviewed/2023/10/GHSA-xjgr-47gv-2g9p/GHSA-xjgr-47gv-2g9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjgr-47gv-2g9p", - "modified": "2023-10-19T06:30:23Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-10-19T06:30:23Z", "aliases": [ "CVE-2023-5204" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-19T06:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-25x6-5f6g-h9pv/GHSA-25x6-5f6g-h9pv.json b/advisories/unreviewed/2023/12/GHSA-25x6-5f6g-h9pv/GHSA-25x6-5f6g-h9pv.json index 6567ca7b39a..c1f654b8d3f 100644 --- a/advisories/unreviewed/2023/12/GHSA-25x6-5f6g-h9pv/GHSA-25x6-5f6g-h9pv.json +++ b/advisories/unreviewed/2023/12/GHSA-25x6-5f6g-h9pv/GHSA-25x6-5f6g-h9pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25x6-5f6g-h9pv", - "modified": "2023-12-19T21:32:20Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-19T21:32:20Z", "aliases": [ "CVE-2023-45105" diff --git a/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json b/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json new file mode 100644 index 00000000000..1887a51215d --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p37-96m9-9qq9", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-51015" + ], + "details": "TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51015" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setDmzCfg/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2q65-8x4g-wppr/GHSA-2q65-8x4g-wppr.json b/advisories/unreviewed/2023/12/GHSA-2q65-8x4g-wppr/GHSA-2q65-8x4g-wppr.json index 6139b6241c9..509e6190ca7 100644 --- a/advisories/unreviewed/2023/12/GHSA-2q65-8x4g-wppr/GHSA-2q65-8x4g-wppr.json +++ b/advisories/unreviewed/2023/12/GHSA-2q65-8x4g-wppr/GHSA-2q65-8x4g-wppr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2q65-8x4g-wppr", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50990" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:35Z" diff --git a/advisories/unreviewed/2023/12/GHSA-3cv7-mfff-4c27/GHSA-3cv7-mfff-4c27.json b/advisories/unreviewed/2023/12/GHSA-3cv7-mfff-4c27/GHSA-3cv7-mfff-4c27.json new file mode 100644 index 00000000000..220f0a430bf --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-3cv7-mfff-4c27/GHSA-3cv7-mfff-4c27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cv7-mfff-4c27", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51021" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51021" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B20220316setRptWizardCfg-merge/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-457r-86mp-h5w4/GHSA-457r-86mp-h5w4.json b/advisories/unreviewed/2023/12/GHSA-457r-86mp-h5w4/GHSA-457r-86mp-h5w4.json new file mode 100644 index 00000000000..a1e31a9da3e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-457r-86mp-h5w4/GHSA-457r-86mp-h5w4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-457r-86mp-h5w4", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51022" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51022" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/3/TOTOlinkEX1800T_V9.1.0cu.2112_B20220316setLanguageCfg-langFlag/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json b/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json index 2b569423314..532b63f14d9 100644 --- a/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json +++ b/advisories/unreviewed/2023/12/GHSA-4c5v-86xf-p6j6/GHSA-4c5v-86xf-p6j6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json b/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json new file mode 100644 index 00000000000..e10d6c565e3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-5m24-g5mr-69cj/GHSA-5m24-g5mr-69cj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m24-g5mr-69cj", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-51014" + ], + "details": "TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51014" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setLanConfig_lanSecDns/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8cvf-jqfj-79q8/GHSA-8cvf-jqfj-79q8.json b/advisories/unreviewed/2023/12/GHSA-8cvf-jqfj-79q8/GHSA-8cvf-jqfj-79q8.json new file mode 100644 index 00000000000..054ef2ff2a2 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8cvf-jqfj-79q8/GHSA-8cvf-jqfj-79q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cvf-jqfj-79q8", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51020" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51020" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B20220316setLanguageCfg-langType/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9f6c-6m59-979h/GHSA-9f6c-6m59-979h.json b/advisories/unreviewed/2023/12/GHSA-9f6c-6m59-979h/GHSA-9f6c-6m59-979h.json new file mode 100644 index 00000000000..2838eb7bfc9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9f6c-6m59-979h/GHSA-9f6c-6m59-979h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f6c-6m59-979h", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-50147" + ], + "details": "There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50147" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/04/a3700r/TOTOlink%20A3700R%28setDiagnosisCfg%29/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9f9x-vfjh-3j83/GHSA-9f9x-vfjh-3j83.json b/advisories/unreviewed/2023/12/GHSA-9f9x-vfjh-3j83/GHSA-9f9x-vfjh-3j83.json index d9df87f75f6..bb8fabbddd6 100644 --- a/advisories/unreviewed/2023/12/GHSA-9f9x-vfjh-3j83/GHSA-9f9x-vfjh-3j83.json +++ b/advisories/unreviewed/2023/12/GHSA-9f9x-vfjh-3j83/GHSA-9f9x-vfjh-3j83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f9x-vfjh-3j83", - "modified": "2023-12-19T00:30:21Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-19T00:30:21Z", "aliases": [ "CVE-2023-46154" diff --git a/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json b/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json new file mode 100644 index 00000000000..d7ca1dab411 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qq8-mmh8-945v", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51018" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51018" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setWiFiApConfig-opmode/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c372-hwmc-mqg5/GHSA-c372-hwmc-mqg5.json b/advisories/unreviewed/2023/12/GHSA-c372-hwmc-mqg5/GHSA-c372-hwmc-mqg5.json new file mode 100644 index 00000000000..b417a3d5651 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c372-hwmc-mqg5/GHSA-c372-hwmc-mqg5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c372-hwmc-mqg5", + "modified": "2023-12-22T21:30:20Z", + "published": "2023-12-22T21:30:20Z", + "aliases": [ + "CVE-2023-6908" + ], + "details": "A vulnerability, which was classified as problematic, was found in DFIRKuiper Kuiper 2.3.4. This affects the function unzip_file of the file kuiper/app/controllers/case_management.py of the component TAR Archive Handler. The manipulation of the argument dst_path leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.3.5 is able to address this issue. The identifier of the patch is 94fa135153002f651f5526c55a7240e083db8d73. It is recommended to upgrade the affected component. The identifier VDB-248277 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6908" + }, + { + "type": "WEB", + "url": "https://github.com/DFIRKuiper/Kuiper/pull/106" + }, + { + "type": "WEB", + "url": "https://github.com/DFIRKuiper/Kuiper/commit/94fa135153002f651f5526c55a7240e083db8d73" + }, + { + "type": "WEB", + "url": "https://github.com/DFIRKuiper/Kuiper/releases/tag/v2.3.5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.248277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.248277" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T04:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c722-cx97-rp6v/GHSA-c722-cx97-rp6v.json b/advisories/unreviewed/2023/12/GHSA-c722-cx97-rp6v/GHSA-c722-cx97-rp6v.json index a083456f847..1cec6a53e26 100644 --- a/advisories/unreviewed/2023/12/GHSA-c722-cx97-rp6v/GHSA-c722-cx97-rp6v.json +++ b/advisories/unreviewed/2023/12/GHSA-c722-cx97-rp6v/GHSA-c722-cx97-rp6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c722-cx97-rp6v", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50988" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:35Z" diff --git a/advisories/unreviewed/2023/12/GHSA-cfr4-r47j-2q46/GHSA-cfr4-r47j-2q46.json b/advisories/unreviewed/2023/12/GHSA-cfr4-r47j-2q46/GHSA-cfr4-r47j-2q46.json new file mode 100644 index 00000000000..c4b0ecc4237 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-cfr4-r47j-2q46/GHSA-cfr4-r47j-2q46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfr4-r47j-2q46", + "modified": "2023-12-22T21:30:21Z", + "published": "2023-12-22T21:30:21Z", + "aliases": [ + "CVE-2023-32230" + ], + "details": "An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32230" + }, + { + "type": "WEB", + "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gf9m-89mh-m8rh/GHSA-gf9m-89mh-m8rh.json b/advisories/unreviewed/2023/12/GHSA-gf9m-89mh-m8rh/GHSA-gf9m-89mh-m8rh.json index abbf3d4c41c..a33d9821976 100644 --- a/advisories/unreviewed/2023/12/GHSA-gf9m-89mh-m8rh/GHSA-gf9m-89mh-m8rh.json +++ b/advisories/unreviewed/2023/12/GHSA-gf9m-89mh-m8rh/GHSA-gf9m-89mh-m8rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf9m-89mh-m8rh", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50992" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:35Z" diff --git a/advisories/unreviewed/2023/12/GHSA-h9m8-8h93-r67x/GHSA-h9m8-8h93-r67x.json b/advisories/unreviewed/2023/12/GHSA-h9m8-8h93-r67x/GHSA-h9m8-8h93-r67x.json new file mode 100644 index 00000000000..7b613c88d3b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-h9m8-8h93-r67x/GHSA-h9m8-8h93-r67x.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9m8-8h93-r67x", + "modified": "2023-12-22T21:30:21Z", + "published": "2023-12-22T21:30:21Z", + "aliases": [ + "CVE-2023-3430" + ], + "details": "A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3430" + }, + { + "type": "WEB", + "url": "https://github.com/AcademySoftwareFoundation/OpenImageIO/issues/3840" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2218380" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122", + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hj54-qg34-2jrm/GHSA-hj54-qg34-2jrm.json b/advisories/unreviewed/2023/12/GHSA-hj54-qg34-2jrm/GHSA-hj54-qg34-2jrm.json new file mode 100644 index 00000000000..9b9afba0dfb --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hj54-qg34-2jrm/GHSA-hj54-qg34-2jrm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj54-qg34-2jrm", + "modified": "2023-12-22T21:30:21Z", + "published": "2023-12-22T21:30:21Z", + "aliases": [ + "CVE-2023-35867" + ], + "details": "An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35867" + }, + { + "type": "WEB", + "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hj6m-wxm8-r5hg/GHSA-hj6m-wxm8-r5hg.json b/advisories/unreviewed/2023/12/GHSA-hj6m-wxm8-r5hg/GHSA-hj6m-wxm8-r5hg.json index d1ee39a4269..05b236a9799 100644 --- a/advisories/unreviewed/2023/12/GHSA-hj6m-wxm8-r5hg/GHSA-hj6m-wxm8-r5hg.json +++ b/advisories/unreviewed/2023/12/GHSA-hj6m-wxm8-r5hg/GHSA-hj6m-wxm8-r5hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hj6m-wxm8-r5hg", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50984" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:34Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hp25-42wp-6hqm/GHSA-hp25-42wp-6hqm.json b/advisories/unreviewed/2023/12/GHSA-hp25-42wp-6hqm/GHSA-hp25-42wp-6hqm.json new file mode 100644 index 00000000000..3d75580b51e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hp25-42wp-6hqm/GHSA-hp25-42wp-6hqm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp25-42wp-6hqm", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51016" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51016" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/10/EX1800T/TOTOlink%20EX1800T_V9.1.0cu.2112_B20220316%28setRebootScheCfg%29/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json b/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json index c4b247b1fcd..64ad2ad0f96 100644 --- a/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json +++ b/advisories/unreviewed/2023/12/GHSA-hqhw-r7ww-86xw/GHSA-hqhw-r7ww-86xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hqhw-r7ww-86xw", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50986" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:34Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hwfx-2cgg-ppq9/GHSA-hwfx-2cgg-ppq9.json b/advisories/unreviewed/2023/12/GHSA-hwfx-2cgg-ppq9/GHSA-hwfx-2cgg-ppq9.json new file mode 100644 index 00000000000..a6d3678f4ab --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hwfx-2cgg-ppq9/GHSA-hwfx-2cgg-ppq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwfx-2cgg-ppq9", + "modified": "2023-12-22T21:30:21Z", + "published": "2023-12-22T21:30:21Z", + "aliases": [ + "CVE-2022-41677" + ], + "details": "An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41677" + }, + { + "type": "WEB", + "url": "https://psirt.bosch.com/security-advisories/bosch-sa-839739-BT.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-j9r3-qr9f-mqgg/GHSA-j9r3-qr9f-mqgg.json b/advisories/unreviewed/2023/12/GHSA-j9r3-qr9f-mqgg/GHSA-j9r3-qr9f-mqgg.json new file mode 100644 index 00000000000..54e3f396837 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-j9r3-qr9f-mqgg/GHSA-j9r3-qr9f-mqgg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9r3-qr9f-mqgg", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51033" + ], + "details": "TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51033" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/12/ex1200l/totolink_ex1200L_setOpModeCfg/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jmmr-8jx7-f9wr/GHSA-jmmr-8jx7-f9wr.json b/advisories/unreviewed/2023/12/GHSA-jmmr-8jx7-f9wr/GHSA-jmmr-8jx7-f9wr.json new file mode 100644 index 00000000000..572ba7c654d --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-jmmr-8jx7-f9wr/GHSA-jmmr-8jx7-f9wr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmmr-8jx7-f9wr", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-51012" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51012" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setLanConfig-lanGateway/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json b/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json index 41b8da5fc1c..e135fe9fbd8 100644 --- a/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json +++ b/advisories/unreviewed/2023/12/GHSA-m6gh-58ph-rm3q/GHSA-m6gh-58ph-rm3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6gh-58ph-rm3q", - "modified": "2023-12-18T21:30:28Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-18T21:30:28Z", "aliases": [ "CVE-2023-6272" ], "details": "The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-18T20:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mcx3-vm34-5q9w/GHSA-mcx3-vm34-5q9w.json b/advisories/unreviewed/2023/12/GHSA-mcx3-vm34-5q9w/GHSA-mcx3-vm34-5q9w.json new file mode 100644 index 00000000000..8fc37acbe60 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mcx3-vm34-5q9w/GHSA-mcx3-vm34-5q9w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcx3-vm34-5q9w", + "modified": "2023-12-22T21:30:25Z", + "published": "2023-12-22T21:30:25Z", + "aliases": [ + "CVE-2023-51034" + ], + "details": "TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51034" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/12/ex1200l/totolink_ex1200L_UploadFirmwareFile/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-mhh9-22f6-qjjm/GHSA-mhh9-22f6-qjjm.json b/advisories/unreviewed/2023/12/GHSA-mhh9-22f6-qjjm/GHSA-mhh9-22f6-qjjm.json index 5138dad0389..484c08f335e 100644 --- a/advisories/unreviewed/2023/12/GHSA-mhh9-22f6-qjjm/GHSA-mhh9-22f6-qjjm.json +++ b/advisories/unreviewed/2023/12/GHSA-mhh9-22f6-qjjm/GHSA-mhh9-22f6-qjjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhh9-22f6-qjjm", - "modified": "2023-12-19T03:30:17Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-19T03:30:17Z", "aliases": [ "CVE-2023-6488" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-mv2c-c44v-x327/GHSA-mv2c-c44v-x327.json b/advisories/unreviewed/2023/12/GHSA-mv2c-c44v-x327/GHSA-mv2c-c44v-x327.json new file mode 100644 index 00000000000..61c08e873cb --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mv2c-c44v-x327/GHSA-mv2c-c44v-x327.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv2c-c44v-x327", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-51011" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51011" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setLanConfig-lanPriDns/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-pj43-x92m-gprh/GHSA-pj43-x92m-gprh.json b/advisories/unreviewed/2023/12/GHSA-pj43-x92m-gprh/GHSA-pj43-x92m-gprh.json new file mode 100644 index 00000000000..7e7771cb8a7 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-pj43-x92m-gprh/GHSA-pj43-x92m-gprh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj43-x92m-gprh", + "modified": "2023-12-22T21:30:21Z", + "published": "2023-12-22T21:30:21Z", + "aliases": [ + "CVE-2023-39509" + ], + "details": "A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39509" + }, + { + "type": "WEB", + "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-638184-BT.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20", + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-18T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q7xw-xqp3-xj7j/GHSA-q7xw-xqp3-xj7j.json b/advisories/unreviewed/2023/12/GHSA-q7xw-xqp3-xj7j/GHSA-q7xw-xqp3-xj7j.json index 183c676e187..8c9ff4265cf 100644 --- a/advisories/unreviewed/2023/12/GHSA-q7xw-xqp3-xj7j/GHSA-q7xw-xqp3-xj7j.json +++ b/advisories/unreviewed/2023/12/GHSA-q7xw-xqp3-xj7j/GHSA-q7xw-xqp3-xj7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7xw-xqp3-xj7j", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50989" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:35Z" diff --git a/advisories/unreviewed/2023/12/GHSA-qpx2-mjvq-cv4m/GHSA-qpx2-mjvq-cv4m.json b/advisories/unreviewed/2023/12/GHSA-qpx2-mjvq-cv4m/GHSA-qpx2-mjvq-cv4m.json index ff90d0c170d..c1d580742a3 100644 --- a/advisories/unreviewed/2023/12/GHSA-qpx2-mjvq-cv4m/GHSA-qpx2-mjvq-cv4m.json +++ b/advisories/unreviewed/2023/12/GHSA-qpx2-mjvq-cv4m/GHSA-qpx2-mjvq-cv4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpx2-mjvq-cv4m", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50985" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:34Z" diff --git a/advisories/unreviewed/2023/12/GHSA-qq4c-662q-v7qj/GHSA-qq4c-662q-v7qj.json b/advisories/unreviewed/2023/12/GHSA-qq4c-662q-v7qj/GHSA-qq4c-662q-v7qj.json index b55f637b1b3..4fe26a082bb 100644 --- a/advisories/unreviewed/2023/12/GHSA-qq4c-662q-v7qj/GHSA-qq4c-662q-v7qj.json +++ b/advisories/unreviewed/2023/12/GHSA-qq4c-662q-v7qj/GHSA-qq4c-662q-v7qj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qq4c-662q-v7qj", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:21Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50983" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:34Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r8ch-vw3q-8h8q/GHSA-r8ch-vw3q-8h8q.json b/advisories/unreviewed/2023/12/GHSA-r8ch-vw3q-8h8q/GHSA-r8ch-vw3q-8h8q.json index 7e36376f42c..6f85012aabf 100644 --- a/advisories/unreviewed/2023/12/GHSA-r8ch-vw3q-8h8q/GHSA-r8ch-vw3q-8h8q.json +++ b/advisories/unreviewed/2023/12/GHSA-r8ch-vw3q-8h8q/GHSA-r8ch-vw3q-8h8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8ch-vw3q-8h8q", - "modified": "2023-12-21T00:30:24Z", + "modified": "2023-12-22T21:30:22Z", "published": "2023-12-21T00:30:24Z", "aliases": [ "CVE-2023-50987" ], "details": "Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T22:15:34Z" diff --git a/advisories/unreviewed/2023/12/GHSA-v5cv-j9qw-9f6c/GHSA-v5cv-j9qw-9f6c.json b/advisories/unreviewed/2023/12/GHSA-v5cv-j9qw-9f6c/GHSA-v5cv-j9qw-9f6c.json index ca09af10050..af9014f53de 100644 --- a/advisories/unreviewed/2023/12/GHSA-v5cv-j9qw-9f6c/GHSA-v5cv-j9qw-9f6c.json +++ b/advisories/unreviewed/2023/12/GHSA-v5cv-j9qw-9f6c/GHSA-v5cv-j9qw-9f6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5cv-j9qw-9f6c", - "modified": "2023-12-18T00:30:23Z", + "modified": "2023-12-22T21:30:20Z", "published": "2023-12-18T00:30:23Z", "aliases": [ "CVE-2023-50976" ], "details": "Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-18T00:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vrcg-9jfv-rmqj/GHSA-vrcg-9jfv-rmqj.json b/advisories/unreviewed/2023/12/GHSA-vrcg-9jfv-rmqj/GHSA-vrcg-9jfv-rmqj.json index 7e156514657..a8376c7215e 100644 --- a/advisories/unreviewed/2023/12/GHSA-vrcg-9jfv-rmqj/GHSA-vrcg-9jfv-rmqj.json +++ b/advisories/unreviewed/2023/12/GHSA-vrcg-9jfv-rmqj/GHSA-vrcg-9jfv-rmqj.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-vww6-8734-frv4/GHSA-vww6-8734-frv4.json b/advisories/unreviewed/2023/12/GHSA-vww6-8734-frv4/GHSA-vww6-8734-frv4.json new file mode 100644 index 00000000000..3c58b0fa757 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vww6-8734-frv4/GHSA-vww6-8734-frv4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vww6-8734-frv4", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51019" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51019" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/2/TOTOlinkEX1800T_V9.1.0cu.2112_B20220316setWiFiExtenderConfig-key5g/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-w33g-h324-x5g8/GHSA-w33g-h324-x5g8.json b/advisories/unreviewed/2023/12/GHSA-w33g-h324-x5g8/GHSA-w33g-h324-x5g8.json new file mode 100644 index 00000000000..9d96841c27a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-w33g-h324-x5g8/GHSA-w33g-h324-x5g8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w33g-h324-x5g8", + "modified": "2023-12-22T21:30:23Z", + "published": "2023-12-22T21:30:23Z", + "aliases": [ + "CVE-2023-51013" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51013" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setLanConfig-lanNetmask/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wc2j-86rx-j339/GHSA-wc2j-86rx-j339.json b/advisories/unreviewed/2023/12/GHSA-wc2j-86rx-j339/GHSA-wc2j-86rx-j339.json new file mode 100644 index 00000000000..7798664b953 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wc2j-86rx-j339/GHSA-wc2j-86rx-j339.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc2j-86rx-j339", + "modified": "2023-12-22T21:30:25Z", + "published": "2023-12-22T21:30:25Z", + "aliases": [ + "CVE-2023-51035" + ], + "details": "TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51035" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/12/ex1200l/totolink_ex1200L_NTPSyncWithHost/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wcp8-4v73-rcc2/GHSA-wcp8-4v73-rcc2.json b/advisories/unreviewed/2023/12/GHSA-wcp8-4v73-rcc2/GHSA-wcp8-4v73-rcc2.json index acd35a9302a..0780141405a 100644 --- a/advisories/unreviewed/2023/12/GHSA-wcp8-4v73-rcc2/GHSA-wcp8-4v73-rcc2.json +++ b/advisories/unreviewed/2023/12/GHSA-wcp8-4v73-rcc2/GHSA-wcp8-4v73-rcc2.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json b/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json index fa257780d47..5c14a8f185c 100644 --- a/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json +++ b/advisories/unreviewed/2023/12/GHSA-wmh6-wh26-4mj9/GHSA-wmh6-wh26-4mj9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-xx2v-j2rm-5c42/GHSA-xx2v-j2rm-5c42.json b/advisories/unreviewed/2023/12/GHSA-xx2v-j2rm-5c42/GHSA-xx2v-j2rm-5c42.json new file mode 100644 index 00000000000..b5068461a9e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xx2v-j2rm-5c42/GHSA-xx2v-j2rm-5c42.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx2v-j2rm-5c42", + "modified": "2023-12-22T21:30:24Z", + "published": "2023-12-22T21:30:24Z", + "aliases": [ + "CVE-2023-51017" + ], + "details": "TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51017" + }, + { + "type": "WEB", + "url": "https://815yang.github.io/2023/12/11/EX1800T/TOTOlinkEX1800T_V9.1.0cu.2112_B2022031setLanConfig-lanIp/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-22T19:15:09Z" + } +} \ No newline at end of file