Publish Advisories

GHSA-4794-756c-cx7v
GHSA-cr44-jj23-rv3c
GHSA-f88f-9mmf-7xm6
This commit is contained in:
advisory-database[bot]
2023-05-22 12:31:38 +00:00
parent a3adada3e3
commit f4f9c69506
3 changed files with 118 additions and 0 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4794-756c-cx7v",
"modified": "2023-05-22T12:30:25Z",
"published": "2023-05-22T12:30:25Z",
"aliases": [
"CVE-2023-2597"
],
"details": "In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2597"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-openj9/openj9/pull/17259"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr44-jj23-rv3c",
"modified": "2023-05-22T12:30:25Z",
"published": "2023-05-22T12:30:25Z",
"aliases": [
"CVE-2023-2832"
],
"details": " SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2832"
},
{
"type": "WEB",
"url": "https://github.com/unilogies/bumsys/commit/1b426f58a513194206d0ea8ab58baf1461e54978"
},
{
"type": "WEB",
"url": "https://huntr.dev/bounties/37b80402-0edf-4f26-a668-b6f8b48dcdfb"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f88f-9mmf-7xm6",
"modified": "2023-05-22T12:30:25Z",
"published": "2023-05-22T12:30:25Z",
"aliases": [
"CVE-2023-25537"
],
"details": "\nDell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25537"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000213550/dsa-2023-098-security-update-for-dell-poweredge-14g-server-bios-for-an-out-of-bounds-write-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}